Login Register
The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


How To Find If Your Kernel Is Vuln To Public Local Root Exploitation filter_list
Author
Message
RE: How To Find If Your Kernel Is Vuln To Public Local Root Exploitation #11
(02-22-2014, 02:34 AM)tropic Wrote: I disagree. RHEL/Centos boxes use backported kernels. A skid who is unaware of this will run an exploit for '2.6.32' without taking in regard the date when the particular kernel was compiled. This is why pasting the unames of backported kernels to ksplice inspector is futile.

A backported kernel may not be vulnerable to some of the newer exploits, conversely, it may also contain a vulnerability which has been patched in other kernelsdue to neglect (refer to CVE-2010-3081 and CVE: 2010-3081) .

Yes but the point of this tutorial is not to get someone to actually root the kernel they found, but to instead get the person used to using CLI in shells rather than just uploading and browsing files. If someone is able to actually root who is reading this tutorial, then what's the point? I'm quite sure that if someone knows how to root a kernel, they will know how to find if the kernel is actually vulnerable.

This tutorial is nothing more than giving people something new to do with shells or connectbacks. You are right though, I should add something in to cover this.
[Image: F4Z9Dqw.png]

Reply

RE: How To Find If Your Kernel Is Vuln To Public Local Root Exploitation #12
(01-28-2014, 03:36 AM)Adorapuff Wrote: I'm going to disagree here.
I've run into many kernels that start with say the 2.6.32 as mentioned, but the revision removes the vulnerability. At least go right after the hyphen to 220. You should be fine running the 2.6.32 exploit, but if it does not work try and be more specific.
Never the less, great tutorial BreShie. Now kiddies, don't havij a site, find a vuln on exploitdb, figure out how it works, what causes it, and understand the exploit code. Using that exploit you understand, go and "pwn a site", root it, and have some fun. I guarantee its more fun then havij (From personal experience as I used to use havij in the past but not any more), a lot more satisfactory, and you understand whats going on so you can learn something. Now that you can dissect 0days, you can write your own. exploitdb is flooded with wordpress themes for a reason. Its because for the most part, they all have the same vulnerabilities going on. Download some themes from mafiashare and find some vulns, release them, and don't be a skid.

tldr; read it

This.

(I hate it when you don't write in paragraphs..)

Reply

RE: How To Find If Your Kernel Is Vuln To Public Local Root Exploitation #13
Well, I was going to make a post ripping on you, but it seems I've been beaten to it.
Damn.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: How To Find If Your Kernel Is Vuln To Public Local Root Exploitation #14
(02-22-2014, 02:34 AM)tropic Wrote: I disagree. RHEL/Centos boxes use backported kernels. A skid who is unaware of this will run an exploit for '2.6.32' without taking in regard the date when the particular kernel was compiled. This is why pasting the unames of backported kernels to ksplice inspector is futile. The part where it shows '220.7.1' is useful because you can look it up and view repo/git/launchpad comments on vulnerabilities.

A backported kernel may not be vulnerable to some of the newer exploits, conversely, it may also contain a vulnerability which has been patched in other kernels due to neglect (refer to CVE-2010-3081 and CVE-2013-2094) .

How would you approach something like this yourself?

Reply







Users browsing this thread: