# Checklist - Linux Privilege Escalation

{% hint style="success" %}
Learn & practice AWS Hacking:<img src="https://4053168017-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbkAZDoSuRHGdNlWHdyKs%2Fuploads%2Fgit-blob-ce8af1068db7be4ad9003f8ddb02fea8f943f1a4%2Farte.png?alt=media" alt="" data-size="line">[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)<img src="https://4053168017-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbkAZDoSuRHGdNlWHdyKs%2Fuploads%2Fgit-blob-ce8af1068db7be4ad9003f8ddb02fea8f943f1a4%2Farte.png?alt=media" alt="" data-size="line">\
Learn & practice GCP Hacking: <img src="https://4053168017-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbkAZDoSuRHGdNlWHdyKs%2Fuploads%2Fgit-blob-54ee1fb931f39d1e6f50150361b6aa1927f4ee88%2Fgrte.png?alt=media" alt="" data-size="line">[**HackTricks Training GCP Red Team Expert (GRTE)**<img src="https://4053168017-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbkAZDoSuRHGdNlWHdyKs%2Fuploads%2Fgit-blob-54ee1fb931f39d1e6f50150361b6aa1927f4ee88%2Fgrte.png?alt=media" alt="" data-size="line">](https://training.hacktricks.xyz/courses/grte)

<details>

<summary>Support HackTricks</summary>

* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)!
* **Join the** 💬 [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** 🐦 [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**.**
* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.

</details>
{% endhint %}

<figure><img src="https://4053168017-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbkAZDoSuRHGdNlWHdyKs%2Fuploads%2Fgit-blob-7ebaebfa37dac753bd916c91429befb49dfd6309%2Fimage%20(380).png?alt=media" alt=""><figcaption></figcaption></figure>

Join [**HackenProof Discord**](https://discord.com/invite/N3FrSbmwdy) server to communicate with experienced hackers and bug bounty hunters!

**Hacking Insights**\
Engage with content that delves into the thrill and challenges of hacking

**Real-Time Hack News**\
Keep up-to-date with fast-paced hacking world through real-time news and insights

**Latest Announcements**\
Stay informed with the newest bug bounties launching and crucial platform updates

**Join us on** [**Discord**](https://discord.com/invite/N3FrSbmwdy) and start collaborating with top hackers today!

### **Best tool to look for Linux local privilege escalation vectors:** [**LinPEAS**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS)

### [System Information](https://angelica.gitbook.io/hacktricks/privilege-escalation#system-information)

* [ ] Get **OS information**
* [ ] Check the [**PATH**](https://angelica.gitbook.io/hacktricks/privilege-escalation#path), any **writable folder**?
* [ ] Check [**env variables**](https://angelica.gitbook.io/hacktricks/privilege-escalation#env-info), any sensitive detail?
* [ ] Search for [**kernel exploits**](https://angelica.gitbook.io/hacktricks/privilege-escalation#kernel-exploits) **using scripts** (DirtyCow?)
* [ ] **Check** if the [**sudo version** is vulnerable](https://angelica.gitbook.io/hacktricks/privilege-escalation#sudo-version)
* [ ] [**Dmesg** signature verification failed](https://angelica.gitbook.io/hacktricks/privilege-escalation#dmesg-signature-verification-failed)
* [ ] More system enum ([date, system stats, cpu info, printers](https://angelica.gitbook.io/hacktricks/privilege-escalation#more-system-enumeration))
* [ ] [Enumerate more defenses](https://angelica.gitbook.io/hacktricks/privilege-escalation#enumerate-possible-defenses)

### [Drives](https://angelica.gitbook.io/hacktricks/privilege-escalation#drives)

* [ ] **List mounted** drives
* [ ] **Any unmounted drive?**
* [ ] **Any creds in fstab?**

### [**Installed Software**](https://angelica.gitbook.io/hacktricks/privilege-escalation#installed-software)

* [ ] **Check for**[ **useful software**](https://angelica.gitbook.io/hacktricks/privilege-escalation#useful-software) **installed**
* [ ] **Check for** [**vulnerable software**](https://angelica.gitbook.io/hacktricks/privilege-escalation#vulnerable-software-installed) **installed**

### [Processes](https://angelica.gitbook.io/hacktricks/privilege-escalation#processes)

* [ ] Is any **unknown software running**?
* [ ] Is any software running with **more privileges than it should have**?
* [ ] Search for **exploits of running processes** (especially the version running).
* [ ] Can you **modify the binary** of any running process?
* [ ] **Monitor processes** and check if any interesting process is running frequently.
* [ ] Can you **read** some interesting **process memory** (where passwords could be saved)?

### [Scheduled/Cron jobs?](https://angelica.gitbook.io/hacktricks/privilege-escalation#scheduled-jobs)

* [ ] Is the [**PATH** ](https://angelica.gitbook.io/hacktricks/privilege-escalation#cron-path)being modified by some cron and you can **write** in it?
* [ ] Any [**wildcard** ](https://angelica.gitbook.io/hacktricks/privilege-escalation#cron-using-a-script-with-a-wildcard-wildcard-injection)in a cron job?
* [ ] Some [**modifiable script** ](https://angelica.gitbook.io/hacktricks/privilege-escalation#cron-script-overwriting-and-symlink)is being **executed** or is inside **modifiable folder**?
* [ ] Have you detected that some **script** could be or are being [**executed** very **frequently**](https://angelica.gitbook.io/hacktricks/privilege-escalation#frequent-cron-jobs)? (every 1, 2 or 5 minutes)

### [Services](https://angelica.gitbook.io/hacktricks/privilege-escalation#services)

* [ ] Any **writable .service** file?
* [ ] Any **writable binary** executed by a **service**?
* [ ] Any **writable folder in systemd PATH**?

### [Timers](https://angelica.gitbook.io/hacktricks/privilege-escalation#timers)

* [ ] Any **writable timer**?

### [Sockets](https://angelica.gitbook.io/hacktricks/privilege-escalation#sockets)

* [ ] Any **writable .socket** file?
* [ ] Can you **communicate with any socket**?
* [ ] **HTTP sockets** with interesting info?

### [D-Bus](https://angelica.gitbook.io/hacktricks/privilege-escalation#d-bus)

* [ ] Can you **communicate with any D-Bus**?

### [Network](https://angelica.gitbook.io/hacktricks/privilege-escalation#network)

* [ ] Enumerate the network to know where you are
* [ ] **Open ports you couldn't access before** getting a shell inside the machine?
* [ ] Can you **sniff traffic** using `tcpdump`?

### [Users](https://angelica.gitbook.io/hacktricks/privilege-escalation#users)

* [ ] Generic users/groups **enumeration**
* [ ] Do you have a **very big UID**? Is the **machine** **vulnerable**?
* [ ] Can you [**escalate privileges thanks to a group**](https://angelica.gitbook.io/hacktricks/linux-hardening/privilege-escalation/interesting-groups-linux-pe) you belong to?
* [ ] **Clipboard** data?
* [ ] Password Policy?
* [ ] Try to **use** every **known password** that you have discovered previously to login **with each** possible **user**. Try to login also without a password.

### [Writable PATH](https://angelica.gitbook.io/hacktricks/privilege-escalation#writable-path-abuses)

* [ ] If you have **write privileges over some folder in PATH** you may be able to escalate privileges

### [SUDO and SUID commands](https://angelica.gitbook.io/hacktricks/privilege-escalation#sudo-and-suid)

* [ ] Can you execute **any command with sudo**? Can you use it to READ, WRITE or EXECUTE anything as root? ([**GTFOBins**](https://gtfobins.github.io))
* [ ] Is any **exploitable SUID binary**? ([**GTFOBins**](https://gtfobins.github.io))
* [ ] Are [**sudo** commands **limited** by **path**? can you **bypass** the restrictions](https://angelica.gitbook.io/hacktricks/privilege-escalation#sudo-execution-bypassing-paths)?
* [ ] [**Sudo/SUID binary without path indicated**](https://angelica.gitbook.io/hacktricks/privilege-escalation#sudo-command-suid-binary-without-command-path)?
* [ ] [**SUID binary specifying path**](https://angelica.gitbook.io/hacktricks/privilege-escalation#suid-binary-with-command-path)? Bypass
* [ ] [**LD\_PRELOAD vuln**](https://angelica.gitbook.io/hacktricks/privilege-escalation#ld_preload)
* [ ] [**Lack of .so library in SUID binary**](https://angelica.gitbook.io/hacktricks/privilege-escalation#suid-binary-so-injection) from a writable folder?
* [ ] [**SUDO tokens available**](https://angelica.gitbook.io/hacktricks/privilege-escalation#reusing-sudo-tokens)? [**Can you create a SUDO token**](https://angelica.gitbook.io/hacktricks/privilege-escalation#var-run-sudo-ts-less-than-username-greater-than)?
* [ ] Can you [**read or modify sudoers files**](https://angelica.gitbook.io/hacktricks/privilege-escalation#etc-sudoers-etc-sudoers-d)?
* [ ] Can you [**modify /etc/ld.so.conf.d/**](https://angelica.gitbook.io/hacktricks/privilege-escalation#etc-ld-so-conf-d)?
* [ ] [**OpenBSD DOAS**](https://angelica.gitbook.io/hacktricks/privilege-escalation#doas) command

### [Capabilities](https://angelica.gitbook.io/hacktricks/privilege-escalation#capabilities)

* [ ] Has any binary any **unexpected capability**?

### [ACLs](https://angelica.gitbook.io/hacktricks/privilege-escalation#acls)

* [ ] Has any file any **unexpected ACL**?

### [Open Shell sessions](https://angelica.gitbook.io/hacktricks/privilege-escalation#open-shell-sessions)

* [ ] **screen**
* [ ] **tmux**

### [SSH](https://angelica.gitbook.io/hacktricks/privilege-escalation#ssh)

* [ ] **Debian** [**OpenSSL Predictable PRNG - CVE-2008-0166**](https://angelica.gitbook.io/hacktricks/privilege-escalation#debian-openssl-predictable-prng-cve-2008-0166)
* [ ] [**SSH Interesting configuration values**](https://angelica.gitbook.io/hacktricks/privilege-escalation#ssh-interesting-configuration-values)

### [Interesting Files](https://angelica.gitbook.io/hacktricks/privilege-escalation#interesting-files)

* [ ] **Profile files** - Read sensitive data? Write to privesc?
* [ ] **passwd/shadow files** - Read sensitive data? Write to privesc?
* [ ] **Check commonly interesting folders** for sensitive data
* [ ] **Weird Location/Owned files,** you may have access to or alter executable files
* [ ] **Modified** in last mins
* [ ] **Sqlite DB files**
* [ ] **Hidden files**
* [ ] **Script/Binaries in PATH**
* [ ] **Web files** (passwords?)
* [ ] **Backups**?
* [ ] **Known files that contains passwords**: Use **Linpeas** and **LaZagne**
* [ ] **Generic search**

### [**Writable Files**](https://angelica.gitbook.io/hacktricks/privilege-escalation#writable-files)

* [ ] **Modify python library** to execute arbitrary commands?
* [ ] Can you **modify log files**? **Logtotten** exploit
* [ ] Can you **modify /etc/sysconfig/network-scripts/**? Centos/Redhat exploit
* [ ] Can you [**write in ini, int.d, systemd or rc.d files**](https://angelica.gitbook.io/hacktricks/privilege-escalation#init-init-d-systemd-and-rc-d)?

### [**Other tricks**](https://angelica.gitbook.io/hacktricks/privilege-escalation#other-tricks)

* [ ] Can you [**abuse NFS to escalate privileges**](https://angelica.gitbook.io/hacktricks/privilege-escalation#nfs-privilege-escalation)?
* [ ] Do you need to [**escape from a restrictive shell**](https://angelica.gitbook.io/hacktricks/privilege-escalation#escaping-from-restricted-shells)?

<figure><img src="https://4053168017-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbkAZDoSuRHGdNlWHdyKs%2Fuploads%2Fgit-blob-7ebaebfa37dac753bd916c91429befb49dfd6309%2Fimage%20(380).png?alt=media" alt=""><figcaption></figcaption></figure>

Join [**HackenProof Discord**](https://discord.com/invite/N3FrSbmwdy) server to communicate with experienced hackers and bug bounty hunters!

**Hacking Insights**\
Engage with content that delves into the thrill and challenges of hacking

**Real-Time Hack News**\
Keep up-to-date with fast-paced hacking world through real-time news and insights

**Latest Announcements**\
Stay informed with the newest bug bounties launching and crucial platform updates

**Join us on** [**Discord**](https://discord.com/invite/N3FrSbmwdy) and start collaborating with top hackers today!

{% hint style="success" %}
Learn & practice AWS Hacking:<img src="https://4053168017-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbkAZDoSuRHGdNlWHdyKs%2Fuploads%2Fgit-blob-ce8af1068db7be4ad9003f8ddb02fea8f943f1a4%2Farte.png?alt=media" alt="" data-size="line">[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)<img src="https://4053168017-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbkAZDoSuRHGdNlWHdyKs%2Fuploads%2Fgit-blob-ce8af1068db7be4ad9003f8ddb02fea8f943f1a4%2Farte.png?alt=media" alt="" data-size="line">\
Learn & practice GCP Hacking: <img src="https://4053168017-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbkAZDoSuRHGdNlWHdyKs%2Fuploads%2Fgit-blob-54ee1fb931f39d1e6f50150361b6aa1927f4ee88%2Fgrte.png?alt=media" alt="" data-size="line">[**HackTricks Training GCP Red Team Expert (GRTE)**<img src="https://4053168017-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbkAZDoSuRHGdNlWHdyKs%2Fuploads%2Fgit-blob-54ee1fb931f39d1e6f50150361b6aa1927f4ee88%2Fgrte.png?alt=media" alt="" data-size="line">](https://training.hacktricks.xyz/courses/grte)

<details>

<summary>Support HackTricks</summary>

* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)!
* **Join the** 💬 [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** 🐦 [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**.**
* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.

</details>
{% endhint %}


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://angelica.gitbook.io/hacktricks/linux-hardening/linux-privilege-escalation-checklist.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
