( 03 )NOTES/SUID_SGID
SYNC0x4A1F
notes/suid-sgid
linux

SUID & SGID

Quick notes on SUID and SGID permissions, enumeration, and why unusual privileged binaries matter.

2026-09-12
1 min read
linuxsuidsgidprivilage-escalationenumerationred-team

Finding SUID & SGID Files#

permission enumeration
>find / -perm -4000 -type f 2>/dev/null
>find / -perm -2000 -type f 2>/dev/null
>ls -la /usr/bin/passwd
>
SUID is represented by: s in the owner's execute position. Example: -rwsr-xr-x The executable runs with the owner's privileges.
SGID is represented by: s in the group's execute position. Example: -rwxr-sr-x The executable runs with the group's privileges.
Findings
INFO
Pay attention to: • SUID binaries in unusual locations • Custom binaries with SUID/SGID • Unexpected ownership • Binaries writable by unprivileged users • Recently created privileged executables • Applications with known privilege-escalation paths

Takeaway#

Always enumerate SUID and SGID files during Linux privilege-escalation assessments, but treat the results as leads that require further investigation.

Back to Notesnote: suid-sgid