Tuesday, October 27, 22:26
Home security A new bug in the sudo command puts Linux users at risk

A new bug in the sudo command puts Linux users at risk

A vulnerability was recently detected in the Linux sudo command (super user do). This could allow users who do not have rights to execute commands as root. The good news is that not all Linux has been affected servers, as it is a type of vulnerability that affects only informal configurations.

sudo

But first of all, let's look at how the sudo command works and how it can be configured. When commands are executed on operating system For Linux, unauthorized users can use the sudo command to execute commands as root. The basic requirement is that they are licensed or know password of the root.

The sudo command can be configured to allow one user execute commands as another user by adding special instructions to the configuration file. The following commands allow the user `test` to execute the / usr / bin / vim and / usr / bin / id commands as any user other than root.

When a user is created on Linux, he gets a UID. Users can use these UID instead of a username when starting sudo.

Let's go back to that now vulnerability. Apple security researcher Joe Vennix discovered one bug which allows users to start a sudo command as root using the “-1” or “4294967295” UID. For example, the following command could use this error to start user / usr / bin / id as root, even though `test 'refused to do so in / etc / sudoers.

The truth is that this is a powerful error, but it's important to know that it can only work if a user has access to a command via the sudoers file. Otherwise this error will have no effect.

sudo

To be able to exploit a vulnerability, a user must have set up for one mandate, a sudoer instruction that can start other commands.

While this error it is obviously powerful, it can still be used only at informal configurations that will not affect the vast majority of Linux users.

What users are using instructions sudoers, it's best to upgrade to sudo 1.8.28 or later as soon as possible.

LEAVE ANSWER

Please enter your comment!
Please enter your name here

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

LIVE NEWS

00:01:47

Data breach in a law firm exposes data of Google employees

Immigration law firm Fragomen, Del Rey, Bernsen & Loewy, LLP revealed that it suffered a data breach that led to the leakage of personal data ...

How to install a .watchface file on Apple Watch

The Apple Watch lets you customize the faces of the watch to display all kinds of useful information. But did you know ...

The five biggest data breaches of the 21st century

Data is becoming more and more sought after as our daily lives become more digitized. The technology giants that monopolize data are ...

Microsoft is limiting the availability of Windows 10 20H2

Microsoft is currently restricting the availability of Windows 10 20H2 to provide all users who want to ...

How to enable the new Chrome Read more feature

The latest version of Google Chrome browser, v86, released earlier this month, contains a secret feature called Read ...

How to choose a custom color for the Start menu

Starting with the October 2020 update, Windows 10 is the default on a theme that removes bright colors from ...

NASA telescope discovers drinking water on the moon

Eleven years ago, a spacecraft changed our view of the moon forever. The data collected by ...

Microsoft: Enhances password spray attack detection capabilities

Microsoft has significantly improved the ability to detect password spray attacks in the Azure Active Directory (Azure AD) and has reached the point ...

How to prevent companies from finding our phone number

In the age of advertising, the more user information is known the more convenient it is for companies. And in particular, the ...

Violation in a psychotherapy clinic led to blackmail of patients

Two years ago, a cyber attack took place in a Finnish psychotherapy clinic, which resulted in data theft and ransom demand. Now,...