Path: blob/master/documentation/modules/post/linux/gather/igel_dump_file.md
27933 views
Vulnerable Application
IGEL OS < 11.09.260 with a shell or meterpreter session.
IGEL OS is a Linux-based operating system designed for endpoint devices, primarily used in enterprise environments to provide secure access to virtual workspaces. It focuses on enhancing security, simplifying management, and improving user productivity across various sectors, including healthcare and finance.
In previous versions, /config/bin/setup_cmd was an SUID binary, with a preset list of files it could execute with elevated permissions. This allowed /bin/date -f to be used for data extraction as root.
The dumped file is printed to screen and saved as loot.
Verification Steps
Get a
shellormeterpretersession on an IGEL OS < 11.09.260 hostUse:
use post/linux/gather/igel_dump_fileSet:
set SESSION <id>, replacing<id>with the session IDOptionally, set
RPATHRun:
runContents of file is displayed
Options
| Name | Description |
|---|---|
| RPATH | File on the target to dump |