SUID Binary
Also known as:SUID · SGID · Set-User-ID
SUID Binary: Program that runs with the privileges of its owner rather than those of the caller. SUID programs are the classic route to privilege escalationPrivilege EscalationObtaining higher privileges than originally intended. on Unix systems.
How it works and where it fits
When the owner sets the set-user-ID bit, the process starts with the file’s effective user ID — for root-owned programs that means full privileges regardless of who invokes it. This is intentional for tasks such as passwd or ping. It becomes security-relevant because the real and effective IDs diverge: access() checks with the real ID while open() and fopen() act with the effective one. Programs mixing both open a window for a race conditionRace ConditionError where the result depends on the timing or sequence of parallel processes..
Practical security relevance
An inventory via find / -perm -4000 belongs in every system review. Common flaws in custom SUID programs are incomplete path checks without canonicalisation, trusting environment variables, and invoking external programs through a shell. Robust alternatives are fine-grained capabilities instead of full root, permanently dropping privileges before the actual file access, and mounting file systems with the nosuid option.
Related concepts
- Privilege EscalationPrivilege EscalationObtaining higher privileges than originally intended.: Obtaining higher privileges than originally intended.
- Least PrivilegeLeast PrivilegeGrants only the minimum permissions necessary for a specific task and timeframe.: Grants only the minimum permissions necessary for a specific task and timeframe.
- HardeningHardeningReduces the attack surface through secure configuration and the deactivation of unnecessary functions.: Reduces the attack surface through secure configuration and the deactivation of unnecessary functions.
- Access ControlAccess ControlGoverns who is permitted to access specific systems, data, or functions.: Governs who is permitted to access specific systems, data, or functions.