
SSH Zero-Day Made By ClumsyLulz
SSH Zero-Day | Made by ClumsyLulz & Taylor Christian Newsome
This repository contains a C program that accepts input parameters and generates a packet to be sent to a server over the SSH protocol. The program allocates a buffer to hold the data, writes it to a file, and constructs a command-line string to initiate an SSH connection to a specified host and port using the system function.
Several security and stability issues exist in the current implementation:
malloc, but 29 bytes are written, which can cause memory corruption or segmentation faults.printf statement for the return address contains an incorrect format string, leading to undefined behavior.open and write are not verified, risking data loss or incomplete writes.buffer and ssh pointers is never freed.system to execute the SSH command allows arbitrary commands to run with elevated privileges, posing a serious security risk.To improve the program's security and reliability, the following changes are recommended:
printf statement for the return address.open and write calls.buffer and ssh pointers.system with a safer alternative like execvp to avoid executing arbitrary commands.Implementing these fixes will enhance the program’s stability and reduce potential security vulnerabilities.
root@vmi2865841:~/tools/SSH-Remote-Code-Execution# cat /etc/issue
Debian GNU/Linux 12 \n \l
root@vmi2865841:~/tools/SSH-Remote-Code-Execution# docker run -it --rm \
> -v /root/tools/SSH-Remote-Code-Execution:/poc \
> i386/debian:wheezy bash
root@29bcb37807cf:/# cat /etc/issue
Debian GNU/Linux 7 \n \l
root@29bcb37807cf:/# cat /etc/shadow
root:*:17955:0:99999:7:::
daemon:*:17955:0:99999:7:::
bin:*:17955:0:99999:7:::
sys:*:17955:0:99999:7:::
sync:*:17955:0:99999:7:::
games:*:17955:0:99999:7:::
man:*:17955:0:99999:7:::
lp:*:17955:0:99999:7:::
mail:*:17955:0:99999:7:::
news:*:17955:0:99999:7:::
uucp:*:17955:0:99999:7:::
proxy:*:17955:0:99999:7:::
www-data:*:17955:0:99999:7:::
backup:*:17955:0:99999:7:::
list:*:17955:0:99999:7:::
irc:*:17955:0:99999:7:::
gnats:*:17955:0:99999:7:::
nobody:*:17955:0:99999:7:::
libuuid:!:17955:0:99999:7:::
root@29bcb37807cf:/# cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/bin/sh
bin:x:2:2:bin:/bin:/bin/sh
sys:x:3:3:sys:/dev:/bin/sh
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/bin/sh
man:x:6:12:man:/var/cache/man:/bin/sh
lp:x:7:7:lp:/var/spool/lpd:/bin/sh
mail:x:8:8:mail:/var/mail:/bin/sh
news:x:9:9:news:/var/spool/news:/bin/sh
uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh
proxy:x:13:13:proxy:/bin:/bin/sh
www-data:x:33:33:www-data:/var/www:/bin/sh
backup:x:34:34:backup:/var/backups:/bin/sh
list:x:38:38:Mailing List Manager:/var/list:/bin/sh
irc:x:39:39:ircd:/var/run/ircd:/bin/sh
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh
nobody:x:65534:65534:nobody:/nonexistent:/bin/sh
libuuid:x:100:101::/var/lib/libuuid:/bin/sh
root@29bcb37807cf:/# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0@if11: <BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN> mtu 1500 qdisc noqueue state UP
link/ether 1e:13:2e:66:6f:69 brd ff:ff:ff:ff:ff:ff
inet 172.17.0.2/16 brd 172.17.255.255 scope global eth0
valid_lft forever preferred_lft forever
root@29bcb37807cf:/# cd /bin/
root@29bcb37807cf:/bin# ls
bash chmod dash df dnsdomainname egrep findmnt gzexe ip ls mknod mount nisdomainname ping6 readlink run-parts sh.distrib stty tailf touch uname which zcmp zfgrep zless
cat chown date dir domainname false grep gzip ln lsblk mktemp mountpoint pidof pwd rm sed sleep su tar true uncompress ypdomainname zdiff zforce zmore
chgrp cp dd dmesg echo fgrep gunzip hostname login mkdir more mv ping rbash rmdir sh ss sync tempfile umount vdir zcat zegrep zgrep znew
root@29bcb37807cf:/bin# df -h
Filesystem Size Used Avail Use% Mounted on
overlay 1.4T 977G 346G 74% /
tmpfs 64M 0 64M 0% /dev
shm 64M 0 64M 0% /dev/shm
/dev/sda1 1.4T 977G 346G 74% /poc
/dev/sda1 1.4T 977G 346G 74% /etc/resolv.conf
/dev/sda1 1.4T 977G 346G 74% /etc/hostname
/dev/sda1 1.4T 977G 346G 74% /etc/hosts
tmpfs 48G 0 48G 0% /proc/acpi
tmpfs 64M 0 64M 0% /proc/interrupts
tmpfs 64M 0 64M 0% /proc/kcore
tmpfs 64M 0 64M 0% /proc/keys
tmpfs 64M 0 64M 0% /proc/timer_list
tmpfs 48G 0 48G 0% /sys/firmware
root@29bcb37807cf:/bin# cat /proc/keys
root@29bcb37807cf:/bin# cat /etc/resolv.conf
# Generated by Docker Engine.
# This file can be edited; Docker Engine will not make further changes once it
# has been modified.
nameserver 1.1.1.1
nameserver 8.8.8.8
nameserver 213.136.95.10
nameserver 213.136.95.11
search .