Linux Privilege Escalation: Exploiting SUID Binaries and Misconfigurations

In the lifecycle of a penetration test, gaining initial access is a massive victory, but it's rarely the end of the engagement. When you successfully exploit a web application vulnerability and catch a reverse shell, you almost always land as a low-privileged service account—such as www-data or a restricted standard user.

From this position, your permissions are strictly limited. You cannot read the /etc/shadow file, access other users' home directories, or dump the database. To achieve total compromise, you must escalate your privileges to root.

In this post, we will explore the fundamental techniques for Linux privilege escalation, focusing on SUID binaries, misconfigured permissions, and essential automation tools.

Understanding SUID (Set Owner User ID)

One of the most common vectors for privilege escalation involves SUID binaries. By design, Linux permissions dictate that a program executes with the permissions of the user running it.

However, some commands require elevated privileges to function properly. For example, when a standard user runs the passwd command to change their password, the program must write to the /etc/shadow file—a file only root can modify. Linux solves this by setting the SUID bit on the passwd executable. When a binary has the SUID bit set, it temporarily executes with the permissions of the file's owner (usually root), rather than the user running it.

Exploiting SUID Binaries

System administrators occasionally set the SUID bit on custom scripts, or standard utilities (like cp, vim, or find) to quickly solve a permissions issue, completely unaware of the security implications.

Step 1: Find SUID binaries
You can hunt for all files on the system that have the SUID bit set using the find command:

find / -perm -4000 -type f 2>/dev/null

Step 2: Exploit via GTFOBins
Suppose the output of your search reveals that /usr/bin/find has the SUID bit set. You can visit GTFOBins—a curated list of Unix binaries that can be exploited to bypass local security restrictions.

Because the find command has an -exec parameter that allows it to run arbitrary commands, and it's running as root due to the SUID bit, you can execute a shell as root:

find . -exec /bin/sh -p \; -quit

Just like that, your prompt turns into a #, and you have root access.

The Dangers of Sudo Misconfigurations

The sudo command is designed to allow users to run specific commands as root. The configuration is stored in the /etc/sudoers file. Administrators often grant users unrestricted sudo rights to a specific utility to avoid giving them full root access.

Step 1: Check your rights
Run the following command to see what you are allowed to execute:

sudo -l

Step 2: Abusing the privileges
Imagine the output says you can run /usr/bin/tar as root without a password. While tar is just an archiving tool, it has command-line flags that allow you to execute arbitrary commands during the archiving process.

sudo tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh

This command forces tar to spawn a shell, and since tar was run via sudo, the resulting shell belongs to root.

Cron Jobs and Writable Scripts

Cron jobs are scheduled tasks that run automatically in the background. Often, system administrators schedule backup scripts or cleanup utilities to run as root every few minutes.

If an administrator creates a cron job that executes a script (e.g., /opt/cleanup.sh), but accidentally leaves the script globally writable (chmod 777), any low-privileged user can modify the script.

An attacker simply echoes a reverse shell payload into /opt/cleanup.sh. The next time the cron job triggers, root executes the script, and the attacker receives a high-privileged shell on their listener.

Automating the Hunt: LinPEAS

Manually checking SUID bits, sudoers files, cron jobs, network connections, and writable files is incredibly time-consuming. Penetration testers rely on automation scripts to enumerate the environment quickly.

LinPEAS (Linux Privilege Escalation Awesome Script) is the industry standard for this task. It searches for all the vectors mentioned above (and hundreds more, including kernel exploits like Dirty COW or Dirty Pipe) and highlights vulnerable misconfigurations in a color-coded terminal output.

Conclusion

Linux privilege escalation relies on exploiting human error rather than highly complex memory corruption vulnerabilities. By understanding how the operating system handles permissions, and systematically enumerating SUID bits, sudo misconfigurations, and cron jobs, you can reliably turn a foothold into a total system compromise.