Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Webinars
  • Linux Privilege Elevation: Breaking out of Sudo with GTFOBins current page
Link copied

Linux Privilege Elevation: Breaking out of Sudo with GTFOBins

with Randy Franklin Smith, CEO, Monterey Technology Group, Inc. CISA, SSCP, Security MVP; Patrick Schneider, Sr. Solutions Architect
Webinars default
Linux Privilege Elevation: Breaking out of Sudo with GTFOBins

Get Instant Access to this Content

Learn more about how to secure your business from threats in places you didn't even know existed.

To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video

2024 07 25 UWS Webinar Recording 0000001
01:21:54

Linux is all about files and commands and without something like sudo, security is all or nothing. You have monolithic root access, or you don’t. Sudo attempts to impose a more granular approach to privileged access in Linux by limiting which commands you can run with root access by crafting a sudoers file, which in effect allows an organization to delegate specific privileged functions to specific users.

The simplest sudoers policy specifies a user or group and the name of the binary they are allowed to run as root.

But you have to go further than the command. Much further.

To begin with, many commands naturally have more than one function. For example, moduser has different functions for unlocking a user account and for changing its password. If you want to give someone the ability to unlock user accounts without allowing them to also change their password and subsequently logon as that user, you have to add those parameter restrictions to the sudoers entry for that command.

But that’s just the beginning of the story.

There are hundreds of binaries in Linux that provide the ability to run arbitrary commands or even open interactive shells. And these are not unusual commands that users seldom need. Text editors like vi and nano and very common binaries like tar (file compression) and even man (for displaying documentation) can be used to gain access to interactive shells with root access.

To be clear, these are not vulnerabilities per se that can just be patched – they are in most cases intended functions of each binary.

In this real training for free event, we used a valuable project called GTFOBins to explore the many ways that a too simplistic implementation of sudo can be bypassed by a knowledgeable attacker or a determined user.

Randy showed live demonstration examples of bypassing a simplistic sudoers file and then show you how to fix the bypass.

After that. we discussed strategies for thoroughly implementing least privilege on Linux.

BeyondTrust was the sponsor for this event and the very knowledgeable Patrick Schieder helped Randy put this technical deep dive together. Patrick briefly showed:

  • A brief overview of BeyondTrust Endpoint Privilege Management for Linux (EPML), now offered as a SaaS solution.
  • Centralized management of Endpoint policy in SaaS, with event logging and audit recording of activities.
  • Explore how BeyondTrust EPML can improve the security of Linux commands and mitigate common workaround option as published in GTFOBins.

Meet the Presenters

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Randy Franklin Smith 200X200
Randy Franklin Smith
CEO, Monterey Technology Group, Inc. CISA, SSCP, Security MVP

Randy Franklin Smith is an internationally recognized expert on the security and control of Windows and Active Directory security who specializes in Windows and Active Directory security. He performs security reviews for clients ranging from small, privately held firms to Fortune 500 companies, national, and international organizations.

Schneider Patrick 20230124 NC4 B1418
Patrick Schneider
Sr. Solutions Architect

Patrick Schneider is a Senior IGA professional, with 30 years of experience in the Information Technology industry. Prior to joining BeyondTrust as a Senior Solutions Architect, Patrick was a Senior Solutions Engineer for the Security portfolio of a major IAM solutions provider. Patrick holds many industry certifications such as Comptia+, MCP, Certified Directory Engineer, Certified Linux Engineer and more.


Latest
  • The Ghost in the Machine (Securing Non-Human Identities)
    Jun 18, 2026 The Ghost in the Machine (Securing Non-Human Identities)
    Webinar
Related
  • Tech Talk Tuesday: Identity Security Insights
    Dec 12, 2023 Tech Talk Tuesday: Identity Security Insights
    On-demand we...
    16m
Share this Article
  • Link

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.