Skip to content

Instantly share code, notes, and snippets.

@christianparpart
Created October 11, 2018 12:27
Show Gist options
  • Select an option

  • Save christianparpart/2a389cc4fa538383eed3c136ab0478f4 to your computer and use it in GitHub Desktop.

Select an option

Save christianparpart/2a389cc4fa538383eed3c136ab0478f4 to your computer and use it in GitHub Desktop.
// trapni@starfall [~] > cat blah.cc
#include <stdio.h>
#include <stdlib.h>
#include <sys/types.h>
#include <unistd.h>
int main()
{
// EUID is 0 already (because binary's setuid bit is set and binary's uid=0).
// Now we can use that to set UID to 0.
setuid(0);
// Proof:
printf("uid=%d, euid=%d, gid=%d\n", getuid(), geteuid(), getgid());
return EXIT_SUCCESS;
}
// trapni@starfall [~] > gcc -o blah blah.cc
// trapni@starfall [~] > sudo chown root:root ./blah
// trapni@starfall [~] > sudo chmod 04755 blah
// trapni@starfall [~] > ./blah
// uid=0, euid=0, gid=1008
// trapni@starfall [~] >
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment