Files
greyhack/source/privesc.src

210 lines
4.8 KiB
Plaintext

if params.len > 0 and (params[0] == "-h" or params[0] == "--help") then
current_program = get_shell.host_computer.File(program_path)
print "Usage: " + current_program.name + " [-h|<library path> [extra]]"
print " -h show this help message"
print " <library path> only exploit the specified library (e.g. /lib/init.so)"
print " extra optional overflow value to attempt"
print " (no args) try all libraries in /lib and current_path"
exit
end if
mx = include_lib("/lib/metaxploit.so")
if not mx then mx = include_lib(current_path + "/metaxploit.so")
if not mx then exit("Unable to load metaxploit.so")
computer = get_shell.host_computer
ends_with = function(s, suffix)
if s.len < suffix.len then return 0
return s[s.len - suffix.len : ] == suffix
end function
extra = ""
target_lib = null
if params.len > 0 then
if params[0].indexOf("/") != null or ends_with(params[0], ".so") then
target_lib = params[0]
if params.len > 1 then extra = params[1]
else
extra = params[0]
end if
end if
extract_value = function(line)
start = line.indexOf("<b>")
finish = line.indexOf("</b>")
if start == null or finish == null then return ""
if start == -1 or finish == -1 then return ""
if finish > start then
return line[start + 3 : finish]
end if
before_dot = line.split("\.")[0]
words = before_dot.split(" ")
value = ""
for word in words
if word != "" then value = word
end for
return value
end function
shell_user = function(sh)
comp = sh.host_computer
if not comp then return "guest"
rootf = comp.File("/root")
if rootf and rootf.has_permission("w") then return "root"
passwd = comp.File("/etc/passwd")
if passwd and passwd.has_permission("w") then return "root"
home = comp.File("/home")
if not home then return "guest"
folders = home.get_folders
if not folders then return "guest"
for folder in folders
if folder.name == "guest" then continue
if folder.has_permission("w") then return folder.name
end for
return "guest"
end function
known_paths = []
libs = []
add_lib_dir = function(dirpath)
folder = computer.File(dirpath)
if not folder then return
if not folder.is_folder then return
if not folder.has_permission("r") then return
files = folder.get_files
if not files then return
for f in files
if not f.has_permission("r") then continue
if not ends_with(f.name, ".so") then continue
already = 0
for p in known_paths
if p == f.path then
already = 1
break
end if
end for
if already then continue
lib = mx.load(f.path)
if not lib then continue
known_paths.push f.path
libs.push {
"path": f.path,
"name": lib.lib_name,
"version": lib.version,
"lib": lib,
}
end for
end function
if target_lib then
lf = computer.File(target_lib)
if not lf then exit("Unable to locate library: " + target_lib)
lib = mx.load(target_lib)
if not lib then exit("Unable to load library: " + target_lib)
libs.push {
"path": target_lib,
"name": lib.lib_name,
"version": lib.version,
"lib": lib,
}
else
add_lib_dir "/lib"
if current_path != "/lib" then add_lib_dir(current_path)
end if
if libs.len == 0 then
print "Nothing found"
exit
end if
preferred = [
"kernel_module.so",
"init.so",
"net.so",
"kernel_router.so",
]
ordered = []
for name in preferred
for item in libs
if ends_with(item.path, "/" + name) or item.name == name then
ordered.push item
end if
end for
end for
for item in libs
already = 0
for o in ordered
if o.path == item.path then
already = 1
break
end if
end for
if already then continue
ordered.push item
end for
libs = ordered
lines = "PATH LIBRARY VERSION"
for item in libs
lines = lines + "\n" + item.path + " " + item.name + " " + item.version
end for
print format_columns(lines)
try_overflow = function(lib, add, value)
of = lib.overflow(add, value)
if typeof(of) == "shell" then return of
if extra != "" then
of = lib.overflow(add, value, extra)
if typeof(of) == "shell" then return of
end if
return null
end function
user_shell = null
for item in libs
if not target_lib then
print "---"
print item.name
print "---"
end if
adds = mx.scan(item.lib)
if not adds then continue
for add in adds
info = mx.scan_address(item.lib, add)
if not info then continue
parts = info.split("Unsafe check:")
first = 1
for part in parts
if first then
first = 0
continue
end if
value = extract_value(part)
if value == "" then continue
of = try_overflow(item.lib, add, value)
if typeof(of) != "shell" then continue
user = shell_user(of)
if user == "root" then
of.start_terminal
exit
end if
if active_user == "guest" and user != "guest" and user != active_user then
if not user_shell then user_shell = of
end if
end for
end for
end for
if active_user == "guest" and user_shell then
user_shell.start_terminal
exit
end if
print "Nothing found"