Misconfigured Services
Privilege escalation via misconfigured services often hinges on improper path resolution in service definitions. When a service's executable path is either unquoted or contains wildcard characters, attackers can exploit this to execute arbitrary code with the service's privileges. This section explores techniques to identify and leverage such misconfigurations in both Windows and Linux environments.
Identifying Misconfigured Services¶
Windows: Unquoted Service Paths¶
Windows services often define executable paths using quoted strings (e.g., "C:\Program Files\MyApp\service.exe"). If the path is unquoted (e.g., C:\Program Files\MyApp\service.exe), the system will resolve it by searching directories in the PATH environment variable. Attackers can exploit this by placing a malicious file in a directory that appears before the intended path in PATH.
Example:
If a service uses C:\Windows\System32\service.exe (unquoted), an attacker could replace C:\Windows\System32\service.exe with a malicious binary. When the service starts, it would execute the malicious file instead.
Detection:
Use the sc command to query service configurations:
BinaryPathName field. Tools like psexploit or Exploit-Service.exe can automate this check.
Linux: Unquoted Paths in Service Files¶
Linux services (managed by systemd or init.d) may contain unquoted paths in their configuration files. For example, a systemd service file might have:
User or Group privileges elevated beyond the regular user can grant unauthorized access.
Example:
Replace /usr/bin/myapp with a malicious binary and restart the service. If the service runs with elevated privileges, the attacker gains access.
Detection:
Inspect systemd service files using:
ExecStart, ExecStop, or other Exec directives. Check for world-writable permissions (chmod o+w) on service files, which may allow unauthorized modifications.
Exploitation Techniques¶
Windows: Exploiting Unquoted Paths¶
- Replace the Target Executable:
Place a malicious binary (e.g.,nc.exe) in a directory prioritized byPATH(e.g.,C:\Windows\System32).
- Restart the Service:
Usescto restart the service, triggering execution of the malicious binary:
Linux: Exploiting Unquoted Paths¶
- Modify the Service File:
Replace the legitimate binary path with a symlink or malicious file. For example:
- Restart the Service:
Usesystemctlto restart the service:
Common Tools and Mitigations¶
- Tools:
psexploit,Exploit-Service.exe,checksec,ltrace. - Mitigations:
- Quote service paths in Windows.
- Avoid unquoted paths in Linux service files.
- Restrict permissions on service configuration files.
Key takeaways¶
- Misconfigured services with unquoted paths allow attackers to execute arbitrary code with elevated privileges.
- Windows services can be exploited by leveraging
PATHresolution, while Linux services often rely on unquotedExecdirectives. - Always verify service configurations and enforce strict permissions on critical system files.
- Use tools like
sc,systemctl, andchecksecto identify and mitigate misconfigurations.