'Dirty Pipe' Is The Worst Linux Exploit In Years

preview_player
Показать описание
There are some crazy Linux exploits and this is certainly Dirty Pipe is certainly high up there, this exploit is similiar to an earlier exploit called Dirty Cow and allows you to almost complete bypass system permissions.

This video exists for educational purposes only, nothing shown in this video should be replicated.

==========Support The Channel==========

==========Resources==========
CEV Code: CVE-2022-0847

=========Video Platforms==========

==========Social Media==========

==========Time Stamps==========
0:00 Introduction
2:01 The Exploit
3:01 What Can It Do
5:15 Limitations
6:49 Conclusion

==========Credits==========
🎨 Channel Art:
All my art has was created by Supercozman

#Linux #DirtyPipe #DirtyCow #Security

🎵 Ending music

DISCLOSURE: Wherever possible I use referral links, which means if you click one of the links in this video or description and make a purchase I may receive a small commission or other compensation.
Рекомендации по теме
Комментарии
Автор

I like hearing that its already been fixed.

MegaLokopo
Автор

I didn't know it was happening but I suspected something was up when I noticed how fast kernel 5.16.8 thru .11 were pushed out

tedmiles
Автор

Android phone here with kernel version 3.18.71
Hopefully the mass of home routers and IoT are not affected by this only because they are also running 2.x, 3.x and 4.x
whether they are patched for numerous other exploits is doubtful though.

For appliance stuff if they use dual read-only image based OS installs there's at least the possibility of resetting to factory defaults or selecting the inactive image for next boot.

UKprl
Автор

Maybe it is time to redesign the Linux kernel so only the bare minimum features run within the kernel and everything else runs as a user process. The fact the Linux kernel is still be used 30 years after its initial release is both an accomplishment to be celebrated and probably a surprise to Linus Torvalds. The vulnerabilities are patched quickly instead of being swept under the metaphorical rug.

xA
Автор

I figure most github projects are still safe since any developer that includes this exploit in their code for non-demonstrative purposes will absolutely destroy their reputation and future prospects. Just don't run anything from a recently created account or mostly inactive one.

onelazynoob
Автор

Wait wait, lemme get this straight

You are saying that it IS possible to get root access on my bootloader-locked phone?? 😱😱

Could this mean that you can use it to screw anti-consumer smartphone manufacturers, root the phone and then upgrade the kernel??

bob
Автор

0:55 so using older kernel is actually fine? interesting. i thought it would be the other way around.

oplkfdhgk
Автор

Oh time to get a root shell on my phone :P

nonetrix
Автор

Android bootloader doesn't allow system partitions to be modified so don't try this, you'll brick your phone.

DanielClear
Автор

Maybe this exploit can be used to root Android devices with locked bootloaders, such as Huawei? Or root android devices without having to bypass things such as Samsung's Knox?

Just a thought

ThatTrueCJ
Автор

New way to root Android phones i guess 🥴

LawlessSentry
Автор

That was scary, but now I know better and I feel save now. Thanks.

kimorlandonilsson
Автор

I don't use Android nor IOS but I went to check my girlfriend's and it's fine. Her android phone runs on top of linux 3.X.
As for other bugs... that's another story...

brunoais
Автор

I guess with this you can escape from a docker container

oleh
Автор

If I get root access on a system I can do whatever I want? Who would have known?

shaytal
Автор

So happy that my phone is running 5.4 lol. For once being out of date worked out lol

Lutitious
Автор

they couldn't get back the comments

mrvff
Автор

yet another reason to use Debian stable.

_jdfx
Автор

I understand that you probably have a lot of content on the to do list, but could you consider penciling in advice on how to follow linux explotation news? Or maybe could you just reccommend some good news outlets? I know of phoronix but that's about it :P

i am perpetual scrub

Bagginsess
Автор

"Only download from trusted sources"
GitHub seems pretty trustworthy to me...

konnilol
join shbcf.ru