## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ISTAR-LAB-CVE-2021-3560_POC
# CVE-2021-3560_PoC
polkit ์ต์คํ๋ก์ ์คํฌ๋ฆฝํธ
polkit ์๋น์ค๋ฅผ ์ฌ์ฉํ์ฌ ๋ฃจํธ ๊ถํ ์์น์ ์ํ ์๋ํ ์คํฌ๋ฆฝํธ
# ์๊ตฌ ์ฌํญ
* SSH ์๋ฒ (GNOME์ ํตํ ์ธ์ฆ ํ์
์ ํผํ๊ธฐ ์ํจ)
* ์ทจ์ฝํ Linux ๋ฐฐํฌํ:
๋ฐฐํฌํ| ์ทจ์ฝ ์ฌ๋ถ?
---|---
RHEL 7| ์๋์ค
RHEL 8| ์
Fedora 20 (๋๋ ์ด์ )| ์๋์ค
Fedora 21 (๋๋ ์ดํ)| ์
Debian 10 (โbusterโ)| ์๋์ค
Debian testing (โbullseyeโ)| ์
Ubuntu 18.04| ์๋์ค
Ubuntu 20.04| ์
# ์ฌ์ฉ ๊ฐ์ด๋
root@kitploit:~
ssh localhost
git clone https://github.com/tyleraharrison/CVE-2021-3560_PoC.git
cd CVE-2021-3560_PoC
./polkitRoot.sh
# ์๋ ค์ง ๋ฌธ์ ์
* ๋ฌด์ฐจ๋ณ ๋์
(brute-force)์ด ํ์ํ ๋ฌธ์ ์ ๋ํ ํด๊ฒฐ์ฑ
์ ์์ฑ์ด ๋ฏธํกํ ์ฌ๊ท ํจ์์
* GitHub์์ ์ค ๋์ CRLF๋ก ๋ณ๊ฒฝํ์ฌ Bash๊ฐ ์ด๋ฅผ ์ฒ๋ฆฌํ์ง ๋ชปํ๋ฏ๋ก `dos2unix polkitRoot.sh`๋ฅผ ์ฌ์ฉํ์ฌ ์ค ๋์ ๋ณ๊ฒฝํด์ผ ํ ์๋ ์์
Ubuntu 20.04์์ ํ
์คํธ๋จ
์ฐธ๊ณ : https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/