Linux
Linux host’ta düşük yetkili bir shell’den root’a çıkmak, iç ağ ve bulut pentestinde en sık tekrarlanan adımdır. Bu bölüm enumeration → yanlış yapılandırma → sömürü zincirini Türkçe olarak ele alır; çekirdek CVE’lerinden çok SUID, sudo, capability, cron, NFS ve PATH hijack gibi pratik vektörlere odaklanır.
Bağlam
Section titled “Bağlam”Dayanak: web RCE / SSH / reverse shell / container shellHedef: root / CAP_SYS_ADMIN / host FS / docker.sockAraçlar: linpeas, pspy, GTFOBins, busybox, gcc/pythonÇoğu kazanım “eski kernel exploit” değil; yanlış izin, sudo kuralı, yazılabilir cron/script ve paylaşılan dosya sistemidir. Önce kim olduğunuzu ve neleri yazabildiğinizi çıkarın; sonra GTFOBins / capability / cron yollarını deneyin.
Metodoloji
Section titled “Metodoloji”-
Enumeration — kullanıcı, grup, SUID/SGID, sudo, capability, cron, servis, mount, kernel.
-
Hızlı kazanç — sudo NOPASSWD, yazılabilir cron, world-writable SUID, docker.sock.
-
Derin vektör — NFS
no_root_squash, PATH/LD_LIBRARY hijack, capability abuse, LXD. -
Kernel / CVE — yalnızca sürüm+config eşleşince; staging ortamda doğrula.
-
Sonrası — SSH key, shadow, history, cloud metadata, yanal hareket.
Tipik saldırı yüzeyi
Section titled “Tipik saldırı yüzeyi”| Vektör | Ne aranır |
|---|---|
| SUID / SGID | GTFOBins binary’leri, özel setuid araçlar |
| sudo | NOPASSWD, ENV_KEEP, wildcard, LD_PRELOAD |
| Capabilities | cap_setuid, cap_dac_read_search, cap_sys_admin |
| Cron / systemd | Yazılabilir script, PATH hijack, timer unit |
| NFS | no_root_squash, anonuid, yazılabilir export |
| Docker / LXC | docker grubu, sock mount, privileged |
| Kernel | Eski sürüm + bilinen LPE, unprotected modules |
Araç çantası
Section titled “Araç çantası”linpeas.sh / linenum / LES → otomatik enumpspy → cron/process izleme (root gerekmez)GTFOBins → SUID/sudo escape tarifleribusybox / find / python → kısıtlı shell bypasscdk / amicontained → container ortam profiliBölümler
Section titled “Bölümler”- Privilege Escalation — SUID, sudo, capabilities, cron, kernel, NFS, PATH, GTFOBins
- Checklist — adım adım pratik kontrol listesi
- Containers — docker.sock, privileged, namespace kaçışı
İlgili: Container Escape (Cloud), Network, Pivoting.
Zincir örnekleri
Section titled “Zincir örnekleri”www-data shell → linpeas → sudo vim NOPASSWD → root shell → /etc/shadow + SSH keylowpriv → SUID find → GTFOBins find -exec → rootuser in docker group → docker run -v /:/mnt --privileged → chroot host → rootNFS no_root_squash → local root SUID binary → mount + copy → remote rootTüm konu başlıkları
Section titled “Tüm konu başlıkları”- Assessment And Hardening
- Authorization Plugins
- Distroless
- Image Security And Secrets
- Container Security
- Privileged Containers
- AppArmor
- Capabilities
- CGroups
- Protections
- Masked Paths
- CGroup Namespace
- Namespaces
- IPC Namespace
- Mount Namespace
- Network Namespace
- PID Namespace
- Time Namespace
- User Namespace
- UTS Namespace
- No New Privileges
- Read Only Paths
- Seccomp
- Runtime API And Daemon Exposure
- Runtimes And Engines
- Sensitive Host Mounts
- Containerd (ctr) Privilege Escalation
- RunC Privilege Escalation
- ld.so privesc exploit example
- Linux Capabilities
- NFS no_root_squash/no_all_squash misconfiguration PE
- SELinux
- SUID Shared Library and Linker Abuse
- Wildcards Spare tricks
- Arbitrary File Write to Root
- DDexec / EverythingExec
- Bypass FS protections: read-only / no-exec / Distroless
- Bypass Linux Restrictions
- Linux Environment Variables
- Useful Linux Commands
- Escaping from Jails
- Filesystem, Inodes and Recovery
- Copy Fail Af Alg Splice Page Cache Overwrite Cve 2026 31431
- Linux Ptrace Exit Race Pidfd Getfd Fd Theft
- Posix Cpu Timers Toctou Cve 2025 38352
- Vmware Tools Service Discovery Untrusted Search Path Cve 2025 41244
- Kernel Modules and modprobe Abuse
- Checklist - Linux Privilege Escalation
- Sudo Command Abuse
- Cisco - vmanage
- Local Network and Socket Triage
- Socket Command Injection
- Linux Post-Exploitation
- D-Bus Enumeration & Command Injection Privilege Escalation
- Payloads to execute
- Android Rooting Frameworks Manager Auth Bypass Syscall Hook
- Node inspector/CEF debug abuse
- FreeIPA Pentesting
- Logstash
- PAM - Pluggable Authentication Modules
- Splunk LPE and Persistence
- euid, ruid, suid
- Interesting Groups - Linux Privesc
- lxd/lxc Group - Privilege escalation
- Linux Active Directory
- SSH Forward Agent exploitation