Guild icon
Project Sekai
🔒 UIUCTF 2023 / ✅-misc-am-i-not-root
Avatar
Am I not root? - 500 points
Category: Misc Description: Ever wondered why nsjail prints a giant warning when it's run as root? Well, now you know ;) $ socat file:$(tty),raw,echo=0 tcp:am-i-not-root.chal.uiuc.tf:1337 Handout: Same as Zapping a Setuid 1 author: YiFei Zhu Files: No files. Tags: systems
Sutx pinned a message to this channel. 06/30/2023 5:15 PM
Avatar
@Violin wants to collaborate 🤝
Avatar
@Aptx wants to collaborate 🤝
Avatar
@Aptx left you alone, what a chicken! 🐥
Avatar
@unpickled admin bot wants to collaborate 🤝
Avatar
@afterworld wants to collaborate 🤝
Avatar
@nyancat0131 wants to collaborate 🤝
Avatar
how come
Avatar
nyancat0131 07/02/2023 2:01 PM
yeah actually zap 2 is easy when you know how to analyze the patch and play around with namespaces
Avatar
yeah just surprised 1 solve on this only, if its easier
14:02
prob cuz nobody tried
Avatar
@jayden wants to collaborate 🤝
Avatar
nyancat0131 07/02/2023 2:47 PM
hmm
14:47
the hint: disabled core dump and modules
14:47
what else?
14:47
i think bpf? lol
Avatar
nyancat0131 07/02/2023 3:38 PM
request_key is the way i think
15:38
let's see if i can do it
15:39
/* * Search the process keyrings and keyring trees linked from those for a * matching key. Keyrings must have appropriate Search permission to be * searched. * * If a key is found, it will be attached to the destination keyring if there's * one specified and the serial number of the key will be returned. * * If no key is found, /sbin/request-key will be invoked if _callout_info is * non-NULL in an attempt to create a key. The _callout_info string will be * passed to /sbin/request-key to aid with completing the request. If the * _callout_info string is "" then it will be changed to "-". */
15:40
but even with this idk if we can switch namespace
15:42
or even, /sbin/reboot
15:42
lmao
Avatar
Avatar
nyancat0131
used /ctf submit
✅ Well done, challenge solved!
Avatar
nyancat0131 07/02/2023 4:30 PM
too easy (2)
Exported 25 message(s)