• (๑>؂•̀๑)
  • Home
  • Blog
  • Tags
  • Categories
  • Projects
  • Search ﹒◌﹒✦

Search

NOPASSWD-sudo

Found 1 related articles

Back to Tags
  • 2024-10-31

    StellarJWT - JWT Exploitation and Chained SUID Privilege Escalation


    Technical writeup detailing the compromise of the 'StellarJWT' challenge. The methodology involves identifying and decoding an exposed JSON Web Token (JWT) for user enumeration, followed by a dictionary attack using Hydra for SSH access. Privilege escalation is achieved through a chained exploitation of NOPASSWD SUID binaries: using 'socat' for horizontal movement and 'chown' for '/etc/passwd' modification to gain final root access.

    DockerLabs JWT-Exploitation Brute-Force Hydra SUID-Privilege-Escalation NOPASSWD-sudo socat chown-bypass