目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2015-1318 PoC — Ubuntu Apport 安全漏洞

来源
关联漏洞
标题: Ubuntu Apport 安全漏洞 (CVE-2015-1318)
Description:Ubuntu是英国科能(Canonical)公司和Ubuntu基金会共同开发的一套以桌面应用为主的GNU/Linux操作系统。Apport是其中的一个用于收集并反馈错误信息(当应用程序崩溃时操作系统认为有用的信息)的工具包。 Ubuntu Apport 2.13版本至2.17.1之前2.17.x版本的崩溃报告功能中存在安全漏洞。本地攻击者可借助命名空间(容器)中特制的usr/share/apport/apport文件利用该漏洞获取权限。
Description
Exploit I used to claim 10% final-grade extra credit in Matthew Might's Compilers class.
介绍
# CVE-2015-1318

Exploit I used to claim 10% final-grade extra credit in Matthew Might's Compilers class.
https://bugs.launchpad.net/apport/+bug/1438758

Bonus opportunities (http://matt.might.net/teaching/compilers/spring-2015/)

Use an exploit on vulcan to gain root access: +10% for a local user exploit; +15% for a remote exploit (e.g. breaking in via apache). You must exploit a vulnerability (e.g. buffer overflow) for Ubuntu on vulcan to gain root; that is, you can't steal my laptop while it has an open ssh connection to vulcan to claim the prize. You must write up a short summary of the vulnerability and how you exploited it. (You may use a prepackaged tool for exploitation.) Mail the summary to me for approval and then to the class. Each individual exploit may only be claimed once, and the first to exploit wins. To signal that you have claimed root, modify the message of the day.

文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →