T09 · Insecure Skill Coding Practices
- Location
sudo-tool.sh:59- Finding
Sudo Credential Encryption Key Stored Beside Ciphertext
- Content
View full analysis
"$SALT_FILE" # Encrypt and store if ! echo "$PASSWORD" | openssl aes-256-cbc -salt -pbkdf2 -out "$PW_FILE" -pass pass:"$SALT" 2>&1; then echo "❌ Failed to encrypt password" exit 1 fi chmod 600 "$PW_FILE" chmod 600 "$SALT_FILE" echo "" echo "✅ Password configured successfully!" } get_password() { if ! is_configured; then echo "❌ Password not configured. Run: sudo-tool setup" exit 1 fi SALT=$(cat "$SALT_FILE") local PW if ! PW=$(openssl aes-256-cbc -d -pbkdf2 -in "$PW_FILE" -pass pass:"$SALT" 2>/dev/null); then echo "❌ Failed to decrypt password" exit 1 fi ``` ### Technical Analysis The random value named `SALT` is not merely a public cryptographic salt. It is supplied through `-pass pass:"$SALT"` and therefore acts as the secret from which OpenSSL derives the encryption key. The same value is written to `.salt` next to `.password.enc`. Consequently, possession of both files is sufficient to decrypt the stored sudo password. The design does not use a user-supplied master secret, hardware-backed key, operating-system credential vault, or system-bound key. File permissions reduce exposure to other local accounts but do not protect against malicious processes running as the user, compromised backups, accidental archival, or later compromise of that account. This also conflicts with the documentation's assertion that the credential is “not recoverable without your system.” The credential is recoverable using the ciphertext, the adjacent `.salt` file, and OpenSSL. ### Attack Path 1. An attacker obtains execution under the affected user account or gains rea ...[truncated 1206 chars]- Remediation
View remediation
