Services & Internals Enum
Network Interfaces
ip aHosts
cat /etc/hostsUser's Last Login
lastlog
Username Port From Latest
root **Never logged in**
daemon **Never logged in**
bin **Never logged in**
sys **Never logged in**
sync **Never logged in**
...SNIP...
systemd-coredump **Never logged in**
mrb3n pts/1 10.10.14.15 Tue Aug 2 19:33:16 +0000 2022
lxd **Never logged in**
bjones **Never logged in**
administrator.ilfreight **Never logged in**
backupsvc **Never logged in**
cliff.moore pts/0 127.0.0.1 Tue Aug 2 19:32:29 +0000 2022
logger **Never logged in**
shared **Never logged in**
stacey.jenkins pts/0 10.10.14.15 Tue Aug 2 18:29:15 +0000 2022
htb-student pts/0 10.10.14.15 Wed Aug 3 13:37:22 +0000 2022 Logged In Users
Command History
Finding History Files
Services listening
Cron
Cron Job AbuseProc
Installed Packages
Sudo version
CVE-2025-32463 – sudo chroot ("chwoot")
Sudo < 1.8.28
Sudoedit Privesc - CVE 2023-22809
Baron Samedit - CVE-2021-3156
Debian 10 (Sudo 1.8.27)
Ubuntu 20.04 (Sudo 1.8.31)
Poc All In One
CVE-2019-18634 - Sudo before 1.8.26
All versions below 1.8.28 - CVE-2019-14287
Example 1
Example 2
Example 3
Example 4 - iptable and iptable-save
More exploits
Binaries
Vulnerable ServicesGTFOBins
SUID/SGIDTrace System Calls
Configuration files
Credentials HuntingScripts
Running Services by User
Last updated