daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

linux-evasion.md (5623B)


      1 ---
      2 title: "Linux - Evasion"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/evasion/linux-evasion.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/linux-evasion.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Linux - Evasion
     12 
     13 ## Summary
     14 
     15 - [File Names](#file-names)
     16 - [Command History](#command-history)
     17 - [Hiding Text](#hiding-text)
     18 - [Timestomping](#timestomping)
     19 - [Hiding PID Listings From Non-Root Users](#hiding-pid-listings-from-non-root-users)
     20 
     21 ## File Names
     22 
     23 An Unicode zero-width space can be inserted into filenames which makes the names visually indistinguishable:
     24 
     25 ```bash
     26 # A decoy file with no special characters
     27 touch 'index.php'
     28 
     29 # An imposter file with visually identical name
     30 touch $'index\u200D.php'
     31 ```
     32 
     33 ## Command History
     34 
     35 Most shells save their command history so a user can recall them again later.  The command history can be viewed with the `history` command or by manually inspecting the contents of the file pointed to by `$HISTFILE` (e.g. `~/.bash_history`).
     36 This can be prevented in a number of ways.
     37 
     38 ```bash
     39 # Prevent writing to the history file at all
     40 unset HISTFILE
     41 
     42 # Don't save this session's command history in memory
     43 export HISTSIZE=0
     44 ```
     45 
     46 Individual commands that match a pattern in `HISTIGNORE` will be excluded from the command history, regardless of `HISTFILE` or `HISTSIZE` settings.  
     47 By default, `HISTIGNORE` will ignore all commands that begin with whitespace:
     48 
     49 ```bash
     50 # Note the leading space character:
     51  my-sneaky-command
     52 ```
     53 
     54 If commands are accidentally added to the command history, individual command entries can be removed with `history -d`:
     55 
     56 ```bash
     57 # Removes the most recently logged command.
     58 # Note that we actually have to delete two history entries at once,
     59 # otherwise the `history -d` command itself will be logged as well.
     60 history -d -2 && history -d -1
     61 ```
     62 
     63 The entire command history can be purged as well, although this approach is much less subtle and very likely to be noticed:
     64 
     65 ```bash
     66 # Clears the in-memory history and writes the empty history to disk.
     67 history -c && history -w
     68 ```
     69 
     70 For a more destructive approach, you can either delete the contents of the `.bash_history` file or link it to `/dev/null` to prevent future history logging.
     71 
     72 ```ps1
     73 # Permanently disable bash history by linking it to /dev/null
     74 ln /dev/null -/.bash_history -sf
     75 
     76 # Clear the existing bash history
     77 echo "" > .bash history
     78 ```
     79 
     80 ## Hiding Text
     81 
     82 ANSI escape sequences can be abused to hide text under certain circumstances.  
     83 If the file's contents are printed to the terminal (e.g. `cat`, `head`, `tail`) then the text will be hidden.  
     84 If the file is viewed with an editor (e.g. `vim`, `nano`, `emacs`), then the escape sequences will be visible.
     85 
     86 ```bash
     87 echo "sneaky-payload-command" > script.sh
     88 echo "# $(clear)" >> script.sh
     89 echo "# Do not remove. Generated from /etc/issue.conf by configure." >> script.sh
     90 
     91 # When printed, the terminal will be cleared and only the last line will be visible:
     92 cat script.sh
     93 ```
     94 
     95 ## Timestomping
     96 
     97 Timestomping refers to the alteration of a file or directory's modification/access timestamps in order to conceal the fact that it was modified.  
     98 The simplest way to accomplish this is with the `touch` command:
     99 
    100 ```bash
    101 # Changes the access (-a) and modification (-m) times using YYYYMMDDhhmm format.
    102 touch -a -m -t 202210312359 "example"
    103 
    104 # Changes time using a Unix epoch timestamp.
    105 touch -a -m -d @1667275140 "example"
    106 
    107 # Copies timestamp from one file to another.
    108 touch -a -m -r "other_file" "example"
    109 
    110 # Get the file's modification timestamp, modify the file, then restore the timestamp.
    111 MODIFIED_TS=$(stat --format="%Y" "example")
    112 echo "backdoor" >> "example"
    113 touch -a -m -d @$MODIFIED_TS "example"
    114 ```
    115 
    116 It should be noted that `touch` can only modify the access and modification timestamps.  It can't be used to update a file's "change" or "birth" timestamps.  The birth timestamp, if supported by the filesystem, tracks when the file was created.  The change timestamp tracks whenever the file's metadata changes, including updates to the access and modification timestamps.
    117 
    118 If an attacker has root privileges, they can work around this limitation by modifying the system clock, creating or modifying a file, then reverting the system clock:
    119 
    120 ```bash
    121 ORIG_TIME=$(date)
    122 date -s "2022-10-31 23:59:59"
    123 touch -a -m "example"
    124 date -s "${ORIG_TIME}"
    125 ```
    126 
    127 Don't forget that creating a file also updates the parent directory's modification timestamp as well!
    128 
    129 ## Hiding PID Listings From Non-Root Users
    130 
    131 By default, the `/proc` filesystem exposes process information to all users. You can limit this access to only root by modifying the `/proc` mount options.
    132 
    133 ```ps1
    134 sudo mount -o remount,rw,nosuid,nodev,noexec,relatime,hidepid=2 /proc
    135 ```
    136 
    137 - `hidepid=2`: Hides all processes that don't belong to the user.
    138 - `hidepid=1`: Hides only process details (command line, environment variables) but still shows PIDs.
    139 
    140 ## References
    141 
    142 - [ATT&CK - Impair Defenses: Impair Command History Logging](https://attack.mitre.org/techniques/T1562/003/)
    143 - [ATT&CK - Indicator Removal: Timestomp](https://attack.mitre.org/techniques/T1070/006/)
    144 - [ATT&CK - Indicator Removal on Host: Clear Command History](https://attack.mitre.org/techniques/T1070/003/)
    145 - [ATT&CK - Masquerading: Match Legitimate Name or Location](https://attack.mitre.org/techniques/T1036/005/)
    146 - [Wikipedia - ANSI escape codes](https://en.wikipedia.org/wiki/ANSI_escape_code)
    147 - [InverseCos - Detecting Linux Anti-Forensics: Timestomping](https://www.inversecos.com/2022/08/detecting-linux-anti-forensics.html)