Linux is the dominant server and infrastructure platform, and its local attack surface flows from the Unix privilege model: a single root superuser, file-permission and ownership rules, and a handful of mechanisms that deliberately grant elevated execution. Once code runs as an unprivileged user, the work is to find one of those mechanisms misconfigured and ride it to root, then harvest the secrets the host holds.
The local surface#
- Privilege escalation: SUID/SGID binaries (and the GTFOBins that abuse them), permissive
sudorules, overly broad file capabilities, writablecronand systemd units,PATHand library (LD_PRELOAD/LD_LIBRARY_PATH) hijacking, and writable sensitive files (/etc/passwd,/etc/shadow, sudoers). - Credential and secret access: history files, world-readable configs and keys, SSH keys and agents, service credentials, and in-memory secrets.
- Container and namespace boundaries: escaping a container to its host is its own deep area under Containers; the namespace, cgroup, and capability primitives it abuses are the same ones that gate privilege here.
- Kernel: local kernel exploitation (the classic overwrite-and-escalate primitives) for the final step to
root.
Seams#
Container escape is covered under Containers, and hypervisor guest-to-host escape under Virtualization; both are cross-referenced. This area is the Linux host itself.