Skip to content

SUID Binaries

Linux-specific privilege escalation often targets SUID (Set User ID) binaries—executables that run with the permissions of their owner rather than the current user. These binaries are common in tools like passwd or sudo, but misconfigurations or vulnerabilities can allow attackers to escalate privileges. This section explores how to analyze and exploit SUID binaries, focusing on environment variable manipulation and setuid exploitation.


Analyzing SUID Binaries

SUID binaries are identified by the s in their permission string (e.g., -rwsr-xr-x). Use tools like find or ls -l to locate them:

find / -perm -u=s -type f 2>/dev/null
This command searches the filesystem for all SUID binaries. Review each binary for:
- Known vulnerabilities: Check CVE databases or exploit databases for common issues (e.g., buffer overflows, race conditions).
- Binary integrity: Use ldd or readelf to inspect dependencies and potential weaknesses:
readelf -h /path/to/suid_binary


Environment Variable Manipulation

Attackers often exploit SUID binaries by manipulating environment variables, particularly PATH, to execute arbitrary code. For example:
1. Overwriting PATH: A malicious binary with the same name as a legitimate SUID tool could be placed in a modified PATH to execute instead.

export PATH=/tmp:$PATH
/usr/bin/echo "Malicious payload" > /tmp/ls
chmod +x /tmp/ls
If ls is a SUID binary, the attacker’s /tmp/ls would execute instead.
2. Checking for PATH tampering: Analyze the current PATH and verify binaries:
env | grep PATH
ls -l $(which ls)


Setuid Exploitation

Exploiting SUID binaries often involves:
1. Buffer overflows: If a SUID binary has a stack-based overflow, an attacker could inject shellcode. Tools like gdb or pwntools can help craft payloads.

gdb /path/to/suid_binary
(gdb) run < payload.bin
2. Race conditions: Use race condition exploits (e.g., unlink or rename vulnerabilities) to overwrite files or execute code.
3. Privilege escalation via setuid: If a SUID binary calls setuid(0) or similar, it could grant root privileges. Use strace to monitor system calls:
strace -f /path/to/suid_binary


Mitigation Strategies

  • Avoid unnecessary SUID binaries: Use sudo or polkit for privilege delegation instead.
  • Restrict PATH: Avoid using PATH variables in SUID scripts; hardcode absolute paths.
  • Audit and patch: Regularly check for SUID binaries and apply patches for known vulnerabilities.
  • Use non-root accounts: Run services and tools with minimal privileges to limit exploitation impact.

Key takeaways

  • SUID binaries can be exploited via buffer overflows, race conditions, or environment variable manipulation.
  • Always audit SUID binaries for vulnerabilities and ensure they are configured securely.
  • Mitigate risks by avoiding unnecessary SUID usage, restricting PATH, and applying patches promptly.
  • Use tools like strace, gdb, and find to analyze and exploit SUID binaries during authorized testing.