Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sudo priv escalation involving sudo -l requires the user's password #319

Open
cliffe opened this issue Apr 17, 2024 · 0 comments
Open

Sudo priv escalation involving sudo -l requires the user's password #319

cliffe opened this issue Apr 17, 2024 · 0 comments

Comments

@cliffe
Copy link
Owner

cliffe commented Apr 17, 2024

Ideally add a rule to sudoers so that it doesn't, so that these priv escalation attacks work regardless of the method used to obtain access (the attacker doesn't always know the user's password). If not, make sure these modules aren't used in any scenarios where that's not the case.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant