The deploy account is root in all but name SEC-95

Open2 versionsSecurity · Medium · Fix · about 30 min ·Linux, root

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Priya Raman opened SEC-95 at 14:00SEV-4

An audit found that the deploy account may run anything as root. It only ever needs to restart Waybill and check its status.

The deploy account needs root for exactly two things: restarting Waybill and checking its status. It can currently do anything.

"Read waybill-ctl before you write the rule. Vendors love leaving a shell in their tools." (Priya)

sudo rules match the command and its arguments. A rule that allows a program with any arguments allows everything that program can do.

Your task

Rewrite deploy's sudo rule, with visudo -f, so it can run waybill-ctl restart and waybill-ctl status as root and nothing else.

On the machine

  • /etc/sudoers.d/
  • docs/sudo-policy.md
  • /usr/local/bin/waybill-ctl
  • sudo -u deploy sudo -n -l, id deploy

Timeline

2025-11"Temporary" rule: deploy ALL=(ALL) NOPASSWD: ALL, during the Waybill migration.
Last weekInternal audit flags it.
14:00SEC-95.

Done when

  1. deploy can run waybill-ctl restart and waybill-ctl status as root.
  2. deploy cannot run anything else as root, including waybill-ctl debug-shell.
  3. The sudoers configuration is valid and the rule lives in /etc/sudoers.d/deploy.

Hints

Hint 1

sudo -u deploy sudo -n -l lists what deploy may run, from every rule that matches it, including rules for its groups.

Hint 2

Read /usr/local/bin/waybill-ctl. What does debug-shell do?

Hint 3

A rule for waybill-ctl * also allows debug-shell. Name each allowed command with its argument. If a group rule grants the rest, the problem is the membership, not the group's rule.

Hint 4

sudo visudo -f /etc/sudoers.d/deploy, then sudo visudo -c.

Show the solution

`sudo -u deploy sudo -n -l` lists every rule that applies. Replace deploy's rule with deploy ALL=(root) NOPASSWD: /usr/local/bin/waybill-ctl restart, /usr/local/bin/waybill-ctl status using sudo visudo -f /etc/sudoers.d/deploy. If deploy is also in platform-admins (`id deploy`), take it out with `sudo gpasswd -d deploy platform-admins`; the administrators' rule stays as it is. Test again with sudo -u deploy sudo -n -l.