3 ms·
I don't see how this attack is related to the setuid binary. No matter what method you provide to the user to elevate their privileges, they can be tricked into
by remram 1y ago
I don't see how this attack is related to the setuid binary. No matter what method you provide to the user to elevate their privileges, they can be tricked into doing it. If it was provided by a daemon, built into systemd, or anything else, the problem would be the same.
- charcircuit 1y agoIt's related because malicous code can use the setuid binary to elevate its privileges. >If it was provided by a daemon, built into systemd, or anything else Yes, this is also dangerous.
- remram 1y agoSo what's your recommendation? Removing the user?