Dunicot A cybersecurity consultancy and advisory firm.

Linux · Offensive security · 3 min read

Mastering Linux privileges: from fundamentals to escalation

Most Linux escalation is not an exploit at all, but a permission someone granted for a good reason and then forgot about.

Linux controls access to everything through its privilege model, and almost every escalation starts with a small misconfiguration in it rather than a memory-corruption bug. Administrators need to know how the model works to keep it tight; testers need to know it to find where it has been loosened. This guide outlines the journey from mastering fundamental Linux privilege management tactics to leveraging advanced exploits for enhanced system security and penetration testing proficiency.

Understanding Linux Privileges

At its core, Linux distinguishes between two main types of users: regular users and the superuser (root). Root can do anything on the system; regular users are bounded by the permissions set on files and directories. Everything that follows is about the gaps where that boundary is not where the administrator thought it was.

Fundamental Tactics for Privilege Management

User and Group Management

Accounts and groups are created and adjusted with ‘useradd’, ‘usermod’ and ‘groupadd’. Getting the group membership right at this point is what keeps the later permission checks meaningful.

Understanding File Permissions

The ‘chmod’, ‘chown’, and ‘chgrp’ commands are fundamental for setting appropriate access levels on files and directories, ensuring that users can only access data pertinent to their roles.

Leveraging Sudo for Controlled Access

The ‘sudo’ command allows specific users to execute commands with elevated privileges, typically as the root user, without giving them full root access. How ‘sudo’ is configured in ‘/etc/sudoers’ decides how much of that elevation an attacker inherits along with the user.

Use `sudo -l` to list permissible commands for the current user. In certain configurations, users can execute binaries like `find` with root privileges. GTFOBins catalogues which of those binaries can be talked into running arbitrary commands, which turns one permitted binary into a root shell.

Advanced Privilege Escalation Techniques

Privilege escalation involves obtaining a higher level of access than initially granted, usually aiming for root access, to gain control over system resources or sensitive information.

Exploiting Sudo Misconfigurations

Incorrect entries in the /etc/sudoers file may inadvertently grant users more privileges than intended, which can be exploited to gain unauthorized root access.

Exploiting a sudo misconfiguration with find to obtain a root shell

Leveraging SUID/SGID Binaries

Files set with the SUID (Set User ID) or SGID (Set Group ID) permissions can execute as the file owner or group, respectively, regardless of the executing user’s privileges. Identifying and exploiting vulnerable SUID/SGID binaries can lead to significant security breaches.

Path Injection

Manipulating the system’s PATH environment variable to include directories writable by non-root users allows attackers to execute arbitrary commands with elevated privileges.

A writable script invoked by sudo used to create a SUID root shell

Escalations: Kernel Exploits

The kernel’s role in managing system and application communication necessitates high privileges. Exploiting kernel vulnerabilities can, therefore, grant root access. The kernel exploit process involves identifying the current kernel version, finding or coding an exploit, and executing it, bearing in mind the risk of system crashes.

The first step is to determine the kernel version, accomplished with `uname, a’. Upon discovering a vulnerable version, such as 3.13.0, exploit databases like Exploit-DB can be searched for relevant exploits.

For example, CVE-2015-1328 on Exploit-DB reveals a vulnerability in Ubuntu’s overlays. Compiling and running the exploit can elevate privileges to root.

Reading the kernel version with uname -a before selecting an exploit

Conclusion

Almost nothing above required an exploit. It required reading what the system already permits and noticing where that is wider than intended. Audit sudo rules, SUID binaries, capabilities and cron entries on a schedule, and most of this class closes on its own.

In short

Point 1
Read the sudoers policy first, misconfiguration there beats any kernel exploit for reliability.
Point 2
SUID binaries are a standing grant of the owner’s privileges to whoever can run them.
Point 3
A writable directory early in PATH turns any relative command call into code execution.
Point 4
Kernel exploits are the last resort: loud, version-specific and prone to crashing the host.

Want this applied to your stack?

Everything written here comes out of delivered engagements. Describe the platform and the deadline.