su & sudo su Sometimes one user must assume the identity of another user. For example, you might sit down at a friend’s terminal and want to access one of your protected files. Rather than forcing you to log your friend out and log yourself in, UNIX gives you a way to change your user ID temporarily, the su …

sudo will check the ownership of its timestamp directory (/var/run/sudo by default) and ignore the directory's contents if it is not owned by root and only writable by root. On systems that allow non-root users to give away files via chown , if the timestamp directory is located in a directory writable by anyone (e.g.: /tmp ), it is possible

