Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
COPY-FAIL — Copy Fail - CVE-2026-31431 - Hardened C implementation for redteam and authorized penetration testing operations. ⚠️ Legal Notice: This tool is intended solely for authorized security research, authorized penetration testing, and defensive analysis. Use on systems you own or have explicit written permission to test. Unauthorized access to computer systems is illegal. | Kitploit
Tools/GitLabGitLab/toxy4ny/copy-fail
Privilege EscalationExploitationPost-ExploitationCommand and ControlRed TeamingPayload DevelopmentBinary Exploitation
GitLabtoxy4ny/copy-fail

COPY-FAIL

View Repository
1102 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

Copy Fail - CVE-2026-31431 - Hardened C implementation for redteam and authorized penetration testing operations. ⚠️ Legal Notice: This tool is intended solely for authorized security research, authorized penetration testing, and defensive analysis. Use on systems you own or have explicit written permission to test. Unauthorized access to computer systems is illegal.

Website
Share

Copy Fail -- CVE-2026-31431

Hardened C implementation for redteam and authorized penetration testing operations.

⚠️ Legal Notice: This tool is intended solely for authorized security research, authorized penetration testing, and defensive analysis. Use on systems you own or have explicit written permission to test. Unauthorized access to computer systems is illegal.

🚀 Primary development moved to GitLab.
This repository is actively maintained here. For issues and contributions, please use GitLab.


Table of Contents

  • Overview
  • Original Research
  • Our Improvements
  • Architecture
  • Build
  • Usage
  • Modules
  • Operational Security
  • Detection & Mitigation
  • Credits
  • License

Overview

This project is a hardened, production-ready C port of the CVE-2026-31431 ("Copy Fail") local privilege escalation exploit, originally disclosed by Theori and Xint on April 29, 2026.

The original proof-of-concept was written in Python and designed for research demonstration. This implementation transforms it into a redteam-grade toolkit with:

  • Zero disk artifacts (memfd-based fileless execution)
  • Automatic target discovery (setuid binary enumeration with MAC awareness)
  • Anti-forensics (cache dropping, timestamp restoration, self-destruction)
  • Operator control (signal-triggered execution with configurable timeouts)
  • Cross-platform static builds (x86_64, ARM64, RISC-V via musl/zig)

Original Research

CVE-2026-31431: Copy Fail

AttributeValue
Disclosure DateApril 29, 2026
ResearchersTheori (Jinoh Kang, Yonghwi Jin, Seunghyun Lee), Xint
Writeuphttps://copy.fail/
Original PoCtheori-io/copy-fail-CVE-2026-31431 (Python)
C Port (Baseline)tgies/copy-fail-c by Tony Gies
Affected KernelsLinux 4.14 -- 6.14 (before fix commit a664bf3d603d)
SeverityCVSS 7.8 (High) -- Local Privilege Escalation

Vulnerability Mechanism

The vulnerability resides in the Linux kernel's AF_ALG crypto subsystem. The authencesn AEAD template implements an in-place optimization for decryption: when ciphertext is supplied via splice() from a file's page cache, the kernel reuses the same page as both source and destination.

The attack flow:

  1. Open a setuid binary (e.g., /usr/bin/su) read-only
  2. Set up an authencesn(hmac(sha256),cbc(aes)) AEAD operation via AF_ALG
  3. Supply ciphertext via splice() from the target file's page cache
  4. The (failing) decrypt operation overwrites 4 bytes of the page cache page before authentication rejects it
  5. Repeat for each 4-byte window of the payload
  6. execve() the target -- the kernel loads mutated pages from cache, grants setuid-root creds
  7. Payload pivots to full root shell

Key insight: The on-disk inode is never modified. Only the in-memory page cache is mutated, making forensic detection significantly harder than traditional file overwrite exploits.


Our Improvements

This project extends the original research with redteam-oriented hardening across nine modules.

1. Hardened Exploit Primitive (patch_chunk.c)

FeatureOriginalOur Implementation
Socket managementFresh socket per chunkSocket reuse (~60% fewer syscalls)
VerificationNonemmap + memcmp with auto-retry (3 attempts)
Parallel writesSequential onlyFork-based parallel (up to 16 procs)
Error codesBinary success/failGranular: 0=verified, 1=patched kernel, -1=fatal
Heap allocationsmalloc in hot pathStack-only (no alloc jitter)

2. Automatic Target Discovery (target_discovery.c)

  • Three-phase scanning: priority targets → standard dirs → deep scan
  • MAC-aware scoring: penalizes binaries with AppArmor/SELinux profiles
  • 18 priority targets: su, sudo, passwd, pkexec, mount, ping, etc.
  • Fallback chain: if primary target fails, auto-selects next best candidate
  • Snap awareness: skips /snap (non-traditional setuid)

3. Anti-Forensics Suite (anti_forensics.c)

TechniquePurpose
posix_fadvise(POSIX_FADV_DONTNEED)Per-file page cache eviction
echo 3 > /proc/sys/vm/drop_cachesGlobal cache drop (post-root)
utimensat() timestompRestore original atime/mtime
Self-destructOverwrite dropper binary with zeros before exec
Memory wipevolatile zeroing of sensitive buffers

4. Fileless Execution (memfd_exec.c)

  • memfd_create + fexecve: execute without filesystem path
  • Cloaking: memfd named as kworker, anon_inode, eventfd (blends in /proc/$pid/fd/)
  • Fork-and-forget: double-fork to create orphan process (PPID=1)
  • In-memory decryption: XOR and RC4 decrypt-then-exec (payload never plaintext on disk)

5. Stage-1 Payload Delivery (stage1.c)

ChannelStealthSpeedFallback Priority
EmbeddedMaximumInstantLast (airgap)
HTTP directMedium<1sFirst
System curl/wgetLow1-3sSecond (HTTPS support)
DNS TXTHighSlowThird (firewall bypass)

6. Stage-2 C2 Implant (stage2_template.c)

  • Resilient reconnect loop with exponential backoff
  • Three distributions: uniform, triangular, exponential jitter
  • Signal control: SIGUSR1 (trigger), SIGUSR2 (status), SIGTERM (shutdown)
  • DNS beaconing: stealthy C2 health check before TCP connect
  • Process masquerade: [kworker/N:0] in ps/top

7. Process Hiding (proc_hide.c)

  • argv[0] overwrite: in-place replacement of /proc/$pid/cmdline
  • prctl(PR_SET_NAME): kernel thread-style names (16-byte limit)
  • Environment sanitization: selective wipe of SSH_*, AWS_*, TOKEN*, etc.
  • Parent detachment: setsid() + setpgid() for terminal independence

8. Signal Trigger Control (signal_trigger.c)

ModeBehaviorUse Case
trigger_oneshot()Sleep → trigger → execute → exitHit-and-run
trigger_daemon()Sleep → trigger → execute → loopPersistent implant
trigger_auto()Sleep with timeout fallbackUnattended ops

Zero-CPU waiting: sigsuspend() instead of polling loops.

9. Sleep Jitter (sleep_jitter.c)

  • Three RNG backends: getrandom(2), /dev/urandom, rdtsc fallback
  • Rejection sampling: eliminates modulo bias in uniform distribution
  • Drift compensation: sleep_scheduled() maintains average interval despite jitter
  • Sandbox detection: check_sandbox_acceleration() detects patched sleep()

Architecture

Download Tool