Courseiva

GPEN Escalation and Exploitation Practice Question

During a penetration test on a Linux server, you find a cron job that runs every minute as root: '*/1 * * * * root /usr/local/bin/backup.sh'. The script is owned by root but has permissions 777. You are a low-privileged user. What is the most direct way to escalate privileges?

⚠ Common exam trap

The trap here is overcomplicating the escalation when a simple file write to a root-executed script is available; testers sometimes overlook the obvious writable script.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the backup.sh script to include a reverse shell command.

The most direct escalation is to modify the world-writable script because it runs as root every minute. By adding a command to create a reverse shell or copy /bin/bash with SUID permissions, you gain root access. Other methods like LD_PRELOAD or symlinking are less reliable or indirect. The writable script is a clear privilege escalation vector.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a malicious shared library and use LD_PRELOAD in the script's environment.

    Why it's wrong here

    LD_PRELOAD only works if the script or the executed programs use dynamic linking and the environment variable is honored. Cron jobs typically run with a minimal environment, and LD_PRELOAD is not set by default. You cannot influence the environment of the cron job unless you can modify the script or the cron configuration. This method is unreliable and not the most direct approach given the writable script.

  • ✗

    Use the cron job to copy /etc/shadow to a world-readable location.

    Why it's wrong here

    While copying /etc/shadow would give you password hashes for offline cracking, it does not directly escalate privileges. You would still need to crack the root password, which may be strong. Modifying the script to execute a reverse shell or create an SUID binary is a more direct escalation. This method is indirect and depends on weak passwords, which is not guaranteed.

  • ✓

    Modify the backup.sh script to include a reverse shell command.

    Why this is correct

    Since the script is world-writable (777), you can edit it to execute arbitrary commands. The cron job runs as root every minute, so your modified script will execute with root privileges. Adding a reverse shell or copying /bin/bash with SUID will grant you root access. This is a direct and reliable escalation because you control the script's content and it runs as root without any additional checks.

  • ✗

    Replace the /usr/local/bin/backup.sh with a symbolic link to /bin/bash.

    Why it's wrong here

    Replacing the script with a symlink to /bin/bash would cause the cron job to execute bash as root. However, bash without arguments in a non-interactive cron environment may not provide a shell, and the script's execution might not spawn an interactive session. Moreover, you would need to ensure the symlink has execute permissions, but the original file already has 777, so you can simply modify it. This approach is less direct and may not yield a usable shell.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.