Привет,
Я пытаюсь с этим, LG 55UF850V-ZB:
Linux LGwebOSTV 3.10.23-p.21.biscayne.lm15u.11 #1 SMP PREEMPT Wed May 29 06:42:58 UTC 2019 armv7l GNU/Linux
/var/run/nyx $ cat os_info.json
{
"core_os_kernel_version": "3.10.23-p.21.biscayne.lm15u.11",
"core_os_name": "Rockhopper",
"core_os_release": "2.2.1-2147",
"core_os_release_codename": "beehive-biscayne",
"encryption_key_type": "prodkey",
"webos_api_version": "4.1.0",
"webos_build_id": "2147",
"webos_imagename": "starfish-dvb-secured",
"webos_manufacturing_version": "04.05.85",
"webos_name": "webOS TV",
"webos_prerelease": "",
"webos_release": "2.2.1",
"webos_release_codename": "beehive-biscayne"
}
Но эксплойт не работает:
ssh -i webos_rsa -p 9922
prisoner@192.168.1.101 "TERM=xterm exec strace /media/developer/7181474_GetMeIn"
Enter passphrase for key 'webos_rsa':
execve ("/media/developer/7181474_GetMeIn", ["/media/developer/7181474_GetMeIn"], [/* 78 vars */]) = 0
uname ({sys="Linux", node="LGwebOSTV", ... }) = 0
brk (0) = 0xf5000
brk (0xf5ce0) = 0xf5ce0
set_tls (0xf54a0, 0x810d0, 0, 0xf2ff8, 0xf54a0) = 0
brk (0x116ce0) = 0x116ce0
brk (0x117000) = 0x117000
getuid32 () = 5292
getgid32 () = 5000
fstat64 (1, {st_mode=S_IFIFO|0600, st_size=0, ... }) = 0
mmap2 (NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x76d28000
---------------------------------------------------------------
MerrukTechnolog < webOS privelage escalation (
http://www.merruk.com)
---------------------------------------------------------------
write (1, "--------------------------------"..., 193) = 193
lstat64 ("/dev", {st_mode=S_IFDIR|0555, st_size=4096, ... }) = 0
GetMeIn: #* Opening memory device!
lstat64 ("/dev/mem", {st_mode=S_IFCHR|0660, st_rdev=makedev (1, 1), ... }) = 0
stat64 ("/dev/mem", {st_mode=S_IFCHR|0660, st_rdev=makedev (1, 1), ... }) = 0
stat64 ("/dev/mem", {st_mode=S_IFCHR|0660, st_rdev=makedev (1, 1), ... }) = 0
write (1, "GetMeIn: #* Opening memory devic"..., 36) = 36
open ("/dev/mem", O_RDWR|O_DSYNCGetMeIn: #! Cannot read memory device!
---------------------------------------------------------------
) = -1 EPERM (Operation not permitted)
write (1, "GetMeIn: #! Cannot read memory d"..., 104) = 104
exit_group (1) =?
+++ exited with 1 +++
Кто-нибудь сталкивается с той же проблемой?
Спасибо.