Courseiva

GPEN Escalation and Exploitation Practice Question

You have identified an SUID binary on a Linux system that executes a shell command without using an absolute path. What is the most effective way to exploit this for privilege escalation?

⚠ Common exam trap

Candidates often try to exploit missing absolute paths by changing ownership of the binary or attempting direct code injection, forgetting that manipulating the PATH environment variable is the standard vector.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the PATH variable to point to a malicious directory.

When a binary calls a command without an absolute path, it relies on the PATH environment variable to locate the executable. By modifying the PATH to include a directory under the attacker's control, the attacker can place a malicious executable with the same name as the target command. This forces the SUID binary to execute the malicious file instead of the intended system utility, resulting in command execution as the owner.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Overflow the buffer of the binary.

    Why it's wrong here

    Buffer overflows are a complex exploit vector that requires finding a vulnerability in the source code of the binary. While possible, it is significantly more difficult and time-consuming than leveraging an insecure PATH dependency, which is a design flaw that is easily exploited by changing environmental variables.

  • ✓

    Modify the PATH variable to point to a malicious directory.

    Why this is correct

    By prepending a user-controlled directory to the PATH variable, the system searches the attacker's directory first. If the binary calls 'date' and the attacker has placed a malicious file named 'date' in their directory, the system executes the malicious file with the privileges of the SUID binary.

  • ✗

    Use LD_PRELOAD to inject a shared object.

    Why it's wrong here

    LD_PRELOAD is a technique for library injection, but most modern SUID binaries are designed to ignore environmental variables like LD_PRELOAD for security reasons. Relying on this is unreliable on patched systems, whereas PATH manipulation targets the logic of the application rather than the dynamic linker settings.

  • ✗

    Inject arguments into the binary.

    Why it's wrong here

    Injecting arguments into a binary only works if the binary is poorly written and passes the input to a shell without sanitization. While this is an injection vulnerability, it is distinct from the PATH dependency issue, which is specifically concerned with how binaries resolve the location of commands.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.