OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[Full-disclosure] OS X Local Root: Silly SUID Helper in Tunnel Blick

From: Jason A. Donenfeld (Jasonzx2c4.com)
Date: Sat Aug 11 2012 - 02:19:36 CDT


Tunnel Blick is a fun punching bag. Lots of possible exploits.

Lots of vulnerable SUID code:
http://code.google.com/p/tunnelblick/source/search?q=openvpnstart.m&origq=openvpnstart.m&btnG=Search+Trunk

One such exploit: http://git.zx2c4.com/Pwnnel-Blicker/tree/pwnnel-blicker.c

Bla bla demonstration: http://www.youtube.com/watch?v=T6PBfLgEGxM

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/