Home › Linux root and sudo security › Step 9

Lesson 9: Testing sudo security with environment variables

Step 9 of 13 in Linux root and sudo security · video 5:01

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

The environment rules from lesson 8 are put to the test. The account envuser is created with adduser, given a password through chpasswd, and entered with sudo su - envuser. Two variables are planted: LD_PRELOAD pointing at a library that does not exist, and a harmless CUSTOM_VAR. Running sudo env piped through grep -E '(LD_PRELOAD|CUSTOM_VAR|PATH|USER)' shows which variables actually reach the root process, and the dynamic linker prints a warning that the preload library cannot be loaded and is ignored. A second test puts /tmp at the front of PATH; sudo env | grep PATH still shows the secure_path value, not the user's own path. The lesson then takes /usr/bin/env back out of the passwordless command list, since allowing it through sudo is a risk in itself. Quoting trouble with grep along the way shows the value of rebuilding a failing pipeline one piece at a time.

Good to know: the 'cannot be preloaded' warning comes from programs that run as you, such as grep, while LD_PRELOAD is still set in your shell. What the test shows is that sudo removes LD_PRELOAD before it starts the command.

Check yourself

Answer in your head first, then open each question to see the answer.

1. After export PATH="/tmp/malicious:$PATH", what does sudo env | grep PATH show, and why?

The secure_path value from sudoers, not the user's modified PATH. sudo replaces PATH for the command it runs, so directories the user adds, such as /tmp, are never searched as root.

2. Why run sudo env rather than just reading the sudoers file?

env run through sudo prints the environment the root process actually receives, so you see directly whether variables such as LD_PRELOAD or a custom PATH get through, instead of assuming the configuration works.

3. How do you set envuser's password in one command without the interactive prompt?

echo 'envuser:env123' | sudo chpasswd. chpasswd reads user:password pairs from standard input, which is handy for test accounts, although the password is left in shell history.

4. Why does the lesson remove /usr/bin/env from envuser's NOPASSWD list after testing?

Letting a user run env as root is a risk: it exposes environment details, and env can also start any other program, so sudo env /bin/bash would give a root shell. It was only there for the test.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 8: Sudoers environment securityNext: Lesson 10: Sudo session management and timestamp timeouts →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.