Linux Fundamentals
Linux is the attacker’s system (your attack box is Kali/Parrot) and, at the same time, one of the most common targets (web servers, containers, infrastructure). Moving fluently through its filesystem, permissions, processes, and users is a prerequisite for everything else: without it, you can’t drive your tools or understand a privilege escalation.
Filesystem
Section titled “Filesystem”Everything hangs off / (root). The paths that matter:
/etc configuration (passwd, shadow, crontab, services)/home user directories/root superuser's home/var logs (/var/log), webroots (/var/www), queues/tmp temporary, writable by all (handy for payloads)/usr/bin /bin binaries/proc /sys kernel pseudo-FS (process and system info)/etc/passwd users; /etc/shadow password hashes (root only)Permissions (the most important for privesc)
Section titled “Permissions (the most important for privesc)”Each file has an owner, group, and permissions for owner/group/others (rwx):
-rwxr-xr-- 1 root root ... │└┬┘└┬┘└┬┘ │ │ │ └ others: r-- │ │ └ group: r-x │ └ owner: rwx └ type (- file, d directory, l link)
chmod 755 file # rwx r-x r-x (numeric: r=4 w=2 x=1)chown user:grp fileSpecial bits key in security:
- SUID (
chmod u+s, shows asrws): the binary runs with the permissions of its owner, not of whoever launches it. A badly chosen root SUID = escalation to root (see GTFOBins). - SGID and the sticky bit (
/tmp).
find / -perm -4000 -type f 2>/dev/null # find SUID binaries (privesc)Users, groups, and sudo
Section titled “Users, groups, and sudo”id ; whoami ; groups # who I am and what I belong tosudo -l # what I can run as root (key in privesc!)cat /etc/passwd # system userssu - user # switch usersudo -l is the first stop in an escalation: a misconfigured sudo toward a GTFOBins binary is often direct root.
Processes, services, and network
Section titled “Processes, services, and network”ps aux | grep X # processes (what runs and as whom)top / htop # live resourcessystemctl status svc # services (systemd)ss -tulpn # listening ports and their processescrontab -l ; cat /etc/crontab ; ls /etc/cron.* # scheduled tasks (privesc)Shell, redirection, and pipes
Section titled “Shell, redirection, and pipes”command > out.txt # redirect stdout (overwrite)command >> out.txt # appendcommand 2>/dev/null # discard stderrcmd1 | cmd2 # pipe: cmd1's output to cmd2's inputcmd1 && cmd2 # cmd2 only if cmd1 succeeded$(command) # command substitutionMastering pipes + grep/awk/sed/cut/sort/uniq turns thousands of output lines into the datum you want (see Bash Scripting, Regular Expressions).
Why it matters in security
Section titled “Why it matters in security”Linux privilege escalation is, almost all of it, abuse of the above: SUID binaries, sudo -l, writable cron jobs, capabilities, loose permissions in /etc. And as a target, a compromised Linux server is analyzed with these same commands. It’s the basis of the Offensive Python courses and of all infrastructure pentesting.
Mastery checklist
Section titled “Mastery checklist”- I navigate the FHS and know what /etc, /var, /tmp, /proc hold
- I read and interpret rwx permissions and change them with chmod/chown
- I can explain SUID/SGID and why they’re a privesc vector
-
sudo -l,id,/etc/passwd,/etc/shadowand what they’re for - I inspect processes, services, ports, and cron
- I chain commands with pipes and redirection
- I can find SUID binaries and cross-reference GTFOBins