linux-evasion.md (5623B)
1 --- 2 title: "Linux - Evasion" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/evasion/linux-evasion.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/linux-evasion.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Linux - Evasion 12 13 ## Summary 14 15 - [File Names](#file-names) 16 - [Command History](#command-history) 17 - [Hiding Text](#hiding-text) 18 - [Timestomping](#timestomping) 19 - [Hiding PID Listings From Non-Root Users](#hiding-pid-listings-from-non-root-users) 20 21 ## File Names 22 23 An Unicode zero-width space can be inserted into filenames which makes the names visually indistinguishable: 24 25 ```bash 26 # A decoy file with no special characters 27 touch 'index.php' 28 29 # An imposter file with visually identical name 30 touch $'index\u200D.php' 31 ``` 32 33 ## Command History 34 35 Most shells save their command history so a user can recall them again later. The command history can be viewed with the `history` command or by manually inspecting the contents of the file pointed to by `$HISTFILE` (e.g. `~/.bash_history`). 36 This can be prevented in a number of ways. 37 38 ```bash 39 # Prevent writing to the history file at all 40 unset HISTFILE 41 42 # Don't save this session's command history in memory 43 export HISTSIZE=0 44 ``` 45 46 Individual commands that match a pattern in `HISTIGNORE` will be excluded from the command history, regardless of `HISTFILE` or `HISTSIZE` settings. 47 By default, `HISTIGNORE` will ignore all commands that begin with whitespace: 48 49 ```bash 50 # Note the leading space character: 51 my-sneaky-command 52 ``` 53 54 If commands are accidentally added to the command history, individual command entries can be removed with `history -d`: 55 56 ```bash 57 # Removes the most recently logged command. 58 # Note that we actually have to delete two history entries at once, 59 # otherwise the `history -d` command itself will be logged as well. 60 history -d -2 && history -d -1 61 ``` 62 63 The entire command history can be purged as well, although this approach is much less subtle and very likely to be noticed: 64 65 ```bash 66 # Clears the in-memory history and writes the empty history to disk. 67 history -c && history -w 68 ``` 69 70 For a more destructive approach, you can either delete the contents of the `.bash_history` file or link it to `/dev/null` to prevent future history logging. 71 72 ```ps1 73 # Permanently disable bash history by linking it to /dev/null 74 ln /dev/null -/.bash_history -sf 75 76 # Clear the existing bash history 77 echo "" > .bash history 78 ``` 79 80 ## Hiding Text 81 82 ANSI escape sequences can be abused to hide text under certain circumstances. 83 If the file's contents are printed to the terminal (e.g. `cat`, `head`, `tail`) then the text will be hidden. 84 If the file is viewed with an editor (e.g. `vim`, `nano`, `emacs`), then the escape sequences will be visible. 85 86 ```bash 87 echo "sneaky-payload-command" > script.sh 88 echo "# $(clear)" >> script.sh 89 echo "# Do not remove. Generated from /etc/issue.conf by configure." >> script.sh 90 91 # When printed, the terminal will be cleared and only the last line will be visible: 92 cat script.sh 93 ``` 94 95 ## Timestomping 96 97 Timestomping refers to the alteration of a file or directory's modification/access timestamps in order to conceal the fact that it was modified. 98 The simplest way to accomplish this is with the `touch` command: 99 100 ```bash 101 # Changes the access (-a) and modification (-m) times using YYYYMMDDhhmm format. 102 touch -a -m -t 202210312359 "example" 103 104 # Changes time using a Unix epoch timestamp. 105 touch -a -m -d @1667275140 "example" 106 107 # Copies timestamp from one file to another. 108 touch -a -m -r "other_file" "example" 109 110 # Get the file's modification timestamp, modify the file, then restore the timestamp. 111 MODIFIED_TS=$(stat --format="%Y" "example") 112 echo "backdoor" >> "example" 113 touch -a -m -d @$MODIFIED_TS "example" 114 ``` 115 116 It should be noted that `touch` can only modify the access and modification timestamps. It can't be used to update a file's "change" or "birth" timestamps. The birth timestamp, if supported by the filesystem, tracks when the file was created. The change timestamp tracks whenever the file's metadata changes, including updates to the access and modification timestamps. 117 118 If an attacker has root privileges, they can work around this limitation by modifying the system clock, creating or modifying a file, then reverting the system clock: 119 120 ```bash 121 ORIG_TIME=$(date) 122 date -s "2022-10-31 23:59:59" 123 touch -a -m "example" 124 date -s "${ORIG_TIME}" 125 ``` 126 127 Don't forget that creating a file also updates the parent directory's modification timestamp as well! 128 129 ## Hiding PID Listings From Non-Root Users 130 131 By default, the `/proc` filesystem exposes process information to all users. You can limit this access to only root by modifying the `/proc` mount options. 132 133 ```ps1 134 sudo mount -o remount,rw,nosuid,nodev,noexec,relatime,hidepid=2 /proc 135 ``` 136 137 - `hidepid=2`: Hides all processes that don't belong to the user. 138 - `hidepid=1`: Hides only process details (command line, environment variables) but still shows PIDs. 139 140 ## References 141 142 - [ATT&CK - Impair Defenses: Impair Command History Logging](https://attack.mitre.org/techniques/T1562/003/) 143 - [ATT&CK - Indicator Removal: Timestomp](https://attack.mitre.org/techniques/T1070/006/) 144 - [ATT&CK - Indicator Removal on Host: Clear Command History](https://attack.mitre.org/techniques/T1070/003/) 145 - [ATT&CK - Masquerading: Match Legitimate Name or Location](https://attack.mitre.org/techniques/T1036/005/) 146 - [Wikipedia - ANSI escape codes](https://en.wikipedia.org/wiki/ANSI_escape_code) 147 - [InverseCos - Detecting Linux Anti-Forensics: Timestomping](https://www.inversecos.com/2022/08/detecting-linux-anti-forensics.html)