Posted on

Linux privilege escalation for beginners

Hello, aspiring ethical hackers. This blogpost is a detailed guide on Linux privilege escalation. Linux privilege escalation comes after Linux hacking and is part of Post-exploitation of Linux.

What is Linux privilege escalation?

Linux privilege escalation is the process of elevating privileges on a Linux system after successfully gaining access to a Linux system.

Why is it important?

Linux hacking is one of the most important topics in ethical hacking. Why? According to the Statcounter global stats, as of March 2024 operating system market share, the topmost operating systems being used around the world are Linux or its variants. The same report also states that usage of Linux as desktop increased to 4.05% this year. Also note that majority of the servers around the world are Linux servers. So, learning Linux hacking can provide lot of knowledge. But what are the various methods used for hacking Linux systems.

Linux privilege escalation techniques

There are multiple ways by which hackers can elevate privileges on a Linux system. They are,

  1. Exploiting SUID binaries.
  2. Exploiting SUDO privileges.
  3. Exploiting services running as root.
  4. Exploiting misconfigured cron jobs.
  5. Exploiting kernel vulnerabilities.

1.Exploiting SUID binaries:

Just like Windows, Linux too has many binaries on the system. These binary files too have permissions just like any file in Windows. Apart from the regular permissions of a file, Linux has special permissions for some binaries.

These permissions are called SUID or SetUID permissions also known as Set Owner User Identification (SUID). This permission allows a user with low privileges to run a binary or script under the power of the original owner of the particular file. So, if a SUID or SetUID bit is set to a particular binary or a root user has created a binary file and has set a SUID bit to it, this file can be exploited to gain root permissions on the target Linux system.

2. Exploiting SUDO rights:

SUDO is a very important concept in Linux. Sudo stands for ‘Super User Do’ and is pronounced as “su dough”. SUDO lets users run commands with root privileges from their own account. Learn more about exploiting SUDO privileges.

3. Exploiting services running as root:

Privileges can also be elevated on Linux by exploiting services running as root. Some services running on Linux are configured to run with root privileges. By exploiting any vulnerability in these services Root privileges can be acquired.

4. Exploiting misconfigured cron jobs:

In Unix system, cron is used to schedule jobs for automation. Some jobs that are misconfigured can be exploited to gain root privileges.

5. Exploiting kernel vulnerabilities:

Vulnerabilities in the Linux kernel can be exploited to gain root privileges.

Next, learn about Unix-privesc-check, a tool that helps in elevating privileges on UNIX based systems or better still learn about Linux exploit suggester, a shell script that suggest exploits for the target kernel.

Posted on

Windows privilege escalation for beginners

Hello, aspiring ethical hackers. In this blogpost, you will learn about Windows privilege escalation. Windows privilege escalation comes after Windows hacking and is part of Post-exploitation of Windows.

What is Windows privilege escalation?

Windows privilege escalation is the process of elevating privileges on a Windows system after successfully gaining access to a Windows system.

Why is it important?

According to StatCounter Global Stats, over 72.52% of people worldwide use Windows as their Desktop. That is the reason why Windows privilege escalation is one of the most important topics of ethical hacking.

Windows privilege escalation techniques

There are multiple ways by which hackers can elevate privileges on a Windows systems. They are,

  1. Exposed credentials
  2. Bypassing UAC
  3. Exploiting services running with administrator privileges.
  4. Windows kernel vulnerabilities.
  5. Misconfigured services.
  6. Windows Registry.
  7. Scheduled Tasks.

1. Exposed credentials:

Sometimes, the credentials of user accounts with administrator privileges on a Windows system are exposed. Most people still store Windows credentials on Desktop for easy access (you may not believe this but this is true). So, attackers can login as user with high privileges using these exposed credentials.

2. Bypassing UAC:

User Account Control (UAC) is a Windows security feature that was designed to protect the operating system. Introduced with Windows Vista, it is a mandatory access control enforcement feature. It works by limiting application software to standard user privileges until a user with administrator privileges authorizes an elevation in privileges.

This allows only applications that are trusted by users to be assigned administrator privileges. However, vulnerabilities in this UAC sometimes allows hackers to bypass UAC and get administration privileges on the target system.

3. Exploiting services running with administration privileges:

Some applications installed on Windows by users need administrative privileged on the system to run. If attackers exploit any vulnerabilities in these applications, they can easily elevate their privileges on the Windows system.

4. Windows kernel vulnerabilities:

Windows kernel in Windows (or for that matter any operating system) has the highest privileges assigned to it. If attackers exploit any vulnerabilities in the Windows kernel, they can elevate their privileges on the Windows system.

5. Misconfigured services:

Misconfigurations in services on Windows can also be exploited to escalate privileges on Windows system.

6. Windows Registry:

Windows registry is a hierarchical database that stores all low level; settings of Microsoft Windows. Weak permissions in the Windows registry can also be exploited to elevate privileges.

7. Scheduled Tasks:

Windows Task Scheduler (formerly known as Scheduled Tasks) is used to automate jobs and tasks in Windows just like cron jobs in Linux. Weak file permission setting in Task scheduler can be exploited to elevate privileges on a Windows system.

Learn about Windows-privesc-check, an executable that finds misconfigurations in target Windows system and helps in elevating privileges on a Windows target.

Posted on

Dirty Cow vulnerability: Beginners guide

Hello, aspiring ethical hackers. This blogpost is a beginner’s guide to Dirty COW vulnerability. Assigned CVEID, CVE-2016-5195, this vulnerability affects Linux kernel version 2.6.21 since 2007. To exploit this vulnerability, the hackers need to first gain initial access on the target system.

What is this Dirty COW vulnerability?

Dirty COW is a Linux privilege escalation vulnerability which is caused due to a race condition in the way the Linux kernel handled copy-on-write functions. The name Dirty COW came from this Copy-On-Write (COW). By exploiting this vulnerability, an unprivileged user can gain access to the read-only memory mapping subsequently elevating their privileges on the system.

Which kernels are vulnerable?

All the Linux kernels from versions 2.x to 4.x before 4.8.7 are vulnerable to this Dirty COW vulnerability. Let’s demonstrate this vulnerability on a Ubuntu 12 system. To exploit this vulnerability, the hackers need to first gain initial access on the target system.

Download this exploit from Github and extract its contents. It is a C program as shown below.

Compile this code using inbuilt GCC compiler in Ubuntu system. This exploit creates a new user named ‘firefart’ with root privileges on the target system by writing to the /etc/passwd file. Usually, creating an user with root privileges in not possible for low privileged users on Linux systems. But this is a privilege escalation vulnerability.

Now, let’s execute the exploit as shown below. It will prompt you to create a new password for the new user “firefart” it is creating.

Login as the newly created user to see if the exploit was successful in exploiting the vulnerability and creating the news user “firefart”.

As you can see, a new user named “firefart” has been created on the target system with root privileges.

Posted on

Privilege Escalation Guide for Beginners

Privilege escalation is one of the most important concepts beginners encounter when learning ethical hacking and penetration testing.

Getting initial access to a system is often only one part of a security assessment. An account or process may have limited permissions while sensitive files, administrative settings, security controls and critical systems require higher privileges. Understanding how permissions are assigned and how misconfigurations can allow those permissions to be abused—is therefore an essential cybersecurity skill.

This guide explains privilege escalation from a beginner’s perspective, including the difference between horizontal and vertical privilege escalation, common Linux and Windows weaknesses, a typical assessment methodology and safe ways to practice.

Important: Privilege-escalation techniques should only be tested on systems you own or have explicit authorization to assess. Use intentionally vulnerable labs, virtual machines and training platforms.

What Is Privilege Escalation?

Privilege escalation occurs when a user, process or application gains access to resources or capabilities beyond what it was originally authorized to use.

Imagine a system with three users:

  • A standard user
  • A department administrator
  • A system administrator

If the standard user discovers a legitimate path to administrator-level permissions because of a security weakness, that situation represents privilege escalation. The same concept applies to servers, workstations, cloud environments, applications and enterprise identity systems.

Privilege escalation is generally divided into two categories. They are,

Vertical Privilege Escalation:

Vertical escalation occurs when a lower-privileged user gains higher privileges.

For example:

Standard User → Administrator → System-Level Access

This is the type most beginners associate with privilege escalation.

Horizontal Privilege Escalation:

Horizontal escalation occurs when one user accesses resources belonging to another user with a similar privilege level.

For example, imagine two ordinary accounts:

User A → User B’s Account or Data

The attacker may not become an administrator but accessing another user’s resources can still represent a serious security problem. Understanding this distinction is important because not every privilege problem involves becoming a system administrator.

Why Does Privilege Escalation Matter?

Organizations use permissions to limit what users and applications can do. A normal employee may need access to business applications but should not necessarily be able to modify security settings, install arbitrary software or access another employee’s confidential files.

Privilege separation reduces the impact of compromised accounts. If an attacker compromises a standard account and discovers that the account can immediately obtain administrative privileges because of a configuration mistake, the security boundary becomes much weaker.

This is why penetration testers don’t stop after obtaining an initial foothold. They examine what that access actually allows.

How Privilege Escalation Fits Into a Security Assessment

A simplified penetration-testing workflow might look like this:

Reconnaissance → Initial Access → Enumeration → Privilege Assessment → Privilege Escalation → Impact Analysis → Reporting

Privilege escalation generally happens after some level of access has already been obtained.

The tester asks questions such as:

  • What account am I using?
  • What permissions does this account have?
  • What groups is it part of?
  • Which applications are running?
  • Which files are accessible?
  • Which services operate with elevated privileges?
  • Are there incorrectly configured permissions?
  • Are outdated components present?
  • Are credentials or secrets unnecessarily exposed?
  • Are administrative functions restricted correctly?

The important lesson is that enumeration comes before exploitation. Beginners sometimes immediately search for an exploit. A better approach is to first understand the system.

Linux Privilege Escalation

Linux systems use a permission model involving users, groups, files, processes, services and administrative privileges.

A beginner learning Linux privilege escalation should first understand:

Users and Groups

Linux permissions are strongly connected to users and groups. A file might belong to one user and group while allowing different levels of access to the owner, group members and other users. Understanding this model is more important than memorizing individual privilege-escalation tricks.

Sudo and Administrative Permissions

Linux systems can allow selected users to perform certain administrative operations. Misconfigured administrative permissions can create security risks. For example, giving a user permission to perform a powerful administrative operation without sufficient restrictions can potentially allow that user to cross a security boundary.

This is why security assessments examine administrative permissions carefully.

File and Directory Permissions

Incorrect ownership or overly permissive access controls can expose sensitive information or allow unauthorized modification.

A beginner should learn how to reason about:

Owner → Group → Permissions → Sensitive Resource

rather than simply looking for a particular command or exploit.

Services and Scheduled Tasks

Background services and scheduled processes may run with higher privileges. If such a process interacts with files, scripts or other resources that lower-privileged users can modify, the configuration may create a privilege-escalation risk.

This is an important security concept because the weakness can come from the relationship between two individually legitimate components.

Windows Privilege Escalation

Windows privilege escalation has a different ecosystem but follows many of the same underlying principles.

Beginners should understand:

User and Group Membership

Windows uses users and groups to control access to resources. Membership in certain administrative or powerful groups can significantly change what an account can do.

Services

Windows services frequently run in privileged security contexts. A poorly configured service can become a security weakness if a lower-privileged user can improperly influence how that service operates.

File and Registry Permissions

Windows uses access control mechanisms to determine who can read, modify or execute resources. Weak permissions on sensitive files, directories or configuration information can create opportunities for unauthorized access.

Scheduled Tasks

Scheduled tasks can execute automatically under particular accounts or security contexts. Incorrect permissions surrounding a scheduled task can therefore create a privilege boundary problem.

Credentials and Secrets

Passwords, tokens, configuration files and other secrets should never be unnecessarily exposed to low-privileged users.

During an authorized assessment, testers look for situations where sensitive authentication material is stored or exposed incorrectly.

Common Privilege-Escalation Weaknesses

Although every operating system is different, several recurring categories appear in security assessments:

  1. Weak permissions
  2. Misconfigured services
  3. Excessive administrative privileges
  4. Unpatched software
  5. Exposed credentials or secrets
  6. Insecure scheduled tasks
  7. Poorly configured applications
  8. Weak separation between users and resources
  9. Unsafe scripts or automation
  10. Improper access-control design

Notice that many of these are configuration problems rather than sophisticated software vulnerabilities. That is an important lesson for beginners. Security is often broken by ordinary components that have been configured incorrectly.

A Beginner’s Privilege-Escalation Methodology

Instead of memorizing hundreds of techniques, develop a repeatable process.

Step 1: Identify Your Current Context

Determine which account, groups, permissions and security context you currently have.

Step 2: Understand the System

Identify the operating system, installed applications, running services, network configuration and important directories.

Step 3: Review Permissions

Look for resources that your current account can access or modify.

Step 4: Look for Misconfigurations

Focus on excessive privileges, writable sensitive resources, insecure services, exposed credentials and weak access controls.

Step 5: Research the Finding

If you discover an unusual configuration or vulnerable component, research its security implications using trusted documentation and vulnerability databases.

Step 6: Validate Safely

In an authorized laboratory, determine whether the suspected weakness actually crosses a privilege boundary.

Step 7: Document Everything

Record the original privilege level, the weakness discovered, the security impact and the recommended remediation.

This methodology is more valuable than memorizing a collection of commands.

How Beginners Can Practice Safely

The best way to learn privilege escalation is through deliberately vulnerable environments. Create an isolated virtual lab containing systems you control. Beginner-friendly cybersecurity training platforms and vulnerable virtual machines can also provide structured exercises.

Your goal should not simply be:

“How do I become administrator?”

Instead, ask:

“Why was the privilege boundary weak?”

That question develops a much stronger security mindset.

For example, if a lab demonstrates an insecure service configuration, investigate why the service had excessive privileges, what permission allowed the lower-privileged account to influence it and how an administrator could correct the problem.

How to Prevent Privilege Escalation

Learning offensive security should also teach you how to defend systems.

Organizations can reduce privilege-escalation risk by:

  • Applying security updates regularly
  • Following the principle of least privilege
  • Reviewing administrator and group memberships
  • Restricting service permissions
  • Protecting credentials and secrets
  • Monitoring privileged activity
  • Removing unnecessary software and services
  • Reviewing file and registry permissions
  • Separating administrative accounts from normal accounts
  • Auditing configuration changes

Least privilege is particularly important. Users and applications should receive only the permissions they actually need.

What Beginners Should Learn Next

Privilege escalation sits at the intersection of several important cybersecurity fundamentals.

A useful learning sequence is:

Networking → Linux → Windows → Permissions → Authentication → Enumeration → Vulnerability Management → Privilege Escalation → Active Directory → Security Reporting

You don’t need to master everything at once. Start with operating-system fundamentals. Learn how users, groups, processes, services, files, permissions and authentication work.

Then practice identifying security weaknesses in controlled environments. Eventually, privilege escalation becomes less about memorizing tricks and more about recognizing relationships between users, permissions, processes, services, applications and resources.

Conclusion

Privilege escalation is an essential skill for anyone learning ethical hacking. The most important lesson for beginners is that privilege escalation isn’t simply about finding a clever exploit. It is about understanding why a system allows one security boundary to be crossed.

A strong ethical hacker can look at a system and reason about permissions, trust relationships, configuration, and security controls.

Build that foundation first.
Practice only in authorized environments.
Document what you discover.

And most importantly, learn both sides of the problem: how privilege boundaries can fail and how administrators can build stronger ones.

That is what turns privilege escalation from a collection of hacking tricks into a genuine cybersecurity skill.

Posted on

Linux privilege escalation with SUID binaries

Hello, aspiring ethical hackers. In our previous blogpost, you learnt about various methods of Linux privilege escalation. In this article, you will learn in detail how to elevate privileges on Linux using SUID binaries.

What is SUID?

SUID is a shortcut for Set User ID. This is a special permission that can be assigned to Linux executables. When a SUID permission is assigned to a executable or binary, it runs with the privileges of the file’s owner when executed, rather than the user who executed it. For example, when a user with root privileges assigns SUID permission to a Linux binary and a user with low privileges executes that binary, it runs with root privileges and not with privileges of that user with low privileges.

This can be exploited to gain a root shell or perform actions with root privileges on the target Linux system. With the concept of SUID understood, let’s see how binaries with this bit set can be found. One way to find them is by using find command as shown below.

find / -perm -u=s -type f 2>/dev/null
setuid privilege escalation


Here are some examples of gaining root privileges by exploiting Linux binaries with SUID bit set.

1. bash

2. csh

3. env

4. nice

5. node

6. setarch

7. stdbuf

8. strace

9. taskset

10. tclsh

11. time

12. timeout

13. unshared

14. xargs

15. php

16. expect

17. find

18. python

19. flock

20. gdb

21. ionice

22. logsave

23. make

These are some examples of Linux privilege escalation by exploiting SETUID bit. Next, learn how to elevate privileges on a Linux system using cron jobs.