Polar bastion host common user command execution (root permission)

Source: Internet
Author: User
Tags ssh port

Polar bastion host common user command execution (root permission)

Polar internal control bastion hosts use advanced technologies to protect internal network devices and servers, and monitor and audit common access methods for such assets, it can control, track, and determine user behavior to meet the security requirements of the enterprise's internal network.

However, this device has a severe vulnerability. You can directly obtain the root permission.

 

Operator: General O & M personnel permissions.
 





Log on to the bastion host using ssh as an ordinary O & M engineer and run the command whoami.
 



The command is executable.



Try to add a user.
 



User Added successfully.



Add User Password.
 





View the ssh port.
 



The port used to log on to the bastion host is 220.



Try to create a new fastfood user login... view the web root directory file ..
 


 





At this point, you have successfully logged on to the bastion host. You can escalate permissions later ..

Solution:

You know better than me...

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.