binaries
You found a custom Binary
"backup" example
grep -Ri backup . ..find references to 'backup'
find . | grep app.js ..find our app
cat /var/www/myplace/app.js
const backup_key = '45fac123...';
app.get('/api/admin/backup', function (req, res) {
if (req.session.user && req.session.user.is_admin) {
var proc = spawn('/usr/local/bin/backup', ['-q', backup_key, __dirname ]);
var backup = '';
backup -q key /dir ..we learned how to execute!backup /root
Avoid '/root' Filter with Splatting
Work Local
strace
Analyze Assembly: radare2
Analyze Assembly: binaryninja
PrivEsc: Newline Character
PrivEsc: Newline Character printf
Last updated