Linux · Offensive security · 3 min read
Mastering Linux privileges: from fundamentals to escalation
Most Linux escalation is not an exploit at all, but a permission someone granted for a good reason and then forgot about.
Linux controls access to everything through its privilege model, and almost every escalation starts with a small misconfiguration in it rather than a memory-corruption bug. Administrators need to know how the model works to keep it tight; testers need to know it to find where it has been loosened. This guide outlines the journey from mastering fundamental Linux privilege management tactics to leveraging advanced exploits for enhanced system security and penetration testing proficiency.
Understanding Linux Privileges
At its core, Linux distinguishes between two main types of users: regular users and the superuser (root). Root can do anything on the system; regular users are bounded by the permissions set on files and directories. Everything that follows is about the gaps where that boundary is not where the administrator thought it was.
Fundamental Tactics for Privilege Management
User and Group Management
Accounts and groups are created and adjusted with ‘useradd’, ‘usermod’ and ‘groupadd’. Getting the group membership right at this point is what keeps the later permission checks meaningful.
Understanding File Permissions
The ‘chmod’, ‘chown’, and ‘chgrp’ commands are fundamental for setting appropriate access levels on files and directories, ensuring that users can only access data pertinent to their roles.
Leveraging Sudo for Controlled Access
The ‘sudo’ command allows specific users to execute commands with elevated privileges, typically as the root user, without giving them full root access. How ‘sudo’ is configured in ‘/etc/sudoers’ decides how much of that elevation an attacker inherits along with the user.
Use `sudo -l` to list permissible commands for the current user. In certain configurations, users can execute binaries like `find` with root privileges. GTFOBins catalogues which of those binaries can be talked into running arbitrary commands, which turns one permitted binary into a root shell.
Advanced Privilege Escalation Techniques
Privilege escalation involves obtaining a higher level of access than initially granted, usually aiming for root access, to gain control over system resources or sensitive information.
Exploiting Sudo Misconfigurations
Incorrect entries in the /etc/sudoers file may inadvertently grant users more privileges than intended, which can be exploited to gain unauthorized root access.
Leveraging SUID/SGID Binaries
Files set with the SUID (Set User ID) or SGID (Set Group ID) permissions can execute as the file owner or group, respectively, regardless of the executing user’s privileges. Identifying and exploiting vulnerable SUID/SGID binaries can lead to significant security breaches.
Path Injection
Manipulating the system’s PATH environment variable to include directories writable by non-root users allows attackers to execute arbitrary commands with elevated privileges.
Escalations: Kernel Exploits
The kernel’s role in managing system and application communication necessitates high privileges. Exploiting kernel vulnerabilities can, therefore, grant root access. The kernel exploit process involves identifying the current kernel version, finding or coding an exploit, and executing it, bearing in mind the risk of system crashes.
The first step is to determine the kernel version, accomplished with `uname, a’. Upon discovering a vulnerable version, such as 3.13.0, exploit databases like Exploit-DB can be searched for relevant exploits.
For example, CVE-2015-1328 on Exploit-DB reveals a vulnerability in Ubuntu’s overlays. Compiling and running the exploit can elevate privileges to root.
Conclusion
Almost nothing above required an exploit. It required reading what the system already permits and noticing where that is wider than intended. Audit sudo rules, SUID binaries, capabilities and cron entries on a schedule, and most of this class closes on its own.
In short
- Point 1
- Read the sudoers policy first, misconfiguration there beats any kernel exploit for reliability.
- Point 2
- SUID binaries are a standing grant of the owner’s privileges to whoever can run them.
- Point 3
- A writable directory early in PATH turns any relative command call into code execution.
- Point 4
- Kernel exploits are the last resort: loud, version-specific and prone to crashing the host.