Lesson 1 of 1 in Privilege Escalation
A Foothold Is Not The Keys
The first account an attacker gets is almost never the powerful one. The climb from a foothold to full control runs on misconfiguration, cached passwords and over-privileged accounts — ordinary untidiness, weaponised.
3 min read
Not yet reviewed
So they are in as some ordinary user. That is bad, but it is not the admin, right? There is still a wall.
There is a wall, and it is usually already half-down. A password left in a script. A service running as administrator for no reason. A local bug you never patched because "it is only internal". I do not break the wall. I find the gap someone left in it.
And the gaps are almost always tidiness, not genius. Which means the defence is tidiness too.
Legal
Escalating your privileges on a system beyond what you were granted is unauthorised access even when you were allowed onto the system in the first place — being a user is not permission to become an administrator. Practise this only on systems you own or are explicitly authorised to test, such as the labs here.
The climb runs on untidiness
Privilege escalation is the attacker turning a foothold into control, and the striking thing about how it usually happens is how boring it is. The routes are the debris of everyday operations: a secret checked into a repo, an account with more rights than its job needs, a machine a month behind on updates. The attacker's skill is mostly in knowing where people are untidy.
Secret in a file a password or key in a script, config, or repo
Over-privileged account a service running as admin it never needed to be
Cached credentials an admin logged in here once; their password lingers
Unpatched local bug "only internal", so it waited months for a fix
Weak permissions a file the wrong people can change, and it runs as root
- Line 1The most common of all. Someone hard-coded a credential to make a script work, meant to remove it, and did not.
- Line 3An administrator who logged into a compromised machine may have left their credentials in its memory. The attacker harvests them and is now that administrator, everywhere.
Two machines are identical except that on one, the backup service runs as a normal limited account, and on the other it runs as administrator "so it just works". Why is the second machine so much worse if the service is ever compromised?
Least privilege, actually meant
The defence has one governing idea — least privilege — and several plain habits that follow from it: run every account and service with the least it needs and no more, keep secrets out of files and in a proper secret store, patch internal systems as if they were exposed because a foothold makes them exposed, and do not log in with a powerful account on a machine that might already be compromised.
Convenient
Service runs as administrator "to be safe".
API key hard-coded in the deploy script.
One account used for everything.Least privilege
Service runs as an account with only its job.
Secrets in a store, injected at run time.
Admin actions on a separate admin account.Every convenient choice on the left is a shortcut that hands the attacker the next rung of the ladder. None of the choices on the right cost money — they cost the discipline of not taking the shortcut.
One thing you can do this week: stop using an administrator account for everyday work. On your own computer, do your daily browsing and email as a standard user and keep the admin account for when you actually install something. It is the personal version of least privilege, and it means a bad moment stays small.