PoC to demonstrate root permission hijacking by exploiting “systemd-run”

https://twitter.com/hackerfantastic/status/1785495587514638559

user avatar

This isn't the only bug of course, it's not possible on Linux to read the environment of a root owned process but as systemd creates a service in the system slice, you can query D-BUS and learn sensitive information passed to the process env, such as API keys or other secrets.

user avatar

I have only spent a little bit of time digging through the new implementation, I do not see how it is "safer" or more "secure" than existing SUID "sudo" or "su" implementations. It certainly seems to add additional attack surface to Linux as every sudo command is a service.

user avatar

The exploit above works by hijacking the master end of the pty from the process which is communicating with the root process, it uses "reptyr" - a tool for doing these attacks which were common on UNIX in the 90's. This is just quick demo to highlight replacing sudo ends poorly.

user avatar

"systemd-run --pipe" will reuse your user owned pty with the root process and "systemd-run --pty" will create a new root-owned one but root terminal still accessible through the local user pty. Ptrace used for PoC only to hijack the tty fully. tty/sys gid are not required.

{
"by": "mariuz",
"descendants": 19,
"id": 40247399,
"kids": [
40247802,
40247788,
40248293,
40248244,
40254216,
40258100,
40258711,
40247771
],
"score": 31,
"time": 1714742639,
"title": "PoC to demonstrate root permission hijacking by exploiting “systemd-run”",
"type": "story",
"url": "https://twitter.com/hackerfantastic/status/1785495587514638559"
}
{
"author": null,
"date": "2024-05-01T02:24:55.000Z",
"description": "Lennart Poettering intends to replace “sudo” with systemd’s run0. Here’s a quick PoC to demonstrate root permission hijacking by exploiting the fact “systemd-run” (the basis of uid0/run0, the sudo replacer) creates a user owned pty for communication with the new “root” process.",
"image": "https://pbs.twimg.com/media/GMdanXOWkAAwG4K.png:large",
"logo": null,
"publisher": "Twitter",
"title": "hacker.house (@hackerfantastic) on X",
"url": "https://x.com/hackerfantastic/status/1785495587514638559"
}
{
"url": "https://twitter.com/hackerfantastic/status/1785495587514638559",
"title": "hacker.house (@hackerfantastic) on X",
"description": "This isn't the only bug of course, it's not possible on Linux to read the environment of a root owned process but as systemd creates a service in the system slice, you can query D-BUS and learn sensitive...",
"links": [
"https://x.com/hackerfantastic/status/1785495587514638559",
"https://twitter.com/hackerfantastic/status/1785495587514638559"
],
"image": "https://pbs.twimg.com/profile_images/1693092951029600256/9mZ-UZ99_normal.png",
"content": "<div><div><article><div><div><a target=\"_blank\" href=\"https://twitter.com/hackerfantastic\"><p><img alt=\"user avatar\" src=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png\" srcset=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__mini.png 24w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png 48w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__bigger.png 73w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__x96.png 96w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__reasonably_small.png 128w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__200x200.png 200w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__400x400.png 400w\" /></p></a></div><div><p><span>This isn't the only bug of course, it's not possible on Linux to read the environment of a root owned process but as systemd creates a service in the system slice, you can query D-BUS and learn sensitive information passed to the process env, such as API keys or other secrets.</span></p></div></div></article></div><div><article><div><div><a target=\"_blank\" href=\"https://twitter.com/hackerfantastic\"><p><img alt=\"user avatar\" src=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png\" srcset=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__mini.png 24w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png 48w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__bigger.png 73w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__x96.png 96w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__reasonably_small.png 128w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__200x200.png 200w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__400x400.png 400w\" /></p></a></div><div><p><span>I have only spent a little bit of time digging through the new implementation, I do not see how it is \"safer\" or more \"secure\" than existing SUID \"sudo\" or \"su\" implementations. It certainly seems to add additional attack surface to Linux as every sudo command is a service.</span></p></div></div></article></div><div><article><div><div><a target=\"_blank\" href=\"https://twitter.com/hackerfantastic\"><p><img alt=\"user avatar\" src=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png\" srcset=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__mini.png 24w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png 48w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__bigger.png 73w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__x96.png 96w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__reasonably_small.png 128w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__200x200.png 200w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__400x400.png 400w\" /></p></a></div><div><p><span>The exploit above works by hijacking the master end of the pty from the process which is communicating with the root process, it uses \"reptyr\" - a tool for doing these attacks which were common on UNIX in the 90's. This is just quick demo to highlight replacing sudo ends poorly.</span></p></div></div></article></div><div><article><div><div><a target=\"_blank\" href=\"https://twitter.com/hackerfantastic\"><p><img alt=\"user avatar\" src=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png\" srcset=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__mini.png 24w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png 48w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__bigger.png 73w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__x96.png 96w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__reasonably_small.png 128w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__200x200.png 200w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__400x400.png 400w\" /></p></a></div><div><p><span>\"systemd-run --pipe\" will reuse your user owned pty with the root process and \"systemd-run --pty\" will create a new root-owned one but root terminal still accessible through the local user pty. Ptrace used for PoC only to hijack the tty fully. tty/sys gid are not required.</span></p></div></div></article></div></div>",
"author": "@hackerfantastic",
"favicon": "https://twitter.com/favicon.ico",
"source": "twitter.com",
"published": "2024-05-01T02:27:34.000Z",
"ttr": 39,
"type": "article"
}