id: rw-shadow info: name: /etc/shadow writable or readabel - Privilege Escalation author: daffainfo severity: high reference: - https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-etc-shadow metadata: verified: true max-request: 2 tags: code,linux,privesc,local self-contained: true code: - engine: - sh - bash source: | whoami - engine: - sh - bash source: | [ -r "/etc/shadow" ] || [ -w "/etc/shadow" ] && echo "Either readable or writable" || echo "Not readable and not writable" matchers: - type: word part: code_1_response words: - "root" negative: true - type: word part: code_2_response words: - "Either readable or writable" - type: word part: code_2_response words: - "Not readable and not writable" negative: true # digest: 490a0046304402206152b0b3fe7a164b5583cb921d799f47fdcf9f30da2c32cbbb7248aa7068a13102200b3f49d97a93659dc9f1b56c518921e7e3597478d55eddb1cfc6a76dd45cb968:922c64590222798bb761d5b6d8e72950