Skip to content

Sudo Abuse

Privilege escalation via sudo misconfigurations is a common attack vector in Linux environments. Attackers often exploit overly permissive sudoers file entries, such as NOPASSWD directives, to execute commands without authentication. This section explores common sudo configuration vulnerabilities, demonstrates exploitation techniques using tools like sudoedit, and provides mitigation strategies to prevent unauthorized privilege elevation.

NOPASSWD: The Primary Vector

The NOPASSWD directive in the sudoers file allows users to execute specific commands without entering a password. While useful for automation, it becomes a risk if applied to high-privilege commands. For example:

user ALL=(ALL) NOPASSWD: /bin/sh
This grants the user unrestricted shell access without authentication. Attackers can leverage this to escalate privileges by running arbitrary commands as root.

Exploitation Example:
If a user has NOPASSWD access to /usr/bin/python, they could execute:

sudo python -c 'import os; os.system("rm -rf /root")'
This would delete critical system files as root, leading to full system compromise.


Exploiting Sudoedit for Privilege Escalation

sudoedit is a sudo utility that opens a text editor with elevated privileges. Attackers can use it to modify configuration files or inject malicious scripts. For instance:

sudoedit /etc/sudoers
This command opens the sudoers file in the default editor (e.g., nano or vim). An attacker could append a new entry like:
attackuser ALL=(ALL) NOPASSWD: /bin/bash
After saving, the attacker gains root access via:
sudo /bin/bash

Advanced Technique:
If sudoedit is misconfigured to allow editing of other files, attackers might exploit it to modify service configurations (e.g., /etc/cron.d/ or /etc/passwd) to persist access.


Mitigating Sudo Risks

  1. Avoid NOPASSWD for sensitive commands: Use sudo with explicit command restrictions.
  2. Leverage sudoers.d: Store granular rules in /etc/sudoers.d/ instead of the main file.
  3. Audit configurations: Use sudo visudo -c to validate syntax and detect misconfigurations.
  4. Log and monitor: Enable logging for sudo commands via /etc/sudoers settings like timestamp_timeout and syslog directives.

Example Audit Command:

grep -E 'NOPASSWD|ALL' /etc/sudoers /etc/sudoers.d/*
This identifies all instances of NOPASSWD or ALL in sudoers files, highlighting potential risks.


Key takeaways

  • Avoid NOPASSWD for high-privilege commands to prevent passwordless escalation.
  • Regularly audit sudoers files using visudo -c to catch syntax errors or over-permissive rules.
  • Use sudoers.d for modular, manageable configurations instead of a single monolithic file.
  • Monitor sudo activity with logging to detect unauthorized command execution.
  • Restrict sudo to specific commands only, avoiding broad permissions like ALL=(ALL).