Posts

Showing posts with the label ld_preload

Nahamcon2021 CTF - Banking On It - Writeup

Image
Introduction Today we're doing a CTF writeup for the Banking On It challenge from the NahamCon2021 CTF. Banking On It is a Linux PrivEsc challenge, and after we start the challenge we received a string we can use to interact with the challenge: First, we login to the server as the gus user, using an SSH private key captured from a previous challenge: ssh -i guskey.txt -p 31608 gus@challenge.nahamcon.com First, let's see if our user has any special sudo privileges: sudo -l Our user can run the SETENV command as root without a password when using the bank program in the /opt/banking/ directory. That means that if we're able to create a malicious shared object (.so) file, we can use the SETENV LD_PRELOAD command to activate the malicious .so file and elevate our privileges. First, let's see if there's a compiler on the system we can use to compile our .so file. which gcc That being confirmed, we move to a publicly writable directory and create our malicious...