Linux_Exploit_CVE_2021_3490_d369d615
Description
Linux.Exploit.CVE-2021-3490
Query · yara
strings:
$c1 = "frame_dummy_init_array_entry"
$c2 = "leak_oob_map_ptr"
$c3 = "overwrite_cred"
$c4 = "obj_get_info_by_fd"
$c5 = "kernel_write_uint"
$c6 = "search_init_pid_ns_kstrtab"
$c7 = "search_init_pid_ns_ksymtab"
$msg1 = "failed to leak ptr to BPF map"
$msg2 = "preparing to overwrite creds..."
$msg3 = "success! enjoy r00t"
$msg4 = "Useage: %s <path to program to execute as root>"
$msg5 = "searching for init_pid_ns in ksymtab"
condition:
4 of them