CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard
A penetration tester has gained a low-privileged shell on a Linux server. During the privilege escalation phase, the tester discovers a SUID (Set User ID) bit set on a custom utility 'backup_script.sh' owned by root. When executed, this script runs 'tar -czf /tmp/backup.tar.gz /var/www/html'. What is the MOST effective method for the tester to escalate privileges?
- AInjecting a malicious payload into the 'backup_script.sh' file directly.
- BModifying the PATH environment variable to point to a malicious 'tar' executable.
- CUsing 'nmap' to scan for vulnerabilities on the loopback interface.
- DAttempting to brute-force the root password using 'hashcat' on /etc/shadow.
Show answer & explanationAnswer & explanation
Correct answer: B. Modifying the PATH environment variable to point to a malicious 'tar' executable.
The 'backup_script.sh' calls 'tar' without a full path, which means it will use the 'tar' found in the current PATH. By prepending a malicious 'tar' executable to the PATH, the SUID script will execute the malicious 'tar' with root privileges, allowing for privilege escalation.
Why the other options are wrong
- A. As a low-privileged user, the tester likely does not have write permissions to 'backup_script.sh' itself.
- C. 'nmap' is a network scanning tool and not relevant for local privilege escalation through SUID binaries.
- D. Accessing and brute-forcing '/etc/shadow' requires root privileges in the first place, or a separate vulnerability to read it.
SUID Binary PATH Exploitation
A privilege escalation technique where a SUID binary executes another command without specifying its full path, allowing an attacker to inject a malicious version of that command via the PATH environment variable.
- Relies on SUID binary executing external commands.
- Attacker creates a malicious executable with the same name as the called command.
- Modifies PATH to prioritize the malicious executable, leading to privileged execution.
Memory trick: To climb the Linux ladder, look for weak links.