Linux Capabilities Abuse for Privilege Escalation
Explores exploiting misconfigured Linux capabilities (e.g., CAP_SETUID, CAP_NET_RAW) to escalate privileges without full SUID binaries.
HackIndex
Language
Use this platform when the target host or the control plane you’re interacting with is Linux: access, local privilege escalation, filesystem and credential hunting, service misconfigs, and post-ex actions that depend on Linux tooling and layout.
Linux privesc guides covering SUID, sudo, cron, kernel CVEs, and more
Explores exploiting misconfigured Linux capabilities (e.g., CAP_SETUID, CAP_NET_RAW) to escalate privileges without full SUID binaries.
Techniques for locating stored credentials on Linux systems, including config files, history, environment variables, and memory to escalate privileges.
Exploit misconfigured cron jobs running as root to escalate privileges via writable scripts, PATH hijacking, or wildcard injection on Linux systems.
Exploit misconfigured D-Bus services on Linux to escalate privileges by abusing insecure policy rules, exposed interfaces, and unauthorized method calls.
Race condition in Linux kernel's copy-on-write mechanism allows local attackers to gain root privileges by writing to read-only memory mappings.
Exploits Linux kernel pipe buffer flaw (CVE-2022-0847) to overwrite read-only files and escalate privileges to root on kernels 5.8–5.16.11.
Linux post-exploitation guides for exfil, persistence, and creds
TTY upgrades and reverse shell one-liners for Linux
Guides for enumerating users, system, network, services, and jobs on Linux
Enumerate cron jobs, systemd timers, and scheduled tasks on Linux to identify misconfigurations or privileged scripts exploitable for privilege escalation.
Techniques for enumerating local Linux systems post-access: users, groups, SUID binaries, cron jobs, kernel version, and privilege escalation vectors.
SSH tunneling, port forwarding, and credential reuse for pivoting
Covers SSH local, remote & dynamic port forwarding techniques to tunnel traffic, bypass network restrictions and pivot through compromised Linux hosts.
Find, stage, compress, and transfer data from Linux systems
Living-off-the-land file transfer techniques for Linux using built-in utilities like /dev/tcp, base64, and proc when wget/curl/nc are unavailable.
Techniques for locating sensitive files, credentials, and critical data on Linux systems prior to exfiltration using native CLI tools.
Covers techniques for aggregating, archiving, and compressing sensitive data on Linux systems prior to exfiltration, including tar, zip, and encryption methods.
Cron, SSH keys, web shells, backdoors, systemd, and profile persistence
Covers techniques for detecting and preventing unauthorized backdoor accounts on Linux systems used to maintain persistent unauthorized access.
Covers abusing cron jobs and systemd timers to maintain persistent access on Linux systems, including scheduled task backdoors and detection evasion.
Techniques for maintaining persistent access on Linux systems via shell configuration files, profile scripts, and environment variable hijacking.
Covers abusing SSH authorized_keys files to maintain persistent backdoor access on Linux systems by injecting attacker-controlled public keys.
Covers creating malicious systemd service units to maintain persistent code execution across reboots, including unit file structure and enabling techniques.
Covers techniques attackers use to deploy and maintain web shells on Linux servers for persistent backdoor access and remote code execution.
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.