PoC to demonstrate root permission hijacking by exploiting “systemd-run”

https://twitter.com/hackerfantastic/status/1785495587514638559
{
"by": "mariuz",
"descendants": 19,
"id": 40247399,
"kids": [
40247802,
40247788,
40248293,
40248244,
40254216,
40258100,
40258711,
40247771
],
"score": 31,
"time": 1714742639,
"title": "PoC to demonstrate root permission hijacking by exploiting “systemd-run”",
"type": "story",
"url": "https://twitter.com/hackerfantastic/status/1785495587514638559"
}
{
"author": null,
"date": "2024-05-01T02:24:55.000Z",
"description": "Lennart Poettering intends to replace “sudo” with systemd’s run0. Here’s a quick PoC to demonstrate root permission hijacking by exploiting the fact “systemd-run” (the basis of uid0/run0, the sudo replacer) creates a user owned pty for communication with the new “root” process. https://t.co/yS2lB7wrE0",
"image": "https://pbs.twimg.com/media/GMdanXOWkAAwG4K.png:large",
"logo": null,
"publisher": "Twitter",
"title": "hacker.house (@hackerfantastic) on X",
"url": "https://x.com/hackerfantastic/status/1785495587514638559"
}
null