|
|
|
|
|
by infotogivenm
716 days ago
|
|
Think “illegitimate” access to www-data. It’s very common on linux pentests to need to privesc from some lower-privileged foothold (like a command injection in an httpd cgi script). Most linux servers run openssh. So yes I would expect this turns out to be a useful privesc in practice. |
|
I get the point.
My point was the example being given is less than 1% of affected cases.
> It’s very common on linux pentests to need to privesc from some lower-privileged foothold
Sure. Been doing pentests for 20+ years :)
> So yes I would expect this turns out to be a useful privesc in practice.
Nah.