## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-BALDASSARREFE-FEP3370-ADVANCED-ETHICAL-HACKING
# DynoRoot CVE-2018-1111
#### Final project for the course Advanced Ethical Hacking at KTH, Stockholm
This project demonstrates a known vulnerability of Fedora and RedHat machines related to an unsafe client-side implementation of the Dynamic Host Configuration Protocol (DHCP). A rogue DHCP server can craft DHCP offers with a malicious payload that gets executed in a root shell on the victim machine.
The vulnerability is credited to Felix Wilhelm and is known as CVE-2018-1111 or "DynoRoot".

### Table of contents:
* Introduction
* Background
* Vulnerability
* Sources
*
DHCP Session (figure from , under license). Minimal exploit setup. Private network setup with one gateway machine acting as DHCP, router and firewall. /> Installation screenshot: network configuration. Installation screenshot: user creation. Installation screenshot: user creation. Installation screenshot: network configuration. Installation screenshot: user creation. Packet capture of the attack, the DHCP option related to the exploit is highlighted. The letters in the MAC addresses stand for: DHCP server, attacker, Fedora victim