Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <874lr4fttg.fsf@grahamc.com>
Date: Thu, 12 Oct 2017 08:12:59 -0400
From: Graham Christensen <graham@...hamc.com>
To: oss-security@...ts.openwall.com
Subject: Re: Privilege escalation with kill(-1, SIGKILL) in XNU kernel of macOS High Sierra


One follow-up for the discussion on if this is a DoS or privilege
escalation, in the logs we saw:

    Service exited due to signal: Killed: 9 sent by nix-daemon[54108]

and were able to (inconsistently) reproduce this with other unprivileged
users.

This indicated to us that we hadn’t tripped just a crashing bug, but
actually escalated beyond the normal access control protections of kill.

Graham

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.