Sudo and its alternatives
Sudo and its alternatives
Posted Feb 21, 2024 20:02 UTC (Wed) by sping (guest, #103256)In reply to: Sudo and its alternatives by bluca
Parent article: Sudo and its alternatives
Many alternatives to sudo are (unlike recent sudo) vulnerable to TIOCSTI and TIOCLINUX hijacking attacks, either always or at least by default (e.g. runuser of util-linux), including doas and OpenDoas (always, except on OpenBSD) and pleaser. I'm maintaining a list of related CVEs at https://github.com/hartwork/antijack?tab=readme-ov-file#r... if curious. ttyjack (https://github.com/jwilk/ttyjack) would be the exploit demo of choice. For short: please choose your sudo alternatives carefully.