Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] mount-procfs 报错或执行异常(一个错误的反馈 #116

Open
neargle opened this issue Feb 23, 2025 · 1 comment
Open

[BUG] mount-procfs 报错或执行异常(一个错误的反馈 #116

neargle opened this issue Feb 23, 2025 · 1 comment

Comments

@neargle
Copy link
Member

neargle commented Feb 23, 2025

有人反馈 mount-procfs 报错,无法正常利用。

Image

2025/02/22 17:14:32 env GOTRACEBACK not found, trying to set GOTRACEBACK=crash then reload exploit.
2025/02/22 17:14:32 Execute Shell:./cdk_linux_amd64_thin_upx run mount-procfs /mnt/host_proc ps failed with error:signal: aborted (core dumped)
2025/02/22 17:14:32 if you see "(core dumped)" in former err output, means exploit success.

这其实是利用成功了,这个漏洞的利用需要触发 core dumped,而且当前 EXP 没有做成有回显的,所以导致利用成功之后,大家不清楚是否利用成功。利用成功的标识见截图红框。

@neargle
Copy link
Member Author

neargle commented Feb 23, 2025

有个不礼貌的人甚至在公开场合质疑这个 EXP。

虽然生气,但这里也暴露了 EXP 的输出和模式需要改进。当前 EXP 的两个问题,记一个 TODO:

  • 回显: 当前 EXP 没有做成有回显
  • 输出: 输出更合理一点,但这个漏洞的利用需要触发 core dumped

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant