Home › Linux root and sudo security › Step 9
Lesson 9: Testing sudo security with environment variables
Step 9 of 13 in Linux root and sudo security · video 5:01
What you will learn
- Plant test variables and see what sudo passes on
- Confirm secure_path overrides a modified PATH
- Use sudo env as a direct test of the environment
- Remove test-only grants once testing is done
About this lesson
The environment rules from lesson 8 are put to the test. The account envuser is created with adduser, given a password through chpasswd, and entered with sudo su - envuser. Two variables are planted: LD_PRELOAD pointing at a library that does not exist, and a harmless CUSTOM_VAR. Running sudo env piped through grep -E '(LD_PRELOAD|CUSTOM_VAR|PATH|USER)' shows which variables actually reach the root process, and the dynamic linker prints a warning that the preload library cannot be loaded and is ignored. A second test puts /tmp at the front of PATH; sudo env | grep PATH still shows the secure_path value, not the user's own path. The lesson then takes /usr/bin/env back out of the passwordless command list, since allowing it through sudo is a risk in itself. Quoting trouble with grep along the way shows the value of rebuilding a failing pipeline one piece at a time.
Check yourself
1. After export PATH="/tmp/malicious:$PATH", what does sudo env | grep PATH show, and why?
The secure_path value from sudoers, not the user's modified PATH. sudo replaces PATH for the command it runs, so directories the user adds, such as /tmp, are never searched as root.
2. Why run sudo env rather than just reading the sudoers file?
env run through sudo prints the environment the root process actually receives, so you see directly whether variables such as LD_PRELOAD or a custom PATH get through, instead of assuming the configuration works.
3. How do you set envuser's password in one command without the interactive prompt?
echo 'envuser:env123' | sudo chpasswd. chpasswd reads user:password pairs from standard input, which is handy for test accounts, although the password is left in shell history.
4. Why does the lesson remove /usr/bin/env from envuser's NOPASSWD list after testing?
Letting a user run env as root is a risk: it exposes environment details, and env can also start any other program, so sudo env /bin/bash would give a root shell. It was only there for the test.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.
Zero-Trust Linux Administration: Complete Root Sudo Security
Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026
Get the course for $12.99