|
Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
|
|
|
|
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â |
±Û¾´ÀÌ |
¸Þ½ÃÁö |
sCag ¼Õ´Ô
|
¿Ã·ÁÁü: 2009.8.17 ¿ù, 2:35 pm ÁÖÁ¦: ¸®´ª½º, ·ÎÄÿ¡¼ root±ÇÇÑ È¹µæ Ãë¾àÁ¡ (sock_sendpage() ¹®Á¦) |
|
|
¸®´ª½º sock_sendpage() ÇÔ¼ö ¹®Á¦·Î ÀÎÇØ local¿¡¼ root±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ ¹ßÇ¥µÇ¾ú´Ù. ÀÌ¹Ì exploitµµ °ø°³µÈ »óÅÂ
1. ±âº» Á¤º¸
Àοë: |
All Linux 2.4/2.6 versions since May 2001 are believed to be affected:
Linux 2.4, from 2.4.4 up to and including 2.4.37.4
Linux 2.6, from 2.6.0 up to and including 2.6.30.4 |
2) °ü·Ã±Û
* http://hkpco.egloos.com/1497308
* https://bugzilla.redhat.com/show_bug.cgi?id=516949#c10
* Linux NULL pointer dereference due to incorrect proto_ops initializations (CVE-2009-2692)
2. Á¶Ä¡ »çÇ×
1) ÀÓ½Ã
http://rfxn.com/downloads/set_mmap_minaddr ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇØ¼ Àӽ÷ΠĿ³Î ÆÄ¸®¹ÌÅ͸¦ Æ©´×ÇÑ´Ù.
ÀÌ ½ºÅ©¸³Æ®´Â /proc/sys/vm/mmap_min_addr ÆÄÀÏÀÌ ÀÖ´Ù¸é(Áï, mmap_min_addr ±â´ÉÀÌ ÀÖ´Â Ä¿³Î)
sysctlÀ» ÀÌ¿ëÇØ¼ °ªÀ» 4096À¸·Î ¼³Á¤ÇÑ´Ù.
mmap_min_addr ±â´ÉÀÌ ÀÖ´Â Ä¿³ÎÀº vm.mmap_min_addr °ªÀÌ 0 º¸´Ù Å« °ªÀÏ °æ¿ì Ãë¾àÁ¡À» ¸·À» ¼ö Àֱ⠶§¹®ÀÌ´Ù.
Ubuntu 9.04, CentOS 5.3 µîÀº ÀÌ °ªÀÌ 65536ÀÓ.
Àοë: |
$ sysctl vm.mmap_min_addr
vm.mmap_min_addr = 65536 |
2) µ¥ºñ¾È Ä¿³Î ¾÷µ¥ÀÌÆ®
DSA-1864-1 linux-2.6.24 -- privilege escalation
http://www.debian.org/security/2009/dsa-1864
DSA-1862-1 linux-2.6 -- privilege escalation
http://www.debian.org/security/2009/dsa-1862
3. exploitÀÌ ¾ÈµÇ´Â °æ¿ì
Àοë: |
°æ¿ì 1)
$ ./wunderbar_emporium.sh
[+] Personality set to: PER_SVR4
Pulseaudio does not exist!
°æ¿ì 2)
$ ./wunderbar_emporium.sh
[+] MAPPED ZERO PAGE!
[+] Resolved commit_creds to 0xc0135793
[+] Resolved prepare_kernel_cred to 0xc013593b
unable to find a vulnerable domain, sorry
$
|
8.17(¿ù) Ä¿ÇǴнº¿¡¼ À̾߱âµÈ ³»¿ëÀ» °£´ÜÈ÷ Á¤¸® |
|
À§·Î |
|
 |
|
|
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù ¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù
|
Powered by phpBB © 2001, 2005 phpBB Group
|