whatis setuid

SUID and SGID

Also known as: setuid, setgid, SUID, SGID

Special permission bits that make a program run with its owner's (SUID) or group's (SGID) privileges instead of the caller's.

What Are SUID and SGID in Linux?

SUID is how an ordinary user can run passwd and update /etc/shadow: the binary is owned by root with the SUID bit set, so it runs as root. It shows as an s in the owner execute position (-rwsr-xr-x).

SGID on a directory makes new files inherit the directory's group, which is useful for shared team folders. SUID binaries are a classic privilege escalation target, so audit them with find / -perm -4000.

Example

ls -l /usr/bin/passwd
# -rwsr-xr-x 1 root root ... /usr/bin/passwd
chmod g+s /srv/shared