Linux Privilege Escalation

Elevate your access from standard user to root. Learn to identify misconfigured SUID binaries, abuse sudo permissions, hijack cron jobs, and automate enumeration using LinPEAS.

Cybersecurity EngineerCybersecurityLinux

Introduction

Linux privilege escalation begins after a low-privileged foothold: the task is to turn local evidence into a controlled path to root. This hands-on course develops that workflow through system enumeration, permission analysis, and carefully verified exploitation of common Linux misconfigurations.

You will transfer and interpret a streamlined LinPEAS script, investigate unusual SUID programs and sudo rules, and test a privileged cron job whose script is writable by ordinary users. A final challenge asks you to apply the same reasoning to a disguised find binary and retrieve protected evidence without a step-by-step walkthrough.

What You Will Learn

  • Transfer a provided LinPEAS script with a local Python HTTP server and wget
  • Capture and filter enumeration output to isolate suspicious SUID findings
  • Search the filesystem for SUID binaries and distinguish expected entries from risky anomalies
  • Use find -exec to demonstrate command execution through a misconfigured SUID binary
  • Audit sudo permissions with sudo -l and assess an unsafe NOPASSWD rule
  • Prove the impact of delegated root execution by reading restricted files and recording root identity
  • Inspect system cron definitions and exploit a world-writable script executed by root
  • Apply enumeration and exploitation techniques independently in a root-flag challenge

Who This Course Is For

This intermediate course is for cybersecurity learners, penetration testers, and Linux administrators who want practical experience recognizing and validating local privilege-escalation paths. It emphasizes why a finding is dangerous, not merely which command to copy.

Prerequisites: Comfort using a Linux terminal, navigating files and directories, running shell commands, and reading basic Unix permission notation. Familiarity with users, processes, and output redirection is helpful; prior LinPEAS experience is not required.

Learning environment: An interactive Ubuntu 22.04 terminal with prepared vulnerable configurations, a bundled mock LinPEAS script, and automated checks. All attacks are performed inside the isolated lab environment.

Frequently Asked Questions

Does LinPEAS exploit the system automatically?

No. In this course, the provided streamlined LinPEAS script performs enumeration and highlights a suspicious custom SUID binary. You still have to interpret the result and decide what deserves manual investigation.

Do I need internet access to download LinPEAS or consult GTFOBins?

No. The LinPEAS script is already included in the attacker directory and is transferred through a local HTTP server. The course explains the relevant GTFOBins-style find -exec technique directly, so the exercises do not depend on an external website.

Will every exercise open an interactive root shell?

No. Some exercises verify elevated execution safely by saving whoami or id output, reading a restricted file, or capturing a root-only flag. The SUID lab also shows the command that can launch an interactive privileged shell.

Does the course cover kernel exploits or password cracking?

No. The scope is configuration-based local escalation: automated enumeration, SUID permissions, overly broad sudo delegation, and writable cron scripts. It reads a sample /etc/shadow entry to demonstrate impact but does not crack hashes or exploit the kernel.

Teacher

labby
Labby
Labby is the LabEx teacher.