Security

Sudoers File Analyzer

Paste a sudoers file to find the entries that grant more than intended: NOPASSWD on shell capable binaries, wildcard command paths, ALL grants and the known GTFOBins escalation vectors.

Last reviewed by the Radiatus Cloud team

Findings appear here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Almost every sudo rule grants more than it looks like

Delegating a single command through sudo appears narrow and frequently is not. A great many ordinary Unix utilities can execute a shell or read arbitrary files as a side effect, so granting sudo on vi, less, find, awk, tar or a dozen others is functionally equivalent to granting root. The GTFOBins project catalogues these, and the list is long enough that assuming a binary is safe rather than checking it is the wrong default.

Wildcards are the second trap

A rule permitting a path with a wildcard, such as /usr/bin/systemctl restart *, does not constrain the argument the way it appears to. Depending on the utility, the wildcard can be used to reach a different file, to pass an option that changes the behaviour entirely, or to traverse directories. Where a wildcard is genuinely needed, the argument should be validated by a wrapper script owned by root rather than by the sudoers pattern.

NOPASSWD removes the last check

Requiring a password does not stop a determined attacker who already has the user's credentials, but it does stop an unattended session, a stolen browser token that yields shell access, and most automated post exploitation tooling. NOPASSWD on a command that can spawn a shell converts any code execution as that user into immediate root with no further work. Reserve it for genuinely non interactive automation, and prefer a dedicated service account over a human one.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

Why is sudo on vi or less dangerous?

Both can execute a shell from inside the program: in vi, :!sh, and in less, !sh. The shell inherits the elevated privileges, so sudo on either is sudo on everything. The same applies to find, awk, tar, git, nmap and many others catalogued by GTFOBins.

Are wildcards in command paths safe?

Rarely. A wildcard matches more than the author usually intends, including paths that traverse directories and arguments that change the utility’s behaviour. Where a variable argument is genuinely needed, validate it in a root owned wrapper script rather than in the sudoers pattern.

What does the NOEXEC tag do?

It uses an LD_PRELOAD shim to prevent the permitted command from executing other programs, which blocks many shell escapes. It only works for dynamically linked binaries that use the standard library exec functions, so it is a useful hardening layer rather than a guarantee.

Should I edit sudoers directly?

Never with a plain editor. Use visudo, which validates the syntax before saving. A malformed sudoers file can prevent all privilege escalation on the host, and recovering from that usually requires single user mode or console access.

Is a rule limited to a specific host safer?

The host specification limits which machines the rule applies to when the file is shared across an estate, which is useful for a central sudoers. On a single host it has no effect, and ALL in that field is normal rather than a finding.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste your sudoers file or the output of sudo -l to audit it for escalation paths.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.