<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Linux on Njeru Mtwaiti</title>
    <link>https://blog.njerumtwaiti.com/tags/linux/</link>
    <description>Recent content in Linux on Njeru Mtwaiti</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sat, 05 Apr 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://blog.njerumtwaiti.com/tags/linux/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Linux Privilege Escalation: The Checklist I Actually Use</title>
      <link>https://blog.njerumtwaiti.com/posts/linux-privilege-escalation-checklist/</link>
      <pubDate>Sat, 05 Apr 2025 00:00:00 +0000</pubDate>
      <guid>https://blog.njerumtwaiti.com/posts/linux-privilege-escalation-checklist/</guid>
      <description>&lt;p&gt;You&amp;rsquo;ve got a shell. You&amp;rsquo;re running as &lt;code&gt;www-data&lt;/code&gt; or some low-privilege user. Now what?&lt;/p&gt;&#xA;&lt;p&gt;Privilege escalation on Linux is part methodology, part intuition. This is the checklist I actually run — the one I&amp;rsquo;ve refined across dozens of CTF boxes and real engagements. No tool dumps the whole path for you. You need to understand what you&amp;rsquo;re looking at.&lt;/p&gt;&#xA;&lt;h2 id=&#34;0-situational-awareness-first&#34;&gt;&#xA;  0. Situational Awareness First&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#0-situational-awareness-first&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Before running any scripts, understand where you are.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
