Jump to content
Not connected, Your IP: 54.87.61.215
h4ng3r

Start eddie without admin rights planned?

Recommended Posts

I've noticed that in OpenVPN 2.4.* there is a new service "OpenVPNInteractiveService" which apparently provides openvpn gui client (run by an unprivileged user) some controls over the vpn. Is that coming to Eddie? To be able to run eddie and connect to vpn with non-admin account.

Share this post


Link to post

The 2.4.x final steps of the audit should be done soon, so it is safer to see what they think about this feature.

Personally I still think there is an attack vector here, although they only cover the OpenVPN exectuable here:

https://community.openvpn.net/openvpn/wiki/OpenVPNInteractiveService

 

their focus seems to be on preventing abusive OpenVPN directives from being executed for privilege escalation,

such as --up scripts:

This cannot be used anymore for privilege escalation to admin (by running an --up script from openvpn which is run-as-admin).

 

But you can still replace the OpenVPN binary with another one and gain escalation to admin if the service does not check it.


Occasional moderator, sometimes BOFH. Opinions are my own, except when my wife disagrees.

Share this post


Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Security Check
    Play CAPTCHA Audio
    Refresh Image

×
×
  • Create New...