Cybersecurity

15 Linux Misconfigurations Attackers Check Before Running LinPEAS

Most beginners land a shell on a Linux system and immediately run LinPEAS.

September 8, 2026·5 min read
15 Linux Misconfigurations Attackers Check Before Running LinPEAS

Most beginners land a shell on a Linux system and immediately run LinPEAS.

There’s nothing wrong with that. LinPEAS is one of the best privilege escalation enumeration tools available today.

But experienced penetration testers and red teamers rarely start there.

Why?

Because automated tools often generate hundreds of findings, most of which are irrelevant. Skilled attackers first perform manual reconnaissance to understand the system, identify obvious weaknesses, and build an attack path before relying on automation.

In many cases, these quick checks reveal a privilege escalation vector within minutes.

Let’s look at 15 Linux misconfigurations attackers typically investigate before running LinPEAS.

•••

1. Dangerous Sudo Permissions

The first command many attackers run is:

sudo -l

This shows which commands can be executed with elevated privileges.

A common mistake administrators make is granting access to seemingly harmless binaries such as:

sudo vim
sudo less
sudo find
sudo awk
sudo tar

Many of these can be abused to execute arbitrary commands and obtain root access.

One misconfigured sudo rule can completely compromise a system.

2. Custom SUID Binaries

SUID files execute with the privileges of their owner.

To locate them:

find / -perm -4000 -type f 2>/dev/null

While standard Linux binaries are expected, custom applications often introduce serious security flaws.

Questions attackers ask:

  • Is this binary custom-built?

  • Can it call external programs?

  • Does it trust user-controlled input?

Custom SUID binaries are frequently responsible for privilege escalation findings.

3. Writable Cron Jobs

Scheduled tasks run automatically and often execute as root.

Check:

cat /etc/crontab
ls -la /etc/cron.*

Attackers look for:

  • Writable scripts

  • Weak permissions

  • Scripts executed as root

If a root-owned cron task executes a writable script every minute, gaining root becomes trivial.

4. Weak File Permissions

Improper permissions remain one of the most common Linux security mistakes.

Search for writable files:

find / -writable -type f 2>/dev/null

Particularly interesting locations include:

/etc/
/opt/
/usr/local/bin/
/var/www/

A single writable script used by a privileged process may provide a direct path to escalation.

5. Exposed Credentials

Developers often leave passwords inside scripts and configuration files.

Useful searches include:

grep -Ri password /home 2>/dev/null
grep -Ri secret /var/www 2>/dev/null

Common discoveries:

  • Database passwords

  • SSH credentials

  • API keys

  • Backup credentials

These credentials often lead to lateral movement or privilege escalation.

6. Forgotten Backup Files

Many administrators forget to remove old backups.

Examples:

config.php.bak
database.old
backup.zip
credentials.txt

Search for them:

find / -name "*.bak" 2>/dev/null
find / -name "*.old" 2>/dev/null
find / -name "*.zip" 2>/dev/null

Backup files frequently contain information that no longer exists in production systems.

7. SSH Keys

Private SSH keys can provide access to other users or systems.

Search for:

find / -name "id_rsa*" 2>/dev/null

Interesting locations:

/home/
/root/
/opt/
/var/backups/

A single exposed key can dramatically expand an attacker’s access.

8. Environment Variables

Environment variables often contain sensitive information.

Check:

env

Examples include:

AWS_SECRET_ACCESS_KEY
DATABASE_PASSWORD
API_TOKEN

Developers frequently use environment variables for convenience and accidentally expose secrets.

9. Docker Group Membership

Docker access is often overlooked.

Check group memberships:

id

If a user belongs to the Docker group, they may effectively possess root-equivalent privileges.

Many organizations treat Docker access as harmless when it should be considered highly privileged.

10. Writable Directories in PATH

Command hijacking remains an effective technique.

Inspect the PATH variable:

echo $PATH

Then verify permissions:

ls -ld /path/to/directory

If a writable directory appears before a legitimate binary location, attackers may be able to influence command execution.

11. Running Services

Many services listen only on localhost.

Enumerate them:

ss -tulpn

Interesting examples:

  • Databases

  • Admin panels

  • Internal APIs

  • Monitoring interfaces

These services often expose functionality unavailable externally.

12. Kernel Version Analysis

Attackers always check the kernel version:

uname -a

Older systems may contain known local privilege escalation vulnerabilities.

Even if exploitation is not possible, outdated kernels often indicate poor patch management across the environment.

13. Sensitive Configuration Files

Configuration files reveal how systems operate.

Search for:

find / -name "*.conf" 2>/dev/null

Focus on:

/etc/
/opt/
/var/www/

Configuration files frequently expose:

  • Credentials

  • Internal network information

  • Service accounts

  • Third-party integrations

14. User Home Directories

Home directories contain valuable intelligence.

Review:

ls -la /home

Interesting files include:

.bash_history
.notes
.todo
scripts/
projects/

Attackers regularly discover passwords, internal documentation, and development artifacts inside user directories.

15. NFS and Shared Resources

Network shares are often misconfigured.

Check:

cat /etc/exports
showmount -e localhost

Improperly configured shares can allow attackers to modify files that later execute with elevated privileges.

These misconfigurations continue to appear in real-world environments despite being well known.

•••

Why Skilled Attackers Do This First

Tools like LinPEAS are incredibly valuable.

However, automation should enhance your understanding of a system — not replace it.

Manual enumeration provides:

  • Faster identification of obvious weaknesses

  • Better situational awareness

  • Reduced noise

  • Stronger understanding of attack paths

  • More reliable privilege escalation opportunities

Many successful privilege escalations are discovered through observation rather than automation.

The attacker who understands the system usually outperforms the attacker who simply runs more tools.

•••

Final Thoughts

Privilege escalation is rarely about finding a magical exploit.

More often, it’s about identifying small administrative mistakes that have accumulated over time.

A forgotten backup file.

An exposed credential.

A writable script.

A dangerous sudo rule.

These simple oversights are responsible for countless real-world compromises.

Before running LinPEAS on your next engagement, spend five minutes performing these manual checks.

You may discover that the path to root was hiding in plain sight all along.

For educational and authorized security testing purposes only. Always obtain proper permission before assessing any system.

Comments

No comments yet.