EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy
A penetration tester is evaluating a Windows server. They aim to exploit a misconfiguration to gain elevated privileges. During their reconnaissance, they discover that a scheduled task is running with 'SYSTEM' privileges, executing a script from a world-writable directory. Which of the following attack techniques would be most effective for privilege escalation in this scenario?
- APass-the-Hash attack
- BService Path Hijacking
- CScheduled Task Abuse
- DDLL Side-Loading
Show answer & explanationAnswer & explanation
Correct answer: C. Scheduled Task Abuse
The scenario explicitly describes a scheduled task running with high privileges from a world-writable directory. This setup is a classic vulnerability that can be exploited by replacing the legitimate script with a malicious one, leading to privilege escalation.
Why the other options are wrong
- A. Pass-the-Hash is used to authenticate to other systems using NTLM hashes, not directly for local privilege escalation via misconfigured scheduled tasks.
- B. Service Path Hijacking exploits misconfigured service executable paths, often due to unquoted service paths, which is different from a scheduled task executing a script.
- D. DLL Side-Loading involves placing a malicious DLL in a directory where an application expects to load a legitimate DLL, which is not the primary vulnerability described here.
Scheduled Task Abuse
Exploiting misconfigured scheduled tasks on a system to execute malicious code with elevated privileges, typically by replacing the legitimate script or executable.
- Often involves tasks running with SYSTEM or administrator privileges.
- Vulnerable if the task's executable path is writable by low-privileged users.
- Common in Windows environments, but also applicable to cron jobs in Linux.
Memory trick: Elevate your access, bypass the gate, exploit the weak link, seal your fate.