No, the above attack writes that function into bashrc, meaning the next time the user runs sudo themselves, you harvest their password.
No, the above attack writes that function into bashrc, meaning the next time the user runs sudo themselves, you harvest their password.