
Dirty Cow exploit - CVE-2016-5195
Dirty COW adalah Local Privilege Escalation (LPE) di Linux kernel yang dikenal sebagai CVE-2016-5195. :contentReference[oaicite:0]{index=0}
Secara umum, Dirty COW berdampak pada Linux kernel 2.x sampai 4.x sebelum 4.8.3. :contentReference[oaicite:1]{index=1}
Beberapa distro sudah backport patch, jadi versi kernel kelihatan “lama” tapi bisa saja sudah aman.
Dirty COW sudah dipatch pada kernel berikut (dan yang lebih baru):
Cek versi kernel target:
uname -r
# dirtycow
This exploit uses the pokemon exploit of the dirtycow vulnerability as a base and automatically generates a new passwd line.
The user will be prompted for the new password when the binary is run.
The original /etc/passwd file is then backed up to /tmp/passwd.bak and overwrites the root account with the generated line.
After running the exploit you should be able to login with the newly created user.
To use this exploit modify the user values according to your needs.
The default user being created is `toor`.
Original exploit (dirtycow's ptrace_pokedata "pokemon" method):
https://github.com/dirtycow/dirtycow.github.io/blob/master/pokemon.c
Compile with:
```bash
gcc -pthread dirty.c -o dirty -lcrypt
Then run the newly create binary by either doing:
./dirty
or
./dirty my-new-password
Afterwards, you can either su toor or ssh toor@...
DON'T FORGET TO RESTORE YOUR /etc/passwd AFTER RUNNING THE EXPLOIT!
mv /tmp/passwd.bak /etc/passwd
Exploit adopted by Christian "firefart" Mehlmauer