diego-treitos / linux-smart-enumeration

Linux enumeration tool for pentesting and CTFs with verbosity levels
GNU General Public License v3.0
3.45k stars 574 forks source link

Missing "doas" configuration checking #46

Open Reelix opened 3 years ago

Reelix commented 3 years ago

https://book.hacktricks.xyz/linux-unix/privilege-escalation#doas

Paths:

diego-treitos commented 3 years ago

Is there any Linux distribution that uses doas? Isn't it used only in BSD systems?

Reelix commented 3 years ago

I came across this case in two different CTFs and noticed that it was a privesc method that LSE missed, so decided to add it here.

diego-treitos commented 3 years ago

I see. I will look into it but if it is an exclusive BSD command it will a low priority task as it is not really in the scope of the tool, but I agree it would be a "nice to have" test.

Thanks for taking your time to suggest it.

loneicewolf commented 3 years ago

@diego-treitos [Just to confirm this] I can confirm, one CTF I did awhile ago needed LSE; I do not remember what OS it was, (at least not the exact version) Will check it and come back -> edit my comment to include it.

Have a nice day on both of you!