Courseiva
hardMultiple Choice

PT0-002 Practice Question: During an internal penetration test, a tester…

During an internal penetration test, a tester gains a shell as the 'www-data' user on a Linux server. The server runs a PHP web application that connects to a PostgreSQL database using credentials stored in a config file. The tester discovers that the PostgreSQL server trusts all local connections (no password required) and that the web application's database user has the 'CREATEFUNC' privilege. Which technique is most effective for escalating privileges to database administrator (superuser) and executing system commands as the database service account?

⚠ Common exam trap

The trap here is that candidates may overlook the direct power of 'CREATEFUNC' in PostgreSQL and instead focus on password extraction (Option A) or generic kernel exploits (Option C), missing that database-level function creation is the most efficient and immediate escalation path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a PostgreSQL function using a trusted language like Python or Perl that executes arbitrary system commands, then run it.

The 'CREATEFUNC' privilege allows the web application database user to create user-defined functions in PostgreSQL. By creating a function in a trusted language (e.g., Python, Perl, or C) that executes arbitrary system commands, the tester can run those commands with the privileges of the database service account (e.g., 'postgres'), effectively escalating to superuser-level control and executing system commands without needing a password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the stored credentials to log in as the web application user and run SELECT * FROM pg_shadow; to extract password hashes of other users.

    Why it's wrong here

    Running SELECT * FROM pg_shadow after logging in as the web application user is ineffective because pg_shadow is readable only by database superusers or roles with the appropriate attribute; a typical web app role lacks that privilege. Even if hashes were disclosed, they are generally bcrypt or SCRAM-SHA-256 and would require offline cracking, yielding no immediate system-level command execution or superuser escalation.

  • ✓

    Create a PostgreSQL function using a trusted language like Python or Perl that executes arbitrary system commands, then run it.

    Why this is correct

    Creating a PostgreSQL function in an untrusted procedural language such as plpythonu or plperlu, when your role has CREATE and USAGE on that language, lets you embed a command such as os.system('id') that executes as the database service account (postgres). This leverages the database's own functionality to achieve arbitrary command execution, turning the DBMS into a pivot for privilege escalation.

  • ✗

    Exploit a kernel vulnerability to gain root access and then dump the database files.

    Why it's wrong here

    Exploiting a kernel vulnerability is a high-risk, low-reliability approach: it requires a matching kernel version, reliable exploit code, and system stability; a failed attempt can trigger a kernel panic. Moreover, as the web/application user without root, you'd still need to upload/compile the exploit, and the PostgreSQL function method already provides a deterministic code-execution path with the 'postgres' service account.

  • ✗

    Use the 'sudo' command to switch to the postgres user if the www-data user has sudo privileges.

    Why it's wrong here

    Attempting 'sudo -u postgres' assumes the www-data account has a sudoers entry allowing it to run commands as another user, but the scenario provides no such evidence. Sudo would either prompt for a password that you do not have or fail with 'user is not in the sudoers file'; therefore, this is not a reliable escalation vector compared to abusing PostgreSQL's procedural language features.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.