![]() |
|
How do we escalate privileges in linux? - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: How do we escalate privileges in linux? (/Thread-How-do-we-escalate-privileges-in-linux) |
How do we escalate privileges in linux? - m0nk1337 - 02-22-2021 Many people think that finding an appropriate exploit for the kernel version and popping a shell with root privileges is the only way. But NO it is not the only way of getting higher privileges on a Linux system. Let's look into different ways/tools we can use to get higher privileges on a system. PS : For now I'm just listing out all the things on this post and then we will have separate posts for each and everything in detail to get better understanding of it. So as everybody knows that our Information Gathering scene doesn't finishes when we pop a shell after exploiting a vulnerability. We still need to gather a lot of information about the system in order to get more privileges. But what things we need to look? Here : 1. Kernel and System release info(this helps in looking for some local priv esc exploits or kernel exploits). 2. System information like hostname, default route, dns server info and other network details. 3. User information like current logged in user details(including their history ".bash_history/mysql_history"), last logged on user, listing uid/gid information, listing unmask values, extracting password policies/hash storage methods, basic ssh check, checking if the passwd file contains user hashes, attempting to read restricted files like /etc/shadow. 4. Checking access like which user has recently used sudo, checking if the sudoers file is accessible, checking if current user has sudo access without a password, are there any known binaries available with sudo, is root user's home directory accessible. 5. Displaying environmental information and current user's $PATH 6. List cron-jobs and tasks owned by different users on the system and jobs which are world-writable and also all the systemd timers(scheduled tasks). 7. Listing and locating different services and running processes. 8. Checking version information of sudo, mysql, postgres, apache(or any other server software) : locating and reading their configuration files for juicy information or finding an exploit. 9. Checking if we are inside a docker or similar container environment. 10. Locate and list all SUID/GUID files and see if they are writable and/or owned by root user. 11. Locating and checking if any of the files on system has POSIX capabilities. 12. Locate and read all accessible "plan"/"rhosts" files. 13. List all the configuration files which contains keyword supplied at runtime. RE: How do we escalate privileges in linux? - Oni - 02-23-2021 Back when we used shared hosting (first 1-2 years), the host hadn't updated the kernel. There was a privilege escalation vulnerability that hadn't been patched, so I obtained root and updated things for them. They offered us a ~30% discount for life, but we immediately bought a dedicated box elsewhere. Privilege escalation vulnerabilities are an excellent reason to never buy shared hosting, as you're potentially vulnerable to the other clients on the box. |