Apple Mac OSX < 10.7.5/10.8.2/10.9.5/10.10.2 - 'Rootpipe' Local Privilege Escalation
########################################################
local 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
########################################################
setroubleshoot tries to find out which rpm a particular
#!/usr/bin/env python
#!/usr/bin/env python
#!/usr/bin/env python
#!/usr/bin/python
Source: https://code.google.com/p/google-security-research/issues/detail?id=222
Spybot Search & Destroy 1.6.2 Security Center Service Privilege Escalation
Foxit Reader 7.0.6.1126 Unquoted Service Path Elevation Of Privilege
Source: http://www.halfdog.net/Security/2015/UpstartLogrotationPrivilegeEscalation/
Sources:
# Title : Microsoft Office Word 2007 - RTF Object Confusion ASLR and DEP bypass
Ubisoft Uplay 5.0 Insecure File Permissions Local Privilege Escalation
Electronic Arts Origin Client 9.5.5 Multiple Privilege Escalation Vulnerabilities
# Exploit Title: VFU Move Entry Buffer Overflow
#!/usr/bin/python
Realtek 11n Wireless LAN utility privilege escalation.
#!/usr/bin/env python
Exploit Title - SoftSphere DefenseWall FW/IPS Arbitrary Write Privilege Escalation
Exploit Title - BullGuard Multiple Products Arbitrary Write Privilege Escalation
Exploit Title - AVG Internet Security 2015 Arbitrary Write Privilege Escalation
Exploit Title - K7 Computing Multiple Products Arbitrary Write Privilege Escalation
Exploit Title - Symantec Altiris Agent Arbitrary Write Privilege Escalation
Exploit Title - Trend Micro Multiple Products Arbitrary Write Privilege Escalation
Exploit Title - McAfee Data Loss Prevention Endpoint Arbitrary Write Privilege Escalation
# Exploit Title: OS X Gatekeeper bypass Vulnerability
Exploit Title - Comodo Backup Null Pointer Dereference Privilege Escalation
Title : VLC Player 2.1.5 Write Access Violation Vulnerability
Title : VLC Player 2.1.5 DEP Access Violation Vulnerability
// clang -o ig_2_3_exploit ig_2_3_exploit.c -framework IOKit -framework CoreFoundation -m32 -D_FORTIFY_SOURCE=0
// Requires Lorgnette: https://github.com/rodionovd/liblorgnette
#!/usr/bin/python
#!/usr/bin/python
## Source: https://code.google.com/p/google-security-research/issues/detail?id=123
The root user is disabled on Red Star, and it doesn't look like there is a way to enable it.
Red Star 2.0 desktop ships with a world-writeable "/etc/rc.d/rc.sysinit"
#!/bin/bash -e
Source: https://code.google.com/p/google-security-research/issues/detail?id=121
#!/use/bin/perl
# Source: https://hatriot.github.io/blog/2015/01/06/ntpdc-exploit/
create an Android.mk as follow:
# Source: https://code.google.com/p/google-security-research/issues/detail?id=118#c1
SEC Consult Vulnerability Lab Security Advisory < 20141218-1 >