Skip to content

Linux Privilege Escalation

Escalating from an unprivileged user to root is the goal after getting access to a Linux host. You rarely need a kernel exploit: the norm is abusing misconfigurations —SUID, sudo, cron, capabilities, loose permissions— that the admin left exploitable. This card is the overall map; each vector has its own card with the detail.

The system trusts permissions, paths, and privileges configured by the admin. The attacker doesn’t break Linux: they use its rules against it. A badly chosen SUID binary, an over-permissive sudo, or a cron that runs a writable script are, in effect, root for whoever can spot them. Escalation is finding that link; enumeration (see Linux Enumeration) reveals it.

sudo -l # FIRST THING. What can you run as root?

A sudo to a GTFOBins binary (vi, find, python, less, awk…) is often direct root. Also NOPASSWD, env_keep, and CVEs like Baron Samedit (CVE-2021-3156).

find / -perm -4000 -type f 2>/dev/null

A root SUID binary listed in GTFOBins gives you execution as root. Classics: pkexec (PwnKit), badly-written custom binaries.

getcap -r / 2>/dev/null

A binary with cap_setuid, cap_dac_read_search, etc. lets you escalate without being fully SUID.

cat /etc/crontab ; ls -la /etc/cron.* ; pspy

A task running as root that executes a script/binary writable by you (or uses a relative PATH) = root when it fires.

Passwords in configs, histories, SSH keys → reuse toward root or another user (see Linux Credential Theft).

# docker/lxd = trivial root (see lin-docker)
docker run -v /:/mnt -it alpine chroot /mnt sh
# disk, adm, shadow... indirect privileged access
uname -a # -> Dirty COW, Dirty Pipe (CVE-2022-0847), PwnKit, etc.

Noisy and can crash the host; use it when everything else fails.

PATH hijacking, LD_PRELOAD/LD_LIBRARY_PATH with sudo, NFS no_root_squash, wildcards in tar/chown (wildcard injection), writable /etc/passwd.

1. Enumerate (lin-enum) -> linpeas summarizes everything
2. sudo -l and SUID/caps: the most reliable quick wins
3. Cross-reference binaries with GTFOBins
4. pspy for root cron/processes
5. Reused credentials
6. Kernel only if the above bears no fruit
linpeas.sh # automatic detection of ALL the above vectors
pspy # root processes/cron without privileges
GTFOBins # how to abuse a specific binary (sudo/SUID/caps)
linux-exploit-suggester # kernel exploits by version
  • Least privilege in sudo: no wildcards, no dangerous binaries, NOPASSWD only where essential.
  • Review SUID/SGID and capabilities: remove unneeded ones.
  • Secure cron: absolute paths, non-writable scripts, root ownership.
  • No credentials in text: managed secrets, 600 permissions.
  • Kernel patching up to date; auditd/EDR to detect abuse; no unnecessary dangerous groups.