How SUDO on Linux was HACKED! // CVE-2021-3156 @LiveOverflow
How SUDO on Linux was HACKED! // CVE-2021-3156  @LiveOverflow
Uploaded April 2021 | Updated September 2026, 2 weeks ago
The most comprehensive video covering the sudo vulnerability CVE-2021-3156 Baron Samedit. I spent two weeks on rediscovering, analysing and exploitation of the sudoedit heap overflow. We will talk about fuzzing, code review, exploit strategies, heap feng shui and developing the exploit.

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-sudoedit/sudoedit-introduction
Join the Hextree Discord: discord.gg/xgQpCQCpvy

Article: liveoverflow.com/critical-sudo-vulnerability-walkthrough-cve-2021-3156

Binary Exploitation Playlist: youtube.com/playlist?list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN
PwnFunction's Binary Exploitation Playlist: youtube.com/playlist?list=PLI_rLWXMqpSkAYfar0HRA7lykydwmRY_2

Full CVE-2021-3156 Advisory: packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html
Qualys Blog: blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit
milek7's blog on fuzzing sudo: https://milek7.pl/howlongsudofuzz/

CHAPTERS
00:00 - Intro and Motivation
01:33 - afl: Fuzzing argv[]
03:22 - afl: sudo vs. sudoedit
04:27 - afl: Fuzzing setuid Process
06:49 - Fuzzing Conclusion
07:11 - Code Review: Identify Risky Code Through Isolation
09:39 - Code Review: Bypass Safe Conditions
11:15 - Exploit Strategy: Modern Mitigations
12:25 - The service_user Object Overwrite Technique
13:48 - Heap Feng Shui via Environment Variables
14:57 - Bruteforce Script to Find Exploitable Conditions
15:39 - Find and Analyse Useful Crashes
16:31 - Exploitability Analysis Conclusion
17:13 - Qualys Researchers Knew nss From Stack Clash
17:47 - Sudoedit Exploitable on macOs?
18:32 - Research Conclusion
19:27 - Outro

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#BufferOverflow #LinuxSecurity #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
How SUDO on Linux was HACKED! // CVE-2021-3156Best Operating Systems for Hacking?!XSS a Paste Service - Pasteurize (web) Google CTF 2020Developing a Tool to Find Function Pointers on The Heap | Ep. 10Chaining Script Gadgets to Full XSS - All The Little Things 2/2 (web) Google CTF 2020Creating The First (Failed) Sudoedit Exploit | Ep. 15Server Griefed and New Beginnings ...The OpenAI Story Actually Scares MeSECRET HACKER FORUM - The Place Where We Talk and LearnScanning The Internet for Minecraft ServersStart of Cyber Security Challenge Germany 2021 #shortsDissecting Pokemon Red Savegame
LiveOverflow |

How SUDO on Linux was HACKED! // CVE-2021-3156

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER