Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wouldn't this allow modifying a cached version of /sbin/su to nop the password check? This seems really easy to exploit for privilege escalation.


Yes. But you can also inject code into libc.so.6, and all running processes will have it.


Or /etc/passwd


Yes it would. That is implied because writing arbitrary files means you can also edit the permission systems




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: