Common Linux Privesc
Last updated
Last updated
Room Link: https://tryhackme.com/room/commonlinuxprivesc
Download LinEnum Script
Kali
Login to host
Kali
The target's hostname
There are 8 users
4 shells
Some users can write to passwd file
Victim
Running the shell script in user3 home directory gives us root access right away.
Victim
Victim
Victim
Victim
Victim
Victim
Victim
Kali
Kali
Victim
Add our payload we made in Kali to the script
Victim
Wait for the script to run and catch the shell on Kali.
Victim
The script in user5 home directory is just doing the command ls.
Victim
We now create a script called ls that gives us a bash shell.
Victim
Before we change the path we can see ls goes to /bin/ls
Now after running the below command ls is now directed to our script.
Victim
Now the script in user5s directory acts differently, we now have a root shell.
Victim
Run the following to reset the path variable.
Victim