This is an untested thought experiment- maybe I am wrong, feel free to test it and report back. The scenario is so absurd that exploit feinschmecker will enjoy its ugly elegance. Here we go:
-
Show this thread
How can we use the ability to create a file with arb content in the root to get priv escalation? Well- sometimes, security decisions are based on some weird assumption. Like unpriv users cannot create files in the root of the drive.
3:02 AM - 28 Oct 2020
0 replies
0 retweets
5 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.