Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Linux 2.6.0-2.6.19 udp_sendmsg() x86/x64 Local Root Exploit

Loading...

Sign in or sign up now!
2,584
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Sep 1, 2009

Exploits the recent udp_sendmsg() bug found by Julien Tinnes/Tavis Ormandy. Does not require an executable NULL mapping and is 100% stealthy. The vulnerability is interesting, as the path to userland code execution is about 4 functions deep and hidden by a netfilter macro. By forging the dereferenced structure correctly, I'm able to avoid an alerting printk. The exploit is demonstrated on Fedora Core 5 and RHEL 5.3.

Exploit was written in a matter of minutes after I reversed the path to userland code execution. 90% of the code is just reused from Cheddar Bay/Wunderbar Emporium. I have updated the SELinux disabling payload to support older kernels that compiled a particular function differently.

Sorry, no fancy pictures or video in this one.

Category:

Comedy

Tags:

License:

Standard YouTube License

  • likes, 0 dislikes

Link to this comment:

Share to:

All Comments (0)

Sign In or Sign Up now to post a comment!
Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more