CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementEasy

A penetration tester has gained a low-privileged shell on a Linux server. During the post-exploitation phase, the tester identifies that the 'find' command is installed with the SUID bit set for the 'root' user. Which of the following commands would allow the tester to escalate privileges to root?

  1. Afind / -exec chmod +s /bin/bash \;
  2. Bfind . -exec cp /bin/bash /tmp/shell \;
  3. Cfind . -exec /bin/sh -p \; -quit
  4. Dfind / -exec sudo /bin/bash \;
Show answer & explanation

Correct answer: C. find . -exec /bin/sh -p \; -quit

When a command like 'find' has the SUID bit set for root, it runs with root privileges. Using '-exec' allows arbitrary commands to be executed within the context of 'find'. Executing '/bin/sh -p' with the SUID bit preserves the effective user ID, providing a root shell.

Why the other options are wrong

  • A. This command attempts to set the SUID bit on bash, but 'find' might not have the necessary permissions to modify /bin/bash directly.
  • B. This command would copy bash but would not automatically grant a root shell.
  • D. This command requires a password for sudo, which the low-privileged user would not have.

SUID Binary Exploitation

Exploiting legitimate binaries with the SUID bit set to gain elevated privileges, typically by executing a shell or another privileged command.

  • SUID bit allows a program to run with the permissions of its owner.
  • If a root-owned SUID binary can execute arbitrary commands, it can lead to privilege escalation.
  • Common SUID binaries to check include 'find', 'nmap', 'vi', 'more', 'less'.

Memory trick: SUID finds a path to root.

More Post-exploitation and Lateral Movement questions