TGViewer
Proxy Bar Proxy Bar @proxy_bar · 21.5K subscribers
Post #3340 6.75K
Linux System Call of the Day
*
Если достичь определенных ограничений ресурсов (например RLIMIT_NPROC) и программа не проверяет этот сбой, она тихо продолжит выполнение остального кода как root.
Hackers dream.
Man-страница прямо говорит: пропуск проверки return value — это большая ошибка безопасности.
Пример того как сервис дропает привилегии:
#define _GNU_SOURCE
#include <grp.h>
#include <stdio.h>
#include <unistd.h>

int main() {
// Assume 33 is the UID/GID for www-data on Debian/Ubuntu
uid_t target_uid = 33;
gid_t target_gid = 33;

printf("Running setup as root...\n");

// Drop supplementary groups first, then GID, then UID.
// Order matters: once UID is non-root, you can't fix groups.
if (setgroups(0, NULL) == -1) {
perror("setgroups");
return 1;
}
if (setresgid(target_gid, target_gid, target_gid) == -1) {
perror("setresgid");
return 1;
}
if (setresuid(target_uid, target_uid, target_uid) == -1) {
perror("setresuid");
return 1;
}

printf("Privileges dropped successfully. Safe to handle requests!\n");

// Prove we can't go back to root (UID 0)
if (setresuid(0, 0, 0) == -1) {
printf("Confirmed: Cannot restore root privileges.\n");
}

return 0;
}
  • 👍 24
  • 🔥 5
More from @proxy_bar
  1. Sep 28, 2026CVE-2026-19444: kubectl 😆😆😆
  2. Sep 28, 2026Prompt Injection in the Wild
  3. Sep 24, 2026Вспомнилось ! Был такой хороший гайд Introduction to Exploit Development Сегодня он интере…
  4. Sep 23, 2026Linux container escape * PoC
  5. Sep 21, 2026Идея для "быстрых свиданий" Ну это те, которые 5 минут общаешься, потом пересаживаетесь. З…
  6. Sep 20, 2026А скиньте фотки с тусы а )))
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →