Add PoC for CVE-2025-32463 Sudo chroot EoP
This commit is contained in:
commit
a2edc57cb8
3 changed files with 65 additions and 0 deletions
26
chwoot-demo.c
Normal file
26
chwoot-demo.c
Normal file
|
|
@ -0,0 +1,26 @@
|
|||
/*
|
||||
Description: Simulate behavior of CVE-2025-32463 - sudo EoP via chroot.
|
||||
Possible future CTF challenge? :)
|
||||
gcc -Wall -o chwoot-demo chwoot-demo.c
|
||||
cp 4755 chwoot-demo
|
||||
mv chwoot-demo /usr/bin
|
||||
Then get a root shell as a low priv user
|
||||
*/
|
||||
#include <fcntl.h>
|
||||
#include <unistd.h>
|
||||
#include <sys/types.h>
|
||||
#include <grp.h>
|
||||
#include <netdb.h>
|
||||
|
||||
int main() {
|
||||
chdir("/tmp/stage");
|
||||
int saved_root = open("/",O_RDONLY);
|
||||
int saved_cwd = open(".",O_RDONLY);
|
||||
chroot("/tmp/stage");
|
||||
chdir("/");
|
||||
gethostbyname("woot");
|
||||
fchdir(saved_root);
|
||||
chroot(".");
|
||||
fchdir(saved_cwd);
|
||||
getgrnam("got root?");
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue