video thumbnail 8:03
Reaching Vulnerable Code in sudo (C code review)

2021-08-11

[public] 15.3K views, 1.56K likes, 10.0 dislikes audio only

channel thumbLiveOverflow

A bit more code review of sudo to understand why it's vulnerable and what the conditions are to get there.

Full Playlist: /youtube/video/TLa2VqcGGEQ

Grab the files: https://github.com/LiveOverflow/pwnedit

Episode 08:

00:00 - Intro

00:18 - The Heap Overflow

02:27 - Identifying the Conditions to Reach the Vulnerable Code

03:00 - The sudo Modes

03:40 - Sudo is Escaping The Arguments!

04:25 - How to Skip the Escaping?

05:16 - The Curious Case of "sudoedit"

06:15 - Exploring Alternative sudo modes

07:05 - Outro

07:35 - #ads

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Website: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Understanding C Pointer Magic Arithmetic | Ep. 07 by LiveOverflow
/youtube/video/zdzcTh9kUrc
Intro
/youtube/video/RZiGBjrOLY8?t=0
The Heap Overflow
/youtube/video/RZiGBjrOLY8?t=18
Identifying the Conditions to Reach the Vulnerable Code
/youtube/video/RZiGBjrOLY8?t=147
The sudo Modes
/youtube/video/RZiGBjrOLY8?t=180
Sudo is Escaping The Arguments!
/youtube/video/RZiGBjrOLY8?t=220
How to Skip the Escaping?
/youtube/video/RZiGBjrOLY8?t=265
The Curious Case of "sudoedit"
/youtube/video/RZiGBjrOLY8?t=316
Exploring Alternative sudo modes
/youtube/video/RZiGBjrOLY8?t=375
Outro
/youtube/video/RZiGBjrOLY8?t=425
ads
/youtube/video/RZiGBjrOLY8?t=455
I’m moving, no videos sorry 17,544 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
Sudo Vulnerability Walkthrough by LiveOverflow
/youtube/video/TLa2VqcGGEQ