[Post-Explotation] Linux Priviledge Escalation

2023. 12. 19. 14:10ยท๐Ÿค–์ •๋ณด๋ณด์•ˆ/โค๏ธ๋ ˆ๋“œํŒ€

์ผ๋ฐ˜์ ์œผ๋กœ ํ˜ธ์ŠคํŠธ ์‰˜์„ ํš๋“ํ•˜๋ฉด ์ƒ์œ„ ๊ถŒํ•œ ํƒˆ์ทจ๋ฅผ ์œ„ํ•˜์—ฌ ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ํ•ด์•ผํ•œ๋‹ค. ์ด ์ˆ˜์ง‘ํ•˜๋Š” ํ–‰์œ„๋ฅผ Enumeration๋ผ๊ณ  ํ•œ๋‹ค.  ๊ธฐ์ดˆ ์ •๋ณด๋ฅผ ํš๋“ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ ๋‹ค์Œ์˜ ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ํ•˜์ž.

 

์šด์˜์ฒด์ œ ๋ฒ„์ „ - ์ฃผ๋กœ ์•Œ๋ ค์ง„ ์šด์˜์ฒด์ œ์— ๋”ฐ๋ผ ์‚ฌ์šฉํ•˜๋Š” ํˆด ๋˜๋Š” ์ต์Šคํ”Œ๋กœ์ž‡ ์—ฌ๋ถ€๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

์ปค๋„ ๋ฒ„์ „ - ์ž˜์•Œ๋ ค์ง„ ์ปค๋„์ด๋ผ๋ฉด ์ทจ์•ฝ์  ์ •๋ณด๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด์— ์“ฐ์ด๋Š” ์ทจ์•ฝ์ ์€ ์‹œ์Šคํ…œ์„ ์‚ฌ์šฉ๋ถˆ๊ฐ€ ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•˜๋ฏ€๋กœ ์‹คํ–‰ํ•˜๊ธฐ์ „ ํŒŒ๊ธ‰ํšจ๊ณผ๋ฅผ ์ธ์ง€ํ•˜๋„๋ก ํ•˜

์‹ฑํ–‰์ค‘์ธ ์„œ๋น„์Šค - ์‹คํ–‰์ค‘์ธ ํ”„๋กœ์„ธ์Šค์˜ ๊ถŒํ•œ์„ ํ™•์ธํ•œ๋‹ค. ์ž˜๋ชป๋œ ์„ค์ •์œผ๋กœ root๋กœ ์‹คํ–‰๋˜๊ฒŒ ํ•  ์ˆ˜๋„์žˆ๋‹ค.

Cy3erLuna@htb[/htb]$ ps aux | grep root

root         1  1.3  0.1  37656  5664 ?        Ss   23:26   0:01 /sbin/init
root         2  0.0  0.0      0     0 ?        S    23:26   0:00 [kthreadd]
root         3  0.0  0.0      0     0 ?        S    23:26   0:00 [ksoftirqd/0]
root         4  0.0  0.0      0     0 ?        S    23:26   0:00 [kworker/0:0]
root         5  0.0  0.0      0     0 ?        S<   23:26   0:00 [kworker/0:0H]
root         6  0.0  0.0      0     0 ?        S    23:26   0:00 [kworker/u8:0]
root         7  0.0  0.0      0     0 ?        S    23:26   0:00 [rcu_sched]
root         8  0.0  0.0      0     0 ?        S    23:26   0:00 [rcu_bh]
root         9  0.0  0.0      0     0 ?        S    23:26   0:00 [migration/0]

์„ค์น˜๋œ ํŒจํ‚ค์ง€ ๋ฐ ๋ฒ„์ „ - ๋ฒ„์ „์— ๋”ฐ๋ฅธ ์ทจ์•ฝ์ ์ด ์žˆ๋Š” ์„œ๋น„์Šค๋ฅผ ์‹๋ณ„ํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•˜๋‹ค. 

๋กœ๊ทธ์ธ๋œ ์œ ์ € - ๋กœ๊ทธ์ธ๋œ ์œ ์ €๋ฅผ ์‹๋ณ„ํ•˜์—ฌ ๋ฌด์—‡์„ ํ•˜๋Š”์ง€ ํ™•์ธํ•œ๋‹ค. ๊ทธ๋Ÿฌ๋ฉด ํ™•์‚ฐ์ด๋™(leteral movement) ๋ฐ ๊ถŒํ•œ์ƒ์Šน์˜ ๊ธธ์ด ๋  ์ˆ˜ ์žˆ๋‹ค.

Cy3erLuna@htb[/htb]$ ps au

USER       		PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
root      		1256  0.0  0.1  65832  3364 tty1     Ss   23:26   0:00 /bin/login --
cliff.moore     1322  0.0  0.1  22600  5160 tty1     S    23:26   0:00 -bash
shared     		1367  0.0  0.1  22568  5116 pts/0    Ss   23:27   0:00 -bash
root      		1384  0.0  0.1  52700  3812 tty1     S    23:29   0:00 sudo su
root      		1385  0.0  0.1  52284  3448 tty1     S    23:29   0:00 su
root      		1386  0.0  0.1  21224  3764 tty1     S+   23:29   0:00 bash
shared     		1397  0.0  0.1  37364  3428 pts/0    R+   23:30   0:00 ps au

์œ ์ € ํ™ˆ ๋””๋ ‰ํ† ๋ฆฌ - ํƒ€์ธ์˜ ํ™ˆ ๋””๋ ‰ํ† ๋ฆฌ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋‹ค๋ฉด SSH ํ‚ค ๋“ฑ์„ ํš๋“ํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด ๊ฒƒ์œผ๋กœ ๋‹ค๋ฅธ ์‹œ์Šคํ…œ์— ์—‘์„ธ์Šคํ•˜๊ฑฐ๋‚˜ AD ํ™˜๊ฒฝ์— ์นจ์ž…ํ•˜๋Š”๋ฐ ํ™œ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. ๋˜ํ•œ .bash_history ํŒŒ์ผ์„ ํ†ตํ•˜์—ฌ Credentials๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ๋‹ค.

Cy3erLuna@htb[/htb]$ history

    1  id
    2  cd /home/cliff.moore
    3  exit
    4  touch backup.sh
    5  tail /var/log/apache2/error.log
    6  ssh ec2-user@dmz02.inlanefreight.local
    7  history

 

Sudo ๊ถŒํ•œ - ์ผ๋ถ€ ์œ ์ €์˜ ๊ฒฝ์šฐ ๋น„๋ฐ€๋ฒˆํ˜ธ ์ž…๋ ฅ์—†์ด  root๋กœ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋‹ค.

Cy3erLuna@htb[/htb]$ sudo -l

Matching Defaults entries for sysadm on NIX02:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User sysadm may run the following commands on NIX02:
    (root) NOPASSWD: /usr/sbin/tcpdump

 

์„ค์ •ํŒŒ์ผ - ์ค‘์š” ์ •๋ณด๋ฅผ ๋‹ด๊ณ  ์žˆ์œผ๋ฉฐ ๊ณ„์ • ๋น„๋ฐ€๋ฒˆํ˜ธ ๋“ฑ์ด ์žˆ์„ ์ˆ˜ ์žˆ๋‹ค.

Shadow ํŒŒ์ผ๊ณผ passwd ํŒŒ์ผ - ์•ˆ์—๋Š” ๋น„๋ฐ€๋ฒˆํ˜ธ ํ•ด์‰ฌ ๊ฐ’์ด ์žˆ์œผ๋ฉฐ ํ•ด๋‹น ๊ฐ’์„ ํ†ตํ•˜์—ฌ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ Crack ํ•  ์ˆ˜ ์žˆ๋‹ค.

Cy3erLuna@htb[/htb]$ cat /etc/passwd

root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
<...SNIP...>
dnsmasq:x:109:65534:dnsmasq,,,:/var/lib/misc:/bin/false
sshd:x:110:65534::/var/run/sshd:/usr/sbin/nologin
mrb3n:x:1000:1000:mrb3n,,,:/home/mrb3n:/bin/bash
colord:x:111:118:colord colour management daemon,,,:/var/lib/colord:/bin/false
backupsvc:x:1001:1001::/home/backupsvc:
bob.jones:x:1002:1002::/home/bob.jones:
cliff.moore:x:1003:1003::/home/cliff.moore:
logger:x:1004:1004::/home/logger:
shared:x:1005:1005::/home/shared:
stacey.jenkins:x:1006:1006::/home/stacey.jenkins:
sysadm:$6$vdH7vuQIv6anIBWg$Ysk.UZzI7WxYUBYt8WRIWF0EzWlksOElDE0HLYinee38QI1A.0HW7WZCrUhZ9wwDz13bPpkTjNuRoUGYhwFE11:1007:1007::/home/sysadm:

 

Cron Jobs - Windows OS์˜ ์Šค์ผ€์ฅด ํ…Œ์Šคํฌ์™€ ๊ฐ™์€ ์—ญํ• ์„ ํ•œ๋‹ค. ์ž˜๋ชป๋œ ์„ค์ •์œผ๋กœ ์•ฝํ•œ ๊ถŒํ•œ์ด ์žˆ์œผ๋ฉด ์ด ๊ฒƒ์„ ํ†ตํ•˜์—ฌ ๊ถŒํ•œ ์ƒ์Šน ์‹œํ‚ฌ ์ˆ˜ ์žˆ๋‹ค.

Cy3erLuna@htb[/htb]$ ls -la /etc/cron.daily/

total 60
drwxr-xr-x  2 root root 4096 Aug 30 23:49 .
drwxr-xr-x 93 root root 4096 Aug 30 23:47 ..
-rwxr-xr-x  1 root root  376 Mar 31  2016 apport
-rwxr-xr-x  1 root root 1474 Sep 26  2017 apt-compat
-rwx--x--x  1 root root  379 Aug 30 23:49 backup
-rwxr-xr-x  1 root root  355 May 22  2012 bsdmainutils
-rwxr-xr-x  1 root root 1597 Nov 27  2015 dpkg
-rwxr-xr-x  1 root root  372 May  6  2015 logrotate
-rwxr-xr-x  1 root root 1293 Nov  6  2015 man-db
-rwxr-xr-x  1 root root  539 Jul 16  2014 mdadm
-rwxr-xr-x  1 root root  435 Nov 18  2014 mlocate
-rwxr-xr-x  1 root root  249 Nov 12  2015 passwd
-rw-r--r--  1 root root  102 Apr  5  2016 .placeholder
-rwxr-xr-x  1 root root 3449 Feb 26  2016 popularity-contest
-rwxr-xr-x  1 root root  214 May 24  2016 update-notifier-common

 

์–ธ๋งˆ์šดํŠธ ๋œ ํŒŒ์ผ ์‹œ์Šคํ…œ๊ณผ ์ถ”๊ฐ€ ๋“œ๋ผ์ด๋ธŒ - ์ดˆ๊ฐ€ ๋””์Šคํฌ์—์„œ ์ •๋ณด๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ๋‹ค.

SETUID์™€ SETGUI ๊ถŒํ•œ - ๋ฐ”์ด๋„ˆ๋ฆฌ๋Š” ์ด ๊ถŒํ•œ์„ ๊ฐ€์ง€๊ณ  ์œ ์ €๊ฐ€ ์ „์ฒด๊ถŒํ•œ์„ ๊ฐ€์ง€์ง€ ์•Š์•„๋„ ๋ฃจํŠธ์˜ ๊ถŒํ•œ์œผ๋กœ ๋ช…๋ น์–ด๋ฅผ ํ•  ์ˆ˜ ์žˆ๊ฒŒํ•œ๋‹ค.

์“ธ์ˆ˜ ์žˆ๋Š” ๋””๋ ‰ํ† ๋ฆฌ - ํˆด์„ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์„ ์ˆ˜ ์žˆ๋Š” ์žฅ์†Œ๋กœ ํ™œ์šฉ ๋  ์ˆ˜ ์žˆ๋‹ค. ํฌ๋ก ์žก์˜ ํŒŒ์ผ๋“ค์—๊ฒŒ์„œ๋„ ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ์‹๋ณ„ ํ•  ์ˆ˜ ์žˆ๋‹ค. 

 

Cy3erLuna@htb[/htb]$ find / -path /proc -prune -o -type d -perm -o+w 2>/dev/null

/dmz-backups
/tmp
/tmp/VMwareDnD
/tmp/.XIM-unix
/tmp/.Test-unix
/tmp/.X11-unix
/tmp/systemd-private-8a2c51fcbad240d09578916b47b0bb17-systemd-timesyncd.service-TIecv0/tmp
/tmp/.font-unix
/tmp/.ICE-unix
/proc
/dev/mqueue
/dev/shm
/var/tmp
/var/tmp/systemd-private-8a2c51fcbad240d09578916b47b0bb17-systemd-timesyncd.service-hm6Qdl/tmp
/var/crash
/run/lock
์ถœ์ฒ˜ - HACK THE BOX / LINUX PRIVILEGE ESCALATION -Introduction to Linux Privilege Escalation
https://academy.hackthebox.com/module/51/section/466
 

HTB Academy : Cybersecurity Training

Login to HTB Academy and continue levelling up your cybsersecurity skills.

academy.hackthebox.com

 

์ €์ž‘์žํ‘œ์‹œ ๋น„์˜๋ฆฌ ๋ณ€๊ฒฝ๊ธˆ์ง€ (์ƒˆ์ฐฝ์—ด๋ฆผ)

'๐Ÿค–์ •๋ณด๋ณด์•ˆ > โค๏ธ๋ ˆ๋“œํŒ€' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

์ •๋ณด๋ณด์•ˆ ์Šคํ‚ฌ๊พธ๋Ÿฌ๋ฏธ  (0) 2025.01.10
์œ ์šฉํ•œ ONSIT ์‚ฌ์ดํŠธ(geo location)  (0) 2024.01.05
[์ •๋ณด] Blutooth ํ•ดํ‚น ๊ธฐ๋ฒ• ์ข…๋ฅ˜  (0) 2023.10.31
[์ •๋ณด] ํ•ด์‹œ  (0) 2023.06.27
[์ •๋ณด] http ๊ณต๊ฒฉ ์Šคํ‚ฌ  (0) 2023.06.27
'๐Ÿค–์ •๋ณด๋ณด์•ˆ/โค๏ธ๋ ˆ๋“œํŒ€' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
  • ์ •๋ณด๋ณด์•ˆ ์Šคํ‚ฌ๊พธ๋Ÿฌ๋ฏธ
  • ์œ ์šฉํ•œ ONSIT ์‚ฌ์ดํŠธ(geo location)
  • [์ •๋ณด] Blutooth ํ•ดํ‚น ๊ธฐ๋ฒ• ์ข…๋ฅ˜
  • [์ •๋ณด] ํ•ด์‹œ
TwoIceFish
TwoIceFish
https://github.com/TwoIceFIsh
  • TwoIceFish
    Cyber-Luna
    TwoIceFish
  • ์ „์ฒด
    ์˜ค๋Š˜
    ์–ด์ œ
    • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (593)
      • ๐Ÿค–์ •๋ณด๋ณด์•ˆ (77)
        • ๐Ÿ’™๋ธ”๋ฃจํŒ€ (24)
        • โค๏ธ๋ ˆ๋“œํŒ€ (21)
        • ๐Ÿ’œํผํ”ŒํŒ€ (1)
        • ๐Ÿ’ 1๋ถ„์ง€์‹ (30)
      • ํ”„๋กœ์ ํŠธ (14)
        • ๐Ÿ’Œ ์ •๋ณด๋ณด์•ˆ ๋ฉ”์ผ๋ง ์‹œ์Šคํ…œ (8)
        • ๐Ÿ” ์ธ์ฆ์„œ ๊ด€๋ฆฌ ์‹œ์Šคํ…œ (1)
        • ๐Ÿ ๊ธˆ์œต ์ปค๋ฎค๋‹ˆํ‹ฐ (5)
      • ๐Ÿžํ”„๋กœ๊ทธ๋ž˜๋ฐ (49)
        • Next.js (9)
      • ๊ธฐํƒ€์ •๋ณด (68)
        • ๐ŸŒ๊ทธ๋ฆฟ์š”๊ฑฐํŠธ (11)
  • ๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

    • ํ™ˆ
    • ๋ฐฉ๋ช…๋ก
    • ๋กœ์ผ“ํŽ€์น˜
    • ๊นƒํ—ˆ๋ธŒ
    • ์ฝ”์ฝ”๋„ˆ์ธ 
    • ๊ทธ๋ฆฟ์š”๊ฑฐํŠธ
  • ๋งํฌ

  • ๊ณต์ง€์‚ฌํ•ญ

    • ์•ˆ๋…•ํ•˜์„ธ์š”
  • ์ธ๊ธฐ ๊ธ€

  • ํƒœ๊ทธ

    ์‘๋‹ต์—†์Œ
    jsp 200
    ๋‹จ์ผ ๋„๋ฉ”์ธ ์ธ์ฆ์„œ ์—ฌ๋Ÿฌ๊ฐœ
    ์ธ์ฆ์„œ ์—ฌ๋Ÿฌ๊ฐœ
    ์•…์„ฑ๋ฉ”์žƒ๋ถ„์„
    ์ง€๊ฐ‘ ์•ฑ์— ์นด๋“œ ์ถ”๊ฐ€
    ๋ถ€๋™์‚ฐ ์ˆ˜์ต๋ฅ  ๊ณ„์‚ฐ๊ธฐ
    SKํ•˜์ด๋‹‰์Šค
    tomcat servlet
    servlet 404
    ๋ชจ์˜ํ•ดํ‚น
    ์•…์„ฑ๋ฉ”์ผ
    vpn ์˜คํ”ˆ์†Œ์Šค
    ์‚ผ์„ฑ์ „์ž์šฐ
    eclipse
    ์œ ๋‹ˆํ‹ฐ
    ์ˆ˜์ต๋ฅ  ๊ณ„์‚ฐ๊ธฐ
    ์ฝ”์ฝ”๋„›์ธ 
    ๋ฐฉ๋ฒ™
    ๋ถ€ํŠธ์ŠคํŠธ๋žฉ
    vpn ์„ค์น˜
    ๋ฉ”์ผํ—ค๋”๋ถ„์„
    ์• ํ”ŒํŽ˜์ด ์„ค์ •๋ฐฉ๋ฒ•
    ์„œ๋ธŒ๋„๋ฉ”์ธ ์ธ์ฆ์„œ
    ISMS-P
    jsp
    Visual Studio
    ์™€์ดํŒŒ์ด ๋น„๋ฐ€๋ฒˆํ˜ธ ํƒˆ์ทจ
    nmap
    ํ†ฐ์บฃ ์„œ๋ธ”๋ฆฟ
  • ์ตœ๊ทผ ๋Œ“๊ธ€

  • hELLOยท Designed By์ •์ƒ์šฐ.v4.10.0
TwoIceFish
[Post-Explotation] Linux Priviledge Escalation
์ƒ๋‹จ์œผ๋กœ

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”