data:image/s3,"s3://crabby-images/79cd6/79cd6aadab042cd05d2006c38bb0b4f28c426a65" alt=""
CSULB Projects
Linux Security
Linux Security
data:image/s3,"s3://crabby-images/ea95a/ea95a3416e1a0bee4624b7096b0e05aa488a288f" alt=""
This is the badge that was obtained after successfully completing the Linux Security class as part of the CSULB Cybersecurity Bootcamp.
A few of the focused tasks from the following hands on material is to showcase what was learned in the Linux Security Course.
For searching Linux file system from within the Terminal we can use the following:
Open Terminal
If we try to find the log file for the package manager with the following:
find /var/ -name dpkg.logdata:image/s3,"s3://crabby-images/8779c/8779c6e414323e84498c95a19aa9908bc6e524c3" alt="source: imgur.com"
We can see that we don't have permission to access the files in the /var directory, but we can still see the contents of the directory that can be used for enumeration.
If we use the above command with an adjustment to redirect the error messages and prevent them from being displayed, it will show what we are looking for:
find /var/-name dpkg.log 2>/dev/nulldata:image/s3,"s3://crabby-images/88ffb/88ffb6048eea44b1b8a0176bd98d75fa9a2c6809" alt="source: imgur.com"
grep is a big help when looking for specific characters or phrases, for instance:
grep firefox /var/log/dpkg.logdata:image/s3,"s3://crabby-images/20179/20179e26c1b0a2018d22d532b77680f4f8bbd6a3" alt="source: imgur.com"
We can see when the firefox packages have been installed, updated, modified, and when these changes took effect.
Using the wildcard character * we can search for any file name or type of file, in the below example we can look for any shell applications that are in a specific directory. In this case we are looking in the /home/john directory for any file ending in .sh:
find /bin/ -name *.sh 2>/dev/nulldata:image/s3,"s3://crabby-images/13f4a/13f4a7d01c1745a544d515035b80346194416e40" alt="source: imgur.com"
We can also use grep to look for files that contain words like password for instance and by using the color command we can see it highlight password in red:
grep -rw password . --colordata:image/s3,"s3://crabby-images/45981/45981eee6de9aef05375c29d73c35dd121d57280" alt="source: imgur.com"
There are also ways we can try to see previous commands that have been input into the Terminal. This can lead to grabbing credentials that have been entered and we can see them in clear text.
Running the list command to show all files in the directory will also show the hidden files, these can be indicated by the period before the file name for instance here we will look at the history using the concatenate (cat) command: cat .zsh_historydata:image/s3,"s3://crabby-images/38802/38802f8fa2e8442dda8a4c94fd1443de375b92c5" alt="source: imgur.com"
Side note, with .bash_history you can delete it's contents with the 'history -c' command (minus quotes) but this command is not seen with the newer zsh structure. Manually deleting the contents of the file .zsh_history with a file manipulator like nano or vim you can open the file and then manually delete the contents save and exit and then there will be no history listed when doing a cat .zsh_history read out.
Now for some file manipulation
We can get access to the sudoers file as root with the following:
su - visudoOnce open we can scroll all the way down to the bottom of the document and under # User Privilege Specification we can add our normal user in this case is john by adding the following:
john ALL=(ALL:ALL) ALLdata:image/s3,"s3://crabby-images/0a4ae/0a4aea9787f0ed93db0c5b183801e641ffc66a14" alt="source: imgur.com"
Now that we have sudo access we can see the content of the shadow file to grab the hash:data:image/s3,"s3://crabby-images/f23ba/f23ba4a56e6acdd12d321a50c9bf0efadb44b5b0" alt="source: imgur.com"
Now we can get into some bash scripting to make a script
First we can grab our local IP Address, for this lab will be using Pfsense firewall in a VM with our Kali box.
ip adata:image/s3,"s3://crabby-images/1c9e0/1c9e0a2deea442a1505aee1beb95f35c8db8072d" alt="source: imgur.com"
Using the following we can start up a new document for our script within nano:
nano pingsweep.shOnce this is open we will enter the following bash code to get some pings going:data:image/s3,"s3://crabby-images/236ed/236ed2de8f0fa502c8c3bdd667aa3b777a2c1653" alt="source: imgur.com"
For the above if doing this on your own environment you would need to enter the correlating IP address, in my case it is on the 192.168.1.x subnet.
Now to see this in action we can save and exit the above and run the new script to get the following output:
./pingsweep.shdata:image/s3,"s3://crabby-images/40e8d/40e8d642cdae78b03c02803eda1ac8c762fdcfc6" alt="source: imgur.com"