Sploitus

Exploit for FEP3370-advanced-ethical-hacking

kitploit Β· 2026-09-09

Exploit Code

MARKDOWN19 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-BALDASSARREFE-FEP3370-ADVANCED-ETHICAL-HACKING
# DynoRoot CVE-2018-1111

#### Final project for the course Advanced Ethical Hacking at KTH, Stockholm

This project demonstrates a known vulnerability of Fedora and RedHat machines related to an unsafe client-side implementation of the Dynamic Host Configuration Protocol (DHCP). A rogue DHCP server can craft DHCP offers with a malicious payload that gets executed in a root shell on the victim machine.

The vulnerability is credited to Felix Wilhelm and is known as CVE-2018-1111 or "DynoRoot".

![](https://assets.kitploit.com/production/public/readmes/23114/de82a8bbb23835dcc4d0836fe7f906d9610b860d02a0e92b903191be840a799c.gif)

### Table of contents:

  * Introduction
    * Background
    * Vulnerability
    * Sources
  * 
DHCP Session (figure from , under  license). Minimal exploit setup. Private network setup with one gateway machine acting as DHCP, router and firewall. /> Installation screenshot: network configuration. Installation screenshot: user creation. Installation screenshot: user creation. Installation screenshot: network configuration. Installation screenshot: user creation. Packet capture of the attack, the DHCP option related to the exploit is highlighted. The letters in the MAC addresses stand for:  DHCP server,  attacker,  Fedora victim