Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New payload run command as root, without sudo passwod #224

Merged
merged 5 commits into from
May 24, 2024

Conversation

simen64
Copy link
Contributor

@simen64 simen64 commented May 4, 2024

This payload intercepts the .bashrc file so when the user uses sudo they type their password in our fake prompt letting us execute any command with root. We also execute the targets original command, and remove our injection in the .bashrc file to remove traces.

@kalanihelekunihi
Copy link
Collaborator

Really well done. Hope you submit some more in the future!

@kalanihelekunihi kalanihelekunihi merged commit 7946403 into hak5:master May 24, 2024
@simen64 simen64 deleted the New-payload_sudo-phisher branch May 24, 2024 21:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants