meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 26th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 26 January 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Polkit Priv Esc. Vuln; Emotet Stops 0.0.0.0; log4j VMWare Exploits

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 26, 2022 edition of the Sansonet Storm Center's

0:06.8

Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.8

Qualdez discovered a new privilege escalation vulnerability in Unix or really Linux-based systems relying on Polkitt.

0:23.4

Polkid is pretty much installed and part of any modern Unix distribution.

0:29.6

It's not necessarily really just Linux, but of course these days,

0:33.4

mostly people are dealing with Linux.

0:36.5

Policy Kit and PKXC, the binary that sort of comes with it

0:41.2

and allows you to actually execute commands as other users is a little bit similar to the more

0:48.8

popular pseudo, but really a more modern and more fine-cranged version of it. So with P-KXec, which is an

0:58.4

SUID-Root binary, you're able to execute commands as different users and you have then

1:07.9

some restricted access as to what you're able to do with these commands.

1:13.1

With pseudo, on the other hand, once I give you pseudo permissions to execute a certain command

1:18.4

as a certain user, I may be able to restrict what the parameters is where you can pass to it,

1:25.3

but once you're running the command, there's very little

1:28.2

else I can do. And with so many commands, for example, being able to spawn shells and such,

1:34.5

it's very difficult to really get that fine-crain control in pseudo, which is why we do have

1:41.5

Polkkit or Policy Kit and PKXec for that more fine-grained control.

1:47.6

But, well, sadly, something went wrong.

1:50.5

And something went wrong 12 years ago.

1:52.8

That's when the vulnerability was introduced.

1:56.6

Personally, I haven't really looked for an exploit yet, but Boyan, he wrote it up for us.

2:03.0

He was able to create an exploit that worked reliably across different distributions within a relatively short time.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.