
Enumerazione di escalation dei privilegi in post-exploitation su Linux
Enumy è un eseguibile portatile ultra veloce che si inserisce nella macchina Linux di destinazione durante un pentest o CTF nella fase di post-exploitation. Eseguire enumy enumererà la macchina per vulnerabilità di sicurezza comuni.
Puoi scaricare il binario finale dalla scheda release x86 o x64. Collegato staticamente a musl Trasferisci il binario finale di enumy sulla macchina di destinazione.
./enumy
$ ./enumy64 -h
▄█▀─▄▄▄▄▄▄▄─▀█▄ _____
▀█████████████▀ | __|___ _ _ _____ _ _
█▄███▄█ | __| | | | | | |
█████ |_____|_|_|___|_|_|_|_ |
█▀█▀█ |___|
https://github.com/luke-goddard/enumy
Enumy - Used to enumerate the target the target environment & look for
common security vulnerabilities and hostspots
----------------------------------------------------------------------
Output
-o <loc> OUTPUT results to location (default enumy.json)
Walking Filesystem
-i <loc> IGNORE files in this directory (usefull for network shares)
-w <loc> Only WALK files in this directory (usefull for devlopment)
Scan Options
-f run FULL scans (CPU intensive scan's enabled)
-t <num> THREADS (default 4)
Printing Options
-a Print all security AUDIT issues to screen (probably won't help duing a CTF)
Issues are ALWAYS logged in result files regardless of this flag being set.
-d <1|2> Print DEBUG mode (1 low, 2 high) to enable error being printed to screen.
-g <H|M|L> print to screen values GREATER than or equal to high, medium & low
-p <H|M|L|I> do not PRINT to screen high, medium, low & info issues (see below for example)
-m 1-100 MAXIMUM number of issues with same name to print to screen default (unlimited)
Per compilare durante lo sviluppo, sono sufficienti make e la libreria libcap.
sudo apt-get install libcap-dev
make
Per rimuovere la dipendenza da glibc e collegare staticamente tutte le librerie/compilare con musl, procedere come segue. Nota: per farlo dovrai avere docker installato per creare l'ambiente di build Alpine.
./build.sh 64bit
./build.sh 32bit
./build.sh all
cd output

Di seguito è riportata la lista sempre crescente delle scansioni che sono state implementate.