If systemctl is SUID root, then a malicious service file can easily be abused to create a root shell.
Even if systemctl is not SUID root, so long as you have NOPASSWD sudo access to it this trick will still work.
Search
July 31, 20241 min read
If systemctl is SUID root, then a malicious service file can easily be abused to create a root shell.
Even if systemctl is not SUID root, so long as you have NOPASSWD sudo access to it this trick will still work.