david942j / one_gadget

The best tool for finding one gadget RCE in libc.so.6

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

No gadgets found on F34 x86_64 libc

r3pek opened this issue · comments

Well, the subject says it all

I'll leave the library attached here:

libc-2.33.so.gz

Seems can be resolved by #121

Hi @r3pek

I just released one_gadget v1.8.0 which adds posix_spawn support.
Please give it a try.

$ one_gadget --version
OneGadget Version 1.8.0
$ one_gadget libc-2.33.so
0xebc0a posix_spawn(rsp+0x64, "/bin/sh", [rsp+0x38], 0, rsp+0x70, [rsp+0xf0])
constraints:
  [rsp+0x70] == NULL
  [[rsp+0xf0]] == NULL || [rsp+0xf0] == NULL
  [rsp+0x38] == NULL || (s32)[[rsp+0x38]+0x4] <= 0

0xebc12 posix_spawn(rsp+0x64, "/bin/sh", [rsp+0x38], 0, rsp+0x70, r9)
constraints:
  [rsp+0x70] == NULL
  [r9] == NULL || r9 == NULL
  [rsp+0x38] == NULL || (s32)[[rsp+0x38]+0x4] <= 0

0xebc17 posix_spawn(rsp+0x64, "/bin/sh", rdx, 0, rsp+0x70, r9)
constraints:
  [rsp+0x70] == NULL
  [r9] == NULL || r9 == NULL
  rdx == NULL || (s32)[rdx+0x4] <= 0