|
|
|
|
|
by tgv
52 days ago
|
|
I'm not sure I get it. base64 is on the list. That can't do anything but read a file to which the user already has access, I think. Am I mistaken or does "a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems" not mean what I think it does? |
|
A very simple version of this would be if you set a user's default shell to "rbash" but the user can just run "bash" to get a real shell.