╔═══════════════════╗ ═══════════════════════════════╣ Basic information ╠═══════════════════════════════ ╚═══════════════════╝
OS: Linux version 5.15.0-71-generic (buildd@lcy02-amd64-044) (gcc (Ubuntu 11.3.0-1ubuntu1~22.04.1) 11.3.0, GNU ld (GNU Binutils for Ubuntu) 2.38) #78-Ubuntu SMP Tue Apr 18 09:00:29 UTC 2023
User & Groups: uid=1000(maximus_supervisor) gid=1000(maximus_supervisor) groups=1000(maximus_supervisor)
Hostname: emit
Writable folder: /dev/shm [+] /usr/bin/ping is available for network discovery (linpeas can discover hosts, learn more with -h) [+] /usr/bin/bash is available for network discovery, port scanning and port forwarding (linpeas can discover hosts, scan ports, and forward ports. Learn more with -h) [+] /usr/bin/nc is available for network discovery & port scanning (linpeas can discover hosts and scan ports, learn more with -h)
╔══════════╣ Searching Signature verification failed in dmesg ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#dmesg-signature-verification-failed dmesg Not Found
Details: https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html
Exposure: less probable
Tags: ubuntu=20.04{kernel:5.8.0-*}
Download URL: https://raw.githubusercontent.com/google/security-research/master/pocs/linux/cve-2021-22555/exploit.c
ext-url: https://raw.githubusercontent.com/bcoles/kernel-exploits/master/CVE-2021-22555/exploit.c
Comments: ip_tables kernel module must be loaded
[+] [CVE-2017-5618] setuid screen v4.5.0 LPE
Details: https://seclists.org/oss-sec/2017/q1/184
Exposure: less probable
Download URL: https://www.exploit-db.com/download/https://www.exploit-db.com/exploits/41154
╔══════════╣ Executing Linux Exploit Suggester 2 ╚ https://github.com/jondonas/linux-exploit-suggester-2
╔══════════╣ Protections ═╣ AppArmor enabled? .............. You do not have enough privilege to read the profile set.
apparmor module is loaded. ═╣ AppArmor profile? .............. unconfined ═╣ is linuxONE? ................... s390x Not Found ═╣ grsecurity present? ............ grsecurity Not Found ═╣ PaX bins present? .............. PaX Not Found ═╣ Execshield enabled? ............ Execshield Not Found ═╣ SELinux enabled? ............... sestatus Not Found ═╣ Seccomp enabled? ............... enabled ═╣ User namespace? ................ enabled ═╣ Cgroup2 enabled? ............... enabled ═╣ Is ASLR enabled? ............... Yes ═╣ Printer? ....................... No ═╣ Is this a virtual machine? ..... Yes (vmware)
╔═══════════╗ ═══════════════════════════════════╣ Container ╠═══════════════════════════════════ ╚═══════════╝ ╔══════════╣ Container related tools present (if any):
/usr/bin/docker
/usr/sbin/runc ╔══════════╣ Am I Containered? ╔══════════╣ Container details ═╣ Is this a container? ...........No ═╣ Any running containers? ........ No
╔═══════╗ ═════════════════════════════════════╣ Cloud ╠═════════════════════════════════════ ╚═══════╝ ═╣ Google Cloud Platform? ............... No ═╣ AWS ECS? ............................. No ═╣ AWS EC2? ............................. No ═╣ AWS EC2 Beanstalk? ................... No ═╣ AWS Lambda? .......................... No ═╣ AWS Codebuild? ....................... No ═╣ DO Droplet? .......................... No ═╣ IBM Cloud VM? ........................ No ═╣ Azure VM? ............................ No ═╣ Azure APP? ........................... No
╔══════════╣ Binary processes permissions (non 'root root' and not belonging to current user) ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#processes
╔══════════╣ Processes whose PPID belongs to a different user (not root) ╚ You will know if a user can somehow spawn processes as a different user
Proc 494 with ppid 1 is run by user systemd-timesync but the ppid user is root
Proc 524 with ppid 1 is run by user systemd-network but the ppid user is root
Proc 541 with ppid 1 is run by user systemd-resolve but the ppid user is root
Proc 749 with ppid 1 is run by user messagebus but the ppid user is root
Proc 758 with ppid 1 is run by user syslog but the ppid user is root
Proc 1173 with ppid 1 is run by user mysql but the ppid user is root
Proc 1683 with ppid 1677 is run by user 1001 but the ppid user is root
Proc 17808 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17835 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17899 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17903 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17952 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17984 with ppid 1163 is run by user www-data but the ppid user is root
Proc 17987 with ppid 1163 is run by user www-data but the ppid user is root
Proc 18019 with ppid 1163 is run by user www-data but the ppid user is root
Proc 18034 with ppid 1163 is run by user www-data but the ppid user is root
Proc 18109 with ppid 1163 is run by user www-data but the ppid user is root
Proc 22631 with ppid 1 is run by user maximus_supervisor but the ppid user is root
╔══════════╣ Files opened by processes belonging to other users ╚ This is usually empty because of the lack of privileges to read other user processes information
COMMAND PID TID TASKCMD USER FD TYPE DEVICE SIZE/OFF NODE NAME
╔══════════╣ Processes with credentials in memory (root req) ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#credentials-from-process-memory gdm-password Not Found gnome-keyring-daemon Not Found lightdm Not Found vsftpd Not Found apache2 process found (dump creds from memory as root) sshd: process found (dump creds from memory as root)
╔══════════╣ Cron jobs ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#scheduled-cron-jobs
/usr/bin/crontab incrontab Not Found
-rw-r--r-- 1 root root 1136 Mar 23 2022 /etc/crontab
╔══════════╣ Analyzing .service files ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#services
/etc/systemd/system/multi-user.target.wants/grub-common.service could be executing some relative path
/etc/systemd/system/multi-user.target.wants/systemd-networkd.service could be executing some relative path
/etc/systemd/system/sleep.target.wants/grub-common.service could be executing some relative path You can't write on systemd PATH
╔══════════╣ System timers ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#timers
NEXT LEFT LAST PASSED UNIT ACTIVATES
Mon 2023-07-17 16:39:00 UTC 12min left Mon 2023-07-17 16:09:05 UTC 17min ago phpsessionclean.timer phpsessionclean.service
Mon 2023-07-17 19:47:48 UTC 3h 21min left Tue 2023-07-04 00:24:16 UTC 1 week 6 days ago apt-daily.timer apt-daily.service
Mon 2023-07-17 21:01:38 UTC 4h 35min left Mon 2023-07-17 14:27:25 UTC 1h 58min ago ua-timer.timer ua-timer.service
Mon 2023-07-17 22:38:33 UTC 6h left Tue 2023-07-04 05:48:37 UTC 1 week 6 days ago man-db.timer man-db.service
Tue 2023-07-18 00:00:00 UTC 7h left n/a n/a dpkg-db-backup.timer dpkg-db-backup.service
Tue 2023-07-18 00:00:00 UTC 7h left Mon 2023-07-17 13:52:19 UTC 2h 34min ago logrotate.timer logrotate.service
Tue 2023-07-18 01:16:55 UTC 8h left Mon 2023-07-03 21:20:42 UTC 1 week 6 days ago fwupd-refresh.timer fwupd-refresh.service
Tue 2023-07-18 02:27:12 UTC 10h left Mon 2023-07-17 14:35:05 UTC 1h 51min ago motd-news.timer motd-news.service
Tue 2023-07-18 06:56:07 UTC 14h left Mon 2023-07-17 14:27:09 UTC 1h 59min ago apt-daily-upgrade.timer apt-daily-upgrade.service
Tue 2023-07-18 13:57:16 UTC 21h left Mon 2023-07-17 13:57:16 UTC 2h 29min ago update-notifier-download.timer update-notifier-download.service
Tue 2023-07-18 14:07:16 UTC 21h left Mon 2023-07-17 14:07:16 UTC 2h 19min ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service
Thu 2023-07-20 01:48:52 UTC 2 days left Sun 2023-07-02 06:00:53 UTC 2 weeks 1 day ago update-notifier-motd.timer update-notifier-motd.service
Sun 2023-07-23 03:10:00 UTC 5 days left Mon 2023-07-17 13:52:48 UTC 2h 33min ago e2scrub_all.timer e2scrub_all.service
Mon 2023-07-24 01:36:54 UTC 6 days left Mon 2023-07-17 15:09:52 UTC 1h 16min ago fstrim.timer fstrim.service
n/a n/a n/a n/a apport-autoreport.timer apport-autoreport.service
n/a n/a n/a n/a snapd.snap-repair.timer snapd.snap-repair.service
╔══════════╣ Analyzing .socket files ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sockets
/etc/systemd/system/sockets.target.wants/uuidd.socket is calling this writable listener: /run/uuidd/request
/snap/core20/1974/usr/lib/systemd/system/dbus.socket is calling this writable listener: /var/run/dbus/system_bus_socket
/snap/core20/1974/usr/lib/systemd/system/sockets.target.wants/dbus.socket is calling this writable listener: /var/run/dbus/system_bus_socket
/snap/core20/1974/usr/lib/systemd/system/sockets.target.wants/systemd-journald-dev-log.socket is calling this writable listener: /run/systemd/journal/dev-log
/snap/core20/1974/usr/lib/systemd/system/sockets.target.wants/systemd-journald.socket is calling this writable listener: /run/systemd/journal/stdout
/snap/core20/1974/usr/lib/systemd/system/sockets.target.wants/systemd-journald.socket is calling this writable listener: /run/systemd/journal/socket
/snap/core20/1974/usr/lib/systemd/system/syslog.socket is calling this writable listener: /run/systemd/journal/syslog
/snap/core20/1974/usr/lib/systemd/system/systemd-journald-dev-log.socket is calling this writable listener: /run/systemd/journal/dev-log
/snap/core20/1974/usr/lib/systemd/system/systemd-journald.socket is calling this writable listener: /run/systemd/journal/stdout
/snap/core20/1974/usr/lib/systemd/system/systemd-journald.socket is calling this writable listener: /run/systemd/journal/socket
/usr/lib/systemd/system/dbus.socket is calling this writable listener: /run/dbus/system_bus_socket
/usr/lib/systemd/system/sockets.target.wants/dbus.socket is calling this writable listener: /run/dbus/system_bus_socket
/usr/lib/systemd/system/sockets.target.wants/systemd-journald-dev-log.socket is calling this writable listener: /run/systemd/journal/dev-log
/usr/lib/systemd/system/sockets.target.wants/systemd-journald.socket is calling this writable listener: /run/systemd/journal/socket
/usr/lib/systemd/system/sockets.target.wants/systemd-journald.socket is calling this writable listener: /run/systemd/journal/stdout
/usr/lib/systemd/system/syslog.socket is calling this writable listener: /run/systemd/journal/syslog
╔══════════╣ D-Bus config files ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#d-bus
Possible weak user policy found on /etc/dbus-1/system.d/dnsmasq.conf ( dnsmasq">)
Possible weak user policy found on /etc/dbus-1/system.d/org.freedesktop.thermald.conf ( )
╔═══════════════════╗ ═══════════════════════════════╣ Users Information ╠═══════════════════════════════ ╚═══════════════════╝ ╔══════════╣ My user ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#users
uid=1000(maximus_supervisor) gid=1000(maximus_supervisor) groups=1000(maximus_supervisor)
╔══════════╣ Do I have PGP keys?
/usr/bin/gpg netpgpkeys Not Found netpgp Not Found
╔══════════╣ Checking 'sudo -l', /etc/sudoers, and /etc/sudoers.d ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid
╔══════════╣ Login now
16:26:25 up 2:34, 0 users, load average: 0.10, 0.04, 0.01
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
╔══════════╣ Last logons
reboot system boot Mon Jul 17 13:52:16 2023 still running 0.0.0.0
wtmp begins Mon Jul 17 13:52:16 2023
╔══════════╣ Last time logon each user
Username Port From Latest
╔══════════╣ Do not forget to test 'su' as any other user with shell: without password and with their names as password (I don't do it in FAST mode...)
╔══════════╣ Do not forget to execute 'sudo -l' without password or with valid password (if you know it)!!
╔══════════╣ Installed Compilers
ii g++ 4:11.2.0-1ubuntu1 amd64 GNU C++ compiler
ii g++-11 11.3.0-1ubuntu1~22.04.1 amd64 GNU C++ compiler
ii gcc 4:11.2.0-1ubuntu1 amd64 GNU C compiler
ii gcc-11 11.3.0-1ubuntu1~22.04.1 amd64 GNU C compiler
ii rpcsvc-proto 1.4.2-0ubuntu6 amd64 RPC protocol compiler and definitions
/usr/bin/gcc
╔══════════╣ MySQL version
mysql Ver 8.0.33-0ubuntu0.22.04.2 for Linux on x86_64 ((Ubuntu))
═╣ MySQL connection using default root/root ........... No ═╣ MySQL connection using root/toor ................... No ═╣ MySQL connection using root/NOPASS ................. No
╔══════════╣ Searching mysql credentials and exec
From '/etc/mysql/mysql.conf.d/mysqld.cnf' Mysql user: user = mysql
Found readable /etc/mysql/my.cnf
!includedir /etc/mysql/conf.d/
!includedir /etc/mysql/mysql.conf.d/
╔══════════╣ Analyzing Apache-Nginx Files (limit 70)
Apache version: Server version: Apache/2.4.52 (Ubuntu)
Server built: 2023-03-01T22:43:55 httpd Not Found
-rw-r--r-- 1 root root 72928 Feb 22 22:56 /etc/php/8.1/apache2/php.ini
allow_url_fopen = On
allow_url_include = Off
odbc.allow_persistent = On
mysqli.allow_persistent = On
pgsql.allow_persistent = On
-rw-r--r-- 1 root root 72924 Feb 22 22:56 /etc/php/8.1/cli/php.ini
allow_url_fopen = On
allow_url_include = Off
odbc.allow_persistent = On
mysqli.allow_persistent = On
pgsql.allow_persistent = On
╔══════════╣ Analyzing Rsync Files (limit 70)
-rw-r--r-- 1 root root 1044 Oct 11 2022 /usr/share/doc/rsync/examples/rsyncd.conf
[ftp]
comment = public archive
path = /var/www/pub
use chroot = yes
lock file = /var/lock/rsyncd
read only = yes
list = yes
uid = nobody
gid = nogroup
strict modes = yes
ignore errors = no
ignore nonreadable = yes
transfer logging = no
timeout = 600
refuse options = checksum dry-run
dont compress = *.gz *.tgz *.zip *.z *.rpm *.deb *.iso *.bz2 *.tbz
╔══════════╣ Analyzing Ldap Files (limit 70)
The password hash is from the {SSHA} to 'structural'
drwxr-xr-x 2 root root 4096 Jul 4 09:46 /etc/ldap
══╣ Writable ssh and gpg agents
/etc/systemd/user/sockets.target.wants/gpg-agent-ssh.socket
/etc/systemd/user/sockets.target.wants/gpg-agent-extra.socket
/etc/systemd/user/sockets.target.wants/gpg-agent.socket
/etc/systemd/user/sockets.target.wants/gpg-agent-browser.socket ══╣ Some home ssh config file was found /usr/share/openssh/sshd_config
Include /etc/ssh/sshd_config.d/*.conf
KbdInteractiveAuthentication no
UsePAM yes
X11Forwarding yes
PrintMotd no
AcceptEnv LANG LC_*
Subsystem sftp /usr/lib/openssh/sftp-server
══╣ /etc/hosts.allow file found, trying to read the rules:
/etc/hosts.allow
Searching inside /etc/ssh/ssh_config for interesting info
Include /etc/ssh/ssh_config.d/*.conf Host *
SendEnv LANG LC_*
HashKnownHosts yes
GSSAPIAuthentication yes
╔══════════╣ Checking if containerd(ctr) is available ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation ctr was found in /usr/bin/ctr, you may be able to escalate privileges with it
ctr: failed to dial "/run/containerd/containerd.sock": connection error: desc = "transport: error while dialing: dial unix /run/containerd/containerd.sock: connect: permission denied"
╔══════════╣ Checking if runc is available ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation runc was found in /usr/sbin/runc, you may be able to escalate privileges with it
╔══════════╣ Checking misconfigurations of ld.so ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#ld.so /etc/ld.so.conf
Content of /etc/ld.so.conf:
include /etc/ld.so.conf.d/*.conf
Files with capabilities (limited to 50):
/snap/core20/1974/usr/bin/ping cap_net_raw=ep
/usr/bin/mtr-packet cap_net_raw=ep
/usr/bin/ping cap_net_raw=ep
/usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-ptp-helper cap_net_bind_service,cap_net_admin=ep
╔══════════╣ Users with capabilities ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#capabilities
╔══════════╣ AppArmor binary profiles
-rw-r--r-- 1 root root 3500 Jan 31 19:07 sbin.dhclient
-rw-r--r-- 1 root root 3448 Mar 17 2022 usr.bin.man
-rw-r--r-- 1 root root 1518 Feb 10 18:14 usr.bin.tcpdump
-rw-r--r-- 1 root root 28486 Dec 1 2022 usr.lib.snapd.snap-confine.real
-rw-r--r-- 1 root root 2006 May 11 23:15 usr.sbin.mysqld
-rw-r--r-- 1 root root 1592 Nov 16 2021 usr.sbin.rsyslogd
╔══════════╣ Files with ACLs (limited to 50) ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#acls files with acls in searched folders Not Found
╔══════════╣ Permissions in init, init.d, systemd, and rc.d ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#init-init-d-systemd-and-rc-d
═╣ Hashes inside passwd file? ........... No ═╣ Writable passwd file? ................ No ═╣ Credentials in fstab/mtab? ........... No ═╣ Can I read shadow files? ............. No ═╣ Can I read shadow plists? ............ No ═╣ Can I write shadow plists? ........... No ═╣ Can I read opasswd file? ............. No ═╣ Can I write in network-scripts? ...... No ═╣ Can I read root folder? .............. No
╔══════════╣ Searching root files in home dirs (limit 30)
/home/
/root/
/var/www
/var/www/html
╔══════════╣ Searching folders owned by me containing others files on it (limit 100)
╔══════════╣ Readable files belonging to root and readable by me but not world readable
╔══════════╣ Interesting writable files owned by me or writable by everyone (not in Home) (max 500) ╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-files
/dev/mqueue
/dev/shm
/home/maximus_supervisor
/run/lock
/run/screen
/snap/core20/1974/run/lock
/snap/core20/1974/tmp
/snap/core20/1974/var/tmp
/tmp
/tmp/linpeas.sh
/tmp/tmux-1000
/var/crash
/var/lib/php/sessions
/var/lib/php/sessions/sess_4ikv1aamiteg3aurv32939dgms
/var/tmp
/var/www/html/.git
/var/www/html/.git/COMMIT_EDITMSG
/var/www/html/.git/HEAD
/var/www/html/.git/branches
/var/www/html/.git/config
/var/www/html/.git/description
#)You_can_write_even_more_files_inside_last_directory
╔══════════╣ Searching passwords in config PHP files
$password = "dbpass";
╔══════════╣ Searching *password* or *credential* files in home (limit 70)
/etc/pam.d/common-password
/home/maximus_supervisor/.aws/credentials
/usr/bin/systemd-ask-password
/usr/bin/systemd-tty-ask-password-agent
/usr/lib/git-core/git-credential
/usr/lib/git-core/git-credential-cache
/usr/lib/git-core/git-credential-cache--daemon
/usr/lib/git-core/git-credential-store
#)There are more creds/passwds files in the previous parent folder
/usr/lib/grub/i386-pc/password.mod
/usr/lib/grub/i386-pc/password_pbkdf2.mod
/usr/lib/mysql/plugin/component_validate_password.so
/usr/lib/mysql/plugin/validate_password.so
/usr/lib/python3/dist-packages/docker/credentials
/usr/lib/python3/dist-packages/keyring/__pycache__/credentials.cpython-310.pyc
/usr/lib/python3/dist-packages/keyring/credentials.py
/usr/lib/python3/dist-packages/launchpadlib/__pycache__/credentials.cpython-310.pyc
/usr/lib/python3/dist-packages/launchpadlib/credentials.py
/usr/lib/python3/dist-packages/launchpadlib/tests/__pycache__/test_credential_store.cpython-310.pyc
/usr/lib/python3/dist-packages/launchpadlib/tests/test_credential_store.py
/usr/lib/python3/dist-packages/oauthlib/oauth2/rfc6749/grant_types/__pycache__/client_credentials.cpython-310.pyc
/usr/lib/python3/dist-packages/oauthlib/oauth2/rfc6749/grant_types/__pycache__/resource_owner_password_credentials.cpython-310.pyc
/usr/lib/python3/dist-packages/oauthlib/oauth2/rfc6749/grant_types/client_credentials.py
/usr/lib/python3/dist-packages/oauthlib/oauth2/rfc6749/grant_types/resource_owner_password_credentials.py
/usr/lib/python3/dist-packages/twisted/cred/__pycache__/credentials.cpython-310.pyc
/usr/lib/python3/dist-packages/twisted/cred/credentials.py
/usr/lib/systemd/system/multi-user.target.wants/systemd-ask-password-wall.path
/usr/lib/systemd/system/sysinit.target.wants/systemd-ask-password-console.path
/usr/lib/systemd/system/systemd-ask-password-console.path
/usr/lib/systemd/system/systemd-ask-password-console.service
/usr/lib/systemd/system/systemd-ask-password-plymouth.path
/usr/lib/systemd/system/systemd-ask-password-plymouth.service
#)There are more creds/passwds files in the previous parent folder
/usr/local/lib/python3.10/dist-packages/awscli/customizations/ec2/__pycache__/decryptpassword.cpython-310.pyc
/usr/local/lib/python3.10/dist-packages/awscli/customizations/ec2/decryptpassword.py
/usr/local/lib/python3.10/dist-packages/awscli/examples/chime/delete-voice-connector-termination-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/chime/list-voice-connector-termination-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/chime/put-voice-connector-termination-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/codebuild/delete-source-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/codebuild/import-source-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/codebuild/list-source-credentials.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/codecommit/credential-helper.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/cognito-idp/admin-reset-user-password.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/cognito-idp/change-password.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/cognito-idp/confirm-forgot-password.rst
/usr/local/lib/python3.10/dist-packages/awscli/examples/cognito-idp/forgot-password.rst
#)There are more creds/passwds files in the previous parent folder
╔════════════════╗ ════════════════════════════════╣ API Keys Regex ╠════════════════════════════════ ╚════════════════╝
Regexes to search for API keys aren't activated, use param '-r'