Linux SUID Find Privilege Escalation
A penetration tester discovers a Linux server with the SUID bit set on the 'find' command. How could this be exploited for privilege escalation?
Quick Answer
The answer is to exploit the Linux SUID find privilege escalation by running `find / -exec /bin/sh \;`, which spawns a root shell. This works because the SUID bit on the `find` command forces it to execute with the permissions of the file owner—typically root—rather than the current user. The `-exec` option then allows arbitrary command execution within that elevated context, so any command passed to it, such as `/bin/sh`, inherits root privileges. On the Certified Ethical Hacker CEH exam, this scenario tests your understanding of SUID misconfigurations as a common privilege escalation vector, often appearing in the system hacking or post-exploitation domains. A frequent trap is forgetting that `find` itself must be owned by root and have the SUID bit set; otherwise, the exploit fails. Memory tip: think “Find and exec to flex your root access”—the `-exec` flag is the key that turns a file search into a shell.
⚠ Common exam trap
It's easy for candidates to think SUID only applies to obvious binaries like 'passwd' or 'sudo', but CEH tests the lesser-known fact that any binary with SUID and command execution capability (like 'find' with '-exec') can be exploited for privilege escalation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
By running 'find / -exec /bin/sh \;' to spawn a root shell
When the SUID bit is set on the 'find' command, it executes with the privileges of the file owner (typically root). The '-exec' option allows arbitrary command execution. Running 'find / -exec /bin/sh \;' spawns a shell with root privileges, enabling full system compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
By using 'find' to delete log files
Why it's wrong here
Deleting log files requires write permission on those files, which the invoking user's own credentials govern, not find's SUID bit. Log tampering is tempting for covering tracks, and find would be the right tool for locating logs, but deletion does not elevate privileges or spawn a root shell.
- ✗
By using 'find' to search for files owned by root
Why it's wrong here
Searching for root-owned files only lists them; it grants no elevated execution, because SUID 'find' escalates via its -exec flag running commands as root. Enumeration is tempting since find excels at locating files, and would be the right tool for that reconnaissance task, but it does not itself escalate privileges.
- ✗
By using 'find' to mount a remote share
Why it's wrong here
The 'find' binary cannot mount remote shares; mounting requires mount, itself needing root or a configured fstab entry. Remote-share mounting is tempting because SUID tools can sometimes invoke privileged system calls, but find offers no mount primitive, so this path yields nothing.
- ✓
By running 'find / -exec /bin/sh \;' to spawn a root shell
Why this is correct
Because 'find' carries the SUID bit and is owned by root, executing it runs with root's effective UID. The -exec flag then launches /bin/sh inheriting that elevated privilege, spawning an interactive root shell and completing local privilege escalation from an unprivileged account.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a penetration test, a tester gains a low-privilege shell on a Linux server. The command `sudo -l` reveals that the user can run `/usr/bin/find` as root. Which technique can the tester use to escalate privileges?
medium- A.Abuse the SUID bit on find
- ✓ B.Use find with the -exec flag to spawn a shell
- C.Exploit a kernel vulnerability
- D.Run a buffer overflow on the find binary
Why B: The `sudo -l` output shows the user can run `/usr/bin/find` as root without a password. The `find` command has a built-in `-exec` flag that allows executing arbitrary commands on each found file. By running `sudo find / -exec /bin/sh \;`, the tester can spawn a root shell, escalating privileges because the command runs with sudo (root) privileges.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.