Linux Sudo ȨÏÞÈÆ¹ý·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-15

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-14287£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Sudo 1.8.28֮ǰµÄËùÓа汾


·ì϶¸ÅÊö


Sudo µÄÈ«³ÆÊÇ¡°superuserdo¡±£¬£¬£¬£¬£¬£¬£¬ËüÊÇLinuxϵͳÖÎÀíÖ¸Á£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§ÔÚ²»±ØÒªÇл»»·¾³µÄǰÌáÏÂÒÔÆäËüÓû§µÄȨÏÞÔËÐÐÀûÓ÷¨Ê½»òºÅÁ£¬£¬£¬£¬£¬£¬Í¨³£ÊÇÒÔ root Óû§Éí·ÝÔËÐкÅÁ£¬£¬£¬£¬£¬£¬ÒÔÏ÷¼õ root Óû§µÄµÇ¼ºÍÖÎÀí¹¦·ò£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Ìá¸ß°²È«ÐÔ¡£¡£¡£¡£¡£


¸Ã·ì϶ÊÇ sudo°²È«Õ½ÊõÈÆ¹ýÎÊÌ⣬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö¶ñÒâÓû§»ò·¨Ê½ÔÚÖ¸±ê Linux ϵͳÉÏÒÔ root Éí·ÝÖ´ÐÐËÁÒâºÅÁ£¬£¬£¬£¬£¬£¬¼´±ã ¡°sudoers configuration¡± Ã÷È·²»Èݸà root½Ó¼ûȨÏÞÒ²²»Àý±í¡£¡£¡£¡£¡£


ÀûÓø÷ì϶ҪÇóÓû§ÓµÓÐ sudo ȨÏÞ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÒÔËÁÒâÓû§ ID ÔËÐкÅÁî¡£¡£¡£¡£¡£Í¨³£¶øÑÔ£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÓû§µÄ sudoers Ìõ¿îÔÚ Runas ¹æ·¶ÖÐÓµÓÐÌØÊâÖµ ALL¡£¡£¡£¡£¡£Sudo Ö§³ÖÔÚ sudoers Õ½ÊõÔÊÐíµÄÇé¿öÏ£¬£¬£¬£¬£¬£¬£¬ÒÔÓû§Ö¸¶¨µÄÃû³Æ»òÓû§ ID ÔËÐкÅÁî¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬ÈçÏ sudoers Ìõ¿îÔÊÐí id ºÅÁîÒÔËÁÒâÓû§Éí·ÝÔËÐУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÔ̺¬ Runas ¹æ·¶ÖеĹؼü×ÖALL¡£¡£¡£¡£¡£


myhost alice = (ALL) /usr/bin/id


Óû§²»½ö¿ÉÄÜÒÔÆäËüºÏ·¨Óû§Éí·ÝÔËÐиà id ºÅÁ£¬£¬£¬£¬£¬£¬»¹ÄÜʹÓà #uid Óï·¨ÒÔËÁÒâÓû§ ID ÔËÐиúÅÁ£¬£¬£¬£¬£¬£¬ÀýÈ磺


sudo -u#1234 id -u


½«·µ»Ø1234£¬£¬£¬£¬£¬£¬£¬È»¶ø£¬£¬£¬£¬£¬£¬£¬sudo ÔÚÔËÐкÅÁîǰÓû§Åú¸ÄÓû§ ID µÄsetresuid(2) ºÍ setreuid(2)ϵͳŲÓý«ÌØÊâ¶Ô´ýÓû§ IDΪ-1£¨»òÆäδÊðÃûµÄµÈֵͬ 4294967295£©²¢ÇÒ²¢²»»áÅú¸Ä¸ÃÖµµÄÓû§ ID¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬£¬


sudo -u#-1 id -u


»ò


sudo -u#4294967295 id -u


ÏÖʵÉϻ᷵»Ø 0¡£¡£¡£¡£¡£ÕâÊÇÓÉÓÚ sudoºÅÁî×ÔÉí¾ÍÒѾ­ÒÔÓû§ ID Ϊ0 ÔËÐУ¬£¬£¬£¬£¬£¬£¬Òò¶øµ± sudo ÊÔͼ½«Óû§ ID Åú¸Ä³É -1ʱ£¬£¬£¬£¬£¬£¬£¬²»»á²úÉúÈκα䶯¡£¡£¡£¡£¡£Õâ¾Íµ¼Ö sudo ÈÕÖ¾Ìõ¿î½«¸ÃºÅÁî»ã±¨ÎªÒÔÓû§ ID Ϊ 4294967295¶ø·Ç root £¨»òÕßÓû§IDΪ 0£©ÔËÐкÅÁî¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚͨ¹ý¨Cu Ñ¡ÏîÖ¸¶¨µÄÓû§ ID ²¢²»´æÔÚÓÚÃÜÂëÊý¾Ý¿âÖУ¬£¬£¬£¬£¬£¬£¬Òò¶ø²»»áÔËÐÐÈκΠPAM »á»°Ä£¿£¿ £¿£¿£¿é¡£¡£¡£¡£¡£


ÈôÊÇsudoers Ìõ¿î±»Ð´ÈëÔÊÐíÓû§ÒÔ³ý root Éí·ÝÒÔ±íµÄÓû§Éí·ÝÔËÐкÅÁ£¬£¬£¬£¬£¬£¬Ôò¿ÉÀûÓøà bug ÈÆ¹ý¸ÃÏÞ¶È¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬¸ø¶¨ÈçÏ sudoers Ìõ¿î£º


myhost bob = (ALL, !root) /usr/bin/vi


Óû§ bob ±»ÔÊÐíÒÔ³ýÁË rootÒÔ±íµÄÆäËüÓû§Éí·ÝÔËÐÐ vi¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´æÔڸ÷ì϶£¬£¬£¬£¬£¬£¬£¬bob ÏÖʵÉÏ¿ÉÄÜͨ¹ýÔËÐÐ sudo ¨Cu#-1 vi µÄ·½Ê½ÒÔ root Éí·ÝÔËÐÐ vi£¬£¬£¬£¬£¬£¬£¬´Ó¶øÎ¥·´Á˰²È«Õ½Êõ¡£¡£¡£¡£¡£Ö»ÓÐRunas ¹æ·¶ÖдæÔڹؼü×Ö ALL µÄsudoers Ìõ¿îÊÜÓ°Ïì¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬ÈçÏÂsudoers Ìõ¿î²¢²»ÊÜÓ°Ï죺


myhost alice = /usr/bin/id


ÔÚÕâ¸öÀý×ÓÖУ¬£¬£¬£¬£¬£¬£¬alice½ö±»ÔÊÐíÒÔ rootÉí·ÝÔËÐÐ id ºÅÁî¡£¡£¡£¡£¡£ÈκÎÒÔÆäËüÓû§Éí·ÝÔËÐиúÅÁîµÄ³¢ÊÔ¶¼½«Ôâ»Ø¾ø¡£¡£¡£¡£¡£


´Ë·ì϶ÊÇÖÎÀíÔ±ÔÚÅäÖÃÎļþÖÐÓÃÁËALL¹Ø¼ü´ÊºóÔì³ÉµÄ¡£¡£¡£¡£¡£µ«Ä¬ÈϵÄsudoÅäÖÃÎļþ²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


¸´ÏÖ»·¾³£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



µ±/etc/sudoersÎļþ´æÔÚÈçÏ´ó¾ÖµÄÅäÖûᵼÖ·ì϶µÄ²úÉú£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



½¨¸´½¨Òé


¹Ù·½ÒѾ­ÍƳö°²È«¸üУ¬£¬£¬£¬£¬£¬£¬Çë¸üÐÂÖÁ1.8.28°æ±¾£ºhttps://www.sudo.ws/download.html¡£¡£¡£¡£¡£


ÒÔÏÂΪ¸÷³§É̸ø³öµÄ²¼¸æ¼°½¨Ò飺


Red Hat Enterprise Linux / CentOS

https://access.redhat.com/security/cve/CVE-2019-14287


Ubuntu

https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-14287.html


SUSE / openSUSE

https://www.suse.com/security/cve/CVE-2019-14287.html


²Î¿¼Á´½Ó


https://www.sudo.ws/alerts/minus_1_uid.html