SecGen icon indicating copy to clipboard operation
SecGen copied to clipboard

Sudo priv escalation involving sudo -l requires the user's password

Open cliffe opened this issue 1 year ago • 0 comments

Ideally add a rule to sudoers so that it doesn't, so that these priv escalation attacks work regardless of the method used to obtain access (the attacker doesn't always know the user's password). If not, make sure these modules aren't used in any scenarios where that's not the case.

cliffe avatar Apr 17 '24 08:04 cliffe