I wonder if sudo su works if sudoer password is different from root?

|
BarakObama 2022-08-20 03:11:00
https://www.reddit.com/r/linux/comments/wshp92/til_gnomesystemmonitor_only_supports_1024_cpus/

TIL gnome-system-monitor only supports 1024 CPUsreddit
Posted in r/linux by u/foop09 • 1,946 points and 323 comments
smol_mazunki 2022-08-20 03:12:34
BarakObama 2022-08-20 03:11:00
https://www.reddit.com/r/linux/comments/wshp92/til_gnomesystemmonitor_only_supports_1024_cpus/

smh

Brandon Johnson 2022-08-20 05:01:20
exploit for getting in root shell if you know the sudoers pw
baguette_dad 2022-08-20 05:18:15
Brandon Johnson 2022-08-20 05:01:20
exploit for getting in root shell if you know the sudoers pw

Nice

baguette_dad 2022-08-20 05:19:18
But if you know the sudoers password
baguette_dad 2022-08-20 05:19:42
Why not just sudo su?
ActuallyNotGelb 2022-08-20 05:19:58
ikr
ActuallyNotGelb 2022-08-20 05:20:17
it’s like if I used the same key as I use to unlock my car, to also turn it on, using an exploit
ActuallyNotGelb 2022-08-20 05:20:22
when I can just use it regularly
ActuallyNotGelb 2022-08-20 05:20:26
sounds a bit unnecessary
Brandon Johnson 2022-08-20 05:34:12
Yeah on older systems I guess it works without sudo though
Brandon Johnson 2022-08-20 05:35:46
Or if they left a shell open that’s already used sudo
Brandon Johnson 2022-08-20 05:36:22
I wonder if sudo su works if sudoer password is different from root?
Brandon Johnson 2022-08-20 05:36:48
And some features are restricted from sudo
smol_mazunki 2022-08-20 05:43:42
Brandon Johnson 2022-08-20 05:01:20
exploit for getting in root shell if you know the sudoers pw

why would anyone ever run man as sudo

smol_mazunki 2022-08-20 05:44:21
ActuallyNotGelb 2022-08-20 05:20:17
it’s like if I used the same key as I use to unlock my car, to also turn it on, using an exploit

the idea would be that someone added man to the list of accepted commands

Brandon Johnson 2022-08-20 05:44:24
well it overloads the buffer, so if you have sudo user password but not root password, you can still get a root shell
smol_mazunki 2022-08-20 05:44:24
but not su
smol_mazunki 2022-08-20 05:44:54
Brandon Johnson 2022-08-20 05:44:24
well it overloads the buffer, so if you have sudo user password but not root password, you can still get a root shell

just init=/bin/sh to your kernel line smh

Brandon Johnson 2022-08-20 05:45:18
idk I found it in a MOOK lol
smol_mazunki 2022-08-20 05:45:28
(although i guess this may be useful if you’re on an encrypted system xd)
Brandon Johnson 2022-08-20 05:45:38
I’m a data analyst, not a cyber security specialist anyway 😔
smol_mazunki 2022-08-20 05:45:53
im just a nerd
Brandon Johnson 2022-08-20 05:46:00
same actually
smol_mazunki 2022-08-20 05:46:14
linux_group-1396291.jpg
same vibes
Brandon Johnson 2022-08-20 05:46:28
I have a “data analyst” certificate haha, and a few IT certs and a few programming certs, but I’m actually a stay at home dad lmao
smol_mazunki 2022-08-20 05:46:52
i am at a stage where people assume I’m buying stuff for my kid
smol_mazunki 2022-08-20 05:46:57
when it’s for me, all of it
smol_mazunki 2022-08-20 05:47:09
i haven’t even considered starting a family lol
Brandon Johnson 2022-08-20 05:47:10
lmfao
Brandon Johnson 2022-08-20 05:47:15
I have two kids
Brandon Johnson 2022-08-20 05:47:24
my wife is an occupational health nurse
Brandon Johnson 2022-08-20 05:47:31
asked me to stay home
smol_mazunki 2022-08-20 05:47:34
teach them posix, regex, and sed
smol_mazunki 2022-08-20 05:47:43
Brandon Johnson 2022-08-20 05:47:31
asked me to stay home

your family is hot

|