Skip to content

Linux kernel exploitation experiments

License

Notifications You must be signed in to change notification settings

a13xp0p0v/kernel-hack-drill

Repository files navigation

Linux kernel exploitation experiments

This is a playground for the Linux kernel exploitation experiments. Only basic methods. Just for fun.

Contents:

  • drill_mod.c - a small Linux kernel module with nice vulnerabilities. You can interact with it via a simple procfs interface.
  • drill.h - a header file describing the drill_mod.ko interface.
  • drill_exploit_uaf_callback.c - a basic use-after-free exploit overwriting a callback in the drill_item_t struct.
  • drill_exploit_nullderef.c - a basic null-ptr-deref exploit, which uses wonderful mmap_min_addr bypass by Jann Horn.

N.B. Only basic exploit techniques here.

So compile your kernel with x86_64_defconfig and run it with pti=off nokaslr boot arguments.

Also don't forget to run qemu-system-x86_64 with -cpu qemu64,-smep,-smap.

License: GPL-3.0.

Have fun!

Repositories

About

Linux kernel exploitation experiments

Resources

License

Stars

Watchers

Forks

Releases

No releases published