PATH Hijacking
Also known as:Search Path Manipulation
PATH Hijacking: Substituting an attacker-supplied program by manipulating the search path of a relative invocation. The technique is one of the simplest forms of privilege escalationPrivilege EscalationObtaining higher privileges than originally intended. on Unix systems.
How it works and where it fits
When a program invokes another without an absolute path, the system searches the directories in the PATH environment variable in order. Anyone who controls that variable or can write to one of the listed directories places their own executable there under the expected name. If the calling process runs with higher privileges — as a SUID binarySUID BinaryProgram that runs with the privileges of its owner rather than those of the caller. or under a service account — the substituted code inherits exactly those privileges.
Practical security relevance
Calls through system() or popen() are especially exposed because a shell sits in between as well. Related variants exploit writable directories early in the search path, a relative element such as . in PATH, or on Windows the DLL search order. Hardening means invoking external programs only with absolute paths, sanitising the environment before the call, spawning processes without a shell, and strictly limiting write access to directories in the search path.
Related concepts
- SUID BinarySUID BinaryProgram that runs with the privileges of its owner rather than those of the caller.: Program that runs with the privileges of its owner rather than those of the caller.
- Privilege EscalationPrivilege EscalationObtaining higher privileges than originally intended.: Obtaining higher privileges than originally intended.
- Command InjectionCommand InjectionInjecting operating system commands into an application that passes input to a shell.: Injecting operating system commands into an application that passes input to a shell.
- HardeningHardeningReduces the attack surface through secure configuration and the deactivation of unnecessary functions.: Reduces the attack surface through secure configuration and the deactivation of unnecessary functions.