> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/pt-br/privesc/python-library-hijacking/python-library-hijacking-hashlib-linux-privilege-escalation.md).

# Sequestro de biblioteca Python (hashlib) - Escalada de privilégios no Linux

## O que é

O sequestro de bibliotecas Python abusa da resolução de importação do Python quando um script privilegiado importa módulos de um local gravável. Ao colocar um módulo malicioso mais cedo no caminho de importação, o atacante pode executar código como o usuário privilegiado. Esta página específica se concentra em **Sequestro de Biblioteca Python (hashlib)** e mantém o fluxo de exploração prático: identifique a condição, valide-a com segurança e então execute o payload menor necessário para comprovar o impacto.

## Enumeração

Comece confirmando o contexto local e a configuração incorreta exata antes de executar o caminho de exploração.

```bash
python3 -c "import sys; print('/n'.join(sys.path))"
find / -name '*.py' -writable 2>/dev/null
```

## Exemplos

À medida que **usuário jordan**, vemos quais são os privilégios do sudoers, tentamos executar o **script Python** como jordanmacia e funciona corretamente:

<figure><img src="/files/9b7cd57ec10f117ecd6b700a88a507f4c56a741b" alt=""><figcaption></figcaption></figure>

Neste caso, temos **permissões de leitura, mas não de escrita**. Observamos que ele importa a **variável hashlib**. Se fizermos uma **locate** com o nome da variável, veremos onde ele está **armazenado**. Por fim, observamos que no **PATH do Python**, o primeiro está vazio e isso é uma vulnerabilidade:

<figure><img src="/files/c1f4f14d9bc1a50758eda8d316feda17b34b5054" alt=""><figcaption></figcaption></figure>

No mesmo diretório /tmp, criamos o **hashlib.py** arquivo com o seguinte conteúdo. Este script, quando executamos o script **example.py** em geral, o Python começa a procurar por essas bibliotecas no diretório de trabalho atual, depois nos caminhos definidos na **variável sys.path**.

```python
import os 
os.system("bash)
```

Por fim, ao executar a **example.py**, isso nos dará acesso ao Bash como usuário jordanmacia (teremos **mudado para um usuário** com provavelmente mais privilégios):

<figure><img src="/files/a8d8f4d18a47e935b3b4b59891dac9fea5b442c4" alt="" width="563"><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/pt-br/privesc/python-library-hijacking/python-library-hijacking-hashlib-linux-privilege-escalation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
