当前位置:网站首页>阿里云polkit pkexec 本地提权漏洞
阿里云polkit pkexec 本地提权漏洞
2022-07-02 04:14:00 【凌空暗羽】
1.引言
最近由于各种事情好久没有访问自己的阿里云服务器控制台了,因为想了解了解云原生,所以发现可以进一步开拓自己的服务器价值,毕竟对于别的初学者来说算是割肉,但是自己作为阿里云学生机使用者,这里对学生机做一下科普,阿里云学生机算是一种对于学生而言性价比较高的服务器了,是阿里云为学生提供的一种优惠政策,在学生身份有效期内,且服务器未到期前,学生可按学生优惠价格续费,每次续费行为,续费时长在1-12个月内自行选择,实例到期时间不超过学生身份有效期,也就是每年只需要96元就能使用一个比较高性能的服务器了,到你不是学生的时候取消,当然中途应该不能停止续费。因为自己有过一定的服务器使用经验,所以对我来说学习云原生的话反而算是一种优点。为了检测自己是否还有学生机的优惠资格,登录手机阿里云发现提示了一个紧急漏洞:
提权在网安里面算是比较危险的了,由局部直接冲向整体。
2.解决方法
我们都知道Linux作为开源的操作系统,社区庞大,所以有bug肯定有一群大佬站出来,现在网上流行的解决方法如下(如果不是很懂的话直接CV,解决问题就行):
yum -y install polkit #升级这个Linux自带的程序
chmod 0755 /usr/bin/pkexec #pkexec的suid权限取消
3.余下风波
虽然很快就更新了,但是阿里云还是一直提示由漏洞,这个时候不要慌,找到漏洞检测的地方,重新检测一下漏洞,比如如下的两个地方:
点击查看自己已经解决的漏洞,进行确认:
最后再次回到阿里云手机app,发现安全评分也上去了,可以说算是解决了,至于还是一直提示高危漏洞,当营销处理吧,毕竟咱还是学生,学生机的使用往往就是自己小组写项目部署一下方便其他学生指点,真正使用率不是很高。平时的话如果真的想学习Linux,使用虚拟机代替也是可以的。最后就是作为程序员得能保持平静心态对待bug或者漏洞,不能像我一样看到漏洞还在急急忙忙疯狂关闭安全组端口,哈哈哈哈,本文实际内容不多,全是唠嗑,祝大家学习之旅愉快!。
边栏推荐
- Microsoft Research Institute's new book "Fundamentals of data science", 479 Pages pdf
- Sword finger offer II 006 Sort the sum of two numbers in the array
- [Li Kou brush questions] 15 Sum of three numbers (double pointer); 17. Letter combination of phone number (recursive backtracking)
- The confusion I encountered when learning stm32
- Wpviewpdf Delphi and Net PDF viewing component
- PR zero foundation introductory guide note 2
- Cloud service selection of enterprises: comparative analysis of SaaS, PAAS and IAAs
- Feature Engineering: summary of common feature transformation methods
- Sorted out an ECS summer money saving secret, this time @ old users come and take it away
- Recently, the weather has been extremely hot, so collect the weather data of Beijing, Shanghai, Guangzhou and Shenzhen last year, and make a visual map
猜你喜欢
Force buckle 540 A single element in an ordered array
66.qt quick-qml自定义日历组件(支持竖屏和横屏)
Typescript practice for SAP ui5
Yyds dry inventory compiler and compiler tools
The first practical project of software tester: web side (video tutorial + document + use case library)
Déchirure à la main - tri
Realizing deep learning framework from zero -- Introduction to neural network
10 minutes to understand CMS garbage collector in JVM
How to model noise data? Hong Kong Baptist University's latest review paper on "label noise representation learning" comprehensively expounds the data, objective function and optimization strategy of
Spring moves are coming. Watch the gods fight
随机推荐
Use a mask to restrict the input of the qlineedit control
文档声明与字符编码
How to solve the problem that objects cannot be deleted in Editor Mode
微信小程序 - 实现获取手机验证码倒计时 60 秒(手机号+验证码登录功能)
【提高课】ST表解决区间最值问题【2】
Wechat applet calculates the distance between the two places
Yyds dry inventory compiler and compiler tools
Which is better, industrial intelligent gateway or edge computing gateway? How to choose the right one?
Go variables and constants
【leetcode】34. Find the first and last positions of elements in a sorted array
The first practical project of software tester: web side (video tutorial + document + use case library)
SQL: common SQL commands
Actual combat | use composite material 3 in application
[source code analysis] NVIDIA hugectr, GPU version parameter server - (1)
Pandora IOT development board learning (RT thread) - Experiment 1 LED flashing experiment (learning notes)
Mysql中常见的锁
Finally got byte offer. The 25-year-old inexperienced perception of software testing is written to you who are still confused
第十六周作业
powershell_ View PowerShell function source code (environment variable / alias) / take function as parameter
[JS event -- event flow]