Linux Credential Theft
After compromising a Linux host, harvesting credentials is what lets you escalate, move to other systems, and persist. Linux stores secrets in many places: password hashes, SSH keys, application tokens, cloud credentials, command histories, and configurations. A host rarely lives in isolation: the credentials you find here usually open the next system.
System password hashes
Section titled “System password hashes”# if you're root (or have cap_dac_read_search / equivalent)cat /etc/shadow # user password hashescat /etc/passwd # users (combine with shadow -> unshadow -> crack)unshadow /etc/passwd /etc/shadow > hashes.txthashcat -m 1800 hashes.txt rockyou.txt # $6$ = sha512cryptjohn hashes.txt --wordlist=rockyou.txtFormats: $1$ MD5crypt, $5$ sha256, $6$ sha512, $y$/$2$ yescrypt/bcrypt. Crackable offline depending on strength.
SSH keys (lateral movement)
Section titled “SSH keys (lateral movement)”# the user's private keys -> access to other hostscat ~/.ssh/id_rsa ~/.ssh/id_ed25519 2>/dev/nullcat ~/.ssh/config # which hosts it connects to and howcat ~/.ssh/known_hosts # known hosts (targets)cat ~/.ssh/authorized_keys # who can log in (persistence)# search for keys across the systemfind / -name "id_rsa*" -o -name "*.pem" 2>/dev/nullAn SSH private key without a passphrase is direct access to every host it’s authorized on.
Credentials in files and configs
Section titled “Credentials in files and configs”# mass searchgrep -rniE 'password|passwd|secret|api[_-]?key|token' /etc /opt /var/www /home 2>/dev/null# typical locations/var/www/**/wp-config.php, config.php, .env # webapps (DB creds)~/.aws/credentials, ~/.config/gcloud, ~/.kube/config # cloud/k8s~/.netrc, ~/.git-credentials, ~/.pgpass, ~/.my.cnf # services/etc/fstab # mount credentials (CIFS)docker: environment variables, docker inspectHistories and memory
Section titled “Histories and memory”cat ~/.bash_history ~/.zsh_history # prior commands (sometimes cleartext passwords!)history# credentials in process memory (with privileges)strings /proc/<pid>/environ # a process's environment variables# MySQL/psql/redis historycat ~/.mysql_history ~/.psql_history ~/.rediscli_historyThe .bash_history is a classic: mysql -u root -pSuperSecret123 gets logged.
Service and application credentials
Section titled “Service and application credentials”# databases/etc/mysql/, postgres config, mongod.conf# password managers / keyrings (if there's a session)~/.config/keepassxc, gnome-keyring, ~/.password-store (pass)# app and CI/CD tokensapp .env, Jenkins/GitLab runners, pipeline variableslinpeas.sh # flags found credentials automaticallyLinEnum.sh# crackinghashcat / john # /etc/shadow, app hashes# SSH keys with passphrasessh2john id_rsa > hash ; john hashFor the defense
Section titled “For the defense”- No cleartext credentials: use secret managers (Vault, k8s secrets), 600 permissions, never in
.bash_history(HISTIGNORE, use a file/prompt). - SSH keys with a passphrase and rotation; audited
authorized_keys; ssh-agent with expiry. - Strong hashes (sha512/yescrypt) and robust passwords (slows offline cracking).
- Least privilege: a compromised user shouldn’t read
/etc/shadowor other services’ secrets. - Monitor access to sensitive files (auditd) and credential reuse across hosts.
Testing checklist
Section titled “Testing checklist”- /etc/shadow + /etc/passwd → unshadow → crack
- SSH private keys and config/known_hosts (lateral)
- Mass grep for credentials in /etc, /var/www, /home, /opt
- Cloud/k8s credentials (.aws, .kube, gcloud)
- Histories (.bash_history, .mysql_history)
- Process environment variables (/proc/pid/environ)
- App/DB configs with credentials
- Reuse what’s found toward other hosts/users