Ravindra BagaleCourses & study guides

26. Privilege Escalation

Chala mitrano, ata ek mahatvacha tappa. Attacker system madhe shirto tevha bahutek to ek saamanya user mhanun aat yeto – limited power. Pan tyala pahije root (Linux) kiwa Administrator (Windows) – purna control. Ha janya cha marg mhanje privilege escalation – kami adhikaratun jast adhikar milavne. Aaj aapan shiku he kase hote (misconfigurations, weak permissions), Linux var linPEAS ne kase shodhaycha, ani – jsa nehmi – ha attack thambavaycha kasa. Sagle fakt Metasploitable 2 ani tumchya lab VM var. Samjla ka? Chala!

What you will learn in this chapter

  • What privilege escalation is: vertical vs horizontal
  • Common Linux escalation paths: sudo misconfig, SUID binaries, cron jobs, weak permissions, kernel exploits
  • Manual enumeration commands you run first
  • linPEAS and LinEnum: automated enumeration
  • A note on Windows escalation
  • Defences: least privilege, patching, correct permissions, auditing

Lab scope for this whole chapter

Practice escalation only on Metasploitable 2 or your own lab VMs where you already have a shell (for example from Chapter 23). Escalating privileges on any system you are not authorised to test is a crime under the IT Act.

Concepts in this chapter

  1. 26.1What Privilege Escalation Is
  2. 26.2Manual Linux Enumeration
  3. 26.3Common Escalation Paths
  4. 26.4Automated Enumeration: linPEAS and LinEnum
  5. 26.5A Note on Windows Escalation
  6. 26.6Defending Against Privilege Escalation
  7. 26.7Red vs Blue, Project and Real Incidents

The chapter recap is at the end of the last concept page.