Ingeniero. Desarrollador de software. Organizador y liante oficial de eventos de birras. Escéptico, campechano, revoltoso y atolondrado. Newbie hacker.
Lo que tengo:
1. UAF + ARW
2. Resolución dinámica de bases
3. Tabla de syscalls userland
4. Gadgets ROP userland básicos (6/26)
5. Dump RAM kernel 13.02 Ghidra
6. Dumpeador funcional
Lo que me falta:
1. Vector de ataque al kernel 13.02
2. Gadgets ROP userland restantes (~20)
@Lawrence_Ortiz Son las referencias que usa poopsploit 26 gadgets. De momento solo tengo 6, utiles para tartar de actualizar las referencias y ver si sigue funcionando.
@cjtl_2 La verdad es que no tengo nada. Pero día a día avanzo en este nuevo vicio de tratar de entender y sacar algo de provecho. Soy nuevo completamente, pero por cabezon lo saco. Me cansé de esperar la update y luego a Gezine. Si el puede el resto también.
@okaua021 6. an internal analysis to search for the KEX, if it exists. And this is the best-case scenario. As you can see, it takes time and luck, and now you need a Blu-ray burner to get started.
@okaua021 5. If a KEX is found, we’ll need to figure out how to trigger a payload to load the GoldHen version on 13.02. Current status: we’ve managed to open the vault door; next step is to figure out how to open each of the padlocked boxes inside the vault. We still need to perform
@okaua021 4. tested it. If it works, this could let you read memory and access files that you previously listed but couldn’t read. If this works, you’ll be able to obtain system files, run them through Ghidra to view their contents, and decompile them to try to find a KEX (Kernel exploit)
@okaua021 3.or at least I haven’t managed to achieve it.
On the other hand, there’s Gezine’s BDJ. This allows you to enter from the reader with root permissions (UUID=0, privilege escalation), unlike on the web where you’re just a web user (UUID=1). In theory, at least, since I haven’t
@okaua021 2.After reviewing WebKit, vue-after-free remains a valid method for uploading payloads and auditing the web user and the WebKit environment, which is contained within a jail—and I haven’t been able to escape from there. There’s no privilege escalation