added README and LICENSE #3
@@ -0,0 +1,21 @@
|
||||
MIT License
|
||||
|
||||
Copyright (c) 2025 [Your Name]
|
||||
|
||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
of this software and associated documentation files (the "Software"), to deal
|
||||
in the Software without restriction, including without limitation the rights
|
||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||
copies of the Software, and to permit persons to whom the Software is
|
||||
furnished to do so, subject to the following conditions:
|
||||
|
||||
The above copyright notice and this permission notice shall be included in all
|
||||
copies or substantial portions of the Software.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||
SOFTWARE.
|
||||
@@ -0,0 +1,174 @@
|
||||
# sudo - A Simple Sudo Implementation
|
||||
|
||||
A lightweight implementation of the `sudo` command for Unix-like systems, written in C.
|
||||
|
||||
## Overview
|
||||
|
||||
This project provides a minimal yet functional `sudo` replacement that allows users to execute commands with root privileges. It's designed to be simple, secure, and easy to understand.
|
||||
|
||||
## Features
|
||||
|
||||
- Execute commands as root user
|
||||
- Minimal dependencies (standard C library only)
|
||||
- Cross-platform support (Linux focused)
|
||||
- Proper error handling and reporting
|
||||
- Package creation for easy distribution
|
||||
|
||||
## Building
|
||||
|
||||
### Prerequisites
|
||||
|
||||
- GCC compiler
|
||||
- Make utility
|
||||
- Root access (for installation)
|
||||
|
||||
### Compilation
|
||||
|
||||
```bash
|
||||
make build
|
||||
```
|
||||
|
||||
This will:
|
||||
- Create the `bin/` directory if it doesn't exist
|
||||
- Compile the source code with appropriate flags
|
||||
- Set the binary owner to root (0:0)
|
||||
- Set the setuid bit (4755 permissions)
|
||||
|
||||
### Cleaning
|
||||
|
||||
```bash
|
||||
make clean
|
||||
```
|
||||
|
||||
Removes the compiled binary from the `bin/` directory.
|
||||
|
||||
## Installation
|
||||
|
||||
### Manual Installation
|
||||
|
||||
After building, you can manually copy the binary to your system:
|
||||
|
||||
```bash
|
||||
sudo cp bin/sudo /usr/bin/sudo
|
||||
sudo chown root:root /usr/bin/sudo
|
||||
sudo chmod 4755 /usr/bin/sudo
|
||||
```
|
||||
|
||||
### Package Installation
|
||||
|
||||
Create a package for distribution:
|
||||
|
||||
```bash
|
||||
make package
|
||||
```
|
||||
|
||||
This creates a `sudo.pkg.gz` archive containing:
|
||||
- The binary
|
||||
- Installation files
|
||||
- Post-installation script for proper permissions
|
||||
|
||||
## Usage
|
||||
|
||||
```bash
|
||||
sudo COMMAND [ARG...]
|
||||
```
|
||||
|
||||
### Examples
|
||||
|
||||
```bash
|
||||
# Edit a system file
|
||||
sudo nano /etc/hosts
|
||||
|
||||
# Install a package
|
||||
sudo apt update
|
||||
|
||||
# View system logs
|
||||
sudo tail -f /var/log/syslog
|
||||
|
||||
# Run a command as root
|
||||
sudo whoami
|
||||
```
|
||||
|
||||
## Security Considerations
|
||||
|
||||
⚠️ **Important Security Notes:**
|
||||
|
||||
1. **Setuid Root**: This binary runs with setuid root permissions, which is necessary for privilege escalation but comes with security risks.
|
||||
|
||||
2. **No Authentication**: This implementation does not include password authentication. In a production environment, you should implement proper authentication mechanisms.
|
||||
|
||||
3. **No Access Control**: There are no restrictions on which users can use this sudo implementation or which commands they can run.
|
||||
|
||||
4. **Audit Logging**: This version does not log command execution. Consider adding logging for security auditing.
|
||||
|
||||
## Architecture
|
||||
|
||||
The implementation consists of:
|
||||
|
||||
- **Command Line Parsing**: Validates arguments and displays usage information
|
||||
- **Privilege Escalation**: Uses `setuid()`, `setgid()`, and `setgroups()` to gain root privileges
|
||||
- **Command Execution**: Uses `execvp()` to execute the target command
|
||||
- **Error Handling**: Comprehensive error reporting with proper exit codes
|
||||
|
||||
## Code Structure
|
||||
|
||||
```
|
||||
sudo/
|
||||
├── src/
|
||||
│ └── sudo.c # Main implementation
|
||||
├── bin/ # Compiled binary (created during build)
|
||||
├── Makefile # Build configuration
|
||||
├── LICENSE # MIT License
|
||||
└── README.md # This file
|
||||
```
|
||||
|
||||
## Development
|
||||
|
||||
### Building for Development
|
||||
|
||||
```bash
|
||||
# Build the project
|
||||
make build
|
||||
|
||||
# Test the binary
|
||||
./bin/sudo whoami
|
||||
```
|
||||
|
||||
### Debugging
|
||||
|
||||
For debugging, you can modify the `CFLAGS` in the Makefile to include debug symbols:
|
||||
|
||||
```makefile
|
||||
CFLAGS=-Wall -g -DDEBUG
|
||||
```
|
||||
|
||||
## Limitations
|
||||
|
||||
This is a simplified implementation and lacks many features of the full sudo:
|
||||
|
||||
- No configuration file (`/etc/sudoers`)
|
||||
- No password authentication
|
||||
- No user/group restrictions
|
||||
- No command logging
|
||||
- No timeout functionality
|
||||
- No environment variable handling
|
||||
|
||||
## Contributing
|
||||
|
||||
1. Fork the repository
|
||||
2. Create a feature branch
|
||||
3. Make your changes
|
||||
4. Test thoroughly
|
||||
5. Submit a pull request
|
||||
|
||||
## License
|
||||
|
||||
This project is licensed under the MIT License - see the [LICENSE](LICENSE) file for details.
|
||||
|
||||
## Disclaimer
|
||||
|
||||
This software is provided for educational and development purposes. Use in production environments should be done with careful consideration of security implications. The authors are not responsible for any security vulnerabilities or system damage resulting from the use of this software.
|
||||
|
||||
## Support
|
||||
|
||||
For questions, issues, or contributions, please refer to the project's issue tracker or contact the maintainers.
|
||||
Reference in New Issue
Block a user