Linux Flashcards
7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Linux flashcards as text
Which Linux command displays listening network sockets and the processes that own them, useful for identifying attack surfaces?
Answer: netstat -tulpn
netstat -tulpn (or ss -tulpn on modern systems) shows TCP/UDP listening ports along with the PID and program name for each socket.
A root process executes a bash script that uses 'eval' on user-controlled input. What vulnerability does this create?
Answer: Arbitrary command execution via command injection
eval executes its argument as a shell command; if that argument includes attacker-controlled data, the attacker can inject arbitrary commands that run at the script's privilege level.
What is the significance of a binary with both SUID bit and 'cap_setuid' capability set on Linux?
Answer: It can change its effective UID to any user including root, providing two independent escalation paths
SUID runs the binary as its owner's UID, while cap_setuid allows explicit UID changes; either alone provides privilege escalation potential if the binary is exploitable.
An attacker has write access to a user's ~/.bashrc. What persistence technique can be used?
Answer: Add a reverse shell one-liner that executes every time the user opens a bash session
~/.bashrc is sourced on every interactive bash session, so inserting a reverse shell payload establishes persistent callback access whenever the target user logs in.
Which command would reveal kernel version information useful for finding local privilege escalation CVEs?
Answer: uname -a
uname -a prints the kernel name, hostname, kernel release, version, machine hardware, and OS, providing the key version details needed to search for kernel exploits.
During post-exploitation on Linux, which directory often contains bash history files for multiple users that may reveal credentials or internal commands?
Answer: /home/*/.bash_history and /root/.bash_history
Bash history files in each user's home directory often capture previously entered commands including passwords typed as arguments and internal hostnames.
What technique allows an attacker to maintain a persistent rootkit-level backdoor without modifying disk-resident files on Linux?
Answer: Loading a malicious kernel module (LKM rootkit)
Loadable kernel modules (LKMs) run in kernel space and can hide processes, files, and network connections; they can be loaded without leaving obvious file-system artifacts.