Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not if you have a sudo timeout enabled. Or, the proof of concept could be changed to

    alias sudo='sudo ./badscript'
where badscript runs `exec $@`.


Good considerations. Thanks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: