Windows vs Linux Mechanics
Privilege escalation in Windows and Linux operates under fundamentally different architectural paradigms, shaped by their respective operating system designs. Windows relies on a token-based privilege model with mechanisms like User Account Control (UAC) to mediate access, while Linux employs a Unix-style user and group model centered around root and sudo. These differences influence both the attack surface and the techniques used to exploit or bypass privilege boundaries.
Windows Privilege Model: Local System, UAC, and Token-Based Privileges¶
Windows uses a token-based privilege system where each process has an access token defining its permissions. The Local System account is a built-in account with elevated privileges, often used by system services. However, it is not the same as the root user in Linux.
Key Concepts:¶
- User Account Control (UAC): A defense mechanism that prompts users for elevation when applications request administrative privileges. If disabled, escalation becomes easier.
- Privilege Separation: Windows grants specific privileges (e.g.,
SeDebugPrivilege,SeTakeOwnershipPrivilege) rather than full administrative access. - Service Accounts: Many services run under the Local System account, which can be a target for escalation if misconfigured.
Example: Checking UAC Status¶
# Check if UAC is enabled (via registry)
reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" | findstr "EnableLUA"
Linux Privilege Model: Root, Sudo, and Unix User Permissions¶
Linux uses a Unix user and group model where privileges are tied to user IDs (UIDs) and file permissions. The root user has unrestricted access, while sudo allows non-root users to execute commands as root with proper configuration.
Key Concepts:¶
- Root User: The superuser with complete control over the system.
- Sudo: A tool that grants temporary root privileges, often configured via
/etc/sudoers. Misconfigurations (e.g.,NOPASSWD:) can enable privilege escalation. - File Permissions: Access is controlled via owner, group, and others permissions (
chmod), withsetuid/setgidbits allowing programs to execute with elevated privileges.
Example: Checking Sudo Permissions¶
Architectural Differences and Escalation Implications¶
| Feature | Windows | Linux |
|---|---|---|
| Privilege Model | Token-based with specific privileges | UID-based with root/sudo |
| Default Admin | Local System (not equivalent to root) | Root |
| User Management | Complex, with domain/Local Accounts | Simpler, based on UIDs and groups |
| Escalation Vectors | Exploiting misconfigured services | Misconfigured sudoers or file perms |
| Defense Mechanisms | UAC (can be bypassed) | Sudo logging and PAM modules |
Key takeaways¶
- Windows uses token-based privileges and UAC to control elevation, while Linux relies on root and sudo with file permissions.
- Escalation in Windows often targets services running as Local System, whereas Linux focuses on misconfigured sudoers or file permissions.
- Understanding these differences is critical for identifying and mitigating privilege escalation risks in both environments.