LoFP LoFP / legitimate system administrators or developers testing gsm multiplexor configurations may trigger this detection. filter based on known authorized users or testing environments.

Techniques

Sample rules

Linux Possible GSM Privilege Escalation

Description

The following analytic detects the commands used in a race condition found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled. This could allow a local unprivileged user to escalate their privileges on the system.

Detection logic


| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime

from datamodel=Endpoint.Processes where

Processes.process="*rmmod *"
Processes.process="*n_gsm*"
Processes.process="*exec *"
Processes.process IN (
    "*/bin/bash*",
    "*/bin/dash*",
    "*/bin/sh*",
    "*/bin/zsh*"
)

by Processes.process Processes.vendor_product
   Processes.user_id Processes.process_hash Processes.parent_process_name Processes.parent_process_exec
   Processes.action Processes.dest Processes.process_current_directory Processes.process_path
   Processes.process_integrity_level Processes.original_file_name Processes.parent_process
   Processes.parent_process_path Processes.parent_process_guid Processes.parent_process_id
   Processes.process_guid Processes.process_id Processes.user Processes.process_name


| `drop_dm_object_name(Processes)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `linux_possible_gsm_privilege_escalation_filter`