Skip to content
Site Logo
Go back

Privilege Escalation: SUID

Hack Attack Photo by Lucas Andrade

Imagine you’ve just gained a low-level shell on a Linux target. You are currently a standard user, but you need root access to fully compromise the system and evaluate its true risk. One of the most effective ways to elevate your privileges is by hunting for SUID misconfigurations.

What is SUID?

SUID, or “Set owner User ID”, is a special Linux file permission. When applied to an executable, it allows that file to run with the privileges of its owner—which is often root.

If an administrator gets lazy and assigns SUID permissions to the wrong binary, we can exploit it directly from the terminal to pivot to a root shell.

Table of contents

Open Table of contents

Hunting for the Weakness

To hunt for exploitable files, we need to search the entire root directory for files with the 4000 permission bit (the SUID bit).

find / -perm -4000 2>/dev/null
Understanding File Descriptors:

Linux utilizes three standard streams (assigned specific file descriptor numbers) to handle data:

  • 0 - Standard Input (stdin): Accepts data from a source like a keyboard.

  • 1 - Standard Output (stdout): Displays successful results on the screen.

  • 2 - Standard Error (stderr): Isolates and outputs diagnostic error messages.

The 2>/dev/null at the end of our command is crucial. As a low-privileged user, scanning the entire / directory will generate hundreds of “Permission denied” errors. By explicitly targeting stream 2, we send only the standard error messages to /dev/null (the digital void), leaving us with a clean output of the files we actually found.

Looking at the results of our scan, one binary stands out immediately: /usr/bin/find.

The find command shouldn’t normally have SUID permissions. Because it does, and because it has a built-in -exec parameter that lets it run other commands, it can be easily weaponized.

Weaponizing the Binary

By passing the /bin/sh shell to the -exec flag, the find command spawns a new shell. Because find is running as root due to that SUID bit, the new shell it spawns also runs as root!

Here is the exact command to capture the root shell:

find . -exec /bin/sh -p \; -quit

Here is exactly how that command breaks down:

Test it by typing whoami and hitting enter.

Root. We own the system.

The Defender’s Takeaway

As defenders, this is exactly why the principle of least privilege matters. A single misconfigured binary unravels your entire system hardening strategy.

The Mindset Shift:

Remember our mindset: No zero days required. Continuous, progressive growth makes us better defenders today than we were yesterday. We must audit our own permissions before attackers do it for us.

If you are wondering how I knew the exact syntax to weaponize that find command, the secret is that you don’t need to memorize it. Check out my full guide on GTFOBins: A Hacker’s Rosetta Stone to see exactly how to uncover these strings on the fly!

Share this post:
Previous Post
The Threat Actor Naming Paradox: Pandas, Kittens, and Cyber Cartels
Next Post
TryHackMe Writeup: Brute It