You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

setuid(0)在Ubuntu 22与Raspian上的表现差异及原因排查

SetUID工具在Ubuntu 22上无法提权的原因分析

我编写了一个简单的setuid工具escalate.c,目的是无需root权限安全调用shutdown等需要高权限的操作,编译及权限配置步骤如下:

  • 编译:gcc escalate.c -o escalate.out
  • 修改所有者:sudo chown root:root escalate.out
  • 设置setuid权限:sudo chmod 4755 escalate.out

工具代码如下:

//#escalate.c - a setuid utility so that we can call shutdown
//# and other things safely without needing root access.  We 
//# do need to:
//#   gcc escalate.c -o escalate.out
//#   sudo chown root:root escalate.out
//#   sudo chmod 4755 escalate.out

#include <stdio.h>
#include <stdlib.h>
#include <sys/types.h>
#include <unistd.h>
#include <errno.h>

int main()
{
    int status;
    status = setuid( 0 );   // you can set it at run time also
    system("date > /tmp/date.fil");
    return errno;
 }

测试结果对比:

  • 在Raspian系统中,生成的/tmp/date.fil文件属主为root,程序返回值为0,符合预期;
  • 在Ubuntu 22系统中,生成的文件属主为当前用户,程序返回值为1,提权失效。

尝试调整文件权限、重新设置所有者等操作后问题仍未解决,最终定位到核心原因:Ubuntu的加密家目录挂载时默认设置了nosuid参数,该参数会禁用挂载分区上的setuid/setgid权限,导致工具无法正常完成提权操作。

内容的提问来源于stack exchange,提问作者jpmh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 16:01:30