> For the complete documentation index, see [llms.txt](https://morell-tony.gitbook.io/home/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://morell-tony.gitbook.io/home/capture-the-flag/tryhackme/thm-overview/linux-privilege-escalation.md).

# Linux Privilege Escalation

November 13, 2022

{% embed url="<https://tryhackme.com/room/linprivesc>" %}

For this room, I am going to focus on the last tasks which encapsulate all other previous tasks into a final capstone task. We are given a username and password to SSH into in hopes to escalate privileges to receive two flags.

### Enumeration

First, we need to figure out our system and user information. Below is the information found:

* *sudo information*: No sudo rights for our exploited account
* *Kernel information*: 'Linux 3.10.0-1160.el7.x86\_64' running on the system
* *cronjob information*: No cronjobs are running inside of crontab
* *SUID information:* `find / -type f -perm -04000 -ls 2>/dev/null` This helps us find SUID or SGID bit sets.
* *Capabilities information:* `getcap -r / 2>/dev/null` was able to reveal some programs that could be used.

### Privilege Escalation Part 1

Since the current user can read the /etc/passwd file and had no sudo rights I decided the base64 SUID/SGID bit will work well with a gtfobins program exploit. I will be able to use the information here to exploit a file read on /etc/shadow. Then I can use that to find passwords for current users.&#x20;

![](https://850580359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSqAgfe92W3tM8LBhIHHu%2Fuploads%2FZ021Kch5fxgSK8uJ6LMs%2Fimage.png?alt=media\&token=6eae1232-ec9f-46e5-809a-6de24aafe4c3) &#x20;

The SUID for base64 should work for this file read.

![](https://850580359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSqAgfe92W3tM8LBhIHHu%2Fuploads%2FYiZlgBOnsjNeHVS50KJx%2Fimage.png?alt=media\&token=85e18634-1d26-4b31-bad7-4fdc3e1a32a0)

Great! now I can begin copying the contents of /etc/passwd and /etc/shadow over to my attacker machine to see if john can discover some passwords to these usernames.

![](https://850580359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSqAgfe92W3tM8LBhIHHu%2Fuploads%2F8UGg0zza30SnM4GxmpQL%2Fimage.png?alt=media\&token=fd754d0e-d4c5-46d8-9d61-17d07c549924)

A password for another user! Once I logged in I was pleased to find the first flag.

![](https://850580359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSqAgfe92W3tM8LBhIHHu%2Fuploads%2FG9aGCrFA43WguZ61SzkH%2Fimage.png?alt=media\&token=09d47c47-6d72-49af-9fce-186ed73fd4bf)

### Privilege Escalation Part 2

Once I was in the account I enumerated some user information/accesses and found that missy has sudo rights to 'find' which may be helpful for the next exploitation. I go ahead and check gtfobins again and find this line: `sudo find . -exec /bin/sh ; -quit`

This gives me root access and I am able to read the final flag.

![](https://850580359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSqAgfe92W3tM8LBhIHHu%2Fuploads%2FY5so845WFhI4mA1m3QYf%2Fimage.png?alt=media\&token=39dba7aa-4c70-48a7-8669-073d5059b9fa)
