[TUHS] shell escapes in utilities

Ron Natalie ron at ronnatalie.com
Wed Aug 2 07:11:24 AEST 2023


Even without shell escapes there are fun and cames with abusing setuid 
(but accessible) programs.
Things like opening all the available file descriptors, closing 
stdin/out/err before invocation, doing things to overrun buffers, etc…





More information about the TUHS mailing list