vendor:
Ninja
by:
Ben 'highjack' Sheppard
7.2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Ninja
Affected Version From: 2000.1.3
Affected Version To: 2000.1.3
Patch Exists: NO
Related CWE: N/A
CPE: forkbomb.org/ninja/
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux
2015
Ninja privilege escalation detection and prevention system 0.1.3 race condition
There is a small delay between the time of execution of a command and the time privilege escalation is detected. It is therefore possible to use a pty to run a command such as su and provide the password faster than it can be detected. The following PoC becomes root using su and issues killall -9 ninja. The attacker can then run any commands that they wish.
Mitigation:
Ensure that the system is configured to detect privilege escalation attempts and alert the system administrator.