From c94dc021f5c548597785c84617c19d7a59cd9c2f Mon Sep 17 00:00:00 2001 From: "nuo.o" <49533950+nuoxoxo@users.noreply.github.com> Date: Sat, 16 Nov 2024 23:19:07 +0100 Subject: [PATCH] Update README.mdx --- level03/README.mdx | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/level03/README.mdx b/level03/README.mdx index 5af2a16..dd4ec7c 100644 --- a/level03/README.mdx +++ b/level03/README.mdx @@ -13,14 +13,14 @@ > ltrace ./level03 👉 we can see the `s` bit in action -### output +>>> output getegid() = 2003 geteuid() = 2003 setresgid(2003, 2003, 2003, 0xb7e5ee55, 0xb7fed280) = 0 setresuid(2003, 2003, 2003, 0xb7e5ee55, 0xb7fed280) = 0 system("/usr/bin/env echo Exploit me" ... -### observations +>>> observations 👉 getegid & geteuid return a effective group/user ID ie. 2003 👉 setresgid & setresuid set Real/Effective/Saved ID to ensure that the process maintains privileges