Talk With an Expert

Zero Day, UID 0, and SUID Discovering a Local SUID Exploit

Zero Day, UID 0, and SUID Discovering a Local SUID Exploit (PDF, 0.46MB)Published: 01 Jan, 2012
Created by:
Jeff Pike

Although much has been written about software vulnerabilities, little has been made publicly available on how to go about discovering new ones. How does one go about discovering a brand new vulnerability and exploiting it? This paper will provide some insight, by examining a fictitious incident centered on one such vulnerability in a root SUID program. It is the hope of the author to remove any false sense of security about software that does not have publicly disclosed vulnerabilities.

Zero Day, UID 0, and SUID Discovering a Local SUID Exploit