Byte JMP

#privilege-escalation

8 posts

Linux Privilege Escalation: CVE-2025-32463 (sudo chroot)
◆

Linux Privilege Escalation: CVE-2025-32463 (sudo chroot)

How a misplaced chroot call in sudo 1.9.14 through 1.9.17 lets any local user — with no sudoers rule and no password — trick glibc into loading an attacker-controlled shared library as root. Full root cause analysis, lab reproduction, exploitation, and detection.

—20 min read
Linux Privilege Escalation: Abusing make via sudo
◆

Linux Privilege Escalation: Abusing make via sudo

How GNU Make's --eval flag, $(shell), and $(file) functions turn a permissive sudo rule into full root access — shell execution, arbitrary file read, and arbitrary file write — with no vulnerability involved.

—15 min read
Windows Privilege Escalation: AutoLogon Credentials in the Registry
◆

Windows Privilege Escalation: AutoLogon Credentials in the Registry

How Windows AutoLogon stores plaintext credentials in the registry under HKLM\SOFTWARE, why every authenticated user can read them, and how to turn a single reg query into privilege escalation or domain compromise during a penetration test.

—15 min read
Windows Privilege Escalation: Unquoted Service Paths
◆

Windows Privilege Escalation: Unquoted Service Paths

How a missing pair of quotation marks in a service's ImagePath lets a low privilege user place a binary that Windows executes as SYSTEM. Theory behind CreateProcess path resolution, lab setup, enumeration, and exploitation.

—20 min read
Windows Privilege Escalation: Credentials in PowerShell History (ConsoleHost_history.txt)
◆

Windows Privilege Escalation: Credentials in PowerShell History (ConsoleHost_history.txt)

How the PowerShell command history file silently records credentials in cleartext, where to find it, what leaks into it, and how to turn a history file into a privilege escalation during a pentest.

—6 min read
Windows Privilege Escalation: Service Binary Hijacking
◆

Windows Privilege Escalation: Service Binary Hijacking

From a low privileged domain user to NT AUTHORITY\SYSTEM by overwriting a service executable that weak file permissions left writable. Lab setup, enumeration, and exploitation.

—21 min read
Windows Privilege Escalation: SeBackupPrivilege
◆

Windows Privilege Escalation: SeBackupPrivilege

From Backup Operators to Domain Admin. Exploiting SeBackupPrivilege to bypass NTFS ACLs, extract ntds.dit or SAM hives, dump hashes offline, and Pass-the-Hash to SYSTEM.

—11 min read
The Potato Family — Windows Privilege Escalation (2016–2024)
◆

The Potato Family — Windows Privilege Escalation (2016–2024)

Comprehensive guide to the Potato family of Windows privilege escalation exploits. From Hot Potato to Silver Potato, covering SeImpersonatePrivilege abuse, DCOM/RPC coercion, and NTLM relay techniques.

—16 min read