A penetration tester has gained a low-privileged shell on a Linux server and discovers a binary with the SUID bit set owned by root. The binary executes a system command using a relative path without sanitizing user input. Which of the following techniques would the tester MOST likely use to escalate privileges?
PATH hijacking leverages the SUID binary's use of a relative path; by placing a malicious executable earlier in PATH, the binary executes it with root privileges.
Why this answer
The SUID binary executes a system command using a relative path without sanitizing user input. By modifying the PATH environment variable to include a directory containing a malicious script with the same name as the command, the tester can cause the binary to execute the attacker-controlled script instead of the intended system command, thereby escalating privileges to root when the SUID binary runs.
Exam trap
The trap here is that candidates may think kernel exploitation (Option A) is always the go-to for privilege escalation, but the question specifically describes a misconfigured SUID binary with a relative path and unsanitized input, making PATH hijacking the most direct and likely technique.
How to eliminate wrong answers
Option A is wrong because exploiting a kernel vulnerability is a different technique that does not leverage the specific misconfiguration of the SUID binary with a relative path and unsanitized input; it would be used if no such binary existed or if kernel exploits were available, but the question explicitly describes a binary that can be exploited via PATH hijacking. Option C is wrong because impersonating the root user using sudo requires the tester to already have sudo privileges or know the root password, which is not the case here; the tester has a low-privileged shell and cannot simply use sudo without proper authorization.