Why Pick sudo as Research Target? | Ep. 01 @LiveOverflow
Why Pick sudo as Research Target? | Ep. 01  @LiveOverflow
Uploaded April 2021 | Updated September 2026, 2 weeks ago
A serious sudo vulnerability had just been announced, but how do researchers find bugs like it? This first episode explains why sudo is an interesting target, prepares a reproducible research environment, and begins an AFL fuzzing strategy that immediately runs into practical problems.

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-sudoedit/sudoedit-introduction
Join the Hextree Discord: discord.gg/xgQpCQCpvy

RESOURCES
Text version: liveoverflow.com/why-pick-sudo-research-target-part-1
Episode files: github.com/LiveOverflow/pwnedit/tree/main/episode01
Full playlist: youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx

CHAPTERS
00:00 - Intro
01:48 - Prepare the System
03:57 - How to Pick a Research Target?
05:57 - Choose the Strategy: Fuzzing
09:27 - Fuzzing argv[] With AFL
13:00 - Running Into the Next AFL Problem
14:51 - Outro

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#BinaryExploitation #LinuxSecurity #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Why Pick sudo as Research Target? | Ep. 01Can AI Create a Minecraft Hack?Design Flaw in Security Product - ALLES! CTF 2021Log4j Vulnerability (Log4Shell) Explained // CVE-2021-44228Defusing a Bomb at Google London HQ - Having a Blast Google CTF Finals 2019 (hardware)Do you know this common Go vulnerability?Does Hacking Require Programming Skills?Security-driven Rapid Release - Pwn2Own Documentary (Part 4)How The RIDL CPU Vulnerability Was FoundFinding Player and Camera Position for Fly Hack - Pwn Adventure 3Learn Fault Injection at DEF CON 2026Finding 0day in Apache APISIX During CTF (CVE-2022-24112)
LiveOverflow |

Why Pick sudo as Research Target? | Ep. 01

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER