daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

linux-privilege-escalation-checklist.md (12718B)


      1 ---
      2 title: "Linux Privilege Escalation Checklist"
      3 section: "Linux"
      4 sectionSlug: "linux-hardening"
      5 sourcePath: "src/linux-hardening/main-system-information/linux-privilege-escalation-checklist.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/main-system-information/linux-privilege-escalation-checklist.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Linux Privilege Escalation Checklist
     14 
     15 # Checklist - Linux Privilege Escalation
     16 
     17 
     18 ### **Best tool to look for Linux local privilege escalation vectors:** [**LinPEAS**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS)
     19 
     20 ### [System Information](../linux-basics/linux-privilege-escalation/index.html#system-information)
     21 
     22 - [ ] Get **OS information**
     23 - [ ] Check the [**PATH**](../linux-basics/linux-privilege-escalation/index.html#path), any **writable folder**?
     24 - [ ] Check [**env variables**](../linux-basics/linux-privilege-escalation/index.html#env-info), any sensitive detail?
     25 - [ ] Search for [**kernel exploits**](../linux-basics/linux-privilege-escalation/index.html#kernel-exploits) **using scripts** (DirtyCow?)
     26 - [ ] Before running a kernel PoC, verify its **actual prerequisites**, not only `uname -r`: architecture, required `CONFIG_*` options/modules, namespace creation and active mitigations. For example, test user/network namespace availability with `unshare -Urn true`; modern netfilter exploits may require `CONFIG_USER_NS`, unprivileged user namespaces and `CONFIG_NF_TABLES`.<sup>[[3]](#references)</sup>
     27 - [ ] **Check** if the [**sudo version** is vulnerable](../linux-basics/linux-privilege-escalation/index.html#sudo-version)
     28 - [ ] [**Dmesg** signature verification failed](../linux-basics/linux-privilege-escalation/index.html#dmesg-signature-verification-failed)
     29 - [ ] Review [**kernel module and module-loading misconfigurations**](/hacktricks/linux-hardening/main-system-information/kernel-modules-and-modprobe#kernel-module-and-module-loading-misconfigurations): `insmod`, `modinfo`, `lsmod`, `dmesg`, signature enforcement and `modules_disabled`.
     30 - [ ] Check [**kernel.modprobe / modprobe_path abuse paths**](/hacktricks/linux-hardening/main-system-information/kernel-modules-and-modprobe#kernelmodprobe--modprobe_path-abuse-checks) if the helper path can be modified or triggered.
     31 - [ ] Check [**writable /lib/modules paths**](/hacktricks/linux-hardening/main-system-information/kernel-modules-and-modprobe#writable-libmodules-review), including writable `.ko*` files and `modules.*` metadata.
     32 - [ ] More system enum ([date, system stats, cpu info, printers](../linux-basics/linux-privilege-escalation/index.html#more-system-enumeration))
     33 - [ ] [Enumerate more defenses](../linux-basics/linux-privilege-escalation/index.html#enumerate-possible-defenses)
     34 
     35 ### [Drives](../linux-basics/linux-privilege-escalation/index.html#drives)
     36 
     37 - [ ] **List mounted** drives
     38 - [ ] **Any unmounted drive?**
     39 - [ ] **Any creds in fstab?**
     40 
     41 ### [**Installed Software**](../linux-basics/linux-privilege-escalation/index.html#installed-software)
     42 
     43 - [ ] **Check for**[ **useful software**](../linux-basics/linux-privilege-escalation/index.html#useful-software) **installed**
     44 - [ ] **Check for** [**vulnerable software**](../linux-basics/linux-privilege-escalation/index.html#vulnerable-software-installed) **installed**
     45 - [ ] On Debian/Ubuntu, check whether **needrestart interpreter scanning** is installed/enabled: `dpkg-query -W needrestart 2>/dev/null; grep -R interpscan /etc/needrestart 2>/dev/null`. Vulnerable builds crossed the privilege boundary by reusing attacker-controlled `PYTHONPATH`/`RUBYLIB`, racing `/proc/<pid>/exe`, or scanning attacker-controlled Perl paths when APT or `unattended-upgrades` invoked needrestart as root.<sup>[[4]](#references)</sup>
     46 
     47 ### [Processes](../linux-basics/linux-privilege-escalation/index.html#processes)
     48 
     49 - [ ] Is any **unknown software running**?
     50 - [ ] Is any software running with **more privileges than it should have**?
     51 - [ ] Search for **exploits of running processes** (especially the version running).
     52 - [ ] Can you **modify the binary** of any running process?
     53 - [ ] **Monitor processes** and check if any interesting process is running frequently.
     54 - [ ] Can you **read** some interesting **process memory** (where passwords could be saved)?
     55 
     56 ### [Scheduled/Cron jobs?](../linux-basics/linux-privilege-escalation/index.html#scheduled-jobs)
     57 
     58 - [ ] Is the [**PATH** ](../linux-basics/linux-privilege-escalation/index.html#cron-path)being modified by some cron and you can **write** in it?
     59 - [ ] Any [**wildcard** ](../linux-basics/linux-privilege-escalation/index.html#cron-using-a-script-with-a-wildcard-wildcard-injection)in a cron job?
     60 - [ ] Some [**modifiable script** ](../linux-basics/linux-privilege-escalation/index.html#cron-script-overwriting-and-symlink)is being **executed** or is inside **modifiable folder**?
     61 - [ ] Have you detected that some **script** could be or are being [**executed** very **frequently**](../linux-basics/linux-privilege-escalation/index.html#frequent-cron-jobs)? (every 1, 2 or 5 minutes)
     62 
     63 ### [Services](../linux-basics/linux-privilege-escalation/index.html#services)
     64 
     65 - [ ] Any **writable .service** file?
     66 - [ ] Any **writable binary** executed by a **service**?
     67 - [ ] Any writable **helper, config or environment file referenced by a root unit** (`ExecStartPre=`, `ExecStartPost=`, `EnvironmentFile=`)? Inspect the merged unit with `systemctl cat <unit>` and review [service/socket file abuse](/hacktricks/linux-hardening/interesting-files-permissions/write-to-root).
     68 - [ ] Any **writable folder in systemd PATH**?
     69 - [ ] Any **writable systemd unit drop-in** in `/etc/systemd/system/<unit>.d/*.conf` that can override `ExecStart`/`User`?<sup>[[2]](#references)</sup>
     70 
     71 ### [Timers](../linux-basics/linux-privilege-escalation/index.html#timers)
     72 
     73 - [ ] Any **writable timer**?
     74 
     75 ### [Sockets](../linux-basics/linux-privilege-escalation/index.html#sockets)
     76 
     77 - [ ] Any **writable .socket** file?
     78 - [ ] Can you **communicate with any socket**?
     79 - [ ] **HTTP sockets** with interesting info?
     80 - [ ] Can you access a [**container-runtime or node-agent API**](/hacktricks/linux-hardening/containers-namespaces/container-security/runtime-api-and-daemon-exposure) such as `docker.sock`, `containerd.sock`, `crio.sock`, `podman.sock`, `buildkitd.sock` or a kubelet endpoint? Test the raw HTTP/gRPC API even when its usual CLI is absent.
     81 
     82 ### [D-Bus](../linux-basics/linux-privilege-escalation/index.html#d-bus)
     83 
     84 - [ ] Can you **communicate with any D-Bus**?
     85 
     86 ### [Network](../linux-basics/linux-privilege-escalation/index.html#network)
     87 
     88 - [ ] Enumerate the network to know where you are
     89 - [ ] **Open ports you couldn't access before** getting a shell inside the machine?
     90 - [ ] Can you **sniff traffic** using `tcpdump`?
     91 
     92 ### [Users](../linux-basics/linux-privilege-escalation/index.html#users)
     93 
     94 - [ ] Generic users/groups **enumeration**
     95 - [ ] Do you have a **very big UID**? Is the **machine** **vulnerable**?
     96 - [ ] Can you [**escalate privileges thanks to a group**](../user-information/interesting-groups-linux-pe/index.html) you belong to?
     97 - [ ] **Clipboard** data?
     98 - [ ] Password Policy?
     99 - [ ] Try to **use** every **known password** that you have discovered previously to login **with each** possible **user**. Try to login also without a password.
    100 
    101 ### [Writable PATH](../linux-basics/linux-privilege-escalation/index.html#writable-path-abuses)
    102 
    103 - [ ] If you have **write privileges over some folder in PATH** you may be able to escalate privileges
    104 
    105 ### [SUDO and SUID commands](../linux-basics/linux-privilege-escalation/index.html#sudo-and-suid)
    106 
    107 - [ ] Can you execute **any command with sudo**? Can you use it to READ, WRITE or EXECUTE anything as root? ([**GTFOBins**](https://gtfobins.github.io))
    108 - [ ] If `sudo -l` allows `sudoedit`, check for **sudoedit argument injection** (CVE-2023-22809) via `SUDO_EDITOR`/`VISUAL`/`EDITOR` to edit arbitrary files on vulnerable versions (`sudo -V` < 1.9.12p2). Example: `SUDO_EDITOR="vim -- /etc/sudoers" sudoedit /etc/hosts`.<sup>[[1]](#references)</sup>
    109 - [ ] Is any **exploitable SUID binary**? ([**GTFOBins**](https://gtfobins.github.io))
    110 - [ ] Are [**sudo** commands **limited** by **path**? can you **bypass** the restrictions](../linux-basics/linux-privilege-escalation/index.html#sudo-execution-bypassing-paths)?
    111 - [ ] [**Sudo/SUID binary without path indicated**](../linux-basics/linux-privilege-escalation/index.html#sudo-command-suid-binary-without-command-path)?
    112 - [ ] [**SUID binary specifying path**](../linux-basics/linux-privilege-escalation/index.html#suid-binary-with-command-path)? Bypass
    113 - [ ] [**LD_PRELOAD vuln**](/hacktricks/linux-hardening/interesting-files-permissions/suid-shared-library-and-linker-abuse#ld_preload-ld_library_path-and-suid)
    114 - [ ] [**Lack of .so library in SUID binary**](/hacktricks/linux-hardening/interesting-files-permissions/suid-shared-library-and-linker-abuse#missing-shared-object-injection) from a writable folder?
    115 - [ ] [**SUID RPATH/RUNPATH or writable library path**](/hacktricks/linux-hardening/interesting-files-permissions/suid-shared-library-and-linker-abuse#rpath-and-runpath)?
    116 - [ ] [**SUDO tokens available**](../linux-basics/linux-privilege-escalation/index.html#reusing-sudo-tokens)? [**Can you create a SUDO token**](../linux-basics/linux-privilege-escalation/index.html#var-run-sudo-ts-less-than-username-greater-than)?
    117 - [ ] Can you [**read or modify sudoers files**](../linux-basics/linux-privilege-escalation/index.html#etc-sudoers-etc-sudoers-d)?
    118 - [ ] Can you [**modify /etc/ld.so.conf.d/**](/hacktricks/linux-hardening/interesting-files-permissions/suid-shared-library-and-linker-abuse#linker-configuration)?
    119 - [ ] [**OpenBSD DOAS**](../linux-basics/linux-privilege-escalation/index.html#doas) command
    120 
    121 ### [Capabilities](../linux-basics/linux-privilege-escalation/index.html#capabilities)
    122 
    123 - [ ] Has any binary any **unexpected capability**?
    124 
    125 ### [ACLs](../linux-basics/linux-privilege-escalation/index.html#acls)
    126 
    127 - [ ] Has any file any **unexpected ACL**?
    128 
    129 ### [Open Shell sessions](../linux-basics/linux-privilege-escalation/index.html#open-shell-sessions)
    130 
    131 - [ ] **screen**
    132 - [ ] **tmux**
    133 
    134 ### [SSH](../linux-basics/linux-privilege-escalation/index.html#ssh)
    135 
    136 - [ ] **Debian** [**OpenSSL Predictable PRNG - CVE-2008-0166**](../linux-basics/linux-privilege-escalation/index.html#debian-openssl-predictable-prng-cve-2008-0166)
    137 - [ ] [**SSH Interesting configuration values**](../linux-basics/linux-privilege-escalation/index.html#ssh-interesting-configuration-values)
    138 
    139 ### [Interesting Files](../linux-basics/linux-privilege-escalation/index.html#interesting-files)
    140 
    141 - [ ] **Profile files** - Read sensitive data? Write to privesc?
    142 - [ ] **passwd/shadow files** - Read sensitive data? Write to privesc?
    143 - [ ] **Check commonly interesting folders** for sensitive data
    144 - [ ] **Weird Location/Owned files,** you may have access to or alter executable files
    145 - [ ] **Modified** in last mins
    146 - [ ] **Sqlite DB files**
    147 - [ ] **Hidden files**
    148 - [ ] **Script/Binaries in PATH**
    149 - [ ] **Web files** (passwords?)
    150 - [ ] **Backups**?
    151 - [ ] **Known files that contains passwords**: Use **Linpeas** and **LaZagne**
    152 - [ ] **Generic search**
    153 
    154 ### [**Writable Files**](../linux-basics/linux-privilege-escalation/index.html#writable-files)
    155 
    156 - [ ] **Modify python library** to execute arbitrary commands?
    157 - [ ] Can you **modify log files**? **Logtotten** exploit
    158 - [ ] Can you **modify /etc/sysconfig/network-scripts/**? Centos/Redhat exploit
    159 - [ ] Can you [**write in ini, int.d, systemd or rc.d files**](../linux-basics/linux-privilege-escalation/index.html#init-init-d-systemd-and-rc-d)?
    160 
    161 ### [**Other tricks**](../linux-basics/linux-privilege-escalation/index.html#other-tricks)
    162 
    163 - [ ] Can you [**abuse NFS to escalate privileges**](../linux-basics/linux-privilege-escalation/index.html#nfs-privilege-escalation)?
    164 - [ ] Do you need to [**escape from a restrictive shell**](../linux-basics/linux-privilege-escalation/index.html#escaping-from-restricted-shells)?
    165 
    166 
    167 ## References
    168 
    169 - [1] [Sudo advisory: sudoedit arbitrary file edit](https://www.sudo.ws/security/advisories/sudoedit_any/)
    170 - [2] [Oracle Linux docs: systemd drop-in configuration](https://docs.oracle.com/en/operating-systems/oracle-linux/8/systemd/ModifyingsystemdConfigurationFiles.html)
    171 - [3] [Notselwyn: CVE-2024-1086 exploit requirements and research](https://github.com/Notselwyn/CVE-2024-1086)
    172 - [4] [Qualys Security Advisory: LPEs in needrestart](https://www.qualys.com/2024/11/19/needrestart/needrestart.txt)