Sploitus

Exploit for Immunity Canvas: SUDO_TIMESTAMP

canvas Β· 2013-03-05

Exploit Code

MARKDOWN22 lines
## https://sploitus.com/exploit?id=SUDO_TIMESTAMP
**Name**|  sudo_timestamp  
---|---  
**CVE**|  CVE-2013-1775  
**Exploit Pack**|  [CANVAS](<http://http://www.immunityinc.com/products-canvas.shtml>)  
**Description**| sudo_timestamp: Linux/MacOS timestamp privilege escalation  
**Notes**| CVE Name: CVE-2013-1775  
VENDOR: Intel, GNU/Linux, Apple  
Notes:   
This exploit runs on GNU/Linux and MacOS X.  
  
On both systems this exploit requires:  
\- User has run at least once "sudo"  
\- User is an admin  
  
On GNU/Linux it also requires that the user is currently logged in  
on a wm session and has an open terminal with a bound sudo timestamp  
ticket (an open pts/ on which the user has run sudo at least once).  
  
Repeatability: Infinite  
References: http://www.sudo.ws/sudo/alerts/epoch_ticket.html  
CVE Url: https://vulners.com/cve/CVE-2013-1775