mirror of
https://github.com/nikaiw/VMkatz
synced 2026-09-25 07:51:06 +00:00
Fix Python availability claim: included in ESXi 6.x+, not all versions
This commit is contained in:
+1
-1
@@ -23,7 +23,7 @@ esxcli system settings advanced set -o /User/execInstalledOnly -i 0
|
|||||||
|
|
||||||
When `execInstalledOnly` is set to 1 (default on ESXi 7.0+), unsigned binaries cannot be executed directly. The included Python loader (`tools/vmkatz_loader.py`, bundled in the ESXi release archive) bypasses this by loading vmkatz into anonymous memory pages — ESXi allows `PROT_EXEC` on anonymous mappings while blocking `execve` on unsigned files.
|
When `execInstalledOnly` is set to 1 (default on ESXi 7.0+), unsigned binaries cannot be executed directly. The included Python loader (`tools/vmkatz_loader.py`, bundled in the ESXi release archive) bypasses this by loading vmkatz into anonymous memory pages — ESXi allows `PROT_EXEC` on anonymous mappings while blocking `execve` on unsigned files.
|
||||||
|
|
||||||
Python is VIB-signed on all ESXi versions and can execute normally.
|
Python is included in ESXi 6.x and later (used internally by VMware hostd/CIM providers) and can execute normally regardless of VIB settings.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Upload both files
|
# Upload both files
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ Bypasses execInstalledOnly (VIB protection) by loading the vmkatz static
|
|||||||
binary into anonymous mmap pages with PROT_EXEC. ESXi VMkernel allows
|
binary into anonymous mmap pages with PROT_EXEC. ESXi VMkernel allows
|
||||||
PROT_EXEC on anonymous mappings but blocks execve on unsigned binaries.
|
PROT_EXEC on anonymous mappings but blocks execve on unsigned binaries.
|
||||||
|
|
||||||
Python is VIB-signed on ESXi, so it can execute normally.
|
Python is included in ESXi 6.x+ and executes regardless of VIB settings.
|
||||||
|
|
||||||
We parse the ELF, map segments, apply relocations, build a proper
|
We parse the ELF, map segments, apply relocations, build a proper
|
||||||
initial stack (argc/argv/envp/auxv), and jump to _start.
|
initial stack (argc/argv/envp/auxv), and jump to _start.
|
||||||
|
|||||||
Reference in New Issue
Block a user