logoalt Hacker News

SoftTalker • today at 1:59 AM • 4 replies • view on HN

There are programs like sudo whose entire reason for existing is to enable privilege escalation. If you can find a way to make a user "sudo" something, that's an exploit, but it's not a bug in the program.


Replies

odo1242 • today at 2:04 AM

At that point you're exploiting the user, who is not a bug-free program

➕ show 1 reply
PaulDavisThe1st • today at 4:41 AM

Alternatively, consider any program which loads dynamic shared libraries (called "plugins" in many contexts). The program itself might be bug free; any plugin that is loaded will run (typically) with the full priviledges and access of the program (and thus likely the user).

The user may have no idea that the plugin is malicious; the program remains bug-free (if it was beforehand).

catlifeonmars • today at 2:53 AM

But if you squint, it might be a bug in the system to allow access to that program.

bigstrat2003 • today at 3:55 AM

That's also not exploiting the program, it's exploiting the user.