Skip to content

linux desktop (KDE) root-access ptrace() security desaster research (2007) suggesting ptrace_scope like solution into the kernel

Notifications You must be signed in to change notification settings

M64GitHub/kr00tf1sh

Repository files navigation

kro0tf1sh

linux desktop (KDE) root-access security breach (2007) suggesting ptrace_scope like solution into the kernel.

Proof of concept code for kde based gnu/linux systems, that was able to:

  • steal the entered password out of memory from the kdesu process
  • secretly execute other commands than the user wanted, then performing the users task
  • -> open the way for malware to gain root access due to desktop insecurity by design

(see kro0tf1sh.c for the final code)

See gist for more info on the story behind.

About

linux desktop (KDE) root-access ptrace() security desaster research (2007) suggesting ptrace_scope like solution into the kernel

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages