EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium

A penetration tester has successfully exploited a vulnerable web application and gained initial access to a Linux server as a low-privileged user. They now need to elevate their privileges to 'root'. They discover that a cron job is configured to run a script, '/opt/cleanup.sh', every 5 minutes with root privileges. The permissions on '/opt/cleanup.sh' are 'rwxrwxrwx' (777). Which of the following is the most direct and effective method for privilege escalation in this scenario?

  1. AInjecting malicious code into '/opt/cleanup.sh'
  2. BExploiting a SUID binary
  3. CModifying the PATH variable
  4. DLeveraging kernel exploits
Show answer & explanation

Correct answer: A. Injecting malicious code into '/opt/cleanup.sh'

The scenario describes a world-writable script ('/opt/cleanup.sh') being executed as root by a cron job. The most direct method for privilege escalation is to modify this script with malicious code (e.g., a reverse shell or adding a new root user) that will then be executed by the cron job with root privileges.

Why the other options are wrong

  • B. Exploiting SUID binaries is a common technique, but the scenario provides a more direct vulnerability with the writable cron script.
  • C. Modifying the PATH variable is relevant if a script is calling an unprivileged command, but in this case, the script itself is vulnerable.
  • D. Leveraging kernel exploits is a complex technique, usually reserved when simpler misconfigurations like this are not present.

Cron Job Misconfiguration

A vulnerability where scheduled tasks (cron jobs) on Linux systems are configured to run scripts or commands with elevated privileges (e.g., root) from locations that are writable by lower-privileged users, allowing for privilege escalation.

  • Often involves scripts with overly permissive file permissions (e.g., 777).
  • Attackers can inject malicious code into the script to be executed as root.
  • A common method for local privilege escalation on Linux systems.

Memory trick: Linux escalation: SUID for root, Cron for scripts, Kernel for deep, SUDO for rules.

More System Hacking Phases and Attack Techniques questions