Linux Security
Notes on Linux security topics, authentication, and hardening.
Directory map
- Linux Authentication β PAM, /etc/passwd, /etc/shadow, login process, credential storage
- Linux Privilege Escalation β Services & Internals Enumeration β network interfaces, /etc/hosts, lastlog/w/history, cron jobs, /proc, installed packages, sudo version, GTFOBins cross-reference, strace, config files, scripts, ps by user
- Linux Privilege Escalation β Wildcard Abuse β tar βcheckpoint-action exec, cron job wildcard hijack, GTFOBins wildcard entries
- Escaping Restricted Shells β rbash/rksh/rzsh, command injection, command substitution, command chaining, environment variables, shell functions
- Special Permissions (SUID/SGID) & GTFOBins β find -perm 4000/6000 enumeration, reverse engineering vs built-in feature abuse, apt-get Pre-Invoke example
- Linux Privilege Escalation β Sudo Rights Abuse β sudo -l, NOPASSWD entries, tcpdump -z postrotate-command GTFOBins abuse, sudoers best practices