26. Privilege Escalation
Chala mitrano, ata ek mahatvacha tappa. Attacker system madhe shirto tevha bahutek to ek saamanya user mhanun aat yeto – limited power. Pan tyala pahije root (Linux) kiwa Administrator (Windows) – purna control. Ha janya cha marg mhanje privilege escalation – kami adhikaratun jast adhikar milavne. Aaj aapan shiku he kase hote (misconfigurations, weak permissions), Linux var linPEAS ne kase shodhaycha, ani – jsa nehmi – ha attack thambavaycha kasa. Sagle fakt Metasploitable 2 ani tumchya lab VM var. Samjla ka? Chala!
What you will learn in this chapter
- What privilege escalation is: vertical vs horizontal
- Common Linux escalation paths: sudo misconfig, SUID binaries, cron jobs, weak permissions, kernel exploits
- Manual enumeration commands you run first
- linPEAS and LinEnum: automated enumeration
- A note on Windows escalation
- Defences: least privilege, patching, correct permissions, auditing
Lab scope for this whole chapter
Practice escalation only on Metasploitable 2 or your own lab VMs where you already have a shell (for example from Chapter 23). Escalating privileges on any system you are not authorised to test is a crime under the IT Act.
Concepts in this chapter
- 26.1What Privilege Escalation Is
- 26.2Manual Linux Enumeration
- 26.3Common Escalation Paths
- 26.4Automated Enumeration: linPEAS and LinEnum
- 26.5A Note on Windows Escalation
- 26.6Defending Against Privilege Escalation
- 26.7Red vs Blue, Project and Real Incidents
The chapter recap is at the end of the last concept page.