Enumeration
Run linpeas first for a broad sweep, then manually verify the interesting findings. Automated tools flag a lot of noise.Sudo Abuse
sudo -l shows what commands you can run as root. Check every result on GTFOBins.
LD_PRELOAD Abuse
LD_PRELOAD Abuse
When
sudo -l shows env_keep+=LD_PRELOAD, compile a shared library that spawns a root shell.LD_LIBRARY_PATH Abuse
LD_LIBRARY_PATH Abuse
When
env_keep+=LD_LIBRARY_PATH is preserved and the sudo-allowed binary loads a library from a path you can write to.SUID Abuse
SUID binaries run as their owner regardless of who executes them. Anything non-standard owned by root is worth checking on GTFOBins.Cron Jobs
Look for cron jobs running as root that call scripts you can write to: rewrite the script, wait for the next execution.Writable Script
Writable Script
The simplest case: find a root cron job calling a script you own.
PATH Hijacking via Cron
PATH Hijacking via Cron
If
/etc/crontab has a PATH that includes a directory you can write to and the cron job calls a binary by short name.Wildcard Injection
Wildcard Injection
When a cron job runs
tar * or rsync * in a directory you can write to, create filenames that are parsed as flags.Capabilities
Capabilities grant specific root-level privileges to binaries without full SUID.cap_setuid+ep on any interpreter is effectively root.
Common Capabilities and Exploits
Common Capabilities and Exploits
PATH Hijacking
When a SUID binary or root script calls a program by short name without an absolute path, prepend a writable directory toPATH.
env_keep+=PATH:
Shared Library Hijacking
When a SUID binary or root service loads a library from a path you can write to (check RPATH first, thenld.so.conf).
Systemd / Service File Abuse
If you can write to a.service file or its ExecStart script is writable, you control what runs as root on service restart.
/etc/systemd/system/:
Race Conditions (TOCTOU)
Time-of-Check to Time-of-Use: a privileged process checks permissions on a file, then uses it. Swap the file between check and use.Predictable Temp File
Predictable Temp File
When a root process creates a predictable temp file, pre-create a symlink at that path before it does.
inotifywait-Assisted Race
inotifywait-Assisted Race
Trigger your symlink swap exactly when the access check fires.
NFS no_root_squash
When an NFS share is exported withno_root_squash, your attacker machine root maps to root on the share. Create a SUID binary there.
Docker / LXD
Docker Group
Docker Group
Being in the
docker group is effectively root: mount the host filesystem into a privileged container.LXD Group
LXD Group
Writable /etc/passwd
If/etc/passwd is world-writable, add a new root-level user with a known password hash.
Kernel Exploits
Last resort: kernel exploits are noisy, can crash the system, and are hard to control. Identify the kernel version and match to known CVEs.Notable CVEs
Notable CVEs