Loopus

Pro Content

This lesson requires Loopus Pro access. Upgrade to unlock all courses, labs, and challenges.

Privilege EscalationLinux Privilege Escalation

Sudo Misconfigurations

30 min
lab
+70 XP

Learning Objectives

  • Master Sudo Misconfigurations on Linux systems
  • Identify Linux privilege escalation vectors
  • Exploit Linux misconfigurations

Sudo Misconfigurations

Linux privilege escalation exploits misconfigurations in permissions, services, and kernel. This lesson covers sudo misconfigurations.

Understanding the Topic

SUID/SGID bits forms the foundation of this topic. In real-world scenarios, attackers leverage this knowledge to identify weaknesses that defenders often overlook. Understanding how sudo misconfigurations works at a fundamental level is essential before attempting any practical exercises.

Building on that foundation, sudo configuration becomes critically important. Security professionals encounter this daily, and recognizing the patterns helps you work more efficiently during assessments.

Cron jobs represents another key consideration. Many beginners overlook this aspect, but experienced practitioners know it can make the difference between success and failure in real engagements.

Finally, kernel exploits provides the practical context. Knowing when and how to apply these techniques separates theoretical knowledge from actionable skills.

Tools and Environment

For sudo misconfigurations, professionals rely on LinPEAS, linEnum, GTFOBins reference, pspy. The sandbox terminal on the right provides access to these tools. Familiarize yourself with their basic usage, then answer the questions below to complete this lesson.

Answer the Questions0 / 4 completed

📚 KnowledgeQuestion 1

How can sudo rules be abused?

Format: ****(4 chars)
Exact match required
⌨️ Hands-OnQuestion 2

What vim command executes a shell?

Format: ***********(11 chars)
Exact match required
📚 KnowledgeQuestion 3

What is sudo env_keep abuse?

Format: **********(10 chars)
Exact match required
⌨️ Hands-OnQuestion 4

What environment variable enables library injection?

Format: **********(10 chars)
Exact match required
Answer all questions correctly to unlock the next lesson

Interactive Sandbox

Loading sandbox...

Submit Flag

Found the flag? Submit it below to complete this lesson.
Format: LOOPUS{...}

Previous
Answer all questions to continue