╔═══════════════════╗
═══════════════════════════════╣ Basic information ╠═══════════════════════════════
╚═══════════════════╝
OS: Linux version 5.15.0-71-generic (buildd@lcy02-amd64-044) (gcc (Ubuntu 11.3.0-1ubuntu1~22.04.1) 11.3.0, GNU ld (GNU Binutils for Ubuntu) 2.38) #78-Ubuntu SMP Tue Apr 18 09:00:29 UTC 2023
User & Groups: uid=1000(maximus_supervisor) gid=1000(maximus_supervisor) groups=1000(maximus_supervisor)
Hostname: emit
Writable folder: /dev/shm
[+] /usr/bin/ping is available for network discovery (linpeas can discover hosts, learn more with -h)
[+] /usr/bin/bash is available for network discovery, port scanning and port forwarding (linpeas can discover hosts, scan ports, and forward ports. Learn more with -h)
[+] /usr/bin/nc is available for network discovery & port scanning (linpeas can discover hosts and scan ports, learn more with -h)



Caching directories . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . uniq: write error: Broken pipe
DONE

╔════════════════════╗
══════════════════════════════╣ System Information ╠══════════════════════════════
╚════════════════════╝
╔══════════╣ Operative system
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#kernel-exploits
Linux version 5.15.0-71-generic (buildd@lcy02-amd64-044) (gcc (Ubuntu 11.3.0-1ubuntu1~22.04.1) 11.3.0, GNU ld (GNU Binutils for Ubuntu) 2.38) #78-Ubuntu SMP Tue Apr 18 09:00:29 UTC 2023
Distributor ID: Ubuntu
Description: Ubuntu 22.04.2 LTS
Release: 22.04
Codename: jammy

╔══════════╣ Sudo version
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-version
Sudo version 1.9.9


╔══════════╣ PATH
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-path-abuses
/usr/local/sbin:/usr/sbin:/sbin:/usr/local/bin:/usr/bin:/bin

╔══════════╣ Date & uptime
Mon Jul 17 16:25:35 UTC 2023
16:25:35 up 2:33, 0 users, load average: 0.23, 0.05, 0.02

╔══════════╣ Any sd*/disk* disk in /dev? (limit 20)
disk
sda
sda1
sda2
sda3

╔══════════╣ Unmounted file-system?
Check if you can mount umounted devices
/dev/disk/by-uuid/790c151f-485f-4bba-b3ed-fe9b06df494a / ext4 defaults 0 1
/dev/disk/by-uuid/35a4e304-7894-4205-9531-118c4571fde9 none swap sw 0 0

╔══════════╣ Environment
Any private information inside environment variables?
LESSOPEN=| /usr/bin/lesspipe %s
HISTFILESIZE=0
SHLVL=2
OLDPWD=/home/maximus_supervisor/.aws
LC_CTYPE=C.UTF-8
APACHE_RUN_DIR=/var/run/apache2
SYSTEMD_EXEC_PID=1099
APACHE_PID_FILE=/var/run/apache2/apache2.pid
JOURNAL_STREAM=8:22869
_=/tmp/linpeas.sh
TERM=xterm
PATH=/usr/local/sbin:/usr/sbin:/sbin:/usr/local/bin:/usr/bin:/bin
INVOCATION_ID=0986d62e2b5940e89fe00493ddc664f5
APACHE_LOCK_DIR=/var/lock/apache2
LANG=C
HISTSIZE=0
LS_COLORS=
APACHE_RUN_GROUP=www-data
APACHE_RUN_USER=www-data
LESSCLOSE=/usr/bin/lesspipe %s %s
APACHE_LOG_DIR=/var/log/apache2
PWD=/home/maximus_supervisor
HISTFILE=/dev/null

╔══════════╣ Searching Signature verification failed in dmesg
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#dmesg-signature-verification-failed
dmesg Not Found

╔══════════╣ Executing Linux Exploit Suggester
https://github.com/mzet-/linux-exploit-suggester
cat: write error: Broken pipe
cat: write error: Broken pipe
[+] [CVE-2022-32250] nft_object UAF (NFT_MSG_NEWSET)

Details: https://research.nccgroup.com/2022/09/01/settlers-of-netlink-exploiting-a-limited-uaf-in-nf_tables-cve-2022-32250/
https://blog.theori.io/research/CVE-2022-32250-linux-kernel-lpe-2022/
Exposure: probable
Tags: [ ubuntu=(22.04) ]{kernel:5.15.0-27-generic}
Download URL: https://raw.githubusercontent.com/theori-io/CVE-2022-32250-exploit/main/exp.c
Comments: kernel.unprivileged_userns_clone=1 required (to obtain CAP_NET_ADMIN)

[+] [CVE-2022-2586] nft_object UAF

Details: https://www.openwall.com/lists/oss-security/2022/08/29/5
Exposure: less probable
Tags: ubuntu=(20.04){kernel:5.12.13}
Download URL: https://www.openwall.com/lists/oss-security/2022/08/29/5/1
Comments: kernel.unprivileged_userns_clone=1 required (to obtain CAP_NET_ADMIN)

[+] [CVE-2022-0847] DirtyPipe

Details: https://dirtypipe.cm4all.com/
Exposure: less probable
Tags: ubuntu=(20.04|21.04),debian=11
Download URL: https://haxx.in/files/dirtypipez.c

[+] [CVE-2021-4034] PwnKit

Details: https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
Exposure: less probable
Tags: ubuntu=10|11|12|13|14|15|16|17|18|19|20|21,debian=7|8|9|10|11,fedora,manjaro
Download URL: https://codeload.github.com/berdav/CVE-2021-4034/zip/main

[+] [CVE-2021-3156] sudo Baron Samedit

Details: https://www.qualys.com/2021/01/26/cve-2021-3156/baron-samedit-heap-based-overflow-sudo.txt
Exposure: less probable
Tags: mint=19,ubuntu=18|20, debian=10
Download URL: https://codeload.github.com/blasty/CVE-2021-3156/zip/main

[+] [CVE-2021-3156] sudo Baron Samedit 2

Details: https://www.qualys.com/2021/01/26/cve-2021-3156/baron-samedit-heap-based-overflow-sudo.txt
Exposure: less probable
Tags: centos=6|7|8,ubuntu=14|16|17|18|19|20, debian=9|10
Download URL: https://codeload.github.com/worawit/CVE-2021-3156/zip/main

[+] [CVE-2021-22555] Netfilter heap out-of-bounds write

Details: https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html
Exposure: less probable
Tags: ubuntu=20.04{kernel:5.8.0-*}
Download URL: https://raw.githubusercontent.com/google/security-research/master/pocs/linux/cve-2021-22555/exploit.c
ext-url: https://raw.githubusercontent.com/bcoles/kernel-exploits/master/CVE-2021-22555/exploit.c
Comments: ip_tables kernel module must be loaded

[+] [CVE-2017-5618] setuid screen v4.5.0 LPE

Details: https://seclists.org/oss-sec/2017/q1/184
Exposure: less probable
Download URL: https://www.exploit-db.com/download/https://www.exploit-db.com/exploits/41154


╔══════════╣ Executing Linux Exploit Suggester 2
https://github.com/jondonas/linux-exploit-suggester-2

╔══════════╣ Protections
═╣ AppArmor enabled? .............. You do not have enough privilege to read the profile set.
apparmor module is loaded.
═╣ AppArmor profile? .............. unconfined
═╣ is linuxONE? ................... s390x Not Found
═╣ grsecurity present? ............ grsecurity Not Found
═╣ PaX bins present? .............. PaX Not Found
═╣ Execshield enabled? ............ Execshield Not Found
═╣ SELinux enabled? ............... sestatus Not Found
═╣ Seccomp enabled? ............... enabled
═╣ User namespace? ................ enabled
═╣ Cgroup2 enabled? ............... enabled
═╣ Is ASLR enabled? ............... Yes
═╣ Printer? ....................... No
═╣ Is this a virtual machine? ..... Yes (vmware)

╔═══════════╗
═══════════════════════════════════╣ Container ╠═══════════════════════════════════
╚═══════════╝
╔══════════╣ Container related tools present (if any):
/usr/bin/docker
/usr/sbin/runc
╔══════════╣ Am I Containered?
╔══════════╣ Container details
═╣ Is this a container? ........... No
═╣ Any running containers? ........ No


╔═══════╗
═════════════════════════════════════╣ Cloud ╠═════════════════════════════════════
╚═══════╝
═╣ Google Cloud Platform? ............... No
═╣ AWS ECS? ............................. No
═╣ AWS EC2? ............................. No
═╣ AWS EC2 Beanstalk? ................... No
═╣ AWS Lambda? .......................... No
═╣ AWS Codebuild? ....................... No
═╣ DO Droplet? .......................... No
═╣ IBM Cloud VM? ........................ No
═╣ Azure VM? ............................ No
═╣ Azure APP? ........................... No



╔════════════════════════════════════════════════╗
════════════════╣ Processes, Crons, Timers, Services and Sockets ╠════════════════
╚════════════════════════════════════════════════╝
╔══════════╣ Cleaned processes
Check weird & unexpected proceses run by root: https://book.hacktricks.xyz/linux-hardening/privilege-escalation#processes
root 1 0.0 0.2 100680 11636 ? Ss 13:52 0:02 /sbin/init
root 422 0.0 0.3 31472 12712 ? Ssystemd/systemd-journald
root 462 0.0 0.6 289348 27100 ? SLsl 13:52 0:00 /sbin/multipathd -d -s
root 467 0.0 0.1 26368 7332 ? Ss 13:52 0:00 /lib/systemd/systemd-udevd
systemd+ 494 0.0 0.1 89356 6540 ? Ssl 13:52 0:00 /lib/systemd/systemd-timesyncd
└─(Caps) 0x0000000002000000=cap_sys_time
root 507 0.0 0.2 51132 11640 ? Ss 13:52 0:00 /usr/bin/VGAuthService
root 508 0.0 0.2 315304 9468 ? Ssl 13:52 0:04 /usr/bin/vmtoolsd
systemd+ 524 0.0 0.2 16248 8228 ? Ss 13:52 0:00 /lib/systemd/systemd-networkd
└─(Caps) 0x0000000000003c00=cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw
systemd+ 541 0.0 0.3 25524 13352 ? Ss 13:52 0:00 /lib/systemd/systemd-resolved
└─(Caps) 0x0000000000002000=cap_net_raw
root 737 0.0 0.1 101236 6000 ? Ssl 13:52 0:00 /sbin/dhclient -1 -4 -v -i -pf /run/dhclient.eth0.pid -lf /var/lib/dhcp/dhclient.eth0.leases -I -df /var/lib/dhcp/dhclient6.eth0.leases eth0
message+ 749 0.0 0.1 8788 4824 ? Ss 13:52 0:00 @dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
└─(Caps) 0x0000000020000000=cap_audit_write
root 754 0.0 0.0 82828 3808 ? Ssl 13:52 0:00 /usr/sbin/irqbalance --foreground
root 755 0.0 0.4 32760 19460 ? Ss 13:52 0:00 /usr/bin/python3 /usr/bin/networkd-dispatcher --run-startup-triggers
root 757 0.0 0.1 234484 6872 ? Ssl 13:52 0:00 /usr/libexec/polkitd --no-debug
syslog 758 0.0 0.1 222400 5524 ? Ssl 13:52 0:00 /usr/sbin/rsyslogd -n -iNONE
root 759 0.0 0.9 875604 39036 ? Ssl 13:52 0:01 /usr/lib/snapd/snapd
root 760 0.0 0.1 14904 6328 ? Ss 13:52 0:00 /lib/systemd/systemd-logind
root 761 0.0 0.3 392564 12628 ? Ssl 13:52 0:00 /usr/libexec/udisks2/udisksd
root 827 0.0 0.2 244212 11936 ? Ssl 13:52 0:00 /usr/sbin/ModemManager
root 1101 0.0 0.0 6892 2828 ? Ss 13:52 0:00 /usr/sbin/cron -f -P
root 1125 0.0 0.0 10340 4004 ? S 13:52 0:00 _ /usr/sbin/CRON -f -P
root 1144 0.0 0.0 2888 980 ? Ss 13:52 0:00 _ /bin/sh -c cd /root;python3 proxy.py
root 1155 0.0 0.8 191072 34648 ? S 13:52 0:02 _ python3 proxy.py
root 1130 0.0 0.0 6172 1076 tty1 Ss+ 13:52 0:00 /sbin/agetty -o -p -- u --noclear tty1 linux
root 1142 0.0 1.0 1348192 42948 ? Ssl 13:52 0:03 /usr/bin/containerd
root 1163 0.0 0.5 205900 20468 ? Ss 13:52 0:00 /usr/sbin/apache2 -k start
www-data 17808 0.0 0.2 206588 10460 ? S 14:12 0:00 _ /usr/sbin/apache2 -k start
└─(Caps) 0x00000000008000c4=cap_dac_read_search,cap_setgid,cap_setuid,cap_sys_nice
www-data 17835 0.0 0.2 206588 10460 ? S 14:12 0:00 _ /usr/sbin/apache2 -k start
└─(Caps) 0x00000000008000c4=cap_dac_read_search,cap_setgid,cap_setuid,cap_sys_nice
www-data 17899 0.0 0.2 206588 10460 ? S 14:12 0:00 _ /usr/sbin/apache2 -k start
└─(Caps) 0x00000000008000c4=cap_dac_read_search,cap_setgid,cap_setuid,cap_sys_nice
www-data 17903 0.0 0.2 206588 10460 ? S 14:12 0:00 _ /usr/sbin/apache2 -k start
└─(Caps) 0x00000000008000c4=cap_dac_read_search,cap_setgid,cap_setuid,cap_sys_nice
www-data 17952 0.0 0.2 206588 10460 ? S 14:12 0:00 _ /usr/sbin/apache2 -k start
└─(Caps) 0x00000000008000c4=cap_dac_read_search,cap_setgid,cap_setuid,cap_sys_nice
www-data 17984 0.0 0.2 206588 10460 ? S 14:12 0:00 _ /usr/sbin/apache2 -k start
└─(Caps) 0x00000000008000c4=cap_dac_read_search,cap_setgid,cap_setuid,cap_sys_nice
www-data 17987 0.0 0.2 206588 10460 ? S 14:12 0:00 _ /usr/sbin/apache2 -k start
└─(Caps) 0x00000000008000c4=cap_dac_read_search,cap_setgid,cap_setuid,cap_sys_nice
www-data 18019 0.0 0.2 206588 10460 ? S 14:12 0:00 _ /usr/sbin/apache2 -k start
└─(Caps) 0x00000000008000c4=cap_dac_read_search,cap_setgid,cap_setuid,cap_sys_nice
www-data 18034 0.0 0.2 206588 10460 ? S 14:12 0:00 _ /usr/sbin/apache2 -k start
└─(Caps) 0x00000000008000c4=cap_dac_read_search,cap_setgid,cap_setuid,cap_sys_nice
www-data 18109 0.0 0.2 206588 10460 ? S 14:12 0:00 _ /usr/sbin/apache2 -k start
└─(Caps) 0x00000000008000c4=cap_dac_read_search,cap_setgid,cap_setuid,cap_sys_nice
mysql 1173 0.2 10.0 1784584 402740 ? Ssl 13:52 0:19 /usr/sbin/mysqld
root 1174 0.0 1.6 1447320 68288 ? Ssl 13:52 0:01 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
root 1537 0.0 0.0 1074564 2764 ? Sl 13:52 0:00 _ /usr/bin/docker-proxy -proto tcp -host-ip 127.0.0.1 -host-port 8080 -container-ip 172.18.0.2 -container-port 8080
root 1549 0.0 0.0 1222284 3376 ? Sl 13:52 0:00 _ /usr/bin/docker-proxy -proto tcp -host-ip 127.0.0.1 -host-port 4566 -container-ip 172.18.0.2 -container-port 4566
root 1564 0.0 0.2 712468 9208 ? Sl 13:52 0:00 /usr/bin/containerd-shim-runc-v2 -namespace moby -id 76d4018f32ad6f434ee4fa85948e7f4aeda95a420bc002b431028181a49e3acb -address /run/containerd/containerd.sock
root 1588 0.0 0.0 2248 1656 ? Ss 13:52 0:00 _ /bin/bash /usr/local/bin/docker-entrypoint.sh
root 1677 0.0 0.4 21860 19696 ? S 13:52 0:01 _ /usr/bin/python3.8 /usr/bin/supervisord -c /etc/supervisord.conf
1001 1685 0.0 0.0 1168 692 ? S 13:52 0:00 | | _ make web
1001 1687 0.0 2.7 114460 110516 ? Sl 13:52 0:05 | | _ python bin/localstack web
root 1684 0.0 0.0 1168 668 ? S 13:52 0:00 | _ make infra
root 1686 0.1 3.4 147060 138056 ? Sl 13:52 0:17 | _ python bin/localstack start --host
root 1680 0.0 0.0 1576 4 ? S 13:52 0:00 _ tail -qF /tmp/localstack_infra.log /tmp/localstack_infra.err
maximus+ 22631 0.0 0.1 5688 4828 ? Ss 16:23 0:00 /bin/bash -i
maximus+ 22709 0.0 0.0 5688 3236 ? S 16:24 0:00 _ /bin/bash -i
maximus+ 22710 0.0 0.0 5688 1632 ? S 16:24 0:00 _ /bin/bash -i
maximus+ 22711 0.0 0.0 5688 3172 ? S 16:24 0:00 _ /bin/bash -i
maximus+ 22712 0.0 0.2 17844 9236 ? S 16:24 0:00 _ python3 -c import pty;pty.spawn("/bin/bash")
maximus+ 22713 0.0 0.1 9044 5324 pts/0 Ss 16:24 0:00 _ /bin/bash
maximus+ 22827 0.1 0.0 3972 2888 pts/0 S+ 16:25 0:00 _ /bin/sh /tmp/linpeas.sh
maximus+ 26108 0.0 0.0 3972 1200 pts/0 S+ 16:26 0:00 _ /bin/sh /tmp/linpeas.sh
maximus+ 26110 0.0 0.0 10980 3712 pts/0 R+ 16:26 0:00 | _ ps fauxwww
maximus+ 26112 0.0 0.0 3972 1200 pts/0 S+ 16:26 0:00 _ /bin/sh /tmp/linpeas.sh

╔══════════╣ Binary processes permissions (non 'root root' and not belonging to current user)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#processes

╔══════════╣ Processes whose PPID belongs to a different user (not root)
You will know if a user can somehow spawn processes as a different user
Proc 494 with ppid 1 is run by user systemd-timesync but the ppid user is root
Proc 524 with ppid 1 is run by user systemd-network but the ppid user is root
Proc 541 with ppid 1 is run by user systemd-resolve but the ppid user is root
Proc 749 with ppid 1 is run by user messagebus but the ppid user is root
Proc 758 with ppid 1 is run by user syslog but the ppid user is root
Proc 1173 with ppid 1 is run by user mysql but the ppid user is root
Proc 1683 with ppid 1677 is run by user 1001 but the ppid user is root
Proc 17808 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17835 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17899 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17903 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17952 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17984 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17987 with ppid 1163 is run by user www-data but the ppid user is root
Proc 18019 with ppid 1163 is run by user www-data but the ppid user is root
Proc 18034 with ppid 1163 is run by user www-data but the ppid user is root
Proc 18109 with ppid 1163 is run by user www-data but the ppid user is root
Proc 22631 with ppid 1 is run by user maximus_supervisor but the ppid user is root

╔══════════╣ Files opened by processes belonging to other users
This is usually empty because of the lack of privileges to read other user processes information
COMMAND PID TID TASKCMD USER FD TYPE DEVICE SIZE/OFF NODE NAME

╔══════════╣ Processes with credentials in memory (root req)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#credentials-from-process-memory
gdm-password Not Found
gnome-keyring-daemon Not Found
lightdm Not Found
vsftpd Not Found
apache2 process found (dump creds from memory as root)
sshd: process found (dump creds from memory as root)

╔══════════╣ Cron jobs
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#scheduled-cron-jobs
/usr/bin/crontab
incrontab Not Found
-rw-r--r-- 1 root root 1136 Mar 23 2022 /etc/crontab

/etc/cron.d:
total 20
drwxr-xr-x 2 root root 4096 Jul 4 09:46 .
drwxr-xr-x 105 root root 4096 Jul 4 09:58 ..
-rw-r--r-- 1 root root 102 Mar 23 2022 .placeholder
-rw-r--r-- 1 root root 201 Jan 8 2022 e2scrub_all
-rw-r--r-- 1 root root 712 Jan 28 2022 php

/etc/cron.daily:
total 36
drwxr-xr-x 2 root root 4096 Jul 4 09:46 .
drwxr-xr-x 105 root root 4096 Jul 4 09:58 ..
-rw-r--r-- 1 root root 102 Mar 23 2022 .placeholder
-rwxr-xr-x 1 root root 539 Mar 1 22:43 apache2
-rwxr-xr-x 1 root root 376 Nov 11 2019 apport
-rwxr-xr-x 1 root root 1478 Apr 8 2022 apt-compat
-rwxr-xr-x 1 root root 123 Dec 5 2021 dpkg
-rwxr-xr-x 1 root root 377 May 25 2022 logrotate
-rwxr-xr-x 1 root root 1330 Mar 17 2022 man-db

/etc/cron.hourly:
total 12
drwxr-xr-x 2 root root 4096 Jul 4 09:46 .
drwxr-xr-x 105 root root 4096 Jul 4 09:58 ..
-rw-r--r-- 1 root root 102 Mar 23 2022 .placeholder

/etc/cron.monthly:
total 12
drwxr-xr-x 2 root root 4096 Jul 4 09:46 .
drwxr-xr-x 105 root root 4096 Jul 4 09:58 ..
-rw-r--r-- 1 root root 102 Mar 23 2022 .placeholder

/etc/cron.weekly:
total 16
drwxr-xr-x 2 root root 4096 Jul 4 09:46 .
drwxr-xr-x 105 root root 4096 Jul 4 09:58 ..
-rw-r--r-- 1 root root 102 Mar 23 2022 .placeholder
-rwxr-xr-x 1 root root 1020 Mar 17 2022 man-db

SHELL=/bin/sh

17 * * * * root cd / && run-parts --report /etc/cron.hourly
25 6 * * * root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.daily )
47 6 * * 7 root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.weekly )
52 6 1 * * root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.monthly )

╔══════════╣ Systemd PATH
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#systemd-path-relative-paths
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin

╔══════════╣ Analyzing .service files
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#services
/etc/systemd/system/multi-user.target.wants/grub-common.service could be executing some relative path
/etc/systemd/system/multi-user.target.wants/systemd-networkd.service could be executing some relative path
/etc/systemd/system/sleep.target.wants/grub-common.service could be executing some relative path
You can't write on systemd PATH

╔══════════╣ System timers
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#timers
NEXT LEFT LAST PASSED UNIT ACTIVATES
Mon 2023-07-17 16:39:00 UTC 12min left Mon 2023-07-17 16:09:05 UTC 17min ago phpsessionclean.timer phpsessionclean.service
Mon 2023-07-17 19:47:48 UTC 3h 21min left Tue 2023-07-04 00:24:16 UTC 1 week 6 days ago apt-daily.timer apt-daily.service
Mon 2023-07-17 21:01:38 UTC 4h 35min left Mon 2023-07-17 14:27:25 UTC 1h 58min ago ua-timer.timer ua-timer.service
Mon 2023-07-17 22:38:33 UTC 6h left Tue 2023-07-04 05:48:37 UTC 1 week 6 days ago man-db.timer man-db.service
Tue 2023-07-18 00:00:00 UTC 7h left n/a n/a dpkg-db-backup.timer dpkg-db-backup.service
Tue 2023-07-18 00:00:00 UTC 7h left Mon 2023-07-17 13:52:19 UTC 2h 34min ago logrotate.timer logrotate.service
Tue 2023-07-18 01:16:55 UTC 8h left Mon 2023-07-03 21:20:42 UTC 1 week 6 days ago fwupd-refresh.timer fwupd-refresh.service
Tue 2023-07-18 02:27:12 UTC 10h left Mon 2023-07-17 14:35:05 UTC 1h 51min ago motd-news.timer motd-news.service
Tue 2023-07-18 06:56:07 UTC 14h left Mon 2023-07-17 14:27:09 UTC 1h 59min ago apt-daily-upgrade.timer apt-daily-upgrade.service
Tue 2023-07-18 13:57:16 UTC 21h left Mon 2023-07-17 13:57:16 UTC 2h 29min ago update-notifier-download.timer update-notifier-download.service
Tue 2023-07-18 14:07:16 UTC 21h left Mon 2023-07-17 14:07:16 UTC 2h 19min ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service
Thu 2023-07-20 01:48:52 UTC 2 days left Sun 2023-07-02 06:00:53 UTC 2 weeks 1 day ago update-notifier-motd.timer update-notifier-motd.service
Sun 2023-07-23 03:10:00 UTC 5 days left Mon 2023-07-17 13:52:48 UTC 2h 33min ago e2scrub_all.timer e2scrub_all.service
Mon 2023-07-24 01:36:54 UTC 6 days left Mon 2023-07-17 15:09:52 UTC 1h 16min ago fstrim.timer fstrim.service
n/a n/a n/a n/a apport-autoreport.timer apport-autoreport.service
n/a n/a n/a n/a snapd.snap-repair.timer snapd.snap-repair.service

╔══════════╣ Analyzing .timer files
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#timers

╔══════════╣ Analyzing .socket files
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sockets
/etc/systemd/system/sockets.target.wants/uuidd.socket is calling this writable listener: /run/uuidd/request
/snap/core20/1974/usr/lib/systemd/system/dbus.socket is calling this writable listener: /var/run/dbus/system_bus_socket
/snap/core20/1974/usr/lib/systemd/system/sockets.target.wants/dbus.socket is calling this writable listener: /var/run/dbus/system_bus_socket
/snap/core20/1974/usr/lib/systemd/system/sockets.target.wants/systemd-journald-dev-log.socket is calling this writable listener: /run/systemd/journal/dev-log
/snap/core20/1974/usr/lib/systemd/system/sockets.target.wants/systemd-journald.socket is calling this writable listener: /run/systemd/journal/stdout
/snap/core20/1974/usr/lib/systemd/system/sockets.target.wants/systemd-journald.socket is calling this writable listener: /run/systemd/journal/socket
/snap/core20/1974/usr/lib/systemd/system/syslog.socket is calling this writable listener: /run/systemd/journal/syslog
/snap/core20/1974/usr/lib/systemd/system/systemd-journald-dev-log.socket is calling this writable listener: /run/systemd/journal/dev-log
/snap/core20/1974/usr/lib/systemd/system/systemd-journald.socket is calling this writable listener: /run/systemd/journal/stdout
/snap/core20/1974/usr/lib/systemd/system/systemd-journald.socket is calling this writable listener: /run/systemd/journal/socket
/usr/lib/systemd/system/dbus.socket is calling this writable listener: /run/dbus/system_bus_socket
/usr/lib/systemd/system/sockets.target.wants/dbus.socket is calling this writable listener: /run/dbus/system_bus_socket
/usr/lib/systemd/system/sockets.target.wants/systemd-journald-dev-log.socket is calling this writable listener: /run/systemd/journal/dev-log
/usr/lib/systemd/system/sockets.target.wants/systemd-journald.socket is calling this writable listener: /run/systemd/journal/socket
/usr/lib/systemd/system/sockets.target.wants/systemd-journald.socket is calling this writable listener: /run/systemd/journal/stdout
/usr/lib/systemd/system/syslog.socket is calling this writable listener: /run/systemd/journal/syslog

╔══════════╣ Unix Sockets Listening
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sockets
sed: -e expression #1, char 0: no previous regular expression
/org/kernel/linux/storage/multipathd
/run/containerd/containerd.sock
/run/containerd/containerd.sock.ttrpc
/run/containerd/s/d14ffd1f66dc0f6e7a6fa56f57bcd6e1c42f809ab699c6f69482f3fb444277bf
/run/dbus/system_bus_socket
└─(Read Write)
/run/docker.sock
/run/irqbalance/irqbalance754.sock
└─(Read )
/run/lvm/lvmpolld.socket
/run/mysqld/mysqld.sock
└─(Read Write)
/run/mysqld/mysqlx.sock
└─(Read Write)
/run/snapd-snap.socket
└─(Read Write)
/run/snapd.socket
└─(Read Write)
/run/systemd/fsck.progress
/run/systemd/inaccessible/sock
/run/systemd/io.system.ManagedOOM
└─(Read Write)
/run/systemd/journal/dev-log
└─(Read Write)
/run/systemd/journal/io.systemd.journal
/run/systemd/journal/socket
└─(Read Write)
/run/systemd/journal/stdout
└─(Read Write)
/run/systemd/journal/syslog
└─(Read Write)
/run/systemd/notify
└─(Read Write)
/run/systemd/private
└─(Read Write)
/run/systemd/resolve/io.systemd.Resolve
└─(Read Write)
/run/systemd/userdb/io.systemd.DynamicUser
└─(Read Write)
/run/udev/control
/run/uuidd/request
└─(Read Write)
/run/vmware/guestServicePipe
└─(Read Write)
/var/run/docker/libnetwork/cf02cf2668e2.sock
/var/run/docker/metrics.sock
/var/run/mysqld/mysqld.sock
└─(Read Write)
/var/run/mysqld/mysqlx.sock
└─(Read Write)
/var/run/vmware/guestServicePipe
└─(Read Write)
/var/snap/lxd/common/lxd-user/unix.socket
/var/snap/lxd/common/lxd/unix.socket

╔══════════╣ D-Bus config files
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#d-bus
Possible weak user policy found on /etc/dbus-1/system.d/dnsmasq.conf ( dnsmasq">)
Possible weak user policy found on /etc/dbus-1/system.d/org.freedesktop.thermald.conf ( )

╔══════════╣ D-Bus Service Objects list
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#d-bus
NAME PID PROCESS USER CONNECTION UNIT SESSION DESCRIPTION
:1.0 1 systemd root :1.0 init.scope - -
:1.1 541 systemd-resolve systemd-resolve :1.1 systemd-resolved.service - -
:1.17 759 snapd root :1.17 snapd.service - -
:1.2 524 systemd-network systemd-network :1.2 systemd-networkd.service - -
:1.3 494 systemd-timesyn systemd-timesync :1.3 systemd-timesyncd.service - -
:1.31 30417 busctl maximus_supervisor :1.31 apache2.service - -
:1.4 757 polkitd root :1.4 polkit.service - -
:1.5 761 udisksd root :1.5 udisks2.service - -
:1.6 760 systemd-logind root :1.6 systemd-logind.service - -
:1.7 827 ModemManager root :1.7 ModemManager.service - -
:1.9 755 networkd-dispat root :1.9 networkd-dispatcher.service - -
com.ubuntu.SoftwareProperties - - - (activatable) - - -
org.freedesktop.DBus 1 systemd root - init.scope - -
org.freedesktop.ModemManager1 827 ModemManager root :1.7 ModemManager.service - -
org.freedesktop.PackageKit - - - (activatable) - - -
org.freedesktop.PolicyKit1 757 polkitd root :1.4 polkit.service - -
org.freedesktop.UDisks2 761 udisksd root :1.5 udisks2.service - -
org.freedesktop.UPower - - - (activatable) - - -
org.freedesktop.bolt - - - (activatable) - - -
org.freedesktop.fwupd - - - (activatable) - - -
org.freedesktop.hostname1 - - - (activatable) - - -
org.freedesktop.locale1 - - - (activatable) - - -
org.freedesktop.login1 760 systemd-logind root :1.6 systemd-logind.service - -
org.freedesktop.network1 524 systemd-network systemd-network :1.2 systemd-networkd.service - -
org.freedesktop.resolve1 541 systemd-resolve systemd-resolve :1.1 systemd-resolved.service - -
org.freedesktop.systemd1 1 systemd root :1.0 init.scope - -
org.freedesktop.thermald - - - (activatable) - - -
org.freedesktop.timedate1 - - - (activatable) - - -
org.freedesktop.timesync1 494 systemd-timesyn systemd-timesync :1.3 systemd-timesyncd.service - -


╔═════════════════════╗
══════════════════════════════╣ Network Information ╠══════════════════════════════
╚═════════════════════╝
╔══════════╣ Hostname, hosts and DNS
emit
127.0.0.1 localhost
127.0.1.1 emit

::1 ip6-localhost ip6-loopback
fe00::0 ip6-localnet
ff00::0 ip6-mcastprefix
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters

nameserver 127.0.0.53
options edns0 trust-ad
search .

╔══════════╣ Interfaces
# symbolic names for networks, see networks(5) for more information
link-local 169.254.0.0
br-db572463ad6a: flags=4163 mtu 1500
inet 172.18.0.1 netmask 255.255.0.0 broadcast 172.18.255.255
inet6 fe80::42:e0ff:fe96:fe63 prefixlen 64 scopeid 0x20
ether 02:42:e0:96:fe:63 txqueuelen 0 (Ethernet)
RX packets 2029 bytes 334311 (334.3 KB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 2320 bytes 335690 (335.6 KB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0

docker0: flags=4099 mtu 1500
inet 172.17.0.1 netmask 255.255.0.0 broadcast 172.17.255.255
ether 02:42:1c:ad:9f:7c txqueuelen 0 (Ethernet)
RX packets 0 bytes 0 (0.0 B)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 0 bytes 0 (0.0 B)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0

eth0: flags=4163 mtu 1500
inet 10.129.229.92 netmask 255.255.0.0 broadcast 10.129.255.255
inet6 dead:beef::250:56ff:feb0:25e6 prefixlen 64 scopeid 0x0
inet6 fe80::250:56ff:feb0:25e6 prefixlen 64 scopeid 0x20
ether 00:50:56:b0:25:e6 txqueuelen 1000 (Ethernet)
RX packets 1664803 bytes 253116209 (253.1 MB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 1664050 bytes 765249144 (765.2 MB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0

lo: flags=73 mtu 65536
inet 127.0.0.1 netmask 255.0.0.0
inet6 ::1 prefixlen 128 scopeid 0x10
loop txqueuelen 1000 (Local Loopback)
RX packets 17302 bytes 2034903 (2.0 MB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 17302 bytes 2034903 (2.0 MB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0

veth8ca78ed: flags=4163 mtu 1500
inet6 fe80::bc59:b1ff:fe6c:155a prefixlen 64 scopeid 0x20
ether be:59:b1:6c:15:5a txqueuelen 0 (Ethernet)
RX packets 2029 bytes 362717 (362.7 KB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 2337 bytes 336976 (336.9 KB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0


╔══════════╣ Active Ports
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#open-ports
tcp 0 0 127.0.0.1:38491 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:8000 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:8080 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:3306 0.0.0.0:* LISTEN -
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.53:53 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:33060 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:4566 0.0.0.0:* LISTEN -
tcp6 0 0 :::80 :::* LISTEN -
tcp6 0 0 :::22 :::* LISTEN -

╔══════════╣ Can I sniff with tcpdump?
No



╔═══════════════════╗
═══════════════════════════════╣ Users Information ╠═══════════════════════════════
╚═══════════════════╝
╔══════════╣ My user
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#users
uid=1000(maximus_supervisor) gid=1000(maximus_supervisor) groups=1000(maximus_supervisor)

╔══════════╣ Do I have PGP keys?
/usr/bin/gpg
netpgpkeys Not Found
netpgp Not Found

╔══════════╣ Checking 'sudo -l', /etc/sudoers, and /etc/sudoers.d
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid

╔══════════╣ Checking sudo tokens
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#reusing-sudo-tokens
ptrace protection is enabled (1)

╔══════════╣ Checking Pkexec policy
https://book.hacktricks.xyz/linux-hardening/privilege-escalation/interesting-groups-linux-pe#pe-method-2

[Configuration]
AdminIdentities=unix-user:0
[Configuration]
AdminIdentities=unix-group:sudo;unix-group:admin

╔══════════╣ Superusers
root:x:0:0:root:/root:/bin/bash

╔══════════╣ Users with console
maximus_supervisor:x:1000:1000:,,,:/home/maximus_supervisor:/bin/bash
root:x:0:0:root:/root:/bin/bash

╔══════════╣ All users & groups
uid=0(root) gid=0(root) groups=0(root)
uid=1(daemon[0m) gid=1(daemon[0m) groups=1(daemon[0m)
uid=10(uucp) gid=10(uucp) groups=10(uucp)
uid=100(_apt) gid=65534(nogroup) groups=65534(nogroup)
uid=1000(maximus_supervisor) gid=1000(maximus_supervisor) groups=1000(maximus_supervisor)
uid=101(systemd-network) gid=102(systemd-network) groups=102(systemd-network)
uid=102(systemd-resolve) gid=103(systemd-resolve) groups=103(systemd-resolve)
uid=103(messagebus) gid=104(messagebus) groups=104(messagebus)
uid=104(systemd-timesync) gid=105(systemd-timesync) groups=105(systemd-timesync)
uid=105(pollinate) gid=1(daemon[0m) groups=1(daemon[0m)
uid=106(sshd) gid=65534(nogroup) groups=65534(nogroup)
uid=107(syslog) gid=113(syslog) groups=113(syslog),4(adm)
uid=108(uuidd) gid=114(uuidd) groups=114(uuidd)
uid=109(tcpdump) gid=115(tcpdump) groups=115(tcpdump)
uid=110(tss) gid=116(tss) groups=116(tss)
uid=111(landscape) gid=117(landscape) groups=117(landscape)
uid=112(fwupd-refresh) gid=118(fwupd-refresh) groups=118(fwupd-refresh)
uid=113(usbmux) gid=46(plugdev) groups=46(plugdev)
uid=114(dnsmasq) gid=65534(nogroup) groups=65534(nogroup)
uid=115(mysql) gid=122(mysql) groups=122(mysql)
uid=13(proxy) gid=13(proxy) groups=13(proxy)
uid=2(bin) gid=2(bin) groups=2(bin)
uid=3(sys) gid=3(sys) groups=3(sys)
uid=33(www-data) gid=33(www-data) groups=33(www-data)
uid=34(backup) gid=34(backup) groups=34(backup)
uid=38(list) gid=38(list) groups=38(list)
uid=39(irc) gid=39(irc) groups=39(irc)
uid=4(sync) gid=65534(nogroup) groups=65534(nogroup)
uid=41(gnats) gid=41(gnats) groups=41(gnats)
uid=5(games) gid=60(games) groups=60(games)
uid=6(man) gid=12(man) groups=12(man)
uid=65534(nobody) gid=65534(nogroup) groups=65534(nogroup)
uid=7(lp) gid=7(lp) groups=7(lp)
uid=8(mail) gid=8(mail) groups=8(mail)
uid=9(news) gid=9(news) groups=9(news)
uid=999(lxd) gid=100(users) groups=100(users)

╔══════════╣ Login now
16:26:25 up 2:34, 0 users, load average: 0.10, 0.04, 0.01
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT

╔══════════╣ Last logons
reboot system boot Mon Jul 17 13:52:16 2023 still running 0.0.0.0

wtmp begins Mon Jul 17 13:52:16 2023

╔══════════╣ Last time logon each user
Username Port From Latest

╔══════════╣ Do not forget to test 'su' as any other user with shell: without password and with their names as password (I don't do it in FAST mode...)

╔══════════╣ Do not forget to execute 'sudo -l' without password or with valid password (if you know it)!!



╔══════════════════════╗
═════════════════════════════╣ Software Information ╠═════════════════════════════
╚══════════════════════╝
╔══════════╣ Useful software
/usr/local/bin/aws
/usr/bin/base64
/usr/bin/ctr
/usr/bin/curl
/usr/bin/docker
/usr/bin/g++
/usr/bin/gcc
/usr/bin/make
/usr/bin/nc
/usr/bin/netcat
/usr/bin/perl
/usr/bin/php
/usr/bin/ping
/usr/bin/python3
/usr/sbin/runc
/usr/bin/sudo
/usr/bin/wget

╔══════════╣ Installed Compilers
ii g++ 4:11.2.0-1ubuntu1 amd64 GNU C++ compiler
ii g++-11 11.3.0-1ubuntu1~22.04.1 amd64 GNU C++ compiler
ii gcc 4:11.2.0-1ubuntu1 amd64 GNU C compiler
ii gcc-11 11.3.0-1ubuntu1~22.04.1 amd64 GNU C compiler
ii rpcsvc-proto 1.4.2-0ubuntu6 amd64 RPC protocol compiler and definitions
/usr/bin/gcc

╔══════════╣ MySQL version
mysql Ver 8.0.33-0ubuntu0.22.04.2 for Linux on x86_64 ((Ubuntu))


═╣ MySQL connection using default root/root ........... No
═╣ MySQL connection using root/toor ................... No
═╣ MySQL connection using root/NOPASS ................. No

╔══════════╣ Searching mysql credentials and exec
From '/etc/mysql/mysql.conf.d/mysqld.cnf' Mysql user: user = mysql
Found readable /etc/mysql/my.cnf
!includedir /etc/mysql/conf.d/
!includedir /etc/mysql/mysql.conf.d/

╔══════════╣ Analyzing MariaDB Files (limit 70)

-rw------- 1 root root 317 Jul 3 08:12 /etc/mysql/debian.cnf

╔══════════╣ Analyzing Apache-Nginx Files (limit 70)
Apache version: Server version: Apache/2.4.52 (Ubuntu)
Server built: 2023-03-01T22:43:55
httpd Not Found

Nginx version: nginx Not Found

/etc/apache2/mods-available/php8.1.conf-
/etc/apache2/mods-available/php8.1.conf: SetHandler application/x-httpd-php
--
/etc/apache2/mods-available/php8.1.conf-
/etc/apache2/mods-available/php8.1.conf: SetHandler application/x-httpd-php-source
--
/etc/apache2/mods-enabled/php8.1.conf-
/etc/apache2/mods-enabled/php8.1.conf: SetHandler application/x-httpd-php
--
/etc/apache2/mods-enabled/php8.1.conf-
/etc/apache2/mods-enabled/php8.1.conf: SetHandler application/x-httpd-php-source
══╣ PHP exec extensions
drwxr-xr-x 2 root root 4096 Jul 4 09:46 /etc/apache2/sites-enabled
drwxr-xr-x 2 root root 4096 Jul 4 09:46 /etc/apache2/sites-enabled
lrwxrwxrwx 1 root root 35 Jun 30 09:59 /etc/apache2/sites-enabled/000-default.conf -> ../sites-available/000-default.conf


AssignUserId maximus_supervisor maximus_supervisor

ServerAdmin webmaster@localhost
DocumentRoot /var/www/html
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined


ProxyPreserveHost on
ProxyPass / http://localhost:8000/
ProxyPassReverse / http://localhost:8000/

Order deny,allow
Allow from all

ServerAdmin webmaster@localhost
ServerName cloud.emit.htb
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined



-rw-r--r-- 1 root root 1864 Jul 3 08:32 /etc/apache2/sites-available/000-default.conf


AssignUserId maximus_supervisor maximus_supervisor

ServerAdmin webmaster@localhost
DocumentRoot /var/www/html
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined


ProxyPreserveHost on
ProxyPass / http://localhost:8000/
ProxyPassReverse / http://localhost:8000/

Order deny,allow
Allow from all

ServerAdmin webmaster@localhost
ServerName cloud.emit.htb
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined

lrwxrwxrwx 1 root root 35 Jun 30 09:59 /etc/apache2/sites-enabled/000-default.conf -> ../sites-available/000-default.conf


AssignUserId maximus_supervisor maximus_supervisor

ServerAdmin webmaster@localhost
DocumentRoot /var/www/html
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined


ProxyPreserveHost on
ProxyPass / http://localhost:8000/
ProxyPassReverse / http://localhost:8000/

Order deny,allow
Allow from all

ServerAdmin webmaster@localhost
ServerName cloud.emit.htb
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined


-rw-r--r-- 1 root root 72928 Feb 22 22:56 /etc/php/8.1/apache2/php.ini
allow_url_fopen = On
allow_url_include = Off
odbc.allow_persistent = On
mysqli.allow_persistent = On
pgsql.allow_persistent = On
-rw-r--r-- 1 root root 72924 Feb 22 22:56 /etc/php/8.1/cli/php.ini
allow_url_fopen = On
allow_url_include = Off
odbc.allow_persistent = On
mysqli.allow_persistent = On
pgsql.allow_persistent = On



╔══════════╣ Analyzing Rsync Files (limit 70)
-rw-r--r-- 1 root root 1044 Oct 11 2022 /usr/share/doc/rsync/examples/rsyncd.conf
[ftp]
comment = public archive
path = /var/www/pub
use chroot = yes
lock file = /var/lock/rsyncd
read only = yes
list = yes
uid = nobody
gid = nogroup
strict modes = yes
ignore errors = no
ignore nonreadable = yes
transfer logging = no
timeout = 600
refuse options = checksum dry-run
dont compress = *.gz *.tgz *.zip *.z *.rpm *.deb *.iso *.bz2 *.tbz


╔══════════╣ Analyzing Ldap Files (limit 70)
The password hash is from the {SSHA} to 'structural'
drwxr-xr-x 2 root root 4096 Jul 4 09:46 /etc/ldap


╔══════════╣ Searching ssl/ssh files
╔══════════╣ Analyzing SSH Files (limit 70)





-rw-r--r-- 1 root root 601 Apr 27 16:07 /etc/ssh/ssh_host_dsa_key.pub
-rw-r--r-- 1 root root 173 Apr 27 16:07 /etc/ssh/ssh_host_ecdsa_key.pub
-rw-r--r-- 1 root root 93 Apr 27 16:07 /etc/ssh/ssh_host_ed25519_key.pub
-rw-r--r-- 1 root root 565 Apr 27 16:07 /etc/ssh/ssh_host_rsa_key.pub

PermitRootLogin yes
PasswordAuthentication yes
UsePAM yes
══╣ Some certificates were found (out limited):
/etc/pki/fwupd-metadata/LVFS-CA.pem
/etc/pki/fwupd/LVFS-CA.pem
/etc/pollinate/entropy.ubuntu.com.pem
/etc/ssl/certs/ACCVRAIZ1.pem
/etc/ssl/certs/AC_RAIZ_FNMT-RCM.pem
/etc/ssl/certs/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
/etc/ssl/certs/ANF_Secure_Server_Root_CA.pem
/etc/ssl/certs/Actalis_Authentication_Root_CA.pem
/etc/ssl/certs/AffirmTrust_Commercial.pem
/etc/ssl/certs/AffirmTrust_Networking.pem
/etc/ssl/certs/AffirmTrust_Premium.pem
/etc/ssl/certs/AffirmTrust_Premium_ECC.pem
/etc/ssl/certs/Amazon_Root_CA_1.pem
/etc/ssl/certs/Amazon_Root_CA_2.pem
/etc/ssl/certs/Amazon_Root_CA_3.pem
/etc/ssl/certs/Amazon_Root_CA_4.pem
/etc/ssl/certs/Atos_TrustedRoot_2011.pem
/etc/ssl/certs/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
/etc/ssl/certs/Baltimore_CyberTrust_Root.pem
/etc/ssl/certs/Buypass_Class_2_Root_CA.pem
22827PSTORAGE_CERTSBIN

══╣ Writable ssh and gpg agents
/etc/systemd/user/sockets.target.wants/gpg-agent-ssh.socket
/etc/systemd/user/sockets.target.wants/gpg-agent-extra.socket
/etc/systemd/user/sockets.target.wants/gpg-agent.socket
/etc/systemd/user/sockets.target.wants/gpg-agent-browser.socket
══╣ Some home ssh config file was found
/usr/share/openssh/sshd_config
Include /etc/ssh/sshd_config.d/*.conf
KbdInteractiveAuthentication no
UsePAM yes
X11Forwarding yes
PrintMotd no
AcceptEnv LANG LC_*
Subsystem sftp /usr/lib/openssh/sftp-server

══╣ /etc/hosts.allow file found, trying to read the rules:
/etc/hosts.allow


Searching inside /etc/ssh/ssh_config for interesting info
Include /etc/ssh/ssh_config.d/*.conf
Host *
SendEnv LANG LC_*
HashKnownHosts yes
GSSAPIAuthentication yes

╔══════════╣ Analyzing PAM Auth Files (limit 70)
drwxr-xr-x 2 root root 4096 Jul 4 09:46 /etc/pam.d
-rw-r--r-- 1 root root 2133 Nov 23 2022 /etc/pam.d/sshd
account required pam_nologin.so
session [success=ok ignore=ignore module_unknown=ignore default=bad] pam_selinux.so close
session required pam_loginuid.so
session optional pam_keyinit.so force revoke
session optional pam_motd.so motd=/run/motd.dynamic
session optional pam_motd.so noupdate
session optional pam_mail.so standard noenv # [1]
session required pam_limits.so
session required pam_env.so # [1]
session required pam_env.so user_readenv=1 envfile=/etc/default/locale
session [success=ok ignore=ignore module_unknown=ignore default=bad] pam_selinux.so open


╔══════════╣ Analyzing FreeIPA Files (limit 70)
drwxr-xr-x 2 root root 4096 Apr 27 15:55 /usr/src/linux-headers-5.15.0-71/drivers/net/ipa





╔══════════╣ Searching tmux sessions
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#open-shell-sessions
tmux 3.2a


/tmp/tmux-1000
╔══════════╣ Analyzing Cloud Init Files (limit 70)
-rw-r--r-- 1 root root 3787 May 19 17:57 /snap/core20/1974/etc/cloud/cloud.cfg
lock_passwd: True

╔══════════╣ Analyzing Keyring Files (limit 70)
drwxr-xr-x 2 root root 4096 Jul 4 09:46 /etc/apt/keyrings
drwxr-xr-x 2 root root 200 Jun 22 12:46 /snap/core20/1974/usr/share/keyrings
drwxr-xr-x 2 root root 4096 Apr 27 16:11 /usr/share/keyrings




╔══════════╣ Searching uncommon passwd files (splunk)
passwd file: /etc/pam.d/passwd
passwd file: /etc/passwd
passwd file: /snap/core20/1974/etc/pam.d/passwd
passwd file: /snap/core20/1974/etc/passwd
passwd file: /snap/core20/1974/usr/share/bash-completion/completions/passwd
passwd file: /snap/core20/1974/usr/share/lintian/overrides/passwd
passwd file: /snap/core20/1974/var/lib/extrausers/passwd
passwd file: /usr/share/bash-completion/completions/passwd
passwd file: /usr/share/lintian/overrides/passwd

╔══════════╣ Analyzing Github Files (limit 70)

-rw-rw-r-- 1 maximus_supervisor maximus_supervisor 121 Jun 30 10:24 /home/maximus_supervisor/.gitconfig
[user]
name = maximus_supervisor
email = [email protected]
[safe]
directory = /home/maximus_supervisor/repo


drwxrwxr-x 8 maximus_supervisor maximus_supervisor 4096 Jul 4 09:46 /var/www/html/.git

╔══════════╣ Analyzing PGP-GPG Files (limit 70)
/usr/bin/gpg
netpgpkeys Not Found
netpgp Not Found

-rw-r--r-- 1 root root 2794 Mar 26 2021 /etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cdimage.gpg
-rw-r--r-- 1 root root 1733 Mar 26 2021 /etc/apt/trusted.gpg.d/ubuntu-keyring-2018-archive.gpg
-rw-r--r-- 1 root root 7399 Sep 17 2018 /snap/core20/1974/usr/share/keyrings/ubuntu-archive-keyring.gpg
-rw-r--r-- 1 root root 6713 Oct 27 2016 /snap/core20/1974/usr/share/keyrings/ubuntu-archive-removed-keys.gpg
-rw-r--r-- 1 root root 4097 Feb 6 2018 /snap/core20/1974/usr/share/keyrings/ubuntu-cloudimage-keyring.gpg
-rw-r--r-- 1 root root 0 Jan 17 2018 /snap/core20/1974/usr/share/keyrings/ubuntu-cloudimage-removed-keys.gpg
-rw-r--r-- 1 root root 1227 May 27 2010 /snap/core20/1974/usr/share/keyrings/ubuntu-master-keyring.gpg
-rw-r--r-- 1 root root 2899 Jul 4 2022 /usr/share/gnupg/distsigkey.gpg
-rw-r--r-- 1 root root 2247 Apr 5 15:14 /usr/share/keyrings/ubuntu-advantage-cc-eal.gpg
-rw-r--r-- 1 root root 2274 Apr 5 15:14 /usr/share/keyrings/ubuntu-advantage-cis.gpg
-rw-r--r-- 1 root root 2236 Apr 5 15:14 /usr/share/keyrings/ubuntu-advantage-esm-apps.gpg
-rw-r--r-- 1 root root 2264 Apr 5 15:14 /usr/share/keyrings/ubuntu-advantage-esm-infra-trusty.gpg
-rw-r--r-- 1 root root 2275 Apr 5 15:14 /usr/share/keyrings/ubuntu-advantage-fips.gpg
-rw-r--r-- 1 root root 2250 Apr 5 15:14 /usr/share/keyrings/ubuntu-advantage-realtime-kernel.gpg
-rw-r--r-- 1 root root 2235 Apr 5 15:14 /usr/share/keyrings/ubuntu-advantage-ros.gpg
-rw-r--r-- 1 root root 7399 Sep 17 2018 /usr/share/keyrings/ubuntu-archive-keyring.gpg
-rw-r--r-- 1 root root 6713 Oct 27 2016 /usr/share/keyrings/ubuntu-archive-removed-keys.gpg
-rw-r--r-- 1 root root 3023 Mar 26 2021 /usr/share/keyrings/ubuntu-cloudimage-keyring.gpg
-rw-r--r-- 1 root root 0 Jan 17 2018 /usr/share/keyrings/ubuntu-cloudimage-removed-keys.gpg
-rw-r--r-- 1 root root 1227 May 27 2010 /usr/share/keyrings/ubuntu-master-keyring.gpg
-rw-r--r-- 1 root root 2236 Apr 27 16:11 /var/lib/ubuntu-advantage/apt-esm/etc/apt/trusted.gpg.d/ubuntu-advantage-esm-apps.gpg


╔══════════╣ Checking if containerd(ctr) is available
https://book.hacktricks.xyz/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation
ctr was found in /usr/bin/ctr, you may be able to escalate privileges with it
ctr: failed to dial "/run/containerd/containerd.sock": connection error: desc = "transport: error while dialing: dial unix /run/containerd/containerd.sock: connect: permission denied"

╔══════════╣ Checking if runc is available
https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation
runc was found in /usr/sbin/runc, you may be able to escalate privileges with it

╔══════════╣ Searching docker files (limit 70)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation/docker-breakout/docker-breakout-privilege-escalation
lrwxrwxrwx 1 root root 33 Jun 30 06:31 /etc/systemd/system/sockets.target.wants/docker.socket -> /lib/systemd/system/docker.socket
-rw-r--r-- 1 root root 175 Jan 3 2023 /usr/lib/systemd/system/docker.socket
-rw-r--r-- 1 root root 0 Jun 30 06:31 /var/lib/systemd/deb-systemd-helper-enabled/sockets.target.wants/docker.socket


╔══════════╣ Analyzing Postfix Files (limit 70)
-rw-r--r-- 1 root root 813 Feb 2 2020 /snap/core20/1974/usr/share/bash-completion/completions/postfix

-rw-r--r-- 1 root root 761 Nov 15 2021 /usr/share/bash-completion/completions/postfix


╔══════════╣ Analyzing FTP Files (limit 70)



-rw-r--r-- 1 root root 69 Feb 22 22:56 /etc/php/8.1/mods-available/ftp.ini
-rw-r--r-- 1 root root 69 Feb 22 22:56 /usr/share/php8.1-common/common/ftp.ini






╔══════════╣ Analyzing DNS Files (limit 70)
-rw-r--r-- 1 root root 826 Nov 15 2021 /usr/share/bash-completion/completions/bind
-rw-r--r-- 1 root root 826 Nov 15 2021 /usr/share/bash-completion/completions/bind




╔══════════╣ Analyzing Windows Files (limit 70)






















lrwxrwxrwx 1 root root 24 Jul 3 08:12 /etc/mysql/my.cnf -> /etc/alternatives/my.cnf
-rw-r--r-- 1 root root 81 Jul 3 08:12 /var/lib/dpkg/alternatives/my.cnf





























╔══════════╣ Analyzing Other Interesting Files (limit 70)
-rw-r--r-- 1 root root 3771 Jan 6 2022 /etc/skel/.bashrc
-rw-r--r-- 1 maximus_supervisor maximus_supervisor 3771 Jun 30 09:38 /home/maximus_supervisor/.bashrc
-rw-r--r-- 1 root root 3771 Feb 25 2020 /snap/core20/1974/etc/skel/.bashrc



-rw------- 1 maximus_supervisor maximus_supervisor 20 Jul 4 05:25 /home/maximus_supervisor/.lesshst


-rw-r--r-- 1 root root 807 Jan 6 2022 /etc/skel/.profile
-rw-r--r-- 1 maximus_supervisor maximus_supervisor 807 Jun 30 09:38 /home/maximus_supervisor/.profile
-rw-r--r-- 1 root root 807 Feb 25 2020 /snap/core20/1974/etc/skel/.profile






╔════════════════════════════════════╗
══════════════════════╣ Files with Interesting Permissions ╠══════════════════════
╚════════════════════════════════════╝
╔══════════╣ SUID - Check easy privesc, exploits and write perms
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid
-rwsr-xr-x 1 root root 129K May 27 08:41 /snap/snapd/19457/usr/lib/snapd/snap-confine ---> Ubuntu_snapd<2.37_dirty_sock_Local_Privilege_Escalation(CVE-2019-7304)
-rwsr-xr-x 1 root root 84K Nov 29 2022 /snap/core20/1974/usr/bin/chfn ---> SuSE_9.3/10
-rwsr-xr-x 1 root root 52K Nov 29 2022 /snap/core20/1974/usr/bin/chsh
-rwsr-xr-x 1 root root 87K Nov 29 2022 /snap/core20/1974/usr/bin/gpasswd
-rwsr-xr-x 1 root root 55K May 30 15:42 /snap/core20/1974/usr/bin/mount ---> Apple_Mac_OSX(Lion)_Kernel_xnu-1699.32.7_except_xnu-1699.24.8
-rwsr-xr-x 1 root root 44K Nov 29 2022 /snap/core20/1974/usr/bin/newgrp ---> HP-UX_10.20
-rwsr-xr-x 1 root root 67K Nov 29 2022 /snap/core20/1974/usr/bin/passwd ---> Apple_Mac_OSX(03-2006)/Solaris_8/9(12-2004)/SPARC_8/9/Sun_Solaris_2.3_to_2.5.1(02-1997)
-rwsr-xr-x 1 root root 67K May 30 15:42 /snap/core20/1974/usr/bin/su
-rwsr-xr-x 1 root root 163K Apr 4 11:56 /snap/core20/1974/usr/bin/sudo ---> check_if_the_sudo_version_is_vulnerable
-rwsr-xr-x 1 root root 39K May 30 15:42 /snap/core20/1974/usr/bin/umount ---> BSD/Linux(08-1996)
-rwsr-xr-- 1 root systemd-resolve 51K Oct 25 2022 /snap/core20/1974/usr/lib/dbus-1.0/dbus-daemon-launch-helper
-rwsr-xr-x 1 root root 463K Apr 3 22:47 /snap/core20/1974/usr/lib/openssh/ssh-keysign
-rwsr-xr-x 1 root root 40K Nov 24 2022 /usr/bin/newgrp ---> HP-UX_10.20
-rwsr-xr-x 1 root root 71K Nov 24 2022 /usr/bin/gpasswd
-rwsr-xr-x 1 root root 55K Feb 21 2022 /usr/bin/su
-rwsr-xr-x 1 root root 35K Feb 21 2022 /usr/bin/umount ---> BSD/Linux(08-1996)
-rwsr-xr-x 1 root root 44K Nov 24 2022 /usr/bin/chsh
-rwsr-xr-x 1 root root 35K Mar 23 2022 /usr/bin/fusermount3
-rwsr-xr-x 1 root root 227K Apr 3 18:00 /usr/bin/sudo ---> check_if_the_sudo_version_is_vulnerable
-rwsr-xr-x 1 root root 59K Nov 24 2022 /usr/bin/passwd ---> Apple_Mac_OSX(03-2006)/Solaris_8/9(12-2004)/SPARC_8/9/Sun_Solaris_2.3_to_2.5.1(02-1997)
-rwsr-xr-x 1 root root 47K Feb 21 2022 /usr/bin/mount ---> Apple_Mac_OSX(Lion)_Kernel_xnu-1699.32.7_except_xnu-1699.24.8
-rwsr-xr-x 1 root root 72K Nov 24 2022 /usr/bin/chfn ---> SuSE_9.3/10
-rwsr-xr-- 1 root messagebus 35K Oct 25 2022 /usr/lib/dbus-1.0/dbus-daemon-launch-helper
-rwsr-xr-x 1 root root 136K Dec 1 2022 /usr/lib/snapd/snap-confine ---> Ubuntu_snapd<2.37_dirty_sock_Local_Privilege_Escalation(CVE-2019-7304)
-rwsr-xr-x 1 root root 331K Nov 23 2022 /usr/lib/openssh/ssh-keysign
-rwsr-xr-x 1 root root 19K Feb 26 2022 /usr/libexec/polkit-agent-helper-1

╔══════════╣ SGID
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid
-rwxr-sr-x 1 root shadow 83K Nov 29 2022 /snap/core20/1974/usr/bin/chage
-rwxr-sr-x 1 root shadow 31K Nov 29 2022 /snap/core20/1974/usr/bin/expiry
-rwxr-sr-x 1 root systemd-timesync 343K Apr 3 22:47 /snap/core20/1974/usr/bin/ssh-agent
-rwxr-sr-x 1 root tty 35K May 30 15:42 /snap/core20/1974/usr/bin/wall
-rwxr-sr-x 1 root shadow 43K Feb 2 09:22 /snap/core20/1974/usr/sbin/pam_extrausers_chkpwd
-rwxr-sr-x 1 root shadow 43K Feb 2 09:22 /snap/core20/1974/usr/sbin/unix_chkpwd
-rwxr-sr-x 1 root tty 23K Feb 21 2022 /usr/bin/wall
-rwxr-sr-x 1 root _ssh 287K Nov 23 2022 /usr/bin/ssh-agent
-rwxr-sr-x 1 root tty 23K Feb 21 2022 /usr/bin/write.ul (Unknown SGID binary)
-rwxr-sr-x 1 root shadow 23K Nov 24 2022 /usr/bin/expiry
-rwxr-sr-x 1 root crontab 39K Mar 23 2022 /usr/bin/crontab
-rwxr-sr-x 1 root shadow 71K Nov 24 2022 /usr/bin/chage
-rwxr-sr-x 1 root utmp 15K Mar 24 2022 /usr/lib/x86_64-linux-gnu/utempter/utempter
-rwxr-sr-x 1 root shadow 27K Feb 2 09:21 /usr/sbin/unix_chkpwd
-rwxr-sr-x 1 root shadow 23K Feb 2 09:21 /usr/sbin/pam_extrausers_chkpwd

╔══════════╣ Checking misconfigurations of ld.so
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#ld.so
/etc/ld.so.conf
Content of /etc/ld.so.conf:
include /etc/ld.so.conf.d/*.conf

/etc/ld.so.conf.d
/etc/ld.so.conf.d/fakeroot-x86_64-linux-gnu.conf
- /usr/lib/x86_64-linux-gnu/libfakeroot
/etc/ld.so.conf.d/libc.conf
- /usr/local/lib
/etc/ld.so.conf.d/x86_64-linux-gnu.conf
- /usr/local/lib/x86_64-linux-gnu
- /lib/x86_64-linux-gnu
- /usr/lib/x86_64-linux-gnu

/etc/ld.so.preload
╔══════════╣ Capabilities
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#capabilities
══╣ Current shell capabilities
CapInh: 0x0000000000000000=
CapPrm: 0x0000000000000000=
CapEff: 0x0000000000000000=
CapBnd: 0x000001ffffffffff=cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,cap_audit_read,cap_perfmon,cap_bpf,cap_checkpoint_restore
CapAmb: 0x0000000000000000=

══╣ Parent process capabilities
CapInh: 0x0000000000000000=
CapPrm: 0x0000000000000000=
CapEff: 0x0000000000000000=
CapBnd: 0x000001ffffffffff=cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,cap_audit_read,cap_perfmon,cap_bpf,cap_checkpoint_restore
CapAmb: 0x0000000000000000=


Files with capabilities (limited to 50):
/snap/core20/1974/usr/bin/ping cap_net_raw=ep
/usr/bin/mtr-packet cap_net_raw=ep
/usr/bin/ping cap_net_raw=ep
/usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-ptp-helper cap_net_bind_service,cap_net_admin=ep

╔══════════╣ Users with capabilities
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#capabilities

╔══════════╣ AppArmor binary profiles
-rw-r--r-- 1 root root 3500 Jan 31 19:07 sbin.dhclient
-rw-r--r-- 1 root root 3448 Mar 17 2022 usr.bin.man
-rw-r--r-- 1 root root 1518 Feb 10 18:14 usr.bin.tcpdump
-rw-r--r-- 1 root root 28486 Dec 1 2022 usr.lib.snapd.snap-confine.real
-rw-r--r-- 1 root root 2006 May 11 23:15 usr.sbin.mysqld
-rw-r--r-- 1 root root 1592 Nov 16 2021 usr.sbin.rsyslogd

╔══════════╣ Files with ACLs (limited to 50)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#acls
files with acls in searched folders Not Found

╔══════════╣ Files (scripts) in /etc/profile.d/
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#profiles-files
total 32
drwxr-xr-x 2 root root 4096 Jul 4 09:46 .
drwxr-xr-x 105 root root 4096 Jul 4 09:58 ..
-rw-r--r-- 1 root root 96 Oct 15 2021 01-locale-fix.sh
-rw-r--r-- 1 root root 1557 Feb 17 2020 Z97-byobu.sh
-rw-r--r-- 1 root root 835 Dec 1 2022 apps-bin-path.sh
-rw-r--r-- 1 root root 726 Nov 15 2021 bash_completion.sh
-rw-r--r-- 1 root root 1107 Mar 23 2022 gawk.csh
-rw-r--r-- 1 root root 757 Mar 23 2022 gawk.sh

╔══════════╣ Permissions in init, init.d, systemd, and rc.d
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#init-init-d-systemd-and-rc-d

═╣ Hashes inside passwd file? ........... No
═╣ Writable passwd file? ................ No
═╣ Credentials in fstab/mtab? ........... No
═╣ Can I read shadow files? ............. No
═╣ Can I read shadow plists? ............ No
═╣ Can I write shadow plists? ........... No
═╣ Can I read opasswd file? ............. No
═╣ Can I write in network-scripts? ...... No
═╣ Can I read root folder? .............. No

╔══════════╣ Searching root files in home dirs (limit 30)
/home/
/root/
/var/www
/var/www/html

╔══════════╣ Searching folders owned by me containing others files on it (limit 100)

╔══════════╣ Readable files belonging to root and readable by me but not world readable

╔══════════╣ Interesting writable files owned by me or writable by everyone (not in Home) (max 500)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-files
/dev/mqueue
/dev/shm
/home/maximus_supervisor
/run/lock
/run/screen
/snap/core20/1974/run/lock
/snap/core20/1974/tmp
/snap/core20/1974/var/tmp
/tmp
/tmp/linpeas.sh
/tmp/tmux-1000
/var/crash
/var/lib/php/sessions
/var/lib/php/sessions/sess_4ikv1aamiteg3aurv32939dgms
/var/tmp
/var/www/html/.git
/var/www/html/.git/COMMIT_EDITMSG
/var/www/html/.git/HEAD
/var/www/html/.git/branches
/var/www/html/.git/config
/var/www/html/.git/description
#)You_can_write_even_more_files_inside_last_directory

/var/www/html/.git/hooks/applypatch-msg.sample
/var/www/html/.git/hooks/commit-msg.sample
/var/www/html/.git/hooks/fsmonitor-watchman.sample
/var/www/html/.git/hooks/post-update.sample
/var/www/html/.git/hooks/pre-applypatch.sample
#)You_can_write_even_more_files_inside_last_directory

/var/www/html/.git/index
/var/www/html/.git/info
/var/www/html/.git/info/exclude
/var/www/html/.git/logs
/var/www/html/.git/logs/HEAD
/var/www/html/.git/logs/refs
/var/www/html/.git/logs/refs/heads
/var/www/html/.git/logs/refs/heads/master
/var/www/html/.git/objects
/var/www/html/.git/objects/09
/var/www/html/.git/objects/09/c25f1b3e7024f882461711e8483da18613331f
/var/www/html/.git/objects/0c
/var/www/html/.git/objects/0c/9630e5fb5a8eca82b0cf8c7ef7d64899185f0a
/var/www/html/.git/objects/1a
/var/www/html/.git/objects/1a/f1f52484455323b7ceecf3f145a475482b841e
/var/www/html/.git/objects/2a
/var/www/html/.git/objects/2a/e71d32b890edc67a820c3d9ffff418cb372561
/var/www/html/.git/objects/2c
/var/www/html/.git/objects/2c/2ed39df3a0c77f762af86f9a6a40ae567e2f20
/var/www/html/.git/objects/4d
/var/www/html/.git/objects/4d/c2f4f92e665d6628b28cefa00631271a570506
/var/www/html/.git/objects/51
/var/www/html/.git/objects/51/cd630faf190947eb3e8e0cbce4a8d9911e152c
/var/www/html/.git/objects/6d
/var/www/html/.git/objects/6d/99d3007b47069dc29b0e92233056e148c55c02
/var/www/html/.git/objects/77
/var/www/html/.git/objects/77/9fd8c0addcc233c71ae55b5d31108c2fac1f5a
/var/www/html/.git/objects/7e
/var/www/html/.git/objects/7e/13637ad2aac45133458a163326429b99790825
/var/www/html/.git/objects/80
/var/www/html/.git/objects/80/4adaddd95add15db577b95af144dff229fdac8
/var/www/html/.git/objects/8d
/var/www/html/.git/objects/8d/e0f0454018ef58c55796c83acd19bd873f44d0
/var/www/html/.git/objects/9c
/var/www/html/.git/objects/9c/b739e6e09e04bba0aa08b486f58923fb5db514
/var/www/html/.git/objects/a9
/var/www/html/.git/objects/a9/257fef04b544d4b78b5000d348eb3840dec021
/var/www/html/.git/objects/fd
/var/www/html/.git/objects/fd/2ffd54e0360d7c87e63310f2a958a7d78a0ab8
/var/www/html/.git/objects/info
/var/www/html/.git/objects/pack
/var/www/html/.git/refs
/var/www/html/.git/refs/heads
/var/www/html/.git/refs/heads/master
/var/www/html/.git/refs/tags
/var/www/html/images
/var/www/html/images/ico.ico
/var/www/html/index.html
/var/www/html/maximus-admin-panel
/var/www/html/maximus-admin-panel/dashboard.php
/var/www/html/maximus-admin-panel/db.php
/var/www/html/maximus-admin-panel/index.php
/var/www/html/maximus-admin-panel/uploads

╔══════════╣ Interesting GROUP writable files (not in Home) (max 500)
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-files
Group maximus_supervisor:
/var/lib/php/sessions
/var/www/html/.git
/var/www/html/.git/objects
/var/www/html/.git/objects/9c
/var/www/html/.git/objects/a9
/var/www/html/.git/objects/80
/var/www/html/.git/objects/6d
/var/www/html/.git/objects/2c
#)You_can_write_even_more_files_inside_last_directory

/var/www/html/.git/hooks
/var/www/html/.git/hooks/update.sample
/var/www/html/.git/hooks/post-update.sample
/var/www/html/.git/hooks/applypatch-msg.sample
/var/www/html/.git/hooks/fsmonitor-watchman.sample
/var/www/html/.git/hooks/pre-rebase.sample
#)You_can_write_even_more_files_inside_last_directory

/var/www/html/.git/index
/var/www/html/.git/branches
/var/www/html/.git/HEAD
/var/www/html/.git/refs
/var/www/html/.git/refs/tags
/var/www/html/.git/refs/heads
/var/www/html/.git/refs/heads/master
/var/www/html/.git/logs
/var/www/html/.git/logs/HEAD
/var/www/html/.git/logs/refs
/var/www/html/.git/logs/refs/heads
/var/www/html/.git/logs/refs/heads/master
/var/www/html/.git/COMMIT_EDITMSG
/var/www/html/.git/config
/var/www/html/.git/info
/var/www/html/.git/info/exclude
/var/www/html/.git/description
/var/www/html/maximus-admin-panel/uploads
/tmp/linpeas.sh



╔═════════════════════════╗
════════════════════════════╣ Other Interesting Files ╠════════════════════════════
╚═════════════════════════╝
╔══════════╣ .sh files in path
https://book.hacktricks.xyz/linux-hardening/privilege-escalation#script-binaries-in-path
/usr/local/bin/aws_zsh_completer.sh
/usr/bin/rescan-scsi-bus.sh
/usr/bin/gettext.sh

╔══════════╣ Executable files potentially added by user (limit 70)
2023-06-30+12:13:04.9755741330 /usr/local/bin/flask
2023-06-30+11:43:00.9801041630 /usr/local/bin/aws_zsh_completer.sh
2023-06-30+11:43:00.9801041630 /usr/local/bin/aws_completer
2023-06-30+11:43:00.9801041630 /usr/local/bin/aws_bash_completer
2023-06-30+11:43:00.9801041630 /usr/local/bin/aws.cmd
2023-06-30+11:43:00.9801041630 /usr/local/bin/aws
2023-06-30+11:42:59.5161048880 /usr/local/bin/rstpep2html.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2xml.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2xetex.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2s5.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2pseudoxml.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2odt_prepstyles.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2odt.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2man.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2latex.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2html5.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2html4.py
2023-06-30+11:42:59.5161048880 /usr/local/bin/rst2html.py
2023-06-30+11:42:59.4721049100 /usr/local/bin/jp.py
2023-06-30+11:42:59.4281049320 /usr/local/bin/pyrsa-verify
2023-06-30+11:42:59.4281049320 /usr/local/bin/pyrsa-sign
2023-06-30+11:42:59.4281049320 /usr/local/bin/pyrsa-priv2pub
2023-06-30+11:42:59.4281049320 /usr/local/bin/pyrsa-keygen
2023-06-30+11:42:59.4281049320 /usr/local/bin/pyrsa-encrypt
2023-06-30+11:42:59.4281049320 /usr/local/bin/pyrsa-decrypt
2023-04-27+15:41:36.7397629060 /etc/console-setup/cached_setup_terminal.sh
2023-04-27+15:41:36.7357629080 /etc/console-setup/cached_setup_keyboard.sh
2023-04-27+15:41:36.7357629080 /etc/console-setup/cached_setup_font.sh

╔══════════╣ Unexpected in /opt (usually empty)
total 12
drwxr-xr-x 3 root root 4096 Jul 4 09:46 .
drwxr-xr-x 19 root root 4096 Jul 4 09:46 ..
drwx--x--x 4 root root 4096 Jul 4 09:46 containerd

╔══════════╣ Unexpected in root

╔══════════╣ Modified interesting files in the last 5mins (limit 100)
/home/maximus_supervisor/.gnupg/pubring.kbx
/home/maximus_supervisor/.gnupg/trustdb.gpg
/var/log/syslog
/var/log/auth.log
/var/log/kern.log
/var/log/journal/97985f393ecf4d86b4acd0b422f7d8c8/user-1000.journal
/var/log/journal/97985f393ecf4d86b4acd0b422f7d8c8/system.journal


╔══════════╣ Files inside /home/maximus_supervisor (limit 20)
total 56
drwxr-x--- 5 maximus_supervisor maximus_supervisor 4096 Jul 17 16:26 .
drwxr-xr-x 3 root root 4096 Jul 4 09:46 ..
drwxrwxr-x 2 maximus_supervisor maximus_supervisor 4096 Jul 4 09:46 .aws
lrwxrwxrwx 1 maximus_supervisor maximus_supervisor 9 Jun 30 10:05 .bash_history -> /dev/null
-rw-r--r-- 1 maximus_supervisor maximus_supervisor 220 Jun 30 09:38 .bash_logout
-rw-r--r-- 1 maximus_supervisor maximus_supervisor 3771 Jun 30 09:38 .bashrc
-rw-rw-r-- 1 maximus_supervisor maximus_supervisor 121 Jun 30 10:24 .gitconfig
drwx------ 3 maximus_supervisor maximus_supervisor 4096 Jul 17 16:26 .gnupg
-rw------- 1 maximus_supervisor maximus_supervisor 20 Jul 4 05:25 .lesshst
drwxrwxr-x 3 maximus_supervisor maximus_supervisor 4096 Jul 4 09:46 .local
-rw-r--r-- 1 maximus_supervisor maximus_supervisor 807 Jun 30 09:38 .profile
-rw-r--r-- 1 maximus_supervisor maximus_supervisor 928 Jun 30 08:39 cf.yaml
-rw-r--r-- 1 maximus_supervisor maximus_supervisor 1627 Jun 30 09:48 new.yaml
-rw-r--r-- 1 maximus_supervisor maximus_supervisor 2671 Jun 30 08:12 new_agent.py
-rw-r--r-- 1 maximus_supervisor maximus_supervisor 2582 Jun 30 08:19 ssm_agent.py

╔══════════╣ Files inside others home (limit 20)
/var/www/html/index.html
/var/www/html/.git/objects/9c/b739e6e09e04bba0aa08b486f58923fb5db514
/var/www/html/.git/objects/a9/257fef04b544d4b78b5000d348eb3840dec021
/var/www/html/.git/objects/80/4adaddd95add15db577b95af144dff229fdac8
/var/www/html/.git/objects/6d/99d3007b47069dc29b0e92233056e148c55c02
/var/www/html/.git/objects/2c/2ed39df3a0c77f762af86f9a6a40ae567e2f20
/var/www/html/.git/objects/4d/c2f4f92e665d6628b28cefa00631271a570506
/var/www/html/.git/objects/fd/2ffd54e0360d7c87e63310f2a958a7d78a0ab8
/var/www/html/.git/objects/7e/13637ad2aac45133458a163326429b99790825
/var/www/html/.git/objects/09/c25f1b3e7024f882461711e8483da18613331f
/var/www/html/.git/objects/77/9fd8c0addcc233c71ae55b5d31108c2fac1f5a
/var/www/html/.git/objects/51/cd630faf190947eb3e8e0cbce4a8d9911e152c
/var/www/html/.git/objects/0c/9630e5fb5a8eca82b0cf8c7ef7d64899185f0a
/var/www/html/.git/objects/1a/f1f52484455323b7ceecf3f145a475482b841e
/var/www/html/.git/objects/2a/e71d32b890edc67a820c3d9ffff418cb372561
/var/www/html/.git/objects/8d/e0f0454018ef58c55796c83acd19bd873f44d0
/var/www/html/.git/hooks/update.sample
/var/www/html/.git/hooks/post-update.sample
/var/www/html/.git/hooks/applypatch-msg.sample
/var/www/html/.git/hooks/fsmonitor-watchman.sample

╔══════════╣ Searching installed mail applications

╔══════════╣ Mails (limit 50)

╔══════════╣ Backup files (limited 100)
-rw-r--r-- 1 root root 2403 Feb 17 17:23 /etc/apt/sources.list.curtin.old
-rw-r--r-- 1 root root 61 Feb 17 17:22 /var/lib/systemd/deb-systemd-helper-enabled/dpkg-db-backup.timer.dsh-also
-rw-r--r-- 1 root root 0 Feb 17 17:19 /var/lib/systemd/deb-systemd-helper-enabled/timers.target.wants/dpkg-db-backup.timer
-rwxr-xr-x 1 root root 1086 Oct 31 2021 /usr/src/linux-headers-5.15.0-71/tools/testing/selftests/net/tcp_fastopen_backup_key.sh
-rw-r--r-- 1 root root 678 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/emr/schedule-hbase-backup.rst
-rw-r--r-- 1 root root 1760 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/rds/start-db-instance-automated-backups-replication.rst
-rw-r--r-- 1 root root 1837 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/rds/stop-db-instance-automated-backups-replication.rst
-rw-r--r-- 1 root root 1722 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/rds/delete-db-instance-automated-backup.rst
-rw-r--r-- 1 root root 1870 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/rds/describe-db-instance-automated-backups.rst
-rw-r--r-- 1 root root 907 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/backup/get-backup-plan-from-template.rst
-rw-r--r-- 1 root root 3345 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/backup/list-backup-jobs.rst
-rw-r--r-- 1 root root 921 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/backup/create-backup-plan.rst
-rw-r--r-- 1 root root 607 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/backup/create-backup-vault.rst
-rw-r--r-- 1 root root 1326 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/backup/get-backup-plan.rst
-rwxr-xr-x 1 root root 908 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/dynamodb/update-continuous-backups.rst
-rwxr-xr-x 1 root root 1893 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/dynamodb/delete-backup.rst
-rwxr-xr-x 1 root root 2219 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/dynamodb/restore-table-from-backup.rst
-rwxr-xr-x 1 root root 1935 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/dynamodb/describe-backup.rst
-rwxr-xr-x 1 root root 745 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/dynamodb/describe-continuous-backups.rst
-rwxr-xr-x 1 root root 860 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/dynamodb/create-backup.rst
-rw-r--r-- 1 root root 7556 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/dynamodb/list-backups.rst
-rw-r--r-- 1 root root 1703 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/opsworkscm/describe-backups.rst
-rw-r--r-- 1 root root 746 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/opsworkscm/delete-backup.rst
-rw-r--r-- 1 root root 1864 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/opsworkscm/create-backup.rst
-rw-r--r-- 1 root root 1802 Aug 15 2022 /usr/lib/python3/dist-packages/sos/report/plugins/ovirt_engine_backup.py
-rw-r--r-- 1 root root 1423 Feb 17 17:24 /usr/lib/python3/dist-packages/sos/report/plugins/__pycache__/ovirt_engine_backup.cpython-310.pyc
-rw-r--r-- 1 root root 13057 Apr 18 08:37 /usr/lib/modules/5.15.0-71-generic/kernel/drivers/net/team/team_mode_activebackup.ko
-rw-r--r-- 1 root root 10849 Apr 18 08:37 /usr/lib/modules/5.15.0-71-generic/kernel/drivers/power/supply/wm831x_backup.ko
-rw-r--r-- 1 root root 138 Dec 5 2021 /usr/lib/systemd/system/dpkg-db-backup.timer
-rw-r--r-- 1 root root 147 Dec 5 2021 /usr/lib/systemd/system/dpkg-db-backup.service
-rw-r--r-- 1 root root 39456 May 11 23:15 /usr/lib/mysql/plugin/component_mysqlbackup.so
-rw-r--r-- 1 root root 44008 Sep 19 2022 /usr/lib/x86_64-linux-gnu/open-vm-tools/plugins/vmsvc/libvmbackup.so
-rw-r--r-- 1 root root 2747 Feb 16 2022 /usr/share/man/man8/vgcfgbackup.8.gz
-rw-r--r-- 1 root root 416107 Dec 21 2020 /usr/share/doc/manpages/Changes.old.gz
-rw-r--r-- 1 root root 7867 Jul 16 1996 /usr/share/doc/telnet/README.old.gz
-rw-r--r-- 1 root root 11033 Apr 27 15:55 /usr/share/info/dir.old
-rwxr-xr-x 1 root root 226 Feb 17 2020 /usr/share/byobu/desktop/byobu.desktop.old
-rwxr-xr-x 1 root root 2196 May 25 2022 /usr/libexec/dpkg/dpkg-db-backup
-rw-r--r-- 1 root root 4096 Jul 17 16:26 /sys/devices/virtual/net/veth8ca78ed/brport/backup_port

╔══════════╣ Searching tables inside readable .db/.sql/.sqlite files (limit 100)
Found /var/lib/PackageKit/transactions.db: SQLite 3.x database, last written using SQLite version 3037002, file counter 5, database pages 8, cookie 0x4, schema 4, UTF-8, version-valid-for 5
Found /var/lib/command-not-found/commands.db: SQLite 3.x database, last written using SQLite version 3037002, file counter 5, database pages 832, cookie 0x4, schema 4, UTF-8, version-valid-for 5
Found /var/lib/fwupd/pending.db: SQLite 3.x database, last written using SQLite version 3037002, file counter 3, database pages 6, cookie 0x5, schema 4, UTF-8, version-valid-for 3

-> Extracting tables from /var/lib/PackageKit/transactions.db (limit 20)
-> Extracting tables from /var/lib/command-not-found/commands.db (limit 20)
-> Extracting tables from /var/lib/fwupd/pending.db (limit 20)

╔══════════╣ Web files?(output limit)
/var/www/:
total 12K
drwxr-xr-x 3 root root 4.0K Jun 30 09:59 .
drwxr-xr-x 14 root root 4.0K Jun 30 09:59 ..
drwxr-xr-x 5 root root 4.0K Jul 4 09:46 html

/var/www/html:
total 32K
drwxr-xr-x 5 root root 4.0K Jul 4 09:46 .
drwxr-xr-x 3 root root 4.0K Jun 30 09:59 ..

╔══════════╣ All relevant hidden files (not in /sys/ or the ones listed in the previous check) (limit 70)
-rw------- 1 root root 0 Jun 22 04:33 /snap/core20/1974/etc/.pwd.lock
-rw-r--r-- 1 root root 220 Feb 25 2020 /snap/core20/1974/etc/skel/.bash_logout
-rw------- 1 root root 0 Jul 17 13:52 /run/snapd/lock/.lock
-rw-r--r-- 1 root root 0 Jul 17 13:52 /run/ubuntu-fan/.lock
-rw-r--r-- 1 root root 0 Jul 17 13:52 /run/network/.ifstate.lock
-rw-r--r-- 1 root root 220 Jan 6 2022 /etc/skel/.bash_logout
-rw------- 1 root root 0 Feb 17 17:19 /etc/.pwd.lock
-rw-r--r-- 1 maximus_supervisor maximus_supervisor 220 Jun 30 09:38 /home/maximus_supervisor/.bash_logout
-rw-r--r-- 1 landscape landscape 0 Feb 17 17:24 /var/lib/landscape/.cleanup.user

╔══════════╣ Readable files inside /tmp, /var/tmp, /private/tmp, /private/var/at/tmp, /private/var/tmp, and backup folders (limit 70)
-rwxrwxrwx 1 maximus_supervisor maximus_supervisor 836190 Jul 2 04:28 /tmp/linpeas.sh
-rw-r--r-- 1 root root 907 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/backup/get-backup-plan-from-template.rst
-rw-r--r-- 1 root root 3345 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/backup/list-backup-jobs.rst
-rw-r--r-- 1 root root 921 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/backup/create-backup-plan.rst
-rw-r--r-- 1 root root 607 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/backup/create-backup-vault.rst
-rw-r--r-- 1 root root 1326 Jun 30 11:43 /usr/local/lib/python3.10/dist-packages/awscli/examples/backup/get-backup-plan.rst
-rw-r--r-- 1 root root 44 Jun 30 11:42 /usr/local/lib/python3.10/dist-packages/botocore/data/backup/2018-11-15/examples-1.json
-rw-r--r-- 1 root root 1288 Jun 30 11:42 /usr/local/lib/python3.10/dist-packages/botocore/data/backup/2018-11-15/endpoint-rule-set-1.json.gz
-rw-r--r-- 1 root root 2315 Jun 30 11:42 /usr/local/lib/python3.10/dist-packages/botocore/data/backup/2018-11-15/paginators-1.json
-rw-r--r-- 1 root root 288020 Jun 30 11:42 /usr/local/lib/python3.10/dist-packages/botocore/data/backup/2018-11-15/service-2.json
-rw-r--r-- 1 root root 51200 Jul 1 00:00 /var/backups/alternatives.tar.0
-rw-r--r-- 1 root root 32 Jul 1 00:00 /var/backups/dpkg.arch.1.gz
-rw-r--r-- 1 root root 0 Jul 4 00:00 /var/backups/dpkg.arch.0

╔══════════╣ Searching passwords in history files

╔══════════╣ Searching passwords in config PHP files
$password = "dbpass";

╔══════════╣ Searching *password* or *credential* files in home (limit 70)
/etc/pam.d/common-password
/home/maximus_supervisor/.aws/credentials
/usr/bin/systemd-ask-password
/usr/bin/systemd-tty-ask-password-agent
/usr/lib/git-core/git-credential
/usr/lib/git-core/git-credential-cache
/usr/lib/git-core/git-credential-cache--daemon
/usr/lib/git-core/git-credential-store
#)There are more creds/passwds files in the previous parent folder

/usr/lib/grub/i386-pc/password.mod
/usr/lib/grub/i386-pc/password_pbkdf2.mod
/usr/lib/mysql/plugin/component_validate_password.so
/usr/lib/mysql/plugin/validate_password.so
/usr/lib/python3/dist-packages/docker/credentials
/usr/lib/python3/dist-packages/keyring/__pycache__/credentials.cpython-310.pyc
/usr/lib/python3/dist-packages/keyring/credentials.py
/usr/lib/python3/dist-packages/launchpadlib/__pycache__/credentials.cpython-310.pyc
/usr/lib/python3/dist-packages/launchpadlib/credentials.py
/usr/lib/python3/dist-packages/launchpadlib/tests/__pycache__/test_credential_store.cpython-310.pyc
/usr/lib/python3/dist-packages/launchpadlib/tests/test_credential_store.py
/usr/lib/python3/dist-packages/oauthlib/oauth2/rfc6749/grant_types/__pycache__/client_credentials.cpython-310.pyc
/usr/lib/python3/dist-packages/oauthlib/oauth2/rfc6749/grant_types/__pycache__/resource_owner_password_credentials.cpython-310.pyc
/usr/lib/python3/dist-packages/oauthlib/oauth2/rfc6749/grant_types/client_credentials.py
/usr/lib/python3/dist-packages/oauthlib/oauth2/rfc6749/grant_types/resource_owner_password_credentials.py
/usr/lib/python3/dist-packages/twisted/cred/__pycache__/credentials.cpython-310.pyc
/usr/lib/python3/dist-packages/twisted/cred/credentials.py
/usr/lib/systemd/system/multi-user.target.wants/systemd-ask-password-wall.path
/usr/lib/systemd/system/sysinit.target.wants/systemd-ask-password-console.path
/usr/lib/systemd/system/systemd-ask-password-console.path
/usr/lib/systemd/system/systemd-ask-password-console.service
/usr/lib/systemd/system/systemd-ask-password-plymouth.path
/usr/lib/systemd/system/systemd-ask-password-plymouth.service
#)There are more creds/passwds files in the previous parent folder

/usr/local/lib/python3.10/dist-packages/awscli/customizations/ec2/__pycache__/decryptpassword.cpython-310.pyc
/usr/local/lib/python3.10/dist-packages/awscli/customizations/ec2/decryptpassword.py
/usr/local/lib/python3.10/dist-packages/awscli/examples/chime/delete-voice-connector-termination-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/chime/list-voice-connector-termination-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/chime/put-voice-connector-termination-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/codebuild/delete-source-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/codebuild/import-source-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/codebuild/list-source-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/codecommit/credential-helper.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/cognito-idp/admin-reset-user-password.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/cognito-idp/change-password.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/cognito-idp/confirm-forgot-password.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/cognito-idp/forgot-password.rst
#)There are more creds/passwds files in the previous parent folder

/usr/local/lib/python3.10/dist-packages/awscli/examples/ec2/wait/password-data-available.rst

╔══════════╣ Checking for TTY (sudo/su) passwords in audit logs

╔══════════╣ Searching passwords inside logs (limit 70)



╔════════════════╗
════════════════════════════════╣ API Keys Regex ╠════════════════════════════════
╚════════════════╝
Regexes to search for API keys aren't activated, use param '-r'