HomeSecurityNorth Korea's Red Star OS Leak and Vulnerabilities

North Korea's Red Star OS Leak and Vulnerabilities

A few days after Red Star OS was leaked to the West in the form of an ISO, security researchers have begun exposing its vulnerabilities.Red Star OS

According to this post on Seclists, the udev rules in US version 3.0 and the rc.sysint script in version 2.0 are both world writable. Both have root privilege.

Due to the file permissions management of Red Star 3.0, the device manager rules for HP LaserJet printers (1000 series), (/etc/udev/rules.d/85-hplj10xx.rules), can be modified to RUN+= arguments. These commands can be run in the udev daemon as root. There is a presentation on GitHub.

The main job of udev is to monitor the /dev (devices) directory, and when the device is connected to a USB port, it loads the appropriate ruleset.

By writing to the rc.sysint file in the older Red Star OS 2.0, an attacker can execute commands as root (demonstration).

Both vulnerabilities provide privilege escalation for local users.

Download redstar_desktop3.0_sign.iso

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS