🩸
Pentesting Notes
Ctrlk
  • ㊙️r3dcl1ff
    • 🔬Enumeration
    • 🧨Exploitation (deprecated node)
    • 🈲Privesc
      • sudo + GTFObins
      • Docker privilege escalation
      • Kernel Exploits
        • Compiling - General guidelines
        • Linux Kernel < 4.13.9 (Ubuntu 16.04 / Fedora 27)
        • LXD - Alpine
        • Serv-U FTP Server < 15.1.7
        • [CVE-2016-5195] dirtycow 2
        • Linux Kernel 2.6 < 2.6.19 (White Box 4 / CentOS 4.4/4.5...)
        • Linux Kernel 2.6.39 "Mempodipper"
        • Samba 2.2.x - Remote buffer overflow
        • Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' /proc/self/mem Race Condition (Write Access Method)
        • Full Nelson
        • Exim 4.84-3 - Local Privilege Escalation
        • Clown NewUser|Linux 3.0<3.3.5|
        • fasync_helper|Linux Kernel <2.6.28
        • NFS no_root_squash/no_all_squash
      • 'Nix manual enumeration
      • File transfers
      • Windows enumeration
      • Wordpress privesc
      • OpenSSL privesc
      • Privesc scripts | resources
      • vi
    • 🖥️CLI-Fu
    • 🎯OSINT
    • 🛠️Tools
    • 🟦Active Directory
    • 🪓Sysadmin
    • 🗒️Pentesting Checklist(s)
    • 🕷️WebApp Pentest
    • 🌩️Cloud
    • 🧠Threat Intel
    • 📟IoT / IIoT
    • 🏭ICS/OT - SCADA
    • 🩻Private Templates
    • 🐞BBP
    • 📱Mobile
  • Daily Syncs
    • Design Standups
  • Weekly Syncs
    • Company Weeklies
  • Other Regulars
    • Company Weeklies
Powered by GitBook
On this page
  1. ㊙️r3dcl1ff
  2. 🈲Privesc

Kernel Exploits

Bunch of kernel exploits, mostly 'Nix targets

Compiling - General guidelinesLinux Kernel < 4.13.9 (Ubuntu 16.04 / Fedora 27)LXD - AlpineServ-U FTP Server < 15.1.7[CVE-2016-5195] dirtycow 2Linux Kernel 2.6 < 2.6.19 (White Box 4 / CentOS 4.4/4.5...)Linux Kernel 2.6.39 "Mempodipper"Samba 2.2.x - Remote buffer overflowLinux Kernel 2.6.22 < 3.9 - 'Dirty COW' /proc/self/mem Race Condition (Write Access Method)Full NelsonExim 4.84-3 - Local Privilege EscalationClown NewUser|Linux 3.0<3.3.5|fasync_helper|Linux Kernel <2.6.28NFS no_root_squash/no_all_squash
PreviousDocker privilege escalationNextCompiling - General guidelines

Last updated 3 years ago