Linux Privilege Escalation — Special Permissions (SUID/SGID) & GTFOBins
SUID — Set User ID Upon Execution
The setuid bit lets a user execute a program or script with the permissions of the file’s owner (commonly root) rather than their own. It shows up as an s in the owner’s execute position (rws instead of rwx).
rnemeth@htb[/htb]$ find / -user root -perm -4000 -exec ls -ldb {} \; 2>/dev/null
-rwsr-xr-x 1 root root 16728 Sep 1 19:06 /home/htb-student/shared_obj_hijack/payroll
-rwsr-xr-x 1 root root 16728 Sep 1 22:05 /home/mrb3n/payroll
-rwSr--r-- 1 root root 0 Aug 31 02:51 /home/cliff.moore/netracer
-rwsr-xr-x 1 root root 40152 Nov 30 2017 /bin/mount
-rwsr-xr-x 1 root root 40128 May 17 2017 /bin/su
-rwsr-xr-x 1 root root 44168 May 7 2014 /bin/ping
-rwsr-xr-x 1 root root 23376 Jan 18 2016 /usr/bin/pkexec
-rwsr-xr-x 1 root root 136808 Jul 4 2017 /usr/bin/sudo
-rwsr-xr-x 1 root root 54256 May 17 2017 /usr/bin/passwd
-rwsr-xr-x 1 root root 1588768 Aug 31 00:50 /usr/bin/screen-4.5.0
-rwsr-xr-x 1 root root 94240 Jun 9 14:54 /sbin/mount.nfs
Key point: most of this list is expected (mount, su, passwd, sudo, ping ship with the SUID bit set by default). Look for anything unexpected — non-standard binaries in home directories (payroll, netracer above), unusually-versioned system tools (screen-4.5.0), or standard tools with known SUID-abuse footguns. An uppercase S (as on netracer) means the setuid bit is set but the owner-execute bit itself is not — the file can’t actually be run as-is.
Two approaches once a non-default SUID binary is found:
- Reverse engineer it — look for a vulnerability (buffer overflow, insecure file handling, shared library/
PATHhijack) that can be exploited to run arbitrary code as the file’s owner. - Check its built-in features — many otherwise-legitimate binaries have documented options (shell-out flags, file read/write flags, exec flags) that can be abused directly if SUID is set. This is exactly what GTFOBins catalogs (below).
SGID — Set Group ID
The setgid bit is the group analog of setuid: it lets a binary run as if the invoking user were a member of the file’s group rather than (or in addition to) its owner. Enumerate SUID and SGID together with -perm -6000 (the combined bit value):
rnemeth@htb[/htb]$ find / -user root -perm -6000 -exec ls -ldb {} \; 2>/dev/null
-rwsr-sr-x 1 root root 85832 Nov 30 2017 /usr/lib/snapd/snap-confine
SGID binaries are enumerated and abused the same way as SUID ones — reverse engineering or built-in feature abuse — just against group privileges instead of owner privileges.
GTFOBins
GTFOBins is a curated catalog of Unix binaries/scripts that ship with (mis)features useful for escaping restricted shells, escalating privileges, spawning shells, uploading/downloading files, and more. Each entry documents exactly which flag or invocation to use and under what condition (SUID, sudo rule, file capability, etc.) it applies.
Example — apt-get abusing its Pre-Invoke hook to spawn a root shell when run via sudo:
rnemeth@htb[/htb]$ sudo apt-get update -o APT::Update::Pre-Invoke::=/bin/sh
# id
uid=0(root) gid=0(root) groups=0(root)
Workflow: enumerate SUID/SGID binaries (or sudo -l output, or file capabilities) → cross-reference each binary name against GTFOBins → follow the documented technique for the applicable privilege context (SUID / Sudo / Capabilities / Shell).
Key Takeaways
find / -user root -perm -4000 2>/dev/null(SUID) and-perm -6000(SUID+SGID) are the standard sweep — always compare results against a baseline of “expected” SUID binaries for the distro to spot outliers quickly.- An uppercase
S/Gin the permission string means the special bit is set without the corresponding execute bit — note it, but it can’t be leveraged directly. - GTFOBins is the fastest path from “binary name” to “working privesc technique” — memorizing the common entries (
sudo,find,vim,less,awk,python,apt/apt-get,nmap) pays off far more than manually re-deriving each abuse from scratch.