Linux Privilege Escalation Cheatsheet

A practical Linux privilege escalation reference covering high-impact enumeration checks, common misconfigurations, credential hunting, container escapes, and last-resort kernel exploits.

May 25, 2026 · 11 min

HTB: Bashed

Linux machine demonstrating exposed PHP web shell access, sudo-based lateral movement, and cron-driven privilege escalation.

March 3, 2026 · 4 min

HTB: Builder

Linux machine demonstrating Jenkins CLI arbitrary file read, Jenkins user hash extraction, credential cracking, and SSH key abuse for root access.

February 21, 2026 · 5 min

HTB: BoardLight

Linux machine demonstrating vhost discovery, Dolibarr authenticated RCE, credential disclosure, and Enlightenment SUID privilege escalation.

February 18, 2026 · 4 min

HTB: Busqueda

Linux machine demonstrating Python eval command injection, credential reuse, Docker configuration disclosure, and sudo script abuse.

February 15, 2026 · 6 min

HTB: Analytics

Linux machine demonstrating Metabase pre-auth RCE, Docker environment credential disclosure, and OverlayFS kernel exploitation.

December 19, 2025 · 6 min

HTB: Broker

Linux machine demonstrating Apache ActiveMQ CVE-2023-46604 exploitation and sudo nginx abuse for root access.

December 18, 2025 · 4 min

VulnLab: Data

Linux machine demonstrating Grafana arbitrary file read, Grafana credential cracking, SSH access, and Docker privileged container abuse.

May 20, 2025 · 6 min

VulnLab: Sync

Linux machine demonstrating anonymous rsync access, salted MD5 cracking, FTP-based SSH key placement, password reuse, and cronjob abuse.

May 12, 2025 · 5 min