LD_PRELOAD
OFFSEC - Proving Grounds - CARRYOVER
·3043 words·15 mins
OFFSEC PG PRACTICE
SQLMAP
LD_PRELOAD
Carvilla on port 80 is vulnerable to SQL injection, providing initial access via SQLmap. An exposed LD_PRELOAD variable enables a custom shared object to be executed with sudo, escalating privileges to root.
OFFSEC - Proving Grounds - PATHWAY
·1653 words·8 mins
OFFSEC PG PRACTICE
LD_PRELOAD
Port 4566 exposes credentials, enabling SSH access. Sudo permits passwordless /usr/bin/ping, and the set LD_PRELOAD variable can be abused to compile a C payload and escalate privileges to root.