
71

GitHub - Ignitetechnologies/Privilege-Escalation: This cheasheet is aimed at the...
source link: https://github.com/Ignitetechnologies/Privilege-Escalation
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

README.md
Privilege Escalation Cheatsheet (Vulnhub)
This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples. It is not a cheatsheet for Enumeration using Linux Commands. Privilege escalation is all about proper enumeration. There are multiple ways to perform the same tasks. We have performed and compiled this list on our experience. Please share this with your connections and direct queries and feedback to Pavandeep Singh.
Table of Contents
- Abusing Sudo Rights
- SUID Bit
- Kernel Exploit
- Path Variable
- Enumeration
- MySQL
- Crontab
- Wildcard Injection
- Capabilities
- Apache2.conf writable
- Writable etc/passwd file
- Writable files or script as root
- Buffer Overflow
- Docker
Abusing Sudo Rights
- Holynix: v1
- DE-ICE:S1.120
- 21 LTR: Scene1
- Kioptrix : Level 1.2
- Skytower
- Fristileaks
- Breach 2.1
- Zico 2
- RickdiculouslyEasy
- Dina
- Depth
- The Ether: Evil Science
- Basic penetration
- DerpNStink
- W1R3S.inc
- Bob:1.0.1
- The blackmarket
- Violator
- Basic Pentesting : 2
- Temple of Doom
- Wakanda : 1
- Matrix : 1
- KFIOFan : 1
- W34n3ss 1
- Replay : 1
- Unknowndevice64 : 1
- Web Developer : 1
- SP ike
- DC-2
- DC6
- Born2Root2
- DC-4
- Development
- Sputnik 1
- PumpkinRaising
- Matrix-3
- symfonos : 2
- Digitalworld.local : JOY
- PumpkinFestival
- Sunset
- Symfonos:3
- Ted:1
- CLAMP 1.0.1
- Torment
- WestWild: 1.1
- Broken: Gallery
SUID Bit
- Tr0ll 1
- Mr. Robot
- Covfefe
- Toppo:1
- /dev/random : K2
- FourAndSix : 2
- DC-1
- HackinOS : 1
- digitalworld.local - BRAVERY
- Happycorp : 1
- MinU: v2
- hackme1
- dpwwn:2
- Kevgir
Kernel Exploit
- LAMPSecurity: CTF 5
- pWnOS -1.0
- Hackademic-RTB1
- Kioptrix : Level 1.1
- Kioprtix: 5
- SecOS: 1
- Droopy
- Stapler
- Sidney
- Simple
- VulnOS: 2.0
- Lord of the Root
- Acid Reloaded
- Pluck
- Fartknocker
- Nightmare
- Super Mario
- BTRSys:dv 2.1
- Trollcave
- Golden Eye:1
- Lampiao : 1
- WinterMute : 1
- ch4inrulz : 1.0.1
- Typhoon : 1.02
- DC-3
- DC-5
- GrimTheRipper:1
Path Variable
Enumeration
- The Library:1
- The Library:2
- LAMPSecurity: CTF 4
- LAMPSecurity: CTF 7
- LAMPSecurity: CTF 8
- Xerxes: 1
- pWnOS -2.0
- DE-ICE:S1.130
- DE-ICE:S1.140
- Hackademic-RTB2
- SickOS 1.1
- Tommyboy
- Minotaur
- VulnOS: 1
- Spyder Sec
- Acid
- Necromancer
- Freshly
- Fortress
- Billu : B0x
- Defence Space
- Moria 1.1
- Analougepond
- Lazysysadmin
- Bulldog
- BTRSys 1
- G0rmint
- Blacklight : 1
- RootThis : 1
- Cyberry:1
MySQL
Crontab
Wildcard Injection
Capabilities
Apache2.conf Writable
Writable etc/passwd file
Writable files or script as root
- Skydog
- Breach 1.0
- Bot Challenge: Dexter
- Fowsniff : 1
- Mercy
- Casino Royale
- SP eric
- PumpkinGarden
- dpwwn: 1
- Tr0ll: 3
- Nezuko:1
Buffer Overflow
Docker
Recommend
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK