![]() |
|
Tutorial Taking Advantage of Unix Wildcards - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: Tutorial Taking Advantage of Unix Wildcards (/Thread-Tutorial-Taking-Advantage-of-Unix-Wildcards) |
Taking Advantage of Unix Wildcards - whatever - 03-28-2015 Intro: This has nothing to do with modern-day hacking techniques and bypasses like ASLR bypass, buffer overflows, or any of those things. This tutorial and the idea behind it were born out of cleverness and a sharp mind. Unix Wildcards and Their Purpose: You can check that out in @Eclipse's thread - https://www.sinister.ly/Thread-Tutorial-Wildcard-Characters Why not to use wildcards: This example specifically pertains to the asterisk (*) wildcard, particularly with the rm command. Someone could easily abuse the behavior of wildcards and rm by creating a file with a name that has arguments used by rm. The trick behind this technique is that when using shell wildcards, the Unix shell will interpret files beginning with a hyphen character as command line arguments to executed command/program, in this case, rm. This opens up the door of opportunity for a channeling attack. The channeling problem arises when different kinds of information channels are combined into single channel. The example in form of this technique is combining arguments and filenames, as different "channels" into single, because of using shell wildcards. Actually taking advantage of it: Code: 0x0c0c0c0c@debian:~/tutorial$ ls -al
total 20
drwxr-xr-x 5 0x0c0c0c0c 0x0c0c0c0c 4096 Mar 28 01:26 .
drwxr-xr-x 13 0x0c0c0c0c 0x0c0c0c0c 4096 Mar 28 01:24 ..
drwxr-xr-x 2 0x0c0c0c0c 0x0c0c0c0c 4096 Mar 28 01:24 anothershitdir
-rw-r--r-- 1 0x0c0c0c0c 0x0c0c0c0c 0 Mar 28 01:25 cock.txt
drwxr-xr-x 2 0x0c0c0c0c 0x0c0c0c0c 4096 Mar 28 01:25 dir
-rw-r--r-- 1 0x0c0c0c0c 0x0c0c0c0c 0 Mar 28 01:26 file.txt
-rw-r--r-- 1 0x0c0c0c0c 0x0c0c0c0c 0 Mar 28 01:24 shit.txt
drwxr-xr-x 2 0x0c0c0c0c 0x0c0c0c0c 4096 Mar 28 01:24 shitdir
-rw-r--r-- 1 0x0c0c0c0c 0x0c0c0c0c 0 Mar 28 01:24 -rfIn this directory we can see 3 directories, 3 text files, and at the end there's a file named "-rf". Now, let's run "rm *" and see what changes. Code: 0x0c0c0c0c@debian:~/tutorial$ rm *
0x0c0c0c0c@debian:~/tutorial$ ls -al
total 20
drwxr-xr-x 5 0x0c0c0c0c 0x0c0c0c0c 4096 Mar 28 01:26 .
drwxr-xr-x 13 0x0c0c0c0c 0x0c0c0c0c 4096 Mar 28 01:24 ..
-rw-r--r-- 1 0x0c0c0c0c 0x0c0c0c0c 0 Mar 28 01:24 -rfThe last file standing is the "-rf" file. Why? Because of the name, the filename was interpreted as an argument to the rm command instead of an actual file. Running "rm *" in this case is the equivalent to running this - Code: 0x0c0c0c0c@debian:~/tutorial$ rm anothershitdir cock.txt dir file.txt shit.txt shitdir -rfThis wildcard behavior can be taken advantage of in many different ways, this is only the most obvious one. With a little creativity and innovation this "trick" can be leveraged to whatever you want it to. Thanks for reading. RE: Taking Advantage of Unix Wildcards - Satan - 03-28-2015 Would it still work in (for example) running rm *.* ? RE: Taking Advantage of Unix Wildcards - whatever - 03-28-2015 (03-28-2015, 06:49 AM)Six Wrote: Would it still work in (for example) running rm *.* ? If the manipulative filename was "-rf"? No. However, if you could find an argument where you can place a "." somewhere (-rf isn't the only argument for rm, you know) then it would be read by rm as an argument regardless. Like the bottom of the tutorial says, there are many different ways to take advantage of this behavior. You just have to think. RE: Taking Advantage of Unix Wildcards - Misha- - 03-28-2015 You basically took parts of this. http://www.exploit-db.com/papers/33930/ Atleast give some more examples and give credit where credit is due. RE: Taking Advantage of Unix Wildcards - whatever - 03-28-2015 (03-28-2015, 08:28 AM)Misha- Wrote: You basically took parts of this. The only part of this that I "copied" was the part about channeling attacks, as for the actual example I created in my own environment and did it myself. Is it similar to that link? Yes. Does that mean I took everything off of it at slapped it in a thread? No. That would be like me telling you to cite the dictionary in your post because you're using words from it. If I were to copy it, I would've done the whole thing word for word rather than just the part about taking advantage of rm. RE: Taking Advantage of Unix Wildcards - Misha- - 03-28-2015 http://www.thefreedictionary.com/plagiarise RE: Taking Advantage of Unix Wildcards - Eclipse - 03-28-2015 (03-28-2015, 08:28 AM)Misha- Wrote: You basically took parts of this. Nevertheless, it's a clever little trick. EDIT: That link has some really interesting things... Thanks for the share. RE: Taking Advantage of Unix Wildcards - Misha- - 03-28-2015 (03-28-2015, 09:23 AM)Eclipse Wrote: Nevertheless, it's a clever little trick. No problem. This doesn't only work for shit like tar, etc. You can look for other bins on the box to exploit. |