โ† All OSCP Flashcard Decks

Linux Flashcards

7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Linux flashcards as text
  1. Which Linux command displays listening network sockets and the processes that own them, useful for identifying attack surfaces?

    Answer: netstat -tulpn

    netstat -tulpn (or ss -tulpn on modern systems) shows TCP/UDP listening ports along with the PID and program name for each socket.

  2. A root process executes a bash script that uses 'eval' on user-controlled input. What vulnerability does this create?

    Answer: Arbitrary command execution via command injection

    eval executes its argument as a shell command; if that argument includes attacker-controlled data, the attacker can inject arbitrary commands that run at the script's privilege level.

  3. What is the significance of a binary with both SUID bit and 'cap_setuid' capability set on Linux?

    Answer: It can change its effective UID to any user including root, providing two independent escalation paths

    SUID runs the binary as its owner's UID, while cap_setuid allows explicit UID changes; either alone provides privilege escalation potential if the binary is exploitable.

  4. An attacker has write access to a user's ~/.bashrc. What persistence technique can be used?

    Answer: Add a reverse shell one-liner that executes every time the user opens a bash session

    ~/.bashrc is sourced on every interactive bash session, so inserting a reverse shell payload establishes persistent callback access whenever the target user logs in.

  5. Which command would reveal kernel version information useful for finding local privilege escalation CVEs?

    Answer: uname -a

    uname -a prints the kernel name, hostname, kernel release, version, machine hardware, and OS, providing the key version details needed to search for kernel exploits.

  6. During post-exploitation on Linux, which directory often contains bash history files for multiple users that may reveal credentials or internal commands?

    Answer: /home/*/.bash_history and /root/.bash_history

    Bash history files in each user's home directory often capture previously entered commands including passwords typed as arguments and internal hostnames.

  7. What technique allows an attacker to maintain a persistent rootkit-level backdoor without modifying disk-resident files on Linux?

    Answer: Loading a malicious kernel module (LKM rootkit)

    Loadable kernel modules (LKMs) run in kernel space and can hide processes, files, and network connections; they can be loaded without leaving obvious file-system artifacts.