Skip to content
KitploitKITPLOIT
ИнструментыБлог
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
CVE-2022-27666 | Kitploit
Инструменты/GitHubGitHub/ngtuonghung/cve-2022-27666
Криминалистика памятиАнализ уязвимостейЭксплуатацияОтладчикиЭксплуатация Бинарных Файлов
GitHubngtuonghung/cve-2022-27666

CVE-2022-27666

Репозиторий
3 месяцев назадЕщё не проверено

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться

CVE-2022-27666

Переполнение буфера в куче в реализации IPsec ESP6 в ядре Linux (linux 5.13.19).


Настройка (предполагается, что вы root)

1. Сборка ядра (в виртуальной машине)

Установка зависимостей:

root@kitploit:~
apt update && apt install -y \
    build-essential bc bison flex \
    libssl-dev libelf-dev libncurses-dev \
    dwarves pahole gcc make wget xz-utils git python3 libfuse3-dev

Скачивание и распаковка:

root@kitploit:~
cd /home/ubuntu/
wget https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.13.19.tar.xz
tar xf linux-5.13.19.tar.xz
cd linux-5.13.19

Конфигурация:

root@kitploit:~
cp /boot/config-$(uname -r) .config
make olddefconfig

# Enable full debug symbols and GDB support
scripts/config --enable  CONFIG_DEBUG_INFO
scripts/config --enable  CONFIG_DEBUG_INFO_DWARF4
scripts/config --disable CONFIG_DEBUG_INFO_REDUCED
scripts/config --enable  CONFIG_FRAME_POINTER
scripts/config --enable  CONFIG_GDB_SCRIPTS

# Build ESP modules — CVE target
scripts/config --module  CONFIG_INET6_ESP
scripts/config --module  CONFIG_INET_ESP

# Disable KASLR for easier debugging
scripts/config --disable CONFIG_RANDOMIZE_BASE

# Disable module signing to load unsigned modules
scripts/config --disable CONFIG_MODULE_SIG
scripts/config --disable CONFIG_MODULE_SIG_FORCE
scripts/config --disable CONFIG_SYSTEM_TRUSTED_KEYS
scripts/config --disable CONFIG_SYSTEM_REVOCATION_KEYS

# Disable BTF to avoid pahole build errors
scripts/config --disable CONFIG_DEBUG_INFO_BTF

# Disable watchdog to prevent panic/reboot during GDB breakpoints
scripts/config --disable CONFIG_SOFTLOCKUP_DETECTOR
scripts/config --disable CONFIG_HARDLOCKUP_DETECTOR
scripts/config --disable CONFIG_DETECT_HUNG_TASK
scripts/config --disable CONFIG_WQ_WATCHDOG

make olddefconfig

Сборка и установка:

root@kitploit:~
make -j$(nproc) 2>&1 | tee ~/build.log

make modules_install
make install
update-grub

2. Загрузка в ядро 5.13.19

root@kitploit:~
# Find menu entry index
grep -E "menuentry|submenu" /boot/grub/grub.cfg | grep -v "^#" | head -20

# Set default (adjust index as needed)
vi /etc/default/grub
# GRUB_DEFAULT="1>2"

update-grub
reboot

Проверка после перезагрузки:

root@kitploit:~
uname -r          # should print 5.13.19

# Auto-load esp6 on boot and load it now
echo "esp6" >> /etc/modules
modprobe esp6

# Verify
modinfo esp6
grep CONFIG_INET6_ESP /boot/config-5.13.19   # CONFIG_INET6_ESP=m

Отключите ненужные службы, чтобы ускорить загрузку и избежать помех во время тестирования:

root@kitploit:~
# Cloud / network wait
systemctl disable cloud-init cloud-config cloud-final \
    cloud-init-local systemd-networkd-wait-online

# Prevent crash reporter from interfering with kernel panics
systemctl disable apport

# Prevent random disk I/O during testing
systemctl disable apt-daily apt-daily-upgrade \
    apt-daily.timer apt-daily-upgrade.timer

# Not needed in a dev VM
systemctl disable snapd multipathd fwupd

Настройка отладки

Копирование vmlinux для символов (на хосте)

root@kitploit:~
IP=<VM-IP>
scp ubuntu@${IP}:~/linux-5.13.19/vmlinux .
scp ubuntu@${IP}:~/linux-5.13.19/net/ipv6/esp6.ko .
scp ubuntu@${IP}:/usr/bin/fusermount3 ./exploit/bin/
scp ubuntu@${IP}:/usr/lib/x86_64-linux-gnu/libfuse3.so.3 ./exploit/lib/
scp -r ubuntu@${IP}:/usr/include/fuse3 ./exploit/include/

Включение GDB-заглушки через QEMU/libvirt

Добавьте в XML определения домена:

root@kitploit:~
<domain type='kvm' xmlns:qemu='http://libvirt.org/schemas/domain/qemu/1.0'>
  ...
  <qemu:commandline>
    <qemu:arg value='-s'/>
  </qemu:commandline>
</domain>

Общий доступ к каталогу хоста для ВМ

Добавьте внутри <devices> в XML определения домена:

root@kitploit:~
<filesystem type='mount' accessmode='passthrough'>
  <source dir='/path/to/your/host/dir'/>
  <target dir='hostshare'/>
</filesystem>

Монтирование внутри ВМ:

root@kitploit:~
mkdir -p /pwn
mount -t 9p -o trans=virtio hostshare /pwn
Скачать инструмент