4 ms·
>Trick the user into running a program that does 'alias sudo=evil-sudo' >> ~/.bashrc That's only going to get you the user's password, not the root password.
by hnnh 11y ago
>Trick the user into running a program that does 'alias sudo=evil-sudo' >> ~/.bashrc
That's only going to get you the user's password, not the root password.
- ivank 11y agoGood point. I've toned down my comment because that root password would be getting typed in less often. An attacker might still bring an evil-su in addition to an evil-sudo, though. And even if you're logging into that root user only in an another tty, it seems like an unnecessary risk to share the password with LUKS.
- mricon 11y agoYou actually tend to never use the root password on a modern workstation -- just sudo. The situations where you have to use a root password are usually if something has gone wrong and you have to log in via tty.