Linux Flashcards
7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Linux flashcards as text
A script runs as root and calls 'python' without an absolute path. An attacker has write access to /tmp which is in root's PATH before /usr/bin. What attack is possible?
Answer: PATH hijacking by placing a malicious 'python' binary in /tmp
If a directory the attacker controls appears before the real binary location in PATH, placing a malicious file with the same name causes the script to execute the attacker's code.
Which /proc entry reveals the full command line of a running process, useful for finding credentials passed as arguments?
Answer: /proc//cmdline
/proc//cmdline contains the null-delimited command line that was used to start the process, including any arguments like passwords.
What does the command 'sudo -l' reveal during a Linux privilege escalation assessment?
Answer: Commands the current user can run with elevated privileges
sudo -l lists the specific commands the current user is allowed to run as root or other users without a password, often revealing escalation paths.
An OSCP candidate finds a writable /etc/passwd file. Which entry would add a passwordless root-equivalent account?
Answer: hacker::0:0::/root:/bin/bash
An empty password field (::) in /etc/passwd means no password is required, and UID/GID of 0 grants root-level privileges.
What Linux kernel feature does a container escape typically exploit when the container runs as root with excessive capabilities?
Answer: Namespaces and cgroups misconfiguration
Linux namespaces and cgroups provide container isolation; misconfigurations (e.g., privileged containers or mounted host /proc) allow escapes to the host.
Which tool is most commonly used to enumerate Linux privilege escalation vectors automatically during an OSCP exam?
Answer: LinPEAS
LinPEAS (Linux Privilege Escalation Awesome Script) automates checks for SUID binaries, writable paths, weak permissions, and hundreds of other escalation vectors.
An attacker reads /etc/crontab and sees a root cron job running /opt/backup.sh which is world-writable. What is the simplest exploit?
Answer: Append a reverse shell command to /opt/backup.sh
Since root executes /opt/backup.sh and the script is world-writable, appending a reverse shell payload will execute it as root when the cron job fires.