目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2018-1000001 PoC — GNU glibc 权限许可和访问控制问题漏洞

来源
关联漏洞
标题: GNU glibc 权限许可和访问控制问题漏洞 (CVE-2018-1000001)
Description:GNU glibc(又名GNU C Library,libc6)是一种按照LGPL许可协议发布的开源免费的C语言编译程序。 GNU glibc 2.26及之前版本中存在本地提权漏洞。本地攻击者可利用该漏洞获取提升的权限,执行任意代码。
Description
glibc getcwd() local privilege escalation compiled binaries
介绍
# glibc - 'getcwd()' Local Privilege Escalation 

Attention: 
    __All rights to the exploit writer. I have just compiled and organized a repository for this CVE.__

CVE: 2018-1000001
Alias: RationalLove

* exploit-debian - Exploit compiled in debian x64
* exploit-ubuntu - Exploit compiled in ubuntu x64

# Am I vulnerable?
To discover if the machine is vulnerable:
```bash
dpkg --list | grep -i libc6
```

If your libc6 package is:
* 2.24-11+deb9u1 for Debian Stretch
* 2.23-0ubuntu9 for Ubuntu Xenial Xerus

Then you're probably vulnerable. 

If you are lazy, I developed a shell script to check if your machine is vulnerable.

It is in this repository, and it is named `vulncheck.sh`. You can use it to determine if the public exploit will work or not based on the libc6 package.

# Exploitation
Simply drop the binary into the vulnerable system and execute it to get root.
![Exploit](/img/photo_2018-02-06_19-28-12.jpg?raw=true "CVE-2018-1000001 In action")

# Remediation
It is recommended immediate patch of libc package using `apt-get update -y && apt-get upgrade -y`
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →