
End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis.
This project was developed as part of the Digitale Forensik course at the Technische Hochschule Deggendorf.
It demonstrates a full forensic investigation and attack simulation involving:
A Python dependency confusion attack using a malicious PyPI package
Privilege escalation via a vulnerable version of sudo (CVE-2025-32463)
Deployment of a Sliver C2 beacon
A custom rootkit with kernel module loading, syscall hooking, and udev-based persistence
Complete analysis of memory and network artifacts using tools like Volatility, NetworkMiner, and manual reversing
The repository contains scripts, setup instructions, artifacts , and detailed analysis steps to replicate both the attack and the forensic investigation.
shell)
shell binary
CVE-2025-32463
NVD Details
POC Github
[!NOTE]
You must install a vulnerable Sudo version (with chroot support—seeprivesc/setup.sh)
sequenceDiagram
autonumber
participant Attacker
participant PyPI
participant IntDep as Internal Dep Server
participant Dev as Developer
participant C2 as C2 Server
Attacker->>PyPI: Publish package with version v1.0.3
Dev->>IntDep: pip install
IntDep-->>Dev: Returns v1.0.1
Dev->>PyPI: Fallback pip install package==v1.0.3
PyPI-->>Dev: Returns malicious v1.0.3 (stager)
Dev->>Dev: Executes stager (package_evil)
Dev->>C2: Beacon/Sliver implant calls home
Note right of C2: Attacker now has RCE
Attacker->>Dev: Enumerates sudo version (1.9.16p2)
Attacker->>Dev: Runs CVE-2025-32463 exploit
Note right of Dev: PE to root
Dev->>Dev: Downloads & runs rootkit loader binary
Dev->>Dev: Loader installs kernel module & configures udev rule
Dev->>Dev: Schedules reboot
Note right of Dev: Attacker established persistence
Dev->>Dev: System reboots
Dev->>Dev: Udev loads kernel module on boot
Dev->>C2: Kernel-stage beacon calls C2
All artifacts are generated manually. You will use two machines:
We will produce three artifacts:
On the host system:
vboxmanage list vms
"linux-root-kit_default_1752261916398_20346" {c2d4b5bc-d87f-4dcb-af01-85b78c163fef}
virtualboxvm --startvm "linux-root-kit_default_1752261916398_20346" --dbg
Goto interface --> Debug In the Debug Console (VMMR0> prompt):
.pgmphystofile 'dumpmem_linux_root_kit'
Start before simulating the developer. The ! port 22 is useful to not log the vagrant ssh connection.
sudo tcpdump -w output.pcap ! port 22
shell)vagrant up
This can take a while --> downloads an entire vm that was build with Bento.
vagrant ssh
sudo bash /vagrant/privesc/setup.sh
sudo apt install python3.12-venv
You can also execute the make file to build the userland binary shell. This the easiest way to do it - otherwise you would need to install the correct headers first :P.
shell to the Kali to later serve it from there.