sudo & Privilege Escalation
sudo
Logging in directly as root for everyday work is risky - every mistake happens with full system privileges, and there's no record of which admin did what if several people share the root password. sudo ("substitute user, do") solves this: it lets an approved user run a specific command as another user (root, by default) using their own login credentials, with every invocation logged.
| Command | Action |
|---|---|
sudo cmd | Run cmd as root |
sudo -u alice cmd | Run as alice |
sudo -i | Root login shell |
visudo | Safely edit sudo config |
Configuration lives in /etc/sudoers and /etc/sudoers.d/, and this is one of the very few files on Linux you should never open with a plain text editor directly. Always edit with visudo - it locks the file against simultaneous edits and, crucially, validates the syntax before saving. A malformed /etc/sudoers written directly with vim can lock out sudo entirely for every user on the system, with no easy way back in short of booting into rescue mode.
# /etc/sudoers.d/devs
alice ALL=(ALL:ALL) ALL # full sudo
%devs ALL=(ALL) NOPASSWD: /bin/systemctl restart nginx
The second line shows fine-grained delegation in action: instead of full root access, everyone in the devs group is allowed to run exactly one specific command as root, without even needing to enter a password (NOPASSWD) - useful for letting a deployment pipeline restart a service without handing over broad admin rights.
Tip:sudoaccess itself is granted through group membership, and the group name differs by distro family: Debian/Ubuntu uses thesudogroup, while RHEL/Fedora traditionally useswheel. Being in that group (recallusermod -aGfrom the Users module) is what grants the rights defined in/etc/sudoersfor that group. In sudoers syntax, a%prefix before a name (like%devsabove) always means "this is a group, not a single user."