The scenario is this: a brand new Ubuntu 22.04 server has an account which is restricted to running sudo logrotate *. Can we get root? Short answer: Yes. I couldn’t find much online about this type of exploitation of logrotate, so let’s document something for future use.

No comments yet!

appsec

!appsec@infosec.pub

Create post

A community for all things related to application security.

Community stats

  • 1

    Monthly active users

  • 98

    Posts

  • 27

    Comments

Community moderators