EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium
A penetration tester has successfully exploited a vulnerable web application and gained initial access to a Linux server as a low-privileged user. They now need to elevate their privileges to 'root'. They discover that a cron job is configured to run a script, '/opt/cleanup.sh', every 5 minutes with root privileges. The permissions on '/opt/cleanup.sh' are 'rwxrwxrwx' (777). Which of the following is the most direct and effective method for privilege escalation in this scenario?
- AInjecting malicious code into '/opt/cleanup.sh'
- BExploiting a SUID binary
- CModifying the PATH variable
- DLeveraging kernel exploits
Show answer & explanationAnswer & explanation
Correct answer: A. Injecting malicious code into '/opt/cleanup.sh'
The scenario describes a world-writable script ('/opt/cleanup.sh') being executed as root by a cron job. The most direct method for privilege escalation is to modify this script with malicious code (e.g., a reverse shell or adding a new root user) that will then be executed by the cron job with root privileges.
Why the other options are wrong
- B. Exploiting SUID binaries is a common technique, but the scenario provides a more direct vulnerability with the writable cron script.
- C. Modifying the PATH variable is relevant if a script is calling an unprivileged command, but in this case, the script itself is vulnerable.
- D. Leveraging kernel exploits is a complex technique, usually reserved when simpler misconfigurations like this are not present.
Cron Job Misconfiguration
A vulnerability where scheduled tasks (cron jobs) on Linux systems are configured to run scripts or commands with elevated privileges (e.g., root) from locations that are writable by lower-privileged users, allowing for privilege escalation.
- Often involves scripts with overly permissive file permissions (e.g., 777).
- Attackers can inject malicious code into the script to be executed as root.
- A common method for local privilege escalation on Linux systems.
Memory trick: Linux escalation: SUID for root, Cron for scripts, Kernel for deep, SUDO for rules.