当前位置:网站首页>Alibaba cloud polkit pkexec local rights lifting vulnerability
Alibaba cloud polkit pkexec local rights lifting vulnerability
2022-07-02 04:21:00 【Flying dark feather】
1. introduction
Recently, I haven't visited my Alibaba cloud server console for a long time due to various things , Because I want to know about Jieyun primordial , So I found that I can further develop my server value , After all, it's meat cutting for other beginners , But as a student machine user of Alibaba cloud , Here is a popular science for student computers , Alibaba cloud student machine is a kind of server with high cost performance for students , It is a preferential policy provided by Alibaba cloud for students , During the validity of student status , And before the server expires , Students can renew at the preferential price , Every renewal , Renewal duration 1-12 Choose for yourself within months , The expiration time of the instance does not exceed the validity period of the student identity , That is, only need to 96 Yuan can use a relatively high-performance server , Cancel when you are not a student , Of course, the renewal should not be stopped halfway . Because I have some experience in using servers , So for me, learning cloud nativity is an advantage . In order to test whether you still have the preferential qualification of student machine , Logging in to Alibaba cloud on your mobile phone found an emergency vulnerability :
Raising rights is more dangerous in network security , Rush directly from the part to the whole .
2. resolvent
We all know Linux As an open source operating system , The community is huge , So there is bug There must be a group of big guys coming out , Now the popular solutions on the Internet are as follows ( If you don't understand it very well, just CV, Just solve the problem ):
yum -y install polkit # Upgrade this Linux The program that comes with it
chmod 0755 /usr/bin/pkexec #pkexec Of suid Authority cancelled
3. The rest of the storm
Although it was updated soon , However, Alibaba cloud has always been prompted by vulnerabilities , Don't panic at this time , Find the place of vulnerability detection , Re check the vulnerability , For example, the following two places :
Click to view the vulnerabilities you have solved , Confirm :
Finally, return to Alibaba cloud mobile again app, I found that the safety score also went up , It can be said to be solved , As for the high-risk vulnerabilities that have been prompted , When dealing with marketing , After all, I'm still a student , The use of student machine is often to write the project deployment in your own group for the convenience of other students , The real utilization rate is not very high . Usually, if you really want to learn Linux, It is also possible to use virtual machines instead . Finally, as a programmer, you have to be calm bug Or loopholes , I can't see that the vulnerability is still frantically closing the security group port in a hurry like I did , Ha ha ha ha , The actual content of this article is not much , It's all chatter , I wish you all a pleasant study trip !.
边栏推荐
- 【leetcode】74. Search 2D matrix
- Yyds dry inventory compiler and compiler tools
- Arbre binaire pour résoudre le problème (2)
- Sword finger offer II 006 Sort the sum of two numbers in the array
- IDEA xml中sql没提示,且方言设置没用。
- Feature Engineering: summary of common feature transformation methods
- First acquaintance with P4 language
- C语言猜数字游戏
- MySQL error: expression 1 of select list is not in group by claim and contains nonaggre
- Pytorch-Yolov5從0運行Bug解决:
猜你喜欢
66.qt quick-qml自定义日历组件(支持竖屏和横屏)
C language practice - number guessing game
Microsoft Research Institute's new book "Fundamentals of data science", 479 Pages pdf
Typescript practice for SAP ui5
2022-07-01: at the annual meeting of a company, everyone is going to play a game of giving bonuses. There are a total of N employees. Each employee has construction points and trouble points. They nee
Why can't you remember when reading? Why can't you remember- My technology learning methodology
[untitled]
Websites that it people often visit
Pytorch---使用Pytorch进行鸟类的预测
Pytoch --- use pytoch for image positioning
随机推荐
Analysis of the overall design principle of Nacos configuration center (persistence, clustering, information synchronization)
A summary of common interview questions in 2022, including 25 technology stacks, has helped me successfully get an offer from Tencent
云服务器的安全设置常识
Pytoch --- use pytoch for image positioning
Pytorch---使用Pytorch进行鸟类的预测
Typescript practice for SAP ui5
cookie、session、tooken
Free drawing software recommended - draw io
Go variables and constants
Wechat applet - realize the countdown of 60 seconds to obtain the mobile verification code (mobile number + verification code login function)
手撕——排序
WiFi 5GHz frequency
Www2022 | know your way back: self training method of graph neural network under distribution and migration
Pytoch --- use pytoch to predict birds
My first experience of shadowless cloud computer
二叉树解题(二)
Spring recruitment of Internet enterprises: Kwai meituan has expanded the most, and the annual salary of technical posts is up to nearly 400000
Play with concurrency: what's the use of interruptedexception?
Li Kou interview question 02.08 Loop detection
What is 5g industrial wireless gateway? What functions can 5g industrial wireless gateway achieve?