OSCP/시험대비

Manual Privilege Escalation

우와해커 2020. 7. 15. 15:02
https://www.netsecfocus.com/oscp/2019/03/29/The_Journey_to_Try_Harder-_TJNulls_Preparation_Guide_for_PWK_OSCP.html

https://herrfeder.github.io/pentesting/2018/09/30/OSCP-Cheat-Sheet.html
https://www.gitbook.com/book/sushant747/total-oscp-guide
sushant747.gitbooks.io/total-oscp-guide/privilege_escalation_-_linux.html
sushant747.gitbooks.io/total-oscp-guide/privilege_escalation_windows.html
blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/
pentest.blog/windows-privilege-escalation-methods-for-pentesters/

공부 및 정리필요

 

Linux

Kernel exploits
Programs running as root
Installed software
Weak/reused/plaintext passwords
Inside service
Suid misconfiguration
Abusing sudo-rights
World writable scripts invoked by root
Bad path configuration
Cronjobs
Unmounted filesystems