29 ms·
If you want to get the root password hash into memory, just run sudo, or any other root process that reads /etc/shadow. It'll probably get it mapped into the fi
by staticassertion 4y ago
If you want to get the root password hash into memory, just run sudo, or any other root process that reads /etc/shadow. It'll probably get it mapped into the file system cache, but it'll certainly get it mapped into that process's memory - albeit potentially temporarily.
I don't know that sudo takes any measures to protect that memory. You say "lots of modern software" but it's more like "the extreme minority of software" with regards to security effort.
- smileybarry 4y agoThat sounds about right, there's limited avenues for asking the file/page cache to get rid of data. It comes down to lots of suggesting to the FS cache that it's not needed, but it might linger either way.