sudo & Privilege Escalation

sudo

Logging in directly as root for everyday work is risky - every mistake happens with full system privileges, and there's no record of which admin did what if several people share the root password. sudo ("substitute user, do") solves this: it lets an approved user run a specific command as another user (root, by default) using their own login credentials, with every invocation logged.

CommandAction
sudo cmdRun cmd as root
sudo -u alice cmdRun as alice
sudo -iRoot login shell
visudoSafely edit sudo config

Configuration lives in /etc/sudoers and /etc/sudoers.d/, and this is one of the very few files on Linux you should never open with a plain text editor directly. Always edit with visudo - it locks the file against simultaneous edits and, crucially, validates the syntax before saving. A malformed /etc/sudoers written directly with vim can lock out sudo entirely for every user on the system, with no easy way back in short of booting into rescue mode.

# /etc/sudoers.d/devs
alice   ALL=(ALL:ALL) ALL              # full sudo
%devs   ALL=(ALL) NOPASSWD: /bin/systemctl restart nginx

The second line shows fine-grained delegation in action: instead of full root access, everyone in the devs group is allowed to run exactly one specific command as root, without even needing to enter a password (NOPASSWD) - useful for letting a deployment pipeline restart a service without handing over broad admin rights.

Tip: sudo access itself is granted through group membership, and the group name differs by distro family: Debian/Ubuntu uses the sudo group, while RHEL/Fedora traditionally uses wheel. Being in that group (recall usermod -aG from the Users module) is what grants the rights defined in /etc/sudoers for that group. In sudoers syntax, a % prefix before a name (like %devs above) always means "this is a group, not a single user."