> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/es/privesc/path-hijacking/path-hijacking-tar-linux-privilege-escalation.md).

# Secuestro de PATH (tar) - Escalada de privilegios en Linux

## Qué es

El secuestro de PATH abusa de programas o scripts privilegiados que llaman comandos sin rutas absolutas. Si el atacante controla un directorio anterior en `PATH`, el proceso privilegiado puede ejecutar el binario del atacante. Esta página específica se centra en **Secuestro de PATH (tar)** y mantiene práctico el flujo de explotación: identificar la condición, validarla de forma segura y luego ejecutar la carga útil mínima necesaria para demostrar el impacto.

## Enumeración

Comienza confirmando el contexto local y la configuración incorrecta exacta antes de ejecutar la ruta de explotación.

```bash
echo $PATH
strings <binary> | head
ltrace <binary> 2>/dev/null
```

## Ejemplos

**Búsqueda binaria con permisos SUID**

```bash
find / -perm -4000 2>/dev/null
```

Resultado: Se encontró un archivo binario interesante:/ /\&#xNAN;**`/usr/bin/pandora_backup`**.

<figure><img src="/files/09b211f7e5bcf19e6f7e3d34bf0cadd57ef61f92" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/8a5ce924308d23bfc0ba5bbeac5a1314b83d666b" alt=""><figcaption></figcaption></figure>

**Análisis binario con `ltrace`**

Para entender cómo funciona el binario, usamos **`ltrace`** (una herramienta de seguimiento de llamadas al sistema) para observar las llamadas al sistema realizadas por este binario:

```bash
ltrace /usr/bin/pandora_backup
```

Esto nos permitió descubrir que el binario ejecutaba el **`tar`** comando sin usar una ruta absoluta para el ejecutable, lo que crea una posible vulnerabilidad. En otras palabras, si modificamos nuestro **`PATH`** para incluir un directorio que contenga un ejecutable malicioso llamado `tar`, se ejecutaría en lugar del original.

<figure><img src="/files/d622be818c3c014e9e31c48bc9f309117c97f92d" alt=""><figcaption></figcaption></figure>

**Operación mediante desvío del PATH**

**Se creó un `tar` archivo:** Creamos un archivo llamado `tar` en el `/tmp/` directorio con permisos de ejecución **SUID**. Este archivo contiene un comando para abrir una shell bash con privilegios elevados:

```bash
chmod 4777 /bin/bash
```

**Cambio de variable `PATH`:** Para obligar al sistema a usar nuestra versión maliciosa de `tar`, modificamos la variable `PATH` para priorizar el directorio `/tmp/`

```bash
export PATH=/tmp/:$PATH
```

<figure><img src="/files/1ae440a9e7b07646c1c0691f375dd63322f2d36e" alt=""><figcaption></figcaption></figure>

**Ejecución del binario vulnerable:** Después de modificar la `PATH`, ejecutamos el binario **`pandora_backup`**:

<figure><img src="/files/06c6c8ba1250b3de394826504d2c32d7ea7a7361" alt=""><figcaption></figcaption></figure>

Gracias a ejecutar nuestra versión modificada de `tar`, se ha abierto una shell Bash con privilegios elevados, dándonos `root` acceso.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/es/privesc/path-hijacking/path-hijacking-tar-linux-privilege-escalation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
