Earlier quoted context omitted.
I don't understand what you're implying. This is a 0day that could be exploited from any number of outside channels.
Go ahead and give us an example.
OS X 10.10.5 kernel local privilege escalation
21–30 of 143 posts
Re: OS X 10.10.5 kernel local privilege escalation
#22Re: OS X 10.10.5 kernel local privilege escalation
#23Earlier quoted context omitted.
Nice to see a 100% working widely exploitable 0day without any caveats that make it not real-world applicable. Local, so you need a non-admin account on the box which is kinda hard.
I don't understand what you're implying. This is a 0day that could be exploited from any number of outside channels.
Re: OS X 10.10.5 kernel local privilege escalation
#24Does it work on 10.11 with "rootless" mode disabled?
I just tested on 10.11 with rootless being disabled, and it prints out "not vulnerable". I assume that if it doesn't work on 10.11, then rootless being enabled or disabled shouldn't make a difference. You still have a root user either way, it's just that if rootless is enabled, then the root user wouldn't be able to modify certain system directories, which could mitigate the consequences of such an attack if it did w…
Re: OS X 10.10.5 kernel local privilege escalation
#25So for anyone who hasn't tried it but is wondering about it - it works on 10.10.4 and 10.10.5, running the tpwn binary does drop you to a root shell. Looks like a weakness in the address randomization in OS X
Re: OS X 10.10.5 kernel local privilege escalation
#26And here I was pressing "update later tonight." Thanks for the heads up!
Re: OS X 10.10.5 kernel local privilege escalation
#27Re: OS X 10.10.5 kernel local privilege escalation
#28So for anyone who hasn't tried it but is wondering about it - it works on 10.10.4 and 10.10.5, running the tpwn binary does drop you to a root shell. Looks like a weakness in the address randomization in OS X
What about 10.10.3?
10.10.3 was actually the first version it was tested on.
Re: OS X 10.10.5 kernel local privilege escalation
#29Earlier quoted context omitted.
I don't understand what you're implying. This is a 0day that could be exploited from any number of outside channels.
I can't reply to your post lower in the thread, but saying a java applet and flash app can exploit this? It's a C program that requires a local account on the box. You would need to break out of the java sandbox into local unprivileged shell access before you could exploit this via java. Same with flash - you would need a flash exploit that breaks you out of the sandbox before you can exploit this. In other words, yo…
So you're going to tell me that this is a non-issue because it's "unexploitable"?