Comment on Stealthy 'sedexp' Linux malware evaded detection for two years

<- View Parent
sugar_in_your_tea@sh.itjust.works ⁨2⁩ ⁨months⁩ ago

Sure, but this isn’t a privilege escalation, this requires privilege escalation, and it merely installs a backdoor that preserves that privilege.

It’s like installing something in cron or systemd, it’s not a vulnerability in itself, but it can allow an attacker to add a backdoor once they exploit a vulnerability once.

source
Sort:hotnewtop