↑ ↓ select, Enter open, Esc close

Find files with the SUID or SGID bit

root@server
find / -xdev \( -perm -4000 -o -perm -2000 \) -type f -exec ls -l {} + 2>/dev/null

Searches the root filesystem for files with the SUID bit set (runs as the owner, usually root) or the SGID bit (runs with the file’s group). System programs such as passwd, sudo or mount under /usr/bin are normal. Matches in web directories, /tmp or a user’s home directory are a red flag.

Note: -xdev stays on the root filesystem. If /var or /home live on separate partitions, pass them separately as starting paths.

Also searched as

  • find suid files linux
  • check setuid binaries rootkit
  • find programs running as root
  • security audit file permissions

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.