Skip to content

Token Manipulation (Linux)

Linux systems manage user privileges through process tokens, which are used to enforce access control and determine the permissions of a running process. Token manipulation involves altering these tokens to impersonate other users or escalate privileges. This section explores techniques like token impersonation using tools such as ptunnel and pivot attacks, which leverage compromised tokens to access networked systems.


ptunnel: Token Impersonation for Local Escalation

ptunnel is a tool that allows an attacker to impersonate a user by hijacking their process token. This is particularly useful in scenarios where a local user has elevated privileges but needs to maintain access under a different identity.

Mechanism:
ptunnel creates a tunnel that mimics a user's token, enabling the attacker to execute commands as that user. This is often used in local privilege escalation scenarios where the attacker has already gained access to a system with limited privileges.

Example:

# Impersonate a user with elevated privileges (e.g., root)
ptunnel -u root
After running this command, the attacker can execute commands as the impersonated user. Note that ptunnel typically requires root privileges to function, and its use is often limited to local environments.

Detection:
- Monitor for unexpected process creation or unusual network activity.
- Check system logs for unauthorized token manipulation attempts.


Pivot Attacks Using Compromised Tokens

Pivot attacks involve using a compromised system as a bridge to access other networked systems. Token manipulation enables attackers to leverage the compromised system's token to access internal resources without re-authenticating.

Mechanism:
By stealing a user's token (e.g., through credential dumping or local privilege escalation), an attacker can use it to authenticate to other systems. Tools like ssh or netcat can be used to establish connections using the stolen token.

Example:

# Use a stolen token to SSH into a target system
ssh -l target_user 192.168.1.100
If the attacker has access to the target user's token (e.g., via ptunnel or credential theft), they can bypass authentication and gain access to the target system.

Detection:
- Monitor for unauthorized SSH or RDP connections.
- Analyze logs for suspicious authentication patterns.


su and Token Manipulation

The su (switch user) command allows a user to switch to another user account. While su itself does not manipulate tokens, it can be combined with token-based techniques to maintain access.

Example:

# Switch to a user with elevated privileges
su - root
If the attacker has already compromised a system with a token, they can use su to switch to a user with higher privileges, effectively extending their access.

Detection:
- Track frequent or unauthorized su usage.
- Monitor for unexpected user switches in system logs.


Key takeaways

  • Token manipulation in Linux involves altering process tokens to impersonate users or escalate privileges.
  • Tools like ptunnel enable local token impersonation, while pivot attacks use stolen tokens to access networked systems.
  • su can be leveraged to switch to privileged accounts, but its effectiveness depends on prior token manipulation.
  • Detection requires monitoring for unusual process creation, network activity, and authentication patterns.