Skip to content

Unquoted Service Paths (Linux)

Linux systems often use service managers like systemd, sysvinit, or init.d to manage daemons. A critical privilege escalation vector arises when service configuration files specify executable paths without quotation marks, enabling unquoted service paths. This misconfiguration allows attackers to exploit path traversal vulnerabilities, replacing legitimate binaries with malicious payloads, thereby executing arbitrary code under the service's privileges.


How Unquoted Service Paths Work

When a service's executable path is unquoted in a configuration file, the shell (e.g., /bin/sh) interprets it as a list of arguments. For example, consider a systemd service file with:

ExecStart=/usr/lib/myapp/myapp
If this path is unquoted, the shell may resolve it as /usr/lib/myapp/myapp (assuming no directory traversal). However, if an attacker replaces a file in a directory that appears earlier in the system's PATH environment (e.g., /usr/local/bin), the service might inadvertently execute the malicious file instead.


Exploitation Scenario

  1. Identify the service: Locate the service file (e.g., /etc/systemd/system/myservice.service).
  2. Check for unquoted paths: Look for ExecStart, ExecStop, or similar directives without quotes.
  3. Create a malicious file: Replace a file in a directory that appears before the intended path in PATH. For example:
    echo '#!/bin/sh' > /usr/local/bin/myservice
    chmod +x /usr/local/bin/myservice
    
  4. Restart the service: The service will execute the malicious file, granting attacker-controlled code execution under the service's privileges.

Real-World Example: init.d Script

A misconfigured init.d script might contain:

DAEMON=/usr/lib/myapp/myapp
If an attacker replaces /usr/bin/ (a common PATH directory) with a symlink to a malicious binary, the service could execute the payload.


Mitigation Strategies

  • Quote paths in configuration files: Always enclose executable paths in quotes (e.g., ExecStart="/usr/lib/myapp/myapp").
  • Use absolute paths: Avoid relying on environment variables like PATH for resolving executables.
  • Audit service configurations: Regularly scan for unquoted paths using tools like checksec or custom scripts:
    find /etc -type f -exec grep -l '[^"]\$$/[^"]' {} \;
    

Key takeaways

  • Unquoted paths in service configs allow attackers to hijack service execution via path traversal.
  • Exploitation requires replacing a file in a directory prioritized in the system's PATH.
  • Mitigation involves quoting paths, using absolute paths, and auditing service configurations.