Information
Room
- Name: Sudo Security Bypass
- Profile: tryhackme.com
- Difficulty: Easy
- Description: A tutorial room exploring CVE-2019-14287 in the Unix Sudo Program. Room One in the SudoVulns Series
Write-up
Security Bypass
What command are you allowed to run with sudo?
Answer: /bin/bash
To see which command we can run as which user:
What is the flag in /root/root.txt?
Answer: THM{l33t_s3cur1ty_bypass}
We can exploit CVE-2019-14287 as explained in the course material.