Token Manipulation (Linux)
Linux systems manage user privileges through process tokens, which are used to enforce access control and determine the permissions of a running process. Token manipulation involves altering these tokens to impersonate other users or escalate privileges. This section explores techniques like token impersonation using tools such as ptunnel and pivot attacks, which leverage compromised tokens to access networked systems.
ptunnel: Token Impersonation for Local Escalation¶
ptunnel is a tool that allows an attacker to impersonate a user by hijacking their process token. This is particularly useful in scenarios where a local user has elevated privileges but needs to maintain access under a different identity.
Mechanism:
ptunnel creates a tunnel that mimics a user's token, enabling the attacker to execute commands as that user. This is often used in local privilege escalation scenarios where the attacker has already gained access to a system with limited privileges.
Example:
ptunnel typically requires root privileges to function, and its use is often limited to local environments.
Detection:
- Monitor for unexpected process creation or unusual network activity.
- Check system logs for unauthorized token manipulation attempts.
Pivot Attacks Using Compromised Tokens¶
Pivot attacks involve using a compromised system as a bridge to access other networked systems. Token manipulation enables attackers to leverage the compromised system's token to access internal resources without re-authenticating.
Mechanism:
By stealing a user's token (e.g., through credential dumping or local privilege escalation), an attacker can use it to authenticate to other systems. Tools like ssh or netcat can be used to establish connections using the stolen token.
Example:
ptunnel or credential theft), they can bypass authentication and gain access to the target system.
Detection:
- Monitor for unauthorized SSH or RDP connections.
- Analyze logs for suspicious authentication patterns.
su and Token Manipulation¶
The su (switch user) command allows a user to switch to another user account. While su itself does not manipulate tokens, it can be combined with token-based techniques to maintain access.
Example:
su to switch to a user with higher privileges, effectively extending their access.
Detection:
- Track frequent or unauthorized su usage.
- Monitor for unexpected user switches in system logs.
Key takeaways¶
- Token manipulation in Linux involves altering process tokens to impersonate users or escalate privileges.
- Tools like
ptunnelenable local token impersonation, while pivot attacks use stolen tokens to access networked systems. sucan be leveraged to switch to privileged accounts, but its effectiveness depends on prior token manipulation.- Detection requires monitoring for unusual process creation, network activity, and authentication patterns.