
Esfuerzo de investigación de 1 día
Este repositorio contiene mi trabajo en implementar torpemente un exploit 1day público para el bug de sudo. Deséame suerte.
Si deseas ayudar, siéntete libre.
Compila el src/sudo proporcionado
sudoedit ha sido modificado para usar el harness de AFL para obtener entrada desde STDIN
Casos de prueba de crash del bucle difuso de AFL descubiertos hasta ahora, échales un vistazo:
-rw------- 1 root root 309 Jan 28 03:31 id:000000,sig:11,src:000024,time:335,op:havoc,rep:2
-rw------- 1 root root 309 Jan 28 03:31 id:000001,sig:06,src:000024,time:1419,op:havoc,rep:4
-rw------- 1 root root 278 Jan 28 03:31 id:000002,sig:06,src:000024,time:2545,op:havoc,rep:8
-rw------- 1 root root 300 Jan 28 03:31 id:000003,sig:11,src:000024,time:5812,op:havoc,rep:4
-rw------- 1 root root 309 Jan 28 03:31 id:000004,sig:11,src:000024,time:7063,op:havoc,rep:8
-rw------- 1 root root 296 Jan 28 03:31 id:000005,sig:11,src:000024,time:8231,op:havoc,rep:8
-rw------- 1 root root 309 Jan 28 03:31 id:000006,sig:11,src:000024,time:8395,op:havoc,rep:2
-rw------- 1 root root 310 Jan 28 03:31 id:000007,sig:11,src:000024,time:9048,op:havoc,rep:8
-rw------- 1 root root 277 Jan 28 03:31 id:000008,sig:11,src:000024,time:9305,op:havoc,rep:16
-rw------- 1 root root 281 Jan 28 03:31 id:000009,sig:06,src:000024,time:11059,op:havoc,rep:2
-rw------- 1 root root 232 Jan 28 03:31 id:000010,sig:11,src:000024,time:13883,op:havoc,rep:4
-rw------- 1 root root 304 Jan 28 03:31 id:000011,sig:11,src:000024,time:17245,op:havoc,rep:8
-rw------- 1 root root 265 Jan 28 03:31 id:000012,sig:06,src:000024,time:18928,op:havoc,rep:8
-rw------- 1 root root 309 Jan 28 03:31 id:000013,sig:11,src:000024,time:21131,op:havoc,rep:8
-rw------- 1 root root 309 Jan 28 03:31 id:000014,sig:09,src:000024,time:29628,op:havoc,rep:4
-rw------- 1 root root 306 Jan 28 03:32 id:000015,sig:11,src:000024,time:60593,op:havoc,rep:8
-rw------- 1 root root 284 Jan 28 03:32 id:000016,sig:06,src:000024,time:65998,op:havoc,rep:16
-rw------- 1 root root 91053 Jan 28 03:39 id:000017,sig:09,src:000026+000018,time:518485,op:splice,rep:8
-rw------- 1 root root 318 Jan 28 03:39 id:000018,sig:11,src:000026+000045,time:520493,op:splice,rep:2
-rw------- 1 root root 65399 Jan 28 03:42 id:000019,sig:06,src:000012,time:678458,op:havoc,rep:16
-rw------- 1 root root 65441 Jan 28 04:33 id:000020,sig:06,src:000009,time:3762442,op:havoc,rep:16
-rw------- 1 root root 303 Jan 28 04:44 id:000021,sig:11,src:000025+000034,time:4377085,op:splice,rep:4
-rw------- 1 root root 91045 Jan 28 04:46 id:000022,sig:06,src:000019+000058,time:4538775,op:splice,rep:16
-rw------- 1 root root 296 Jan 28 05:14 id:000023,sig:06,src:000051,time:6173954,op:havoc,rep:16
-rw------- 1 root root 279 Jan 28 06:10 id:000024,sig:11,src:000023+000037,time:9549571,op:splice,rep:4
sig:11 significa Segmentation Fault, que es lo que queremos. La señal 06 es SIGABRT, que nos dieron para empezar.
carga el sudoedit compilado (asegúrate de que tenga uid efectivo 0, ejecuta gdb como root)
# gdb /usr/local/bin/sudoedit
Carga el caso de crash desde src/afl3/out/default/crashes: (nota: este es el primer sigsegv que encontré, no es muy bueno; este id:000008 se puede encontrar en crashes_old)
gef➤ r < id:000008*
[ Legend: Modified register | Code | Heap | Stack | String ]
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── registers ────
$rax : 0x414196c9adb30e58
$rbx : 0x4141414141414140 ("@AAAAAAA"?)
$rcx : 0x000055886c706010 → 0x0000000000000007
$rdx : 0x4141414141414148 ("HAAAAAAA"?)
$rsp : 0x00007fffdfe911d0 → 0x00007fb17cea12d0 → "<- %s @ %s:%d := %s"
$rbp : 0x00007fb17ccceb80 → 0x0000000000000000
$rsi : 0x000055886c71cca0 → 0x4141414141414180
$rdi : 0x00007fb17ccceb80 → 0x0000000000000000
$rip : 0x00007fb17cb96a79 → <_int_free+409> mov rax, QWORD PTR [r13+0x8]
$r8 : 0x7
$r9 : 0x1
$r10 : 0xfffffffffffff1ed
$r11 : 0x5
$r12 : 0x000055886c71cca0 → 0x4141414141414180
$r13 : 0x414196c9adb30de0
$r14 : 0x00007fb17cccf578 → 0x000055886c71ccb0 → "AAAAAAAAAAAAAAAAAAAAAAAAARAAFAAAAAAAAAAAAAAAAAAAAA[...]"
$r15 : 0x00007fffdfe91290 → 0x00007fb17cc9bb5f → 0x636d656d5f5f0043 ("C"?)
$eflags: [zero CARRY PARITY ADJUST SIGN trap INTERRUPT direction overflow RESUME virtualx86 identification]
$cs: 0x0033 $ss: 0x002b $ds: 0x0000 $es: 0x0000 $fs: 0x0000 $gs: 0x0000
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── stack ────
0x00007fffdfe911d0│+0x0000: 0x00007fb17cea12d0 → "<- %s @ %s:%d := %s" ← $rsp
0x00007fffdfe911d8│+0x0008: 0x000055886c70e880 → 0x0000000000000043 ("C"?)
0x00007fffdfe911e0│+0x0010: 0x0000000000000000
0x00007fffdfe911e8│+0x0018: 0x000000017ce94e8e
0x00007fffdfe911f0│+0x0020: 0x0000000000000000
0x00007fffdfe911f8│+0x0028: 0x00007fb17cb416bb → <new_composite_name+203> test eax, eax
0x00007fffdfe91200│+0x0030: 0x00007fffdfe91290 → 0x00007fb17cc9bb5f → 0x636d656d5f5f0043 ("C"?)
0x00007fffdfe91208│+0x0038: 0xdfb8629d88483900
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── code:x86:64 ────
0x7fb17cb96a69 <_int_free+393> je 0x7fb17cb97018 <_int_free+1848>
0x7fb17cb96a6f <_int_free+399> test BYTE PTR [rbp+0x4], 0x2
0x7fb17cb96a73 <_int_free+403> je 0x7fb17cb97028 <_int_free+1864>
→ 0x7fb17cb96a79 <_int_free+409> mov rax, QWORD PTR [r13+0x8]
0x7fb17cb96a7d <_int_free+413> test al, 0x1
0x7fb17cb96a7f <_int_free+415> je 0x7fb17cb97050 <_int_free+1904>
0x7fb17cb96a85 <_int_free+421> mov r14, rax
0x7fb17cb96a88 <_int_free+424> and r14, 0xfffffffffffffff8
0x7fb17cb96a8c <_int_free+428> cmp rax, 0x10
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── threads ────
[#0] Id 1, Name: "sudoedit", stopped 0x7fb17cb96a79 in _int_free (), reason: SIGSEGV
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── trace ────
[#0] 0x7fb17cb96a79 → _int_free(av=0x7fb17ccceb80 <main_arena>, p=0x55886c71cca0, have_lock=<optimized out>)
[#1] 0x7fb17cb41e5c → setname(name=0x7fb17cc9bb5f <_nl_C_name> "C", category=0xb)
[#2] 0x7fb17cb41e5c → __GI_setlocale(category=0xb, locale=<optimized out>)
[#3] 0x7fb17c70cc59 → sudoers_setlocale(locale_type=0x1, prev_locale=<optimized out>)
[#4] 0x7fb17c722336 → sudoers_policy_main(argc=<optimized out>, argv=<optimized out>, pwflag=0x0, env_add=<optimized out>, verbose=0x0, closure=0x7fffdfe93488)
[#5] 0x7fb17c71d65e → sudoers_policy_check(argc=0x7, argv=0x55886c709570, env_add=0x0, command_infop=0x7fffdfe93520, argv_out=0x7fffdfe93558, user_env_out=0x7fffdfe93540, errstr=0x7fffdfe93620)
[#6] 0x55886b1185db → policy_check(argc=0x7, argv=0x55886c709570, env_add=0x0, command_info=0x7fffdfe93520, argv_out=0x7fffdfe93558, user_env_out=0x7fffdfe93540)
[#7] 0x55886b1185db → main(argc=<optimized out>, argv=<optimized out>, envp=0x7fffdfe94758)
───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
gef➤