Skip to content

Linux Fundamentals

Linux is the attacker’s system (your attack box is Kali/Parrot) and, at the same time, one of the most common targets (web servers, containers, infrastructure). Moving fluently through its filesystem, permissions, processes, and users is a prerequisite for everything else: without it, you can’t drive your tools or understand a privilege escalation.

Everything hangs off / (root). The paths that matter:

/etc configuration (passwd, shadow, crontab, services)
/home user directories
/root superuser's home
/var logs (/var/log), webroots (/var/www), queues
/tmp temporary, writable by all (handy for payloads)
/usr/bin /bin binaries
/proc /sys kernel pseudo-FS (process and system info)
/etc/passwd users; /etc/shadow password hashes (root only)

Permissions (the most important for privesc)

Section titled “Permissions (the most important for privesc)”

Each file has an owner, group, and permissions for owner/group/others (rwx):

-rwxr-xr-- 1 root root ...
│└┬┘└┬┘└┬┘
│ │ │ └ others: r--
│ │ └ group: r-x
│ └ owner: rwx
└ type (- file, d directory, l link)
chmod 755 file # rwx r-x r-x (numeric: r=4 w=2 x=1)
chown user:grp file

Special bits key in security:

  • SUID (chmod u+s, shows as rws): the binary runs with the permissions of its owner, not of whoever launches it. A badly chosen root SUID = escalation to root (see GTFOBins).
  • SGID and the sticky bit (/tmp).
find / -perm -4000 -type f 2>/dev/null # find SUID binaries (privesc)
id ; whoami ; groups # who I am and what I belong to
sudo -l # what I can run as root (key in privesc!)
cat /etc/passwd # system users
su - user # switch user

sudo -l is the first stop in an escalation: a misconfigured sudo toward a GTFOBins binary is often direct root.

ps aux | grep X # processes (what runs and as whom)
top / htop # live resources
systemctl status svc # services (systemd)
ss -tulpn # listening ports and their processes
crontab -l ; cat /etc/crontab ; ls /etc/cron.* # scheduled tasks (privesc)
command > out.txt # redirect stdout (overwrite)
command >> out.txt # append
command 2>/dev/null # discard stderr
cmd1 | cmd2 # pipe: cmd1's output to cmd2's input
cmd1 && cmd2 # cmd2 only if cmd1 succeeded
$(command) # command substitution

Mastering pipes + grep/awk/sed/cut/sort/uniq turns thousands of output lines into the datum you want (see Bash Scripting, Regular Expressions).

Linux privilege escalation is, almost all of it, abuse of the above: SUID binaries, sudo -l, writable cron jobs, capabilities, loose permissions in /etc. And as a target, a compromised Linux server is analyzed with these same commands. It’s the basis of the Offensive Python courses and of all infrastructure pentesting.

  • I navigate the FHS and know what /etc, /var, /tmp, /proc hold
  • I read and interpret rwx permissions and change them with chmod/chown
  • I can explain SUID/SGID and why they’re a privesc vector
  • sudo -l, id, /etc/passwd, /etc/shadow and what they’re for
  • I inspect processes, services, ports, and cron
  • I chain commands with pipes and redirection
  • I can find SUID binaries and cross-reference GTFOBins