Linux Privilege Escalation
Escalating from an unprivileged user to root is the goal after getting access to a Linux host. You rarely need a kernel exploit: the norm is abusing misconfigurations —SUID, sudo, cron, capabilities, loose permissions— that the admin left exploitable. This card is the overall map; each vector has its own card with the detail.
Threat model
Section titled “Threat model”The system trusts permissions, paths, and privileges configured by the admin. The attacker doesn’t break Linux: they use its rules against it. A badly chosen SUID binary, an over-permissive sudo, or a cron that runs a writable script are, in effect, root for whoever can spot them. Escalation is finding that link; enumeration (see Linux Enumeration) reveals it.
The vectors (most to least common)
Section titled “The vectors (most to least common)”1. Misconfigured sudo (see Sudo Abuse)
Section titled “1. Misconfigured sudo (see Sudo Abuse)”sudo -l # FIRST THING. What can you run as root?A sudo to a GTFOBins binary (vi, find, python, less, awk…) is often direct root. Also NOPASSWD, env_keep, and CVEs like Baron Samedit (CVE-2021-3156).
2. SUID/SGID binaries (see SUID/SGID Binaries)
Section titled “2. SUID/SGID binaries (see SUID/SGID Binaries)”find / -perm -4000 -type f 2>/dev/nullA root SUID binary listed in GTFOBins gives you execution as root. Classics: pkexec (PwnKit), badly-written custom binaries.
3. Capabilities (see Linux Capabilities)
Section titled “3. Capabilities (see Linux Capabilities)”getcap -r / 2>/dev/nullA binary with cap_setuid, cap_dac_read_search, etc. lets you escalate without being fully SUID.
4. Cron jobs and timers (see Cron Jobs and Timers)
Section titled “4. Cron jobs and timers (see Cron Jobs and Timers)”cat /etc/crontab ; ls -la /etc/cron.* ; pspyA task running as root that executes a script/binary writable by you (or uses a relative PATH) = root when it fires.
5. Reused credentials
Section titled “5. Reused credentials”Passwords in configs, histories, SSH keys → reuse toward root or another user (see Linux Credential Theft).
6. Dangerous groups
Section titled “6. Dangerous groups”# docker/lxd = trivial root (see lin-docker)docker run -v /:/mnt -it alpine chroot /mnt sh# disk, adm, shadow... indirect privileged access7. Kernel exploits (last resort, see Linux Kernel Exploits)
Section titled “7. Kernel exploits (last resort, see Linux Kernel Exploits)”uname -a # -> Dirty COW, Dirty Pipe (CVE-2022-0847), PwnKit, etc.Noisy and can crash the host; use it when everything else fails.
8. Others
Section titled “8. Others”PATH hijacking, LD_PRELOAD/LD_LIBRARY_PATH with sudo, NFS no_root_squash, wildcards in tar/chown (wildcard injection), writable /etc/passwd.
Methodology
Section titled “Methodology”1. Enumerate (lin-enum) -> linpeas summarizes everything2. sudo -l and SUID/caps: the most reliable quick wins3. Cross-reference binaries with GTFOBins4. pspy for root cron/processes5. Reused credentials6. Kernel only if the above bears no fruitlinpeas.sh # automatic detection of ALL the above vectorspspy # root processes/cron without privilegesGTFOBins # how to abuse a specific binary (sudo/SUID/caps)linux-exploit-suggester # kernel exploits by versionFor the defense
Section titled “For the defense”- Least privilege in sudo: no wildcards, no dangerous binaries, NOPASSWD only where essential.
- Review SUID/SGID and capabilities: remove unneeded ones.
- Secure cron: absolute paths, non-writable scripts, root ownership.
- No credentials in text: managed secrets, 600 permissions.
- Kernel patching up to date; auditd/EDR to detect abuse; no unnecessary dangerous groups.
Testing checklist
Section titled “Testing checklist”-
sudo -l→ GTFOBins / NOPASSWD / CVEs - SUID/SGID → GTFOBins (SUID/SGID Binaries)
- Dangerous capabilities (Linux Capabilities)
- Cron/timers with writable scripts or relative PATH (Cron Jobs and Timers)
- Reused credentials (Linux Credential Theft)
- Dangerous groups (docker/lxd/disk)
- Vulnerable kernel (Linux Kernel Exploits) as last resort
- PATH/LD_PRELOAD/NFS/wildcard and other vectors