Linux Flashcards
7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Linux flashcards as text
Which command finds SUID binaries on a Linux system that could be leveraged for privilege escalation?
Answer: find / -perm -u=s -type f 2>/dev/null
The find command with -perm -u=s locates all files with the SUID bit set, which run as the file owner regardless of who executes them.
What does the /etc/passwd file store in a modern Linux system?
Answer: User account information including username, UID, GID, home directory, and shell
In modern Linux, /etc/passwd stores user account metadata but passwords are stored as 'x' with actual hashes in /etc/shadow.
An attacker has a low-privilege shell. Which file, if world-readable, would allow them to crack user password hashes offline?
Answer: /etc/shadow
/etc/shadow contains hashed passwords and is normally readable only by root, making it a high-value target for privilege escalation.
Which Linux capability, if assigned to a binary, allows it to bypass file permission checks and is dangerous from a security perspective?
Answer: cap_dac_override
cap_dac_override allows a process to bypass discretionary access control (DAC) file read/write/execute permission checks, enabling access to any file.
How do you list all running cron jobs for all users on a Linux system as root?
Answer: ls -la /var/spool/cron/crontabs/ && cat /etc/cron*
Cron jobs per user live in /var/spool/cron/crontabs/ and system-wide jobs are in /etc/cron*, so both locations must be checked.
What is the purpose of the 'sticky bit' on a directory like /tmp?
Answer: Only the file owner or root can delete files within the directory
The sticky bit on a directory means that only the file's owner, the directory's owner, or root can delete or rename files within it.
Which command would an attacker use to enumerate writable directories in the PATH that could enable a path hijacking attack?
Answer: echo $PATH | tr ':' '\n' | xargs ls -ld
Splitting $PATH and checking directory permissions reveals writable entries where a malicious binary can be placed to hijack script execution.