id: rw-shadow info: name: /etc/shadow writable or readabel - Privilege Escalation author: daffainfo severity: high reference: - https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-etc-shadow metadata: verified: true max-request: 2 tags: code,linux,privesc,local self-contained: true code: - engine: - sh - bash source: | whoami - engine: - sh - bash source: | [ -r "/etc/shadow" ] || [ -w "/etc/shadow" ] && echo "Either readable or writable" || echo "Not readable and not writable" matchers: - type: word part: code_1_response words: - "root" negative: true - type: word part: code_2_response words: - "Either readable or writable" - type: word part: code_2_response words: - "Not readable and not writable" negative: true # digest: 490a004630440220516036fa8622068621421ac043a6fb20b6551a6ca3d7851726474cfff7e4d9f902205a1a9ce09b5827f39e2311e6716793a917e29383f5e4d4a4b9a56925afa68e61:922c64590222798bb761d5b6d8e72950