EXPL_HKTL_LNX_DirtyFragLPE_May26
Description
Detects dirtyfrag, a local privilege escalation exploit for Linux.
Query · yara
strings:
// Indicators of exploitation attempts
$x1 = "gained CAP_NET_RAW within netn" ascii
$x2 = "DIRTYFRAG_VERBOSE" ascii
$s1 = { 15 7C 4A 7F B9 79 37 9E } // fc_splitmix64
$s2 = "/proc/self/setgroups" ascii fullword
$s3 = "pcbc(fcrypt)" ascii fullword
$s4 = { 17 bb c7 f3 3f 36 ba 71 8e 97 65 60 69 b6 f6 e6 }
condition:
filesize < 100KB
and uint32be(0) == 0x7f454c46
and (
1 of ($x*)
or 3 of ($s*)
)