1 2 3<!DOCTYPE html> 4<html class="writer-html5" lang="en" data-content_root="../"> 5<head> 6 <meta charset="utf-8" /><meta name="viewport" content="width=device-width, initial-scale=1" /> 7 8 <meta name="viewport" content="width=device-width, initial-scale=1.0" /> 9 <title>What is libxdk? — kernelXDK 0.0.1 documentation</title> 10 <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=80d5e7a1" /> 11 <link rel="stylesheet" type="text/css" href="../_static/css/theme.css?v=e59714d7" /> 12 <link rel="stylesheet" type="text/css" href="../_static/collapsible-lists/css/tree_view.css?v=a885cde7" /> 13 14 15
15<script src="../_static/jquery.js?v=5d32c60e"></script>
15 16
16<script src="../_static/_sphinx_javascript_frameworks_compat.js?v=2cd50e6c"></script>
16 17
17<script src="../_static/documentation_options.js?v=d45e8c67"></script>
17 18
18<script src="../_static/doctools.js?v=9bcbadda"></script>
18 19
19<script src="../_static/sphinx_highlight.js?v=dc90522c"></script>
19 20
20<script src="../_static/collapsible-lists/js/CollapsibleLists.compressed.js?v=73120307"></script>
20 21
21<script src="../_static/collapsible-lists/js/apply-collapsible-lists.js?v=660e4f45"></script>
21 22
22<script src="../_static/js/theme.js"></script>
22 23 <link rel="index" title="Index" href="../genindex.html" /> 24 <link rel="search" title="Search" href="../search.html" /> 25 <link rel="next" title="How to get started" href="how_to_get_started.html" /> 26 <link rel="prev" title="KXDB Database" href="../about/kxdb_database.html" /> 27</head> 28 29<body class="wy-body-for-nav"> 30 <div class="wy-grid-for-nav"> 31 <nav data-toggle="wy-nav-shift" class="wy-nav-side"> 32 <div class="wy-side-scroll"> 33 <div class="wy-side-nav-search" > 34 35 36 37 <a href="../index.html" class="icon icon-home"> 38 kernelXDK 39 </a> 40<div role="search"> 41 <form id="rtd-search-form" class="wy-form" action="../search.html" method="get"> 42 <input type="text" name="q" placeholder="Search docs" aria-label="Search docs" /> 43 <input type="hidden" name="check_keywords" value="yes" /> 44 <input type="hidden" name="area" value="default" /> 45 </form> 46</div> 47 </div><div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="Navigation menu"> 48 <p class="caption" role="heading"><span class="caption-text">About</span></p> 49<ul> 50<li class="toctree-l1"><a class="reference internal" href="../about/introduction.html">Introduction</a></li> 51<li class="toctree-l1"><a class="reference internal" href="../about/introduction.html#what-is-kernelxdk">What is kernelXDK?</a></li> 52<li class="toctree-l1"><a class="reference internal" href="../about/kxdb_database.html">KXDB Database</a></li> 53</ul> 54<p class="caption" role="heading"><span class="caption-text">libxdk</span></p> 55<ul class="current"> 56<li class="toctree-l1 current"><a class="current reference internal" href="#">What is libxdk?</a><ul> 57<li class="toctree-l2"><a class="reference internal" href="#planned-features">Planned Features</a></li> 58</ul> 59</li> 60<li class="toctree-l1"><a class="reference internal" href="#installation">Installation</a><ul> 61<li class="toctree-l2"><a class="reference internal" href="#binary-release">Binary release</a><ul> 62<li class="toctree-l3"><a class="reference internal" href="#compiling-sample-exploits">Compiling sample exploits</a></li> 63<li class="toctree-l3"><a class="reference internal" href="#integrating-libxdk-into-an-existing-c-exploit">Integrating libxdk into an existing C exploit</a></li> 64</ul> 65</li> 66<li class="toctree-l2"><a class="reference internal" href="#source-code-compilation">Source code compilation</a><ul> 67<li class="toctree-l3"><a class="reference internal" href="#prerequisites">Prerequisites</a></li> 68<li class="toctree-l3"><a class="reference internal" href="#compilation">Compilation</a></li> 69<li class="toctree-l3"><a class="reference internal" href="#building-and-running-samples">Building and running samples</a></li> 70</ul> 71</li> 72<li class="toctree-l2"><a class="reference internal" href="#tests">Tests</a><ul> 73<li class="toctree-l3"><a class="reference internal" href="#disclaimer">Disclaimer</a></li> 74</ul> 75</li> 76</ul> 77</li> 78<li class="toctree-l1"><a class="reference internal" href="how_to_get_started.html">How to get started</a></li> 79<li class="toctree-l1"><a class="reference internal" href="sample_exploit.html">How to port an existing exploit</a></li> 80<li class="toctree-l1"><a class="reference internal" href="api.html">API Reference</a></li> 81</ul> 82<p class="caption" role="heading"><span class="caption-text">Command Line Tools</span></p> 83<ul> 84<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/image_db.html">Kernel Image DB</a></li> 85<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/image_runner.html">Kernel Image Runner</a></li> 86<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/kxdb_tool.html">KXDB Tool</a></li> 87<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/rop_generator.html">Kernel ROP Generator</a></li> 88</ul> 89 90 </div> 91 </div> 92 </nav> 93 94 <section data-toggle="wy-nav-shift" class="wy-nav-content-wrap"><nav class="wy-nav-top" aria-label="Mobile navigation menu" > 95 <i data-toggle="wy-nav-top" class="fa fa-bars"></i> 96 <a href="../index.html">kernelXDK</a> 97 </nav> 98 99 <div class="wy-nav-content"> 100 <div class="rst-content"> 101 <div role="navigation" aria-label="Page navigation"> 102 <ul class="wy-breadcrumbs"> 103 <li><a href="../index.html" class="icon icon-home" aria-label="Home"></a></li> 104 <li class="breadcrumb-item active">What is libxdk?</li> 105 <li class="wy-breadcrumbs-aside"> 106 <a href="../_sources/libxdk/README.md.txt" rel="nofollow"> View page source</a> 107 </li> 108 </ul> 109 <hr/> 110</div> 111 <div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article"> 112 <div itemprop="articleBody"> 113 114 <section id="what-is-libxdk"> 115<h1>What is libxdk?<a class="headerlink" href="#what-is-libxdk" title="Link to this heading">ï</a></h1> 116<p><code class="docutils literal notranslate"><span class="pre">libxdk</span></code> is the <strong>main component</strong> of the <strong>kernelXDK</strong>. Itâs a C++ library designed to be linked with exploit code, providing the following features:</p> 117<ul class="simple"> 118<li><p><strong>Target Detection:</strong> Detect the target environment the exploit is running on (currently supports <strong>kernelCTF</strong> targets).</p></li> 119<li><p><strong>Symbol and Structure Information:</strong> Provide symbols, structure and field information specific to the target.</p></li> 120<li><p><strong>ROP Payload Generation:</strong> Generate ROP payloads for privilege escalation and escaping namespaces and sandboxes.</p></li> 121<li><p><strong>
121Payload Layout Planner:</strong> Finds the right <strong>stack pivoting</strong> gadgets.</p></li> 122<li><p><strong>Convenience Functions:</strong> Offer functions for commonly used exploit functionality.</p></li> 123</ul> 124<section id="planned-features"> 125<h2>Planned Features<a class="headerlink" href="#planned-features" title="Link to this heading">ï</a></h2> 126<p>The following functionalities are not yet implemented but are planned for future releases:</p> 127<ul class="simple"> 128<li><p><strong>EntryBleed</strong> and <strong>prefetch</strong>-based KASLR leaks.</p></li> 129<li><p>Smaller utilities like <strong>namespace setup</strong>, <strong>CPU pinning</strong>, and <strong>communication between threads</strong>.</p></li> 130<li><p><strong>Spraying support</strong> with features like <strong>limit bypassing</strong>, <strong>leaking</strong>, <strong>victim object identification</strong>, <strong>cross-cache</strong>, and <strong>Dirty PageTable</strong> support.</p></li> 131<li><p><code class="docutils literal notranslate"><span class="pre">core_pattern</span></code> <strong>overwrite</strong> and eBPF-based <strong>shellcode spraying</strong>.</p></li> 132</ul> 133</section> 134</section> 135<section id="installation"> 136<h1>Installation<a class="headerlink" href="#installation" title="Link to this heading">ï</a></h1> 137<p>The library is available via a pre-compiled binary distribution or through source code compilation.</p> 138<section id="binary-release"> 139<h2>Binary release<a class="headerlink" href="#binary-release" title="Link to this heading">ï</a></h2> 140<p>The most recent stable <strong>libxdk</strong> binary release is available for download on the <strong><a class="reference external" href="https://github.com/google/kernel-research/releases">Github releases page</a></strong>.</p> 141<p>This binary is <strong>built</strong> using <strong>GCC 9.4.0</strong> on <strong>Ubuntu 20.04</strong> to maximize compatibility. However, please be aware that compatibility issues may arise depending on your specific system environment. Should you encounter incompatibilities, recompiling the library from the <strong>source code</strong> is recommended (refer to the following section for details).</p> 142<section id="compiling-sample-exploits"> 143<h3>Compiling sample exploits<a class="headerlink" href="#compiling-sample-exploits" title="Link to this heading">ï</a></h3> 144<p>The binary release package includes several <strong>sample exploits</strong>. Follow these steps to compile them:</p> 145<ol class="arabic"> 146<li><p><strong>Download and extract the latest libxdk release:</strong></p> 147<div class="highlight-bash notranslate"><div class="highlight"><pre><span></span>wget<span class="w"> </span>https://github.com/google/kernel-research/releases/download/libxdk%2Fv0.1/libxdk-v0.1.tar.gz 148tar<span class="w"> </span>-xzvf<span class="w"> </span>libxdk-v0.1.tar.gz 149</pre></div> 150</div> 151</li> 152<li><p><strong>Go the sample folder and compile the exploit:</strong></p> 153<div class="highlight-bash notranslate"><div class="highlight"><pre><span></span><span class="nb">cd</span><span class="w"> </span>samples/exp65 154make 155</pre></div> 156</div> 157</li> 158</ol> 159<p>Upon successful execution, the <strong>statically compiled</strong> binary, named <code class="docutils literal notranslate"><span class="pre">exp</span></code>, will be located in the <code class="docutils literal notranslate"><span class="pre">samples/exp65</span></code> directory.</p> 160</section> 161<section id="integrating-libxdk-into-an-existing-c-exploit"> 162<h3>Integrating libxdk into an existing C exploit<a class="headerlink" href="#integrating-libxdk-into-an-existing-c-exploit" title="Link to this heading">ï</a></h3> 163<p>To integrate the <strong>libxdk</strong> binary release into an existing C exploit that currently compiles with a command such as:</p> 164<div class="highlight-bash notranslate"><div class="highlight"><pre><span></span>gcc<span class="w"> </span>-o<span class="w"> </span>exp<span class="w"> </span>exploit.cpp<span class="w"> </span>-static 165</pre></div> 166</div> 167<p>Follow these steps:</p> 168<ol class="arabic"> 169<li><p><strong>Download and extract libxdk:</strong> 170First, download and extract the libxdk release into your exploitâs project folder:</p> 171<div class="highlight-bash notranslate"><div class="highlight"><pre><span></span>wget<span class="w"> </span>https://github.com/google/kernel-research/releases/download/libxdk%2Fv0.1/libxdk-v0.1.tar.gz 172tar<span class="w"> </span>-xzvf<span class="w"> </span>libxdk-v0.1.tar.gz 173</pre></div> 174</div> 175</li> 176<li><p><strong>Update the command line:</strong> 177Use the following command line for compilation and linking:</p> 178<div class="highlight-bash notranslate"><div class="highlight"><pre><span></span>g++<span class="w"> </span>-o<span class="w"> </span>exp<span class="w"> </span>exploit.cpp<span class="w"> </span>-static<span class="w"> </span>-Iinclude<span class="w"> </span>-Llib<span class="w"> </span>-lkernelXDK 179</pre></div> 180</div> 181<p><strong>Changes in the command line:</strong></p> 182<ul class="simple"> 183<li><p><strong>Compiler change:</strong> The compiler is switched from the C compiler (<code class="docutils literal notranslate"><span class="pre">gcc</span></code>) to the <strong>C++ compiler</strong> (<code class="docutils literal notranslate"><span class="pre">g++</span></code>) as libxdk is a C++ library.</p></li> 184<li><p><strong>Include paths:</strong></p> 185<ul> 186<li><p><code class="docutils literal notranslate"><span class="pre">-Iinclude</span></code> adds the <code class="docutils literal notranslate"><span class="pre">include</span></code>
186 directory to the header search path.</p></li> 187<li><p><code class="docutils literal notranslate"><span class="pre">-Llib</span></code> adds the <code class="docutils literal notranslate"><span class="pre">lib</span></code> directory to the library search path.</p></li> 188</ul> 189</li> 190<li><p><strong>Linking:</strong> <code class="docutils literal notranslate"><span class="pre">-lkernelXDK</span></code> links the exploit with the static library file, <code class="docutils literal notranslate"><span class="pre">libkernelXDK.a</span></code>.</p></li> 191</ul> 192</li> 193</ol> 194</section> 195</section> 196<section id="source-code-compilation"> 197<h2>Source code compilation<a class="headerlink" href="#source-code-compilation" title="Link to this heading">ï</a></h2> 198<section id="prerequisites"> 199<h3>Prerequisites<a class="headerlink" href="#prerequisites" title="Link to this heading">ï</a></h3> 200<p>The library requires the following package before compilation:</p> 201<div class="highlight-bash notranslate"><div class="highlight"><pre><span></span>sudo<span class="w"> </span>apt<span class="w"> </span>install<span class="w"> </span>libkeyutils-dev 202</pre></div> 203</div> 204</section> 205<section id="compilation"> 206<h3>Compilation<a class="headerlink" href="#compilation" title="Link to this heading">ï</a></h3> 207<p>Once the prerequisite is installed, compile the core library:</p> 208<div class="highlight-bash notranslate"><div class="highlight"><pre><span></span>./build.sh 209</pre></div> 210</div> 211<p>This process generates the static library binary at <code class="docutils literal notranslate"><span class="pre">build/libkernelXDK.a</span></code>, ready for linking with exploits (see âBinary releaseâ section).</p> 212</section> 213<section id="building-and-running-samples"> 214<h3>Building and running samples<a class="headerlink" href="#building-and-running-samples" title="Link to this heading">ï</a></h3> 215<p>To build the samples, run the following script:</p> 216<div class="highlight-bash notranslate"><div class="highlight"><pre><span></span>./build_samples.sh 217</pre></div> 218</div> 219<p>Successful execution will create the sample binaries, named <code class="docutils literal notranslate"><span class="pre">exp</span></code>, located within their respective directories (e.g., <code class="docutils literal notranslate"><span class="pre">samples/exp65/exp</span></code>).</p> 220<p><strong>Note:</strong> some samples require installing prerequisites, which can be done with <code class="docutils literal notranslate"><span class="pre">sudo</span> <span class="pre">PREREQ=1</span> <span class="pre">./build_samples.sh</span></code>.</p> 221<p>To test a sample exploit, run the following commands:</p> 222<div class="highlight-bash notranslate"><div class="highlight"><pre><span></span><span class="nb">cd</span><span class="w"> </span>samples/exp65 223make<span class="w"> </span><span class="nb">test</span> 224</pre></div> 225</div> 226</section> 227</section> 228<section id="tests"> 229<h2>Tests<a class="headerlink" href="#tests" title="Link to this heading">ï</a></h2> 230<p>The library provides two distinct test execution scripts:</p> 231<ul> 232<li><p><strong>Local tests (<code class="docutils literal notranslate"><span class="pre">./run_local_tests.sh</span></code>)</strong></p> 233<p>This script executes a subset of tests that <strong>do not require kernel exploitation</strong> and can be safely run directly on your host machine.</p> 234</li> 235<li><p><strong>Integration tests (<code class="docutils literal notranslate"><span class="pre">./run_tests.sh</span></code>)</strong></p> 236<p>This script runs the <strong>complete test suite</strong>, including tests that perform kernel exploitation. These tests require a VM setup, utilizing the <code class="docutils literal notranslate"><span class="pre">image_runner</span></code> tool and the <code class="docutils literal notranslate"><span class="pre">xdk_device</span></code> kernel module.</p> 237<p>To specify a target kernel for the integration test, use the following syntax (e.g., targeting kernelCTFâs <code class="docutils literal notranslate"><span class="pre">lts-6.6.69</span></code> release):</p> 238<div class="highlight-bash notranslate"><div class="highlight"><pre><span></span>./run_tests.sh<span class="w"> </span>kernelctf<span class="w"> </span>lts-6.6.69 239</pre></div> 240</div> 241</li> 242</ul> 243<section id="disclaimer"> 244<h3>Disclaimer<a class="headerlink" href="#disclaimer" title="Link to this heading">ï</a></h3> 245<p>This is not an officially supported Google product.</p> 246</section> 247</section> 248</section> 249 250 251 </div> 252 </div> 253 <footer><div class="rst-footer-buttons" role="navigation" aria-label="Footer"> 254 <a href="../about/kxdb_database.html" class="btn btn-neutral float-left" title="KXDB Database" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left" aria-hidden="true"></span> Previous</a> 255 <a href="how_to_get_started.html" class="btn btn-neutral float-right" title="How to get started" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right" aria-hidden="true"></span></a> 256 </div> 257 258 <hr/> 259 260 <div role="contentinfo"> 261 <p>© Copyright 2025, Google.</p> 262 </div> 263 264 Built with <a href="https://www.sphinx-doc.org/">Sphinx</a> using a 265 <a href="https://github.com/readthedocs/sphinx_rtd_theme">theme</a> 266 provided by <a href="https://readthedocs.org">Read the Docs</a>. 267 268 269</footer> 270 </div> 271 </div> 272 </section> 273 </div> 274
274<script> 275 jQuery(function () { 276 SphinxRtdTheme.Navigation.enable(true); 277 }); 278 </script>
278 279 280</body> 281</html>
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.