Skip to content

Linux Exploits

Gaining initial access to a Linux host by exploiting an exposed service or application.

Why It Matters

Linux hosts run much of the internet-facing infrastructure a tester meets: web servers, SSH, databases, and application services. The initial foothold usually comes from one of those exposed services rather than the OS itself.

Approach

  1. Enumerate first. Identify every exposed service and its exact version with Nmap -sV. The version is what maps to a known vulnerability.
  2. Check for known vulnerabilities. Search the service and version against Exploit-DB (searchsploit <service>), vendor advisories, and CVE databases.
  3. Target the application, not just the OS. Web apps, CMS platforms, and management interfaces on the host are common entry points; see Web Authentication Bypass, SQL Injection, and Network Services Attacks.
  4. Weak credentials. Exposed SSH, FTP, and database services are worth a controlled Hydra attempt with a targeted wordlist.
  5. Validate before firing. Confirm the target is actually vulnerable before running an exploit, and prefer the least disruptive option.

Public exploits can be destructive or fake

Read any public exploit before running it. Some crash the target, and some proof-of-concept code is itself malicious. Test in a lab where possible.

After a Foothold

Move to Linux Post-Exploitation Discovery to enumerate the host, then Linux Privilege Escalation.

Resources