欢迎来到 嗅灵易学

零基础也能上手的脚本技术课,一对一答疑带你入门

[原创]linux kernel pwn笔记

[原创]linux kernel pwn笔记

距离上一次说要更新kernel pwn的总结过去了很长时间,原因是最近学业繁忙,尤其是英语课为了拍一个小电影,身体被掏空。所以博客就没有再更新。今天准备把这一个月学习的kernel pwn知识总结一下,做个笔记。自己以后方便一些,希望其它入门的同学也能学到一些东西。

一些结构体

如果存在use after free,就可以利用这些结构体进行提权。

tty_struct的利用:

#include<tty.h>

Size:0x2e0

struct tty_operations

{

    struct tty_struct *(*lookup)(struct tty_driver *, struct file *, int); /*     0     8 */

    int (*install)(struct tty_driver *, struct tty_struct *);              /*     8     8 */

    void (*remove)(struct tty_driver *, struct tty_struct *);              /*    16     8 */

    int (*open)(struct tty_struct *, struct file *);                       /*    24     8 */

    void (*close)(struct tty_struct *, struct file *);                     /*    32     8 */

    void (*shutdown)(struct tty_struct *);                                 /*    40     8 */

    void (*cleanup)(struct tty_struct *);                                  /*    48     8 */

    int (*write)(struct tty_struct *, const unsigned char *, int);         /*    56     8 */

    /* --- cacheline 1 boundary (64 bytes) --- */

    int (*put_char)(struct tty_struct *, unsigned char);                            /*    64     8 */

    void (*flush_chars)(struct tty_struct *);                                       /*    72     8 */

    int (*write_room)(struct tty_struct *);                                         /*    80     8 */

    int (*chars_in_buffer)(struct tty_struct *);                                    /*    88     8 */

    int (*ioctl)(struct tty_struct *, unsigned int, long unsigned int);             /*    96     8 */

    long int (*compat_ioctl)(struct tty_struct *, unsigned int, long unsigned int); /*   104     8 */

    void (*set_termios)(struct tty_struct *, struct ktermios *);                    /*   112     8 */

    void (*throttle)(struct tty_struct *);                                          /*   120     8 */

    /* --- cacheline 2 boundary (128 bytes) --- */

    void (*unthrottle)(struct tty_struct *);           /*   128     8 */

    void (*stop)(struct tty_struct *);                 /*   136     8 */

    void (*start)(struct tty_struct *);                /*   144     8 */

    void (*hangup)(struct tty_struct *);               /*   152     8 */

    int (*break_ctl)(struct tty_struct *, int);        /*   160     8 */

    void (*flush_buffer)(struct tty_struct *);         /*   168     8 */

    void (*set_ldisc)(struct tty_struct *);            /*   176     8 */

    void (*wait_until_sent)(struct tty_struct *, int); /*   184     8 */

    /* --- cacheline 3 boundary (192 bytes) --- */

    void (*send_xchar)(struct tty_struct *, char);                           /*   192     8 */

    int (*tiocmget)(struct tty_struct *);                                    /*   200     8 */

    int (*tiocmset)(struct tty_struct *, unsigned int, unsigned int);        /*   208     8 */

    int (*resize)(struct tty_struct *, struct winsize *);                    /*   216     8 */

    int (*set_termiox)(struct tty_struct *, struct termiox *);               /*   224     8 */

    int (*get_icount)(struct tty_struct *, struct serial_icounter_struct *); /*   232     8 */

    const struct file_operations *proc_fops;                                 /*   240     8 */

    /* size: 248, cachelines: 4, members: 31 */

    /* last cacheline: 56 bytes */

};

我们来看一下内核中关于tty的源码

static void __init unix98_pty_init(void)

{

    ptm_driver = tty_alloc_driver(NR_UNIX98_PTY_MAX,

            TTY_DRIVER_RESET_TERMIOS |

            TTY_DRIVER_REAL_RAW |

            TTY_DRIVER_DYNAMIC_DEV |

            TTY_DRIVER_DEVPTS_MEM |

            TTY_DRIVER_DYNAMIC_ALLOC);

    if (IS_ERR(ptm_driver))

        panic("Couldn't allocate Unix98 ptm driver");

    pts_driver = tty_alloc_driver(NR_UNIX98_PTY_MAX,

            TTY_DRIVER_RESET_TERMIOS |

            TTY_DRIVER_REAL_RAW |

            TTY_DRIVER_DYNAMIC_DEV |

            TTY_DRIVER_DEVPTS_MEM |

            TTY_DRIVER_DYNAMIC_ALLOC);

    if (IS_ERR(pts_driver))

        panic("Couldn't allocate Unix98 pts driver");

ptm_driver->driver_name = "pty_master";

    ptm_driver->name = "ptm";

    ptm_driver->major = UNIX98_PTY_MASTER_MAJOR;

    ptm_driver->minor_start = 0;

    ptm_driver->type = TTY_DRIVER_TYPE_PTY;

    ptm_driver->subtype = PTY_TYPE_MASTER;

    ptm_driver->init_termios = tty_std_termios;

    ptm_driver->init_termios.c_iflag = 0;

    ptm_driver->init_termios.c_oflag = 0;

    ptm_driver->init_termios.c_cflag = B38400 | CS8 | CREAD;

    ptm_driver->init_termios.c_lflag = 0;

    ptm_driver->init_termios.c_ispeed = 38400;

    ptm_driver->init_termios.c_ospeed = 38400;

    ptm_driver->other = pts_driver;

    tty_set_operations(ptm_driver, &ptm_unix98_ops);

pts_driver->driver_name = "pty_slave";

    pts_driver->name = "pts";

    pts_driver->major = UNIX98_PTY_SLAVE_MAJOR;

    pts_driver->minor_start = 0;

    pts_driver->type = TTY_DRIVER_TYPE_PTY;

    pts_driver->subtype = PTY_TYPE_SLAVE;

    pts_driver->init_termios = tty_std_termios;

    pts_driver->init_termios.c_cflag = B38400 | CS8 | CREAD;

    pts_driver->init_termios.c_ispeed = 38400;

    pts_driver->init_termios.c_ospeed = 38400;

    pts_driver->other = ptm_driver;

    tty_set_operations(pts_driver, &pty_unix98_ops);

if (tty_register_driver(ptm_driver))

        panic("Couldn't register Unix98 ptm driver");

    if (tty_register_driver(pts_driver))

        panic("Couldn't register Unix98 pts driver");

/* Now create the /dev/ptmx special device */

    tty_default_fops(&ptmx_fops);

    ptmx_fops.open = ptmx_open;

cdev_init(&ptmx_cdev, &ptmx_fops);

    if (cdev_add(&ptmx_cdev, MKDEV(TTYAUX_MAJOR, 2), 1) ||

        register_chrdev_region(MKDEV(TTYAUX_MAJOR, 2), 1, "/dev/ptmx") < 0)

        panic("Couldn't register /dev/ptmx driver");

    device_create(tty_class, NULL, MKDEV(TTYAUX_MAJOR, 2), NULL, "ptmx");

}

tty_set_operations(ptm_driver, &ptm_unix98_ops);

将全局变量ptm_drivere de ops 设置成ptm_unix98_ops,

注意:上传附件及图片大小不得大于30M。

⚠️ 版权声明:
本博客所有内容(含教程、源码、工具)仅供个人技术学习与研究交流使用,严禁商用、倒卖、二次分发及非法用途
未经作者书面授权,任何组织或个人不得转载、复制或用于其他平台,违者将追究相关责任。

0 0 0 举报
复制成功