Sploitus

Exploit for Immunity Canvas: LINUX_PTRACE_SETREGS

canvas Β· 2013-02-18

Exploit Code

MARKDOWN38 lines
## https://sploitus.com/exploit?id=LINUX_PTRACE_SETREGS
**Name**|  linux_ptrace_setregs  
---|---  
**CVE**|  CVE-2013-0871  
**Exploit Pack**|  [CANVAS](<http://http://www.immunityinc.com/products-canvas.shtml>)  
**Description**| linux_ptrace_setregs local root  
**Notes**| Repeatability: Infinite  
Notes:   
  
Vulnerable kernels &lt;= 3.5 64-bit only.  
  
Tested on:  
\- Ubuntu 12.10 64bit  
\- Ubuntu 12.04 64bit  
\- Debian 6 64bit  
  
Besides running the module inside CANVAS (which requires an existing MOSDEF connection)  
one can simply upload the exploit executable (CANVAS_ROOT/exploits/linux_ptrace_setregs/Resources/x)  
to the target machine and execute it.  
  
./x -h  
  
Usage: ./x   
  
Options: -h this help message  
-x  (default: 64)  
-n  (default: 19)  
-i  (default: 5)  
-s  (default: 10)  
-u  (default: autodetect)  
-z  (default: 0)  
-f  (default: random)  
-t  (default: /tmp)  
  
  
VENDOR: Linux  
CVE Url: https://vulners.com/cve/CVE-2013-0871  
CVE Name: CVE-2013-0871