Escalacion de privilegios usando crontabs
â•─[/srv/Backup_Invoices]─[gerh@spartan]─[1]─[27]
╰─[:(] % ls -la Bk
total 3384
-rw-r--r-- 1 root root 3858 Sep 29 18:36 2024-9-29-6-36.json
-rw-r--r-- 1 root root 3858 Sep 29 18:39 2024-9-29-6-39.json
â•─[/srv/Backup_Invoices]─[gerh@spartan]─[0]─[28]
╰─[:)] % cat index.js
var fs = require('fs');
var mysql = require('mysql');
var moment = require('moment');
var connection = mysql.createConnection({
host: "localhost",
database:"techshop_db",
user: "gerh",
password: "0.0.0.0:3306/Tech"
});
connection.connect();
connection.query('SELECT * FROM detalle_factura', function(err, results, fields) {
if(err) throw err;
var date = moment().format('YYYY-M-D-h-mm');
console.log(date)
fs.writeFile('/srv/Backup_Invoices/Bk/'+date+'.json', JSON.stringify(results), function (err) {
if (err) throw err;
console.log('Saved!');
});
connection.end();
});PreviousExfiltrando informacion sensible para una escalacion de privilegios en linuxNextAtacando una base de datos redis con CVE-2022-0543
Last updated