Can we please stop talking about that sudo bug? It only affects systems using an insane configuration (allow $command as anyone *but* root). I can't come up with any situation where that configuration makes any sense (vs e.g. "allow $command as any member of a given group).
-
Show this thread
-
I wouldn't be surprised if the number of systems affected by the vuln that *aren't* already intrinsically vulnerable to nasty privescs because the configuration is a terrible idea when working as intended is, well, essentially 0.
3 replies 5 retweets 57 likesShow this thread -
Since people still don't understand the vulnerable config: you have to allow $someone to sudo into *ANY USER* (not one specifically, *ANY*), which means giving them root, and then add an *exception* to take root away (but still let them become *any* other user).
3 replies 17 retweets 64 likesShow this thread -
To illustrate why this is a ridiculous idea and gives you root anyway even if sudo didn't have the bug: 'adm' is a member of 'disk' which can write to raw block devices, so you can just sudo to 'adm' instead of root and edit the sudoers file, or give suid to /bin/sh.
2 replies 14 retweets 92 likesShow this thread -
So if there are people there who actually had the sample config in the vuln report, they are vulnerable to all hell and back *anyway*, and if they've been trying to play whack-a-mole by excluding all "root-equivalent" user accounts, that's a ridiculous idea and they'll miss one.
2 replies 8 retweets 58 likesShow this thread -
Replying to @marcan42
Hmm will look into that, but i believe its about allowing ANY to run a specific CMD as root (say, you allow ANY to run ifconfig) that can be triggered to allow anyone to eacalate, using the named UID’s. That, is a config, seen in many setups.
1 reply 0 retweets 0 likes
No, that's backwards. It's about allowing someone to run something as ANY except root. Which is ridiculous.
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.