logo

Something about sudo, Kingcope and re-inventing the wheel

ID: f10e5f9c-3d0a-5dd0-88bd-21bdb6e7f0eb

STIX ID: report--f10e5f9c-3d0a-5dd0-88bd-21bdb6e7f0eb

Feed Name: SensePost Blog

Threat Score
35/100

Date Published: 2013-05-27

Date Updated: 2026-04-29

...
...

This write-up documents a proof-of-concept local privilege escalation that abuses LD_PRELOAD with sudo when the environment is preserved (e.g., Defaults setenv or older sudo versions). The author reproduces and refines a 2008 Kingcope exploit, providing C source for a shared object, build and invocation steps to execute a root shell by running a sudo-allowed command, and notes the limitation that this requires a specific sudo configuration or outdated sudo.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.