Skip to main content

Enumeration

Run linpeas first for a broad sweep, then manually verify the interesting findings. Automated tools flag a lot of noise.
Use pspy to watch for processes spawned by root without needing root yourself.

Sudo Abuse

sudo -l shows what commands you can run as root. Check every result on GTFOBins.
When sudo -l shows env_keep+=LD_PRELOAD, compile a shared library that spawns a root shell.
When env_keep+=LD_LIBRARY_PATH is preserved and the sudo-allowed binary loads a library from a path you can write to.

SUID Abuse

SUID binaries run as their owner regardless of who executes them. Anything non-standard owned by root is worth checking on GTFOBins.

Cron Jobs

Look for cron jobs running as root that call scripts you can write to: rewrite the script, wait for the next execution.
The simplest case: find a root cron job calling a script you own.
If /etc/crontab has a PATH that includes a directory you can write to and the cron job calls a binary by short name.
When a cron job runs tar * or rsync * in a directory you can write to, create filenames that are parsed as flags.

Capabilities

Capabilities grant specific root-level privileges to binaries without full SUID. cap_setuid+ep on any interpreter is effectively root.

PATH Hijacking

When a SUID binary or root script calls a program by short name without an absolute path, prepend a writable directory to PATH.
With sudo and env_keep+=PATH:

Shared Library Hijacking

When a SUID binary or root service loads a library from a path you can write to (check RPATH first, then ld.so.conf).

Systemd / Service File Abuse

If you can write to a .service file or its ExecStart script is writable, you control what runs as root on service restart.
If you can write to /etc/systemd/system/:

Race Conditions (TOCTOU)

Time-of-Check to Time-of-Use: a privileged process checks permissions on a file, then uses it. Swap the file between check and use.
When a root process creates a predictable temp file, pre-create a symlink at that path before it does.
Trigger your symlink swap exactly when the access check fires.

NFS no_root_squash

When an NFS share is exported with no_root_squash, your attacker machine root maps to root on the share. Create a SUID binary there.

Docker / LXD

Being in the docker group is effectively root: mount the host filesystem into a privileged container.

Writable /etc/passwd

If /etc/passwd is world-writable, add a new root-level user with a known password hash.

Kernel Exploits

Last resort: kernel exploits are noisy, can crash the system, and are hard to control. Identify the kernel version and match to known CVEs.