> For the complete documentation index, see [llms.txt](https://infosecsanyam261.gitbook.io/tryharder/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://infosecsanyam261.gitbook.io/tryharder/priv-escalation/linux-priv-escalation/checklist-linux-privilege-escalation.md).

# Checklist - Linux Privilege Escalation

https\://book.hacktricks.xyz/linux-unix/privilege-escalation/nfs-no\_root\_squash-misconfiguration-pe

## Checklist - Linux Privilege Escalation

Checklist for privilege escalation in Linux

### **Best tool to look for Linux local privilege escalation vectors:** [**LinPEAS**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS)**​** <a href="#best-tool-to-look-for-linux-local-privilege-escalation-vectors-linpeas" id="best-tool-to-look-for-linux-local-privilege-escalation-vectors-linpeas"></a>

### ​[Vulnerable Kernel?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#kernel-exploits)​ <a href="#vulnerable-kernel" id="vulnerable-kernel"></a>

* Search for kernel **exploits using scripts** (linux.exploit-suggester.sh, inux-exploit-suggester2.pl, linuxprivcheckser.py)
* Use **Google to search** for kernel **exploits**
* Use **searchsploit to search** for kernel **exploits**
* **Check** if the [**sudo version** is vulnerable](https://book.hacktricks.xyz/linux-unix/privilege-escalation#sudo-version)​

### ​[Vulnerable Processes?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#processes)​ <a href="#vulnerable-processes" id="vulnerable-processes"></a>

* Is any **unknown software running**?
* Is any software with **more privileges that it should have running**?
* Search for **exploits for running processes** (specially if running of versions)
* Can you **read** some interesting **process memory** (where passwords could be saved)?

### ​[Known users/passwords?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#users)​ <a href="#known-users-passwords" id="known-users-passwords"></a>

* Try to **use** every **known password** that you have discovered previously to login **with each** possible **user**. Try to login also without password.

### ​[Interesting Groups?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#groups)​ <a href="#interesting-groups" id="interesting-groups"></a>

* Check **if** you [**belong** to any **group** that can grant you **root rights**](https://book.hacktricks.xyz/linux-unix/privilege-escalation/interesting-groups-linux-pe).

### ​[Weird scheduled jobs?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#scheduled-jobs)​ <a href="#weird-scheduled-jobs" id="weird-scheduled-jobs"></a>

* Is the **PATH** being modified by some cron and you can **write** in it?
* Some **modifiable script** is being **executed** or is inside **modifiable folder**?
* Is some cron **script calling other** script that is **modifiable** by you? or using **wildcards**?
* Have you detected that some **script** could be being **executed** very **frequently**? (every 1, 2 or 5 minutes)

### ​[Any sudo command?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#commands-with-sudo-and-suid-commands)​ <a href="#any-sudo-command" id="any-sudo-command"></a>

* Can you execute **any comand with sudo**? Can you use it to READ, WRITE or EXECUTE anything as root?
* Is some **wildcard used**?
* Is the binary specified **without path**?
* Is ***env\_keep+=LD\_PRELOAD***?

### ​[Any weird suid command?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#commands-with-sudo-and-suid-commands)​ <a href="#any-weird-suid-command" id="any-weird-suid-command"></a>

* **SUID** any **interesting command**? Can you use it to READ, WRITE or EXECUTE anything as root?
* Is some **wildcard used**?
* Is the SUID binary **executing some other binary without specifying the path**? or specifying it?
* Is it trying to **load .so from writable folders**?

### ​[Weird capabilities?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#capabilities)​ <a href="#weird-capabilities" id="weird-capabilities"></a>

* Has any binary any **uncommon capability**?

### ​[Open Shell sessions?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#open-shell-sessions)​ <a href="#open-shell-sessions" id="open-shell-sessions"></a>

* screen?
* tmux?

### ​[Can you read some sensitive data?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#read-sensitive-data)​ <a href="#can-you-read-some-sensitive-data" id="can-you-read-some-sensitive-data"></a>

* Can you **read** some **interesting files**? (files with passwords, \*\_history, backups...)

### ​[Can you write important files?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#writable-files)​ <a href="#can-you-write-important-files" id="can-you-write-important-files"></a>

* Are you able to **write files that could grant you more privileges**? (service conf files, shadow,a script that is executed by other users, libraries...)

### ​[Internal open ports?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#internal-open-ports)​ <a href="#internal-open-ports" id="internal-open-ports"></a>

* You should check if any undiscovered service is running in some port/interface. Maybe it is running with more privileges that it should or it is vulnerable to some kind of privilege escalation vulnerability.

### ​[Can you sniff some passwords in the network?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#sniffing)​ <a href="#can-you-sniff-some-passwords-in-the-network" id="can-you-sniff-some-passwords-in-the-network"></a>

* Can you **sniff** and get **passwords** from the **network**?

### ​[Any service missconfigurated? NFS? belongs to docker or lxd?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#privesc-exploiting-service-misconfigurations)​ <a href="#any-service-missconfigurated-nfs-belongs-to-docker-or-lxd" id="any-service-missconfigurated-nfs-belongs-to-docker-or-lxd"></a>

1. Any well known missconfiguration? ([**NFS no\_root\_squash**](https://book.hacktricks.xyz/linux-unix/privilege-escalation/nfs-no_root_squash-misconfiguration-pe))

### ​[Any weird executable in path?](https://book.hacktricks.xyz/linux-unix/privilege-escalation#check-for-weird-executables)​ <a href="#any-weird-executable-in-path" id="any-weird-executable-in-path"></a>
