DigiNews

Tech Watch by Johan Denoyer

← Back to articles

sudo and OpenDoas timestamp files

Quality: 8/10 Relevance: 9/10

Summary

The article explains how sudo and OpenDoas timestamp files are used for password caching, describes a PoC exploit that reuses timestamp files across PTYs and PPIDs, and notes a mitigated approach using the start time of the session leader that was adopted by sudo since version 1.8.22 (2017). It references commit links and the sudo stable page.

🚀 Service construit par Johan Denoyer