MagicLinPwn is a powerful and automated Linux privilege escalation script designed to help security professionals and CTF enthusiasts identify potential misconfigurations, vulnerabilities, and weaknesses that can lead to privilege escalation.
Once the script finishes, a comprehensive summary is displayed, providing an overview of the findings and highlighting potential risks.
./MagicLinPwn.sh- OS Information Gathering:
- Detects and displays the operating system, kernel version, architecture, and hostname.
- User and Group Information:
- Displays the current user, UID, GID, primary group, and group memberships with line wrapping.
- Highlights critical groups that may allow privilege escalation (e.g.,
wheel,sudo,docker,lxd,shadow, etc.). - Provides explanations for highlighted groups, including how they can be abused for privilege escalation.
- Where applicable, includes direct links to HackTricks for detailed exploitation techniques.
- Root Privilege Check:
- Detects if the script is running with root privileges (via
UIDorEUID).- If running as root, suggests using additional tools for credential dumping:
- Detects if the script is running with root privileges (via
- Active Directory Integration Check:
- Detects if the Linux machine is joined to an Active Directory domain.
- Displays relevant domain information if detected.
- If running as root and AD integration is found, suggests using Linikatz for dumping secrets.
- Docker Container Detection:
- Detects if the script is running inside a Docker container by checking:
/proc/1/cgroup- The existence of the
/.dockerenvfile - Environment variables (e.g.,
DOCKER_CONTAINER)
- Suggests running
deepcefor container breakout checks if a container is detected.
- Detects if the script is running inside a Docker container by checking:
- Sudo Privileges Check:
- Checks if
sudois installed, displays the sudo version and if the user can executesudocommands without a password. - Highlights critical configurations such as
ALL,NOPASSWD, andSETENV.
- Checks if
- Network Interfaces and Listening Ports:
- Displays all active network interfaces with assigned IP addresses.
- Lists open listening ports along with their associated processes.
- Uses
ss(ornetstatas a fallback) to detect services that may be exploited.
- Environment Variable Check:
- Scans environment variables for potential sensitive information such as
PASSWORD,TOKEN,SECRET,DBetc. - Highlights detected variables for further investigation.
- Provides a clear message if no sensitive information is found.
- Scans environment variables for potential sensitive information such as
- SUID Binary Check:
- Finds and lists all binaries with the SUID bit set.
- Highlights potentially dangerous binaries (e.g., interpreters like
bashorpython). - Includes a timeout mechanism to skip the check if it takes too long.
- SGID Binary Check:
- Finds and lists all binaries with the SGID bit set.
- Highlights potentially dangerous binaries (e.g.,
mail,write,wall). - Includes a timeout mechanism to skip the check if it takes too long.
- Cron Job Analysis:
- System-Wide Cron Jobs: Lists cron jobs from
/etc/cron.dand their contents. - User-Specific Cron Jobs: Checks the current user’s crontab for entries.
- /etc/crontab Analysis: Displays the contents of
/etc/crontaband checks if it is writable. - Writable Cron Files: Identifies writable cron files across
/etc/cron*directories and highlights potential security risks.
- System-Wide Cron Jobs: Lists cron jobs from
- Capabilities Check:
- Finds and lists all files with Linux capabilities.
- Highlights potentially dangerous capabilities (e.g.,
cap_setuid,cap_net_raw,cap_dac_override). - Includes a timeout mechanism to skip the check if it takes too long.
- Writable Critical Files and Directories Check:
- Checks critical system files (e.g.,
/etc/passwd,/etc/shadow,/etc/sudoers) for write permissions. - Checks critical directories (e.g.,
/etc/sudoers.d,/etc/cron.d) for write permissions and scans for writable files within them. - Highlights writable files and directories as potential security risks.
- Provides clear summary messages when no writable files or directories are detected.
- Checks critical system files (e.g.,
- Potentially Interesting Files Search:
- Searches for files with potentially sensitive extensions (e.g.,
.xls,.doc,.pdf,.conf,.key). - Excludes common irrelevant directories like
lib,fonts,share, andcore. - Displays results clearly for each file extension.
- Handles cases where no files are found with a clean message.
- Searches for files with potentially sensitive extensions (e.g.,
- Email Enumeration:
- Searches for readable mailboxes in
/var/mail/and prints their full content. - Displays email metadata (sender, recipient, date) and message body.
- Highlights any discovered emails that may contain sensitive information.
- If no readable mailboxes are found, it provides a clear message.
- Searches for readable mailboxes in
- Sensitive Content Search:
- Searches
.cnf,.conf, and.configfiles for sensitive keywords likepasswordorpass. - Excludes unnecessary directories (e.g.,
doc,lib) to reduce noise. - Highlights matches for better readability.
- Only displays filenames and content when matches are found.
- Searches
- SSH Private Key Search:
- Searches common directories like
/root,/home, and/etc/sshfor files containing ssh private keys. - Highlights private keys in the results for better visibility.
- Filters out irrelevant matches, ensuring only valid keys are displayed.
- Provides a clear message if no private keys are found.
- Searches common directories like
- Shell History File Dump:
- Searches for commonly used shell history files (e.g.,
.bash_history,.zsh_history,.ash_history, etc.) in/homeand/rootdirectories. - Dumps the contents of any accessible history files for analysis.
- Highlights the file paths and their contents, providing insights into commands executed by users.
- Clearly indicates if no history files are found or accessible.
- Searches for commonly used shell history files (e.g.,
- Credential Discovery in Log Files:
- Searches common log files (
auth.log,access.log,syslog, etc.) for potential credentials. - Identifies sensitive information such as usernames, passwords, API tokens, and secrets.
- Highlights findings and provides a summary indicating whether credentials were discovered.
- Searches common log files (
- Systemd-Related Privilege Escalation Checks:
- Identifies writable
.servicefiles in common systemd directories (e.g.,/etc/systemd/system,/lib/systemd/system). - Detects writable binaries executed by services via the
ExecStart=directive in.servicefiles. - Searches for writable folders in systemd
UnitPath, which could allow malicious file placements. - Checks for writable
.timerfiles, which could be exploited to schedule malicious tasks. - Includes timeout mechanisms to ensure efficient scans and prevent prolonged execution.
- Highlights writable files, binaries, directories, and timers as potential security risks.
- Identifies writable
- Writable Files and Directories Check:
- Searches for files and directories writable by the current user.
- Excludes system-critical paths like
/proc,/sys,/tmp, and/runto avoid unnecessary output. - Displays both writable files and writable directories separately.
- Includes a timeout mechanism to prevent the scan from running indefinitely.
- Clearly indicates if no writable files or directories are found.
- Brief Summary at the End: Provides a summary of all findings from the script. Highlights areas that require attention (e.g., writable files, dangerous capabilities, sensitive environment variables). Displays reassuring messages when no issues are found in specific checks. Ensures users have a quick overview of potential privilege escalation vectors without scrolling through the detailed output.
