Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Understated opportunity: CopyFail means we get to jailbreak a whole new generation of locked down Linux devices.

Understated opportunity: CopyFail means we get to jailbreak a whole new generation of locked down Linux devices.

Scheduled Pinned Locked Moved Uncategorized
cybersecuritycopyfaillinuxjailbreakinghacking
5 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • anthropy@mastodon.derg.nzA This user is from outside of this forum
    anthropy@mastodon.derg.nzA This user is from outside of this forum
    anthropy@mastodon.derg.nz
    wrote last edited by
    #1

    Understated opportunity: CopyFail means we get to jailbreak a whole new generation of locked down Linux devices.

    Ever wanted root access on your router, phone, (tv/portable/etc) media player, washing machine, Jumbo jet, newag train, etc?

    If you find a way to run the copyfail POC through somewhere, you'll be root!

    Just make sure to try this before the next update gets installed on the device

    #cybersecurity #copyfail #linux #jailbreaking #hacking

    23n27@dgc.social2 wdormann@infosec.exchangeW bms48@mastodon.socialB anthropy@mastodon.derg.nzA 4 Replies Last reply
    1
    0
    • R relay@relay.mycrowd.ca shared this topic
    • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

      Understated opportunity: CopyFail means we get to jailbreak a whole new generation of locked down Linux devices.

      Ever wanted root access on your router, phone, (tv/portable/etc) media player, washing machine, Jumbo jet, newag train, etc?

      If you find a way to run the copyfail POC through somewhere, you'll be root!

      Just make sure to try this before the next update gets installed on the device

      #cybersecurity #copyfail #linux #jailbreaking #hacking

      23n27@dgc.social2 This user is from outside of this forum
      23n27@dgc.social2 This user is from outside of this forum
      23n27@dgc.social
      wrote last edited by
      #2

      @anthropy I don't think it will help much:

      - On embedded systems, more often than not there's only root / getting access as a regular user is as hard as getting root.

      - Custom kernel builds might not have AF_ALG support (though some might, I specifically implemented support for AF_ALG based hashing in casync-nano because we used that on one particular piece of hardware)

      1 Reply Last reply
      0
      • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

        Understated opportunity: CopyFail means we get to jailbreak a whole new generation of locked down Linux devices.

        Ever wanted root access on your router, phone, (tv/portable/etc) media player, washing machine, Jumbo jet, newag train, etc?

        If you find a way to run the copyfail POC through somewhere, you'll be root!

        Just make sure to try this before the next update gets installed on the device

        #cybersecurity #copyfail #linux #jailbreaking #hacking

        wdormann@infosec.exchangeW This user is from outside of this forum
        wdormann@infosec.exchangeW This user is from outside of this forum
        wdormann@infosec.exchange
        wrote last edited by
        #3

        @anthropy
        Phones and other bespoke things are unlikely to use algif_aead, and as such will not be affected.

        1 Reply Last reply
        0
        • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

          Understated opportunity: CopyFail means we get to jailbreak a whole new generation of locked down Linux devices.

          Ever wanted root access on your router, phone, (tv/portable/etc) media player, washing machine, Jumbo jet, newag train, etc?

          If you find a way to run the copyfail POC through somewhere, you'll be root!

          Just make sure to try this before the next update gets installed on the device

          #cybersecurity #copyfail #linux #jailbreaking #hacking

          bms48@mastodon.socialB This user is from outside of this forum
          bms48@mastodon.socialB This user is from outside of this forum
          bms48@mastodon.social
          wrote last edited by
          #4

          @anthropy the AF_ALG vector and small payload betrays itself

          1 Reply Last reply
          0
          • anthropy@mastodon.derg.nzA anthropy@mastodon.derg.nz

            Understated opportunity: CopyFail means we get to jailbreak a whole new generation of locked down Linux devices.

            Ever wanted root access on your router, phone, (tv/portable/etc) media player, washing machine, Jumbo jet, newag train, etc?

            If you find a way to run the copyfail POC through somewhere, you'll be root!

            Just make sure to try this before the next update gets installed on the device

            #cybersecurity #copyfail #linux #jailbreaking #hacking

            anthropy@mastodon.derg.nzA This user is from outside of this forum
            anthropy@mastodon.derg.nzA This user is from outside of this forum
            anthropy@mastodon.derg.nz
            wrote last edited by
            #5

            (I know this requires some way to run the POC as normal user, and that not every kernel build and device has the necessary exploitable bits, but it will still be an available way that you can try; I do suggest trying it simply to see if it works, wouldn't be the first time an (embedded or otherwise) device has weird libraries, oversized kernel builds, and bad protection past the frontend)

            1 Reply Last reply
            1
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups