The GIAC
Case Study on Internal Root Compromise Incident
Pages
51
Time to read
63 mins
Publication
Language
English
Pages
51
Time to read
63 mins
Publication
Language
English
This document is a case study that details an internal root compromise incident that occurred at a software development company in India. The paper outlines the method employed by the attacker to compromise the system and analyzes the investigative and incident-handling procedures that were utilized. The incident involved a remote exploit known as 'openssl-too-open' that allowed the attacker to gain shell access with limited privileges. Subsequently, the attacker escalated their privileges to root using a local exploit called 'myptrace.c'. The paper discusses the workings of the 'myptrace.c' exploit and the associated Linux kernel vulnerabilities in depth. Additionally, it addresses the incident handling process, including preparation, identification, containment, and eradication steps taken during the incident. The author aims to highlight the seriousness of kernel-level vulnerabilities and the need for comprehensive security policies and practices within organizations.