Potential bypass of Runas user restrictions in sudo
1–10 of 29 posts
Re: Potential bypass of Runas user restrictions in sudo
#2Re: Potential bypass of Runas user restrictions in sudo
#3I do love that this command has its own website - and a delightfully on-point XKCD-inspired logo :)
Re: Potential bypass of Runas user restrictions in sudo
#4This seems pretty serious, but I wonder if there is a way to measure how many systems are affected by this. Does anyone have telemetry on how many Runas configs are set up this way? How would someone collect this data?
Re: Potential bypass of Runas user restrictions in sudo
#5Re: Potential bypass of Runas user restrictions in sudo
#6 myhost alice = (ALL) /usr/bin/id
All the examples I've seen of sudoers files do it this way: alice myhost = (ALL) /usr/bin/id
This is important because the host is rarely used; the host field is usually replaced with ALL, meaning the host name is not important for the rule: alice ALL = (ALL) /usr/bin/id
I hope this isn't some new sudoers syntax.As I consider whether this bug impacts my company, I see two types of rules in our sudoers files: (1) rules that let already-privileged users do privileged things and (2) rules that let processes with minimal privileges make an exception to normal security rules. This bug doesn't impact rules for highly privileged users because they already have many ways to do whatever they want. This bug doesn't impact the second type of rules either because those rules specify exactly which user to change to; I tested the '-u#-1' trick with one of those rules on an unpatched sudo and sudo didn't allow it.
The behavior I observed seems to match the advisory, which says the exploitable rules are those that don't specify a specific user to run as.
Now I wonder: what kind of well-written rule would be exploitable?
Re: Potential bypass of Runas user restrictions in sudo
#7The fix appears to be to reject -1 as invalid.
The article should have included in the fix section a link to the commit and a summary of what the fix was.
Re: Potential bypass of Runas user restrictions in sudo
#8https://www.sudo.ws/repos/sudo/file/f75f786eddd5
It has more than 10 thousand commits, ~600 files, and close to 11MB of C code. Also, the code seems to have no unit tests, the main file is 1.4K lines long, has quintuple-nested conditionals and liberally uses goto statements.
Am I missing something here?
Re: Potential bypass of Runas user restrictions in sudo
#9Is this the official sudo repository? https://www.sudo.ws/repos/sudo/file/f75f786eddd5 It has more than 10 thousand commits, ~600 files, and close to 11MB of C code. Also, the code seems to have no unit tests, the main file is 1.4K lines long, has quintuple-nested conditionals and liberally uses goto statements. Am I missing something here?
Re: Potential bypass of Runas user restrictions in sudo
#10Is this the official sudo repository? https://www.sudo.ws/repos/sudo/file/f75f786eddd5 It has more than 10 thousand commits, ~600 files, and close to 11MB of C code. Also, the code seems to have no unit tests, the main file is 1.4K lines long, has quintuple-nested conditionals and liberally uses goto statements. Am I missing something here?