How to Find SetUID (SUID) Files in Ubuntu (find -perm /4000)

The Root Escalation Threat

In Ubuntu Linux, the SetUID (SUID) permission bit is a special security feature that allows a normal user to temporarily execute a specific program with the elevated privileges of the file’s owner (usually root). While this is necessary for certain system commands (like passwd, which needs root access to modify your password), it is historically one of the most dangerous vulnerabilities in Linux. If a hacker compromises a low-level account, their first objective is to find obscure SUID binaries they can exploit to escalate their privileges to full root control. You must audit these files constantly.

Using the find Command with -perm /4000

The Linux find command utilizes the octal permission flag -perm /4000 to explicitly search the filesystem for any file carrying the SetUID bit.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire root filesystem (/) for SUID binaries and suppress error messages from directories you don’t have access to, type the following command exactly:
  3. find / -type f -perm /4000 2>/dev/null
  4. Press Enter.

Auditing the Security Posture

The syntax utilizes the forward slash (/) before the 4000 octal code. This instructs the search engine to look for files where the SUID bit is set, regardless of what the read, write, or execute permissions are for the group or world. The 2>/dev/null at the end is crucial; it silently discards the hundreds of “Permission denied” errors that will occur when scanning a live system as a non-root user. This command provides system administrators with an exact, isolated manifest of every single binary on the server capable of granting root access.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.