linux-privilege-escalation-checklist.md (12718B)
1 --- 2 title: "Linux Privilege Escalation Checklist" 3 section: "Linux" 4 sectionSlug: "linux-hardening" 5 sourcePath: "src/linux-hardening/main-system-information/linux-privilege-escalation-checklist.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/main-system-information/linux-privilege-escalation-checklist.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Linux Privilege Escalation Checklist 14 15 # Checklist - Linux Privilege Escalation 16 17 18 ### **Best tool to look for Linux local privilege escalation vectors:** [**LinPEAS**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS) 19 20 ### [System Information](../linux-basics/linux-privilege-escalation/index.html#system-information) 21 22 - [ ] Get **OS information** 23 - [ ] Check the [**PATH**](../linux-basics/linux-privilege-escalation/index.html#path), any **writable folder**? 24 - [ ] Check [**env variables**](../linux-basics/linux-privilege-escalation/index.html#env-info), any sensitive detail? 25 - [ ] Search for [**kernel exploits**](../linux-basics/linux-privilege-escalation/index.html#kernel-exploits) **using scripts** (DirtyCow?) 26 - [ ] Before running a kernel PoC, verify its **actual prerequisites**, not only `uname -r`: architecture, required `CONFIG_*` options/modules, namespace creation and active mitigations. For example, test user/network namespace availability with `unshare -Urn true`; modern netfilter exploits may require `CONFIG_USER_NS`, unprivileged user namespaces and `CONFIG_NF_TABLES`.<sup>[[3]](#references)</sup> 27 - [ ] **Check** if the [**sudo version** is vulnerable](../linux-basics/linux-privilege-escalation/index.html#sudo-version) 28 - [ ] [**Dmesg** signature verification failed](../linux-basics/linux-privilege-escalation/index.html#dmesg-signature-verification-failed) 29 - [ ] Review [**kernel module and module-loading misconfigurations**](/hacktricks/linux-hardening/main-system-information/kernel-modules-and-modprobe#kernel-module-and-module-loading-misconfigurations): `insmod`, `modinfo`, `lsmod`, `dmesg`, signature enforcement and `modules_disabled`. 30 - [ ] Check [**kernel.modprobe / modprobe_path abuse paths**](/hacktricks/linux-hardening/main-system-information/kernel-modules-and-modprobe#kernelmodprobe--modprobe_path-abuse-checks) if the helper path can be modified or triggered. 31 - [ ] Check [**writable /lib/modules paths**](/hacktricks/linux-hardening/main-system-information/kernel-modules-and-modprobe#writable-libmodules-review), including writable `.ko*` files and `modules.*` metadata. 32 - [ ] More system enum ([date, system stats, cpu info, printers](../linux-basics/linux-privilege-escalation/index.html#more-system-enumeration)) 33 - [ ] [Enumerate more defenses](../linux-basics/linux-privilege-escalation/index.html#enumerate-possible-defenses) 34 35 ### [Drives](../linux-basics/linux-privilege-escalation/index.html#drives) 36 37 - [ ] **List mounted** drives 38 - [ ] **Any unmounted drive?** 39 - [ ] **Any creds in fstab?** 40 41 ### [**Installed Software**](../linux-basics/linux-privilege-escalation/index.html#installed-software) 42 43 - [ ] **Check for**[ **useful software**](../linux-basics/linux-privilege-escalation/index.html#useful-software) **installed** 44 - [ ] **Check for** [**vulnerable software**](../linux-basics/linux-privilege-escalation/index.html#vulnerable-software-installed) **installed** 45 - [ ] On Debian/Ubuntu, check whether **needrestart interpreter scanning** is installed/enabled: `dpkg-query -W needrestart 2>/dev/null; grep -R interpscan /etc/needrestart 2>/dev/null`. Vulnerable builds crossed the privilege boundary by reusing attacker-controlled `PYTHONPATH`/`RUBYLIB`, racing `/proc/<pid>/exe`, or scanning attacker-controlled Perl paths when APT or `unattended-upgrades` invoked needrestart as root.<sup>[[4]](#references)</sup> 46 47 ### [Processes](../linux-basics/linux-privilege-escalation/index.html#processes) 48 49 - [ ] Is any **unknown software running**? 50 - [ ] Is any software running with **more privileges than it should have**? 51 - [ ] Search for **exploits of running processes** (especially the version running). 52 - [ ] Can you **modify the binary** of any running process? 53 - [ ] **Monitor processes** and check if any interesting process is running frequently. 54 - [ ] Can you **read** some interesting **process memory** (where passwords could be saved)? 55 56 ### [Scheduled/Cron jobs?](../linux-basics/linux-privilege-escalation/index.html#scheduled-jobs) 57 58 - [ ] Is the [**PATH** ](../linux-basics/linux-privilege-escalation/index.html#cron-path)being modified by some cron and you can **write** in it? 59 - [ ] Any [**wildcard** ](../linux-basics/linux-privilege-escalation/index.html#cron-using-a-script-with-a-wildcard-wildcard-injection)in a cron job? 60 - [ ] Some [**modifiable script** ](../linux-basics/linux-privilege-escalation/index.html#cron-script-overwriting-and-symlink)is being **executed** or is inside **modifiable folder**? 61 - [ ] Have you detected that some **script** could be or are being [**executed** very **frequently**](../linux-basics/linux-privilege-escalation/index.html#frequent-cron-jobs)? (every 1, 2 or 5 minutes) 62 63 ### [Services](../linux-basics/linux-privilege-escalation/index.html#services) 64 65 - [ ] Any **writable .service** file? 66 - [ ] Any **writable binary** executed by a **service**? 67 - [ ] Any writable **helper, config or environment file referenced by a root unit** (`ExecStartPre=`, `ExecStartPost=`, `EnvironmentFile=`)? Inspect the merged unit with `systemctl cat <unit>` and review [service/socket file abuse](/hacktricks/linux-hardening/interesting-files-permissions/write-to-root). 68 - [ ] Any **writable folder in systemd PATH**? 69 - [ ] Any **writable systemd unit drop-in** in `/etc/systemd/system/<unit>.d/*.conf` that can override `ExecStart`/`User`?<sup>[[2]](#references)</sup> 70 71 ### [Timers](../linux-basics/linux-privilege-escalation/index.html#timers) 72 73 - [ ] Any **writable timer**? 74 75 ### [Sockets](../linux-basics/linux-privilege-escalation/index.html#sockets) 76 77 - [ ] Any **writable .socket** file? 78 - [ ] Can you **communicate with any socket**? 79 - [ ] **HTTP sockets** with interesting info? 80 - [ ] Can you access a [**container-runtime or node-agent API**](/hacktricks/linux-hardening/containers-namespaces/container-security/runtime-api-and-daemon-exposure) such as `docker.sock`, `containerd.sock`, `crio.sock`, `podman.sock`, `buildkitd.sock` or a kubelet endpoint? Test the raw HTTP/gRPC API even when its usual CLI is absent. 81 82 ### [D-Bus](../linux-basics/linux-privilege-escalation/index.html#d-bus) 83 84 - [ ] Can you **communicate with any D-Bus**? 85 86 ### [Network](../linux-basics/linux-privilege-escalation/index.html#network) 87 88 - [ ] Enumerate the network to know where you are 89 - [ ] **Open ports you couldn't access before** getting a shell inside the machine? 90 - [ ] Can you **sniff traffic** using `tcpdump`? 91 92 ### [Users](../linux-basics/linux-privilege-escalation/index.html#users) 93 94 - [ ] Generic users/groups **enumeration** 95 - [ ] Do you have a **very big UID**? Is the **machine** **vulnerable**? 96 - [ ] Can you [**escalate privileges thanks to a group**](../user-information/interesting-groups-linux-pe/index.html) you belong to? 97 - [ ] **Clipboard** data? 98 - [ ] Password Policy? 99 - [ ] Try to **use** every **known password** that you have discovered previously to login **with each** possible **user**. Try to login also without a password. 100 101 ### [Writable PATH](../linux-basics/linux-privilege-escalation/index.html#writable-path-abuses) 102 103 - [ ] If you have **write privileges over some folder in PATH** you may be able to escalate privileges 104 105 ### [SUDO and SUID commands](../linux-basics/linux-privilege-escalation/index.html#sudo-and-suid) 106 107 - [ ] Can you execute **any command with sudo**? Can you use it to READ, WRITE or EXECUTE anything as root? ([**GTFOBins**](https://gtfobins.github.io)) 108 - [ ] If `sudo -l` allows `sudoedit`, check for **sudoedit argument injection** (CVE-2023-22809) via `SUDO_EDITOR`/`VISUAL`/`EDITOR` to edit arbitrary files on vulnerable versions (`sudo -V` < 1.9.12p2). Example: `SUDO_EDITOR="vim -- /etc/sudoers" sudoedit /etc/hosts`.<sup>[[1]](#references)</sup> 109 - [ ] Is any **exploitable SUID binary**? ([**GTFOBins**](https://gtfobins.github.io)) 110 - [ ] Are [**sudo** commands **limited** by **path**? can you **bypass** the restrictions](../linux-basics/linux-privilege-escalation/index.html#sudo-execution-bypassing-paths)? 111 - [ ] [**Sudo/SUID binary without path indicated**](../linux-basics/linux-privilege-escalation/index.html#sudo-command-suid-binary-without-command-path)? 112 - [ ] [**SUID binary specifying path**](../linux-basics/linux-privilege-escalation/index.html#suid-binary-with-command-path)? Bypass 113 - [ ] [**LD_PRELOAD vuln**](/hacktricks/linux-hardening/interesting-files-permissions/suid-shared-library-and-linker-abuse#ld_preload-ld_library_path-and-suid) 114 - [ ] [**Lack of .so library in SUID binary**](/hacktricks/linux-hardening/interesting-files-permissions/suid-shared-library-and-linker-abuse#missing-shared-object-injection) from a writable folder? 115 - [ ] [**SUID RPATH/RUNPATH or writable library path**](/hacktricks/linux-hardening/interesting-files-permissions/suid-shared-library-and-linker-abuse#rpath-and-runpath)? 116 - [ ] [**SUDO tokens available**](../linux-basics/linux-privilege-escalation/index.html#reusing-sudo-tokens)? [**Can you create a SUDO token**](../linux-basics/linux-privilege-escalation/index.html#var-run-sudo-ts-less-than-username-greater-than)? 117 - [ ] Can you [**read or modify sudoers files**](../linux-basics/linux-privilege-escalation/index.html#etc-sudoers-etc-sudoers-d)? 118 - [ ] Can you [**modify /etc/ld.so.conf.d/**](/hacktricks/linux-hardening/interesting-files-permissions/suid-shared-library-and-linker-abuse#linker-configuration)? 119 - [ ] [**OpenBSD DOAS**](../linux-basics/linux-privilege-escalation/index.html#doas) command 120 121 ### [Capabilities](../linux-basics/linux-privilege-escalation/index.html#capabilities) 122 123 - [ ] Has any binary any **unexpected capability**? 124 125 ### [ACLs](../linux-basics/linux-privilege-escalation/index.html#acls) 126 127 - [ ] Has any file any **unexpected ACL**? 128 129 ### [Open Shell sessions](../linux-basics/linux-privilege-escalation/index.html#open-shell-sessions) 130 131 - [ ] **screen** 132 - [ ] **tmux** 133 134 ### [SSH](../linux-basics/linux-privilege-escalation/index.html#ssh) 135 136 - [ ] **Debian** [**OpenSSL Predictable PRNG - CVE-2008-0166**](../linux-basics/linux-privilege-escalation/index.html#debian-openssl-predictable-prng-cve-2008-0166) 137 - [ ] [**SSH Interesting configuration values**](../linux-basics/linux-privilege-escalation/index.html#ssh-interesting-configuration-values) 138 139 ### [Interesting Files](../linux-basics/linux-privilege-escalation/index.html#interesting-files) 140 141 - [ ] **Profile files** - Read sensitive data? Write to privesc? 142 - [ ] **passwd/shadow files** - Read sensitive data? Write to privesc? 143 - [ ] **Check commonly interesting folders** for sensitive data 144 - [ ] **Weird Location/Owned files,** you may have access to or alter executable files 145 - [ ] **Modified** in last mins 146 - [ ] **Sqlite DB files** 147 - [ ] **Hidden files** 148 - [ ] **Script/Binaries in PATH** 149 - [ ] **Web files** (passwords?) 150 - [ ] **Backups**? 151 - [ ] **Known files that contains passwords**: Use **Linpeas** and **LaZagne** 152 - [ ] **Generic search** 153 154 ### [**Writable Files**](../linux-basics/linux-privilege-escalation/index.html#writable-files) 155 156 - [ ] **Modify python library** to execute arbitrary commands? 157 - [ ] Can you **modify log files**? **Logtotten** exploit 158 - [ ] Can you **modify /etc/sysconfig/network-scripts/**? Centos/Redhat exploit 159 - [ ] Can you [**write in ini, int.d, systemd or rc.d files**](../linux-basics/linux-privilege-escalation/index.html#init-init-d-systemd-and-rc-d)? 160 161 ### [**Other tricks**](../linux-basics/linux-privilege-escalation/index.html#other-tricks) 162 163 - [ ] Can you [**abuse NFS to escalate privileges**](../linux-basics/linux-privilege-escalation/index.html#nfs-privilege-escalation)? 164 - [ ] Do you need to [**escape from a restrictive shell**](../linux-basics/linux-privilege-escalation/index.html#escaping-from-restricted-shells)? 165 166 167 ## References 168 169 - [1] [Sudo advisory: sudoedit arbitrary file edit](https://www.sudo.ws/security/advisories/sudoedit_any/) 170 - [2] [Oracle Linux docs: systemd drop-in configuration](https://docs.oracle.com/en/operating-systems/oracle-linux/8/systemd/ModifyingsystemdConfigurationFiles.html) 171 - [3] [Notselwyn: CVE-2024-1086 exploit requirements and research](https://github.com/Notselwyn/CVE-2024-1086) 172 - [4] [Qualys Security Advisory: LPEs in needrestart](https://www.qualys.com/2024/11/19/needrestart/needrestart.txt)