Courseiva
Linux Privilege Escalation →mediumMultiple Choice

PEN-200 Linux Privilege Escalation Practice Question

During post-exploitation on a Linux target, you discover a binary with the SUID bit set owned by root. Running 'strings' on the binary reveals it calls 'system("ps")' without specifying an absolute path. Which of the following techniques is most likely to allow you to escalate privileges by exploiting this behavior?

⚠ Common exam trap

The trap here is assuming that LD_PRELOAD or binary modification is needed, while overlooking the simpler PATH hijacking due to the relative command invocation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a malicious 'ps' executable in a directory earlier in the PATH, then run the SUID binary.

The SUID binary calls system("ps") without an absolute path, meaning it relies on the PATH environment variable to locate the ps command. If an attacker can prepend a writable directory to PATH and place a malicious ps script there, the SUID binary will execute it with root privileges. This is a classic PATH hijacking privilege escalation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Overwrite the /bin/ps binary with a malicious script, then run the SUID binary.

    Why it's wrong here

    Overwriting /bin/ps requires write permissions to that file, which a low-privileged user typically does not have. Even if possible, it would affect all users and might be detected. The intended vulnerability is the relative path in system(), not the ps binary itself.

  • ✗

    Modify the binary to replace system("ps") with system("/bin/sh"), then run it.

    Why it's wrong here

    Modifying the binary requires write permissions to the binary itself, which is owned by root and likely not writable by the attacker. Additionally, even if possible, it would alter the binary's integrity and might not be feasible. The PATH hijacking method does not require modifying the binary.

  • ✗

    Use LD_PRELOAD to inject a shared library that hijacks the system() call.

    Why it's wrong here

    LD_PRELOAD is ignored for SUID binaries for security reasons, as the dynamic linker strips it. Therefore, this technique will not work on a SUID binary. The vulnerability lies in the relative path, not in library injection.

  • ✓

    Create a malicious 'ps' executable in a directory earlier in the PATH, then run the SUID binary.

    Why this is correct

    The binary uses system("ps"), which invokes the shell to run the command. If the PATH environment variable includes a writable directory before /bin, you can place a malicious 'ps' there. When the SUID binary runs, it will execute your 'ps' as root, granting escalation. This is a classic PATH hijacking attack.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.