Sudo Abuse
Privilege escalation via sudo misconfigurations is a common attack vector in Linux environments. Attackers often exploit overly permissive sudoers file entries, such as NOPASSWD directives, to execute commands without authentication. This section explores common sudo configuration vulnerabilities, demonstrates exploitation techniques using tools like sudoedit, and provides mitigation strategies to prevent unauthorized privilege elevation.
NOPASSWD: The Primary Vector¶
The NOPASSWD directive in the sudoers file allows users to execute specific commands without entering a password. While useful for automation, it becomes a risk if applied to high-privilege commands. For example:
Exploitation Example:
If a user has NOPASSWD access to /usr/bin/python, they could execute:
Exploiting Sudoedit for Privilege Escalation¶
sudoedit is a sudo utility that opens a text editor with elevated privileges. Attackers can use it to modify configuration files or inject malicious scripts. For instance:
nano or vim). An attacker could append a new entry like:After saving, the attacker gains root access via:
Advanced Technique:
If sudoedit is misconfigured to allow editing of other files, attackers might exploit it to modify service configurations (e.g., /etc/cron.d/ or /etc/passwd) to persist access.
Mitigating Sudo Risks¶
- Avoid
NOPASSWDfor sensitive commands: Usesudowith explicit command restrictions. - Leverage
sudoers.d: Store granular rules in/etc/sudoers.d/instead of the main file. - Audit configurations: Use
sudo visudo -cto validate syntax and detect misconfigurations. - Log and monitor: Enable logging for sudo commands via
/etc/sudoerssettings liketimestamp_timeoutandsyslogdirectives.
Example Audit Command:
NOPASSWD or ALL in sudoers files, highlighting potential risks.
Key takeaways¶
- Avoid
NOPASSWDfor high-privilege commands to prevent passwordless escalation. - Regularly audit sudoers files using
visudo -cto catch syntax errors or over-permissive rules. - Use
sudoers.dfor modular, manageable configurations instead of a single monolithic file. - Monitor sudo activity with logging to detect unauthorized command execution.
- Restrict sudo to specific commands only, avoiding broad permissions like
ALL=(ALL).