{"id":109592,"date":"2020-06-01T22:41:58","date_gmt":"2020-06-01T14:41:58","guid":{"rendered":"http:\/\/4563.org\/?p=109592"},"modified":"2020-06-01T22:41:58","modified_gmt":"2020-06-01T14:41:58","slug":"su-user-c-xxx%e8%83%bd%e5%ae%9e%e7%8e%b0%e5%85%8d%e5%af%86%e7%a0%81%e6%89%a7%e8%a1%8c%e5%90%97","status":"publish","type":"post","link":"http:\/\/4563.org\/?p=109592","title":{"rendered":"su user -c &#8220;xxx&#8221;\u80fd\u5b9e\u73b0\u514d\u5bc6\u7801\u6267\u884c\u5417"},"content":{"rendered":"<div>\n<div>\n<div>\n<h1>                  su user -c &#8220;xxx&#8221;\u80fd\u5b9e\u73b0\u514d\u5bc6\u7801\u6267\u884c\u5417               <\/h1>\n<p> <\/p>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : AmrtaShiva <\/span>  <span><i><\/i> 0<\/span> <\/div>\n<div> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div isfirst=\"1\"> <\/p>\n<p>\u5982\u9898\uff0c\u5f53\u524d\u7528\u6237\u6240\u5728\u7684\u7ec4\u9ed8\u8ba4 sudo \u65e0\u9700\u8f93\u5165\u5bc6\u7801\u3002 su user -c &#8220;xxxx&#8221;\u4e4b\u540e\u8fd8\u5f97\u8f93\u5165\u5bc6\u7801\uff0c\u914d\u7f6e\u4e86 \/etc\/sudoers \u8c8c\u4f3c\u5bf9 su \u4e0d\u8d77\u4f5c\u7528\u3002 \u8fd9\u79cd\u64cd\u4f5c\u80fd\u5b9e\u73b0\u5982 sudo \u514d\u5bc6\u5417\uff1f\u8c22\u8c22<\/p>\n<\/p><\/div>\n<div> <b>\u5927\u4f6c\u6709\u8a71\u8aaa<\/b> (<span>9<\/span>)        <\/div>\n<div> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<ul>\n<li data-pid=\"1827235\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : python35 <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             sudo su user -c &#8220;xxxx&#8221; \u8bd5\u8bd5                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"1827236\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : codehz <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             su \u5f53\u7136\u4e0d\u4f1a\u8bfb sudo \u7684\u8bbe\u7f6e\uff08<br \/>\u4e0d\u8fc7\u8fd9\u79cd\u60c5\u51b5\u4e3a\u5565\u4e0d\u7528 sudo -u user &#8220;xxxx&#8221;                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"1827237\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : AmrtaShiva <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @codehz #2 \u7528\u4e86\u4e0d\u884c                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"1827238\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : iamverylovely <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             sudo \u53ea\u9700\u8981\u7b2c\u4e00\u6b21\u8f93\u5165\u5bc6\u7801\uff0c\u540e\u9762\u4e00\u6bb5\u65f6\u95f4\u662f\u514d\u5bc6\u7684\uff0c\u4f60\u662f\u9700\u8981\u505a\u4ec0\u4e48\u5462\u3002                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"1827239\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : yanqiyu <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             \u5982\u679c\u8fd9\u4e2a xxxx \u5f88\u5e38\u7528\u5e76\u4e14\u5f88\u5b89\u5168\u5f88\u53ef\u9760, \u5c31\u76f4\u63a5\u7ed9\u5b83\u4e2a setuid \u5457                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"1827240\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : baobao1270 <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             sudo su &lt;user&gt;                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"1827241\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : AmrtaShiva <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @yanqiyu #5 \u8c22\u8c22                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"1827242\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : nnd <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             [[email&#160;protected] ~]$ whoami <br \/>user1<br \/>[[email&#160;protected] ~]$ id<br \/>uid=1001(user1) gid=1001(user1) groups=1001(user1) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023<br \/>[[email&#160;protected] ~]$ sudo cat \/etc\/sudoers | grep -v &#8220;^#&#8221; | grep user<br \/>user1 ALL=(ALL) NOPASSWD: ALL<br \/>user2 ALL=(ALL) NOPASSWD: ALL<br \/>[[email&#160;protected] ~]$ ls \/root\/<br \/>ls: cannot open directory \/root\/: Permission denied<br \/>[[email&#160;protected] ~]$ sudo su user2 -c &#8220;sudo ls \/root&#8221;<br \/>anaconda-ks.cfg anaconda-ks.cfg_bak original-ks.cfg                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"1827243\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : hasdream <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             sudo \u8fbe\u5230 \u67d0\u4e2a\u7528\u6237 su \u67d0\u4e2a\u7528\u6237 <br \/>visudo #\u6700\u540e\u589e\u52a0<br \/>user1 ALL=(ALL) NOPASSWD: \/bin\/su &#8211; user2 # user1 \u767b\u9646\u540e sudo su &#8211; user2 sudo \u6388\u6743 su &#8211; user2 \u547d\u4ee4<\/p>\n<p>\u65b9\u6cd5 2<br \/>visudo<br \/>user1 ALL=(user2) NOPASSWD: ALL # user1 \u4f7f\u7528 sudo -u user2 id # sudo \u6388\u6743 user1 \u53ef\u4ee5\u4ee5 user2 \u8eab\u4efd\u6267\u884c\u547d\u4ee4                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li>\n","protected":false},"excerpt":{"rendered":"<p>su user -c &#038;#8220&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[],"_links":{"self":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/109592"}],"collection":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=109592"}],"version-history":[{"count":0,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/109592\/revisions"}],"wp:attachment":[{"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=109592"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=109592"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=109592"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}