all modules module 03 · beginner

Linux & CLI Mastery

Servers run Linux, hacking tools assume Linux. Four lessons to make the terminal your default habitat.

01The filesystem & moving with purpose~5 min

Everything starts at / (root). The layout is standardized:

  • /etc — config files (passwords, ssh settings) · /var/log — logs · /home — user dirs · /tmp — world-writable scratch space

Navigate and inspect:

pwd                  # where am I
ls -la               # list all, long format, hidden files
cd /var/www          # go there
find / -name "*.conf" 2>/dev/null   # hunt configs, silence errors
cat /etc/os-release  # what distro is this

Muscle memory drill: on any box (even the arcade terminal here), list everything, read anything that looks like notes or config, check for hidden files. That exact habit finds flags in CTFs and secrets on real engagements.

02Permissions: rwx, sudo & SUID~6 min

-rwxr-xr-- reads as: owner can read/write/execute, group can read/execute, others just read. Change with chmod, ownership with chown.

  • sudo runs a command as root. Check what’s allowed: sudo -l. If it lists commands you can run passwordless, some let you escape to a root shell (check GTFOBins).
  • SUID bit (-rws): the program runs as its owner (often root). A misconfigured SUID binary = privilege escalation. Find them: find / -perm -4000 2>/dev/null
  • World-writable files + weak defaults are classic privesc routes.

Permission errors during an attack aren’t dead ends — they’re a map of what the system thinks you shouldn’t have, i.e., exactly what’s valuable.

03Pipes, grep & text fu~5 min

The superpower: chaining small tools with |.

cat access.log | grep "admin" | awk '{print $1}' | sort | uniq -c | sort -rn
history | grep ssh
ps aux | grep -i pass
grep -ri "password" /home --include="*.txt"

That first line reads a web log, filters admin traffic, extracts IPs, counts and sorts by frequency — instant “who’s hammering this server”. Tools to learn in order: grep (search), cut/awk (columns), sort+uniq (dedupe/count), wc (count lines), head/tail (peek).

Blue teams use these exact pipelines on logs; red teams use them on loot. One skill, two salaries.

04Your first recon toolkit~6 min
nmap -sV -sC target.com            # ports, versions, default scripts
nmap -p- target.com                # ALL 65535 ports (slow but thorough)
curl -i http://target.com          # raw response with headers
curl -X POST -d "user=a&pass=b" URL  # send form data
dig +short sub.target.com          # quick DNS answer
nc -nv target.com 80               # raw TCP conversation

Ethics checkpoint: only scan systems you own or have explicit written permission to test. Practice legally on TryHackMe/HackTheBox boxes or your own VMs.

Challenge yourself: spin up the Terminal Heist game after this lesson — it simulates exactly this workflow: enumerate, read files, find the flag.