id: rw-shadow info: name: /etc/shadow writable or readabel - Privilege Escalation author: daffainfo severity: high reference: - https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-etc-shadow metadata: verified: true max-request: 2 tags: code,linux,privesc,local self-contained: true code: - engine: - sh - bash source: | whoami - engine: - sh - bash source: | [ -r "/etc/shadow" ] || [ -w "/etc/shadow" ] && echo "Either readable or writable" || echo "Not readable and not writable" matchers: - type: word part: code_1_response words: - "root" negative: true - type: word part: code_2_response words: - "Either readable or writable" - type: word part: code_2_response words: - "Not readable and not writable" negative: true # digest: 4a0a00473045022100eb188c9515d521fa04359befea4e72a984d0fb008f92fedb7026fbdf0e3cb93b02200b58a0d7ff63a300b598ceaeed8bf03e78c1a78ce63472fdf6c526a07814e53c:922c64590222798bb761d5b6d8e72950