video thumbnail 11:32
Learning about nss (Linux Name Service Switch) During Sudo Exploitation

2022-01-03

[public] 17.4K views, 1.82K likes, dislikes audio only

channel thumbLiveOverflow

To understand a crash in nss_load_function() better, we have to look at the libc source code. While doing this we find a very interesting exploit strategy using dlopen.

Grab the files: https://github.com/LiveOverflow/pwnedit

Read libc Code: https://elixir.bootlin.com/glibc/glibc-2.31/source

Episode 14:

00:00 - Intro

00:22 - Select Testcases For Crash Analysis

01:19 - Debug Crash in gdb

02:02 - Code Examples from grep.app

02:53 - Reading libc Source Code

04:43 - Learning about nss

05:29 - Reaching nss_lookup

06:00 - The service_user Struct ni

07:55 - nss_lookup_function

08:57 - The Crash Reason

09:58 - Exploit Brainstorming

10:57 - Outro

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Instagram: https://instagram.com/LiveOverflow/

→ Blog: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Can We Find a New Exploit Strategy? | Ep. 13 by LiveOverflow
/youtube/video/Y8qljlUjEEM
Intro
/youtube/video/0ti-YgB2iR4?t=0
Select Testcases For Crash Analysis
/youtube/video/0ti-YgB2iR4?t=22
Debug Crash in gdb
/youtube/video/0ti-YgB2iR4?t=79
Code Examples from grep.app
/youtube/video/0ti-YgB2iR4?t=122
Reading libc Source Code
/youtube/video/0ti-YgB2iR4?t=173
Learning about nss
/youtube/video/0ti-YgB2iR4?t=283
Reaching nss_lookup
/youtube/video/0ti-YgB2iR4?t=329
The service_user Struct ni
/youtube/video/0ti-YgB2iR4?t=360
nss_lookup_function
/youtube/video/0ti-YgB2iR4?t=475
The Crash Reason
/youtube/video/0ti-YgB2iR4?t=537
Exploit Brainstorming
/youtube/video/0ti-YgB2iR4?t=598
Outro
/youtube/video/0ti-YgB2iR4?t=657
I’m moving, no videos sorry 17,510 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
Sudo Vulnerability Walkthrough by LiveOverflow
/youtube/video/TLa2VqcGGEQ