Most beginners land a shell on a Linux system and immediately run LinPEAS.
There’s nothing wrong with that. LinPEAS is one of the best privilege escalation enumeration tools available today.
But experienced penetration testers and red teamers rarely start there.
Why?
Because automated tools often generate hundreds of findings, most of which are irrelevant. Skilled attackers first perform manual reconnaissance to understand the system, identify obvious weaknesses, and build an attack path before relying on automation.
In many cases, these quick checks reveal a privilege escalation vector within minutes.
Let’s look at 15 Linux misconfigurations attackers typically investigate before running LinPEAS.
1. Dangerous Sudo Permissions
The first command many attackers run is:
sudo -lThis shows which commands can be executed with elevated privileges.
A common mistake administrators make is granting access to seemingly harmless binaries such as:
sudo vim
sudo less
sudo find
sudo awk
sudo tarMany of these can be abused to execute arbitrary commands and obtain root access.
One misconfigured sudo rule can completely compromise a system.
2. Custom SUID Binaries
SUID files execute with the privileges of their owner.
To locate them:
find / -perm -4000 -type f 2>/dev/nullWhile standard Linux binaries are expected, custom applications often introduce serious security flaws.
Questions attackers ask:
Is this binary custom-built?
Can it call external programs?
Does it trust user-controlled input?
Custom SUID binaries are frequently responsible for privilege escalation findings.
3. Writable Cron Jobs
Scheduled tasks run automatically and often execute as root.
Check:
cat /etc/crontab
ls -la /etc/cron.*Attackers look for:
Writable scripts
Weak permissions
Scripts executed as root
If a root-owned cron task executes a writable script every minute, gaining root becomes trivial.
4. Weak File Permissions
Improper permissions remain one of the most common Linux security mistakes.
Search for writable files:
find / -writable -type f 2>/dev/nullParticularly interesting locations include:
/etc/
/opt/
/usr/local/bin/
/var/www/A single writable script used by a privileged process may provide a direct path to escalation.
5. Exposed Credentials
Developers often leave passwords inside scripts and configuration files.
Useful searches include:
grep -Ri password /home 2>/dev/null
grep -Ri secret /var/www 2>/dev/nullCommon discoveries:
Database passwords
SSH credentials
API keys
Backup credentials
These credentials often lead to lateral movement or privilege escalation.
6. Forgotten Backup Files
Many administrators forget to remove old backups.
Examples:
config.php.bak
database.old
backup.zip
credentials.txtSearch for them:
find / -name "*.bak" 2>/dev/null
find / -name "*.old" 2>/dev/null
find / -name "*.zip" 2>/dev/nullBackup files frequently contain information that no longer exists in production systems.
7. SSH Keys
Private SSH keys can provide access to other users or systems.
Search for:
find / -name "id_rsa*" 2>/dev/nullInteresting locations:
/home/
/root/
/opt/
/var/backups/A single exposed key can dramatically expand an attacker’s access.
8. Environment Variables
Environment variables often contain sensitive information.
Check:
envExamples include:
AWS_SECRET_ACCESS_KEY
DATABASE_PASSWORD
API_TOKENDevelopers frequently use environment variables for convenience and accidentally expose secrets.
9. Docker Group Membership
Docker access is often overlooked.
Check group memberships:
idIf a user belongs to the Docker group, they may effectively possess root-equivalent privileges.
Many organizations treat Docker access as harmless when it should be considered highly privileged.
10. Writable Directories in PATH
Command hijacking remains an effective technique.
Inspect the PATH variable:
echo $PATHThen verify permissions:
ls -ld /path/to/directoryIf a writable directory appears before a legitimate binary location, attackers may be able to influence command execution.
11. Running Services
Many services listen only on localhost.
Enumerate them:
ss -tulpnInteresting examples:
Databases
Admin panels
Internal APIs
Monitoring interfaces
These services often expose functionality unavailable externally.
12. Kernel Version Analysis
Attackers always check the kernel version:
uname -aOlder systems may contain known local privilege escalation vulnerabilities.
Even if exploitation is not possible, outdated kernels often indicate poor patch management across the environment.
13. Sensitive Configuration Files
Configuration files reveal how systems operate.
Search for:
find / -name "*.conf" 2>/dev/nullFocus on:
/etc/
/opt/
/var/www/Configuration files frequently expose:
Credentials
Internal network information
Service accounts
Third-party integrations
14. User Home Directories
Home directories contain valuable intelligence.
Review:
ls -la /homeInteresting files include:
.bash_history
.notes
.todo
scripts/
projects/Attackers regularly discover passwords, internal documentation, and development artifacts inside user directories.
15. NFS and Shared Resources
Network shares are often misconfigured.
Check:
cat /etc/exports
showmount -e localhostImproperly configured shares can allow attackers to modify files that later execute with elevated privileges.
These misconfigurations continue to appear in real-world environments despite being well known.
Why Skilled Attackers Do This First
Tools like LinPEAS are incredibly valuable.
However, automation should enhance your understanding of a system — not replace it.
Manual enumeration provides:
Faster identification of obvious weaknesses
Better situational awareness
Reduced noise
Stronger understanding of attack paths
More reliable privilege escalation opportunities
Many successful privilege escalations are discovered through observation rather than automation.
The attacker who understands the system usually outperforms the attacker who simply runs more tools.
Final Thoughts
Privilege escalation is rarely about finding a magical exploit.
More often, it’s about identifying small administrative mistakes that have accumulated over time.
A forgotten backup file.
An exposed credential.
A writable script.
A dangerous sudo rule.
These simple oversights are responsible for countless real-world compromises.
Before running LinPEAS on your next engagement, spend five minutes performing these manual checks.
You may discover that the path to root was hiding in plain sight all along.
For educational and authorized security testing purposes only. Always obtain proper permission before assessing any system.

No comments yet.