CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard

A penetration tester has gained a low-privileged shell on a Linux server. During the privilege escalation phase, the tester discovers a SUID (Set User ID) bit set on a custom utility 'backup_script.sh' owned by root. When executed, this script runs 'tar -czf /tmp/backup.tar.gz /var/www/html'. What is the MOST effective method for the tester to escalate privileges?

  1. AInjecting a malicious payload into the 'backup_script.sh' file directly.
  2. BModifying the PATH environment variable to point to a malicious 'tar' executable.
  3. CUsing 'nmap' to scan for vulnerabilities on the loopback interface.
  4. DAttempting to brute-force the root password using 'hashcat' on /etc/shadow.
Show answer & explanation

Correct answer: B. Modifying the PATH environment variable to point to a malicious 'tar' executable.

The 'backup_script.sh' calls 'tar' without a full path, which means it will use the 'tar' found in the current PATH. By prepending a malicious 'tar' executable to the PATH, the SUID script will execute the malicious 'tar' with root privileges, allowing for privilege escalation.

Why the other options are wrong

  • A. As a low-privileged user, the tester likely does not have write permissions to 'backup_script.sh' itself.
  • C. 'nmap' is a network scanning tool and not relevant for local privilege escalation through SUID binaries.
  • D. Accessing and brute-forcing '/etc/shadow' requires root privileges in the first place, or a separate vulnerability to read it.

SUID Binary PATH Exploitation

A privilege escalation technique where a SUID binary executes another command without specifying its full path, allowing an attacker to inject a malicious version of that command via the PATH environment variable.

  • Relies on SUID binary executing external commands.
  • Attacker creates a malicious executable with the same name as the called command.
  • Modifies PATH to prioritize the malicious executable, leading to privileged execution.

Memory trick: To climb the Linux ladder, look for weak links.

More Post-exploitation and Lateral Movement questions