Previously Ruud de Rooij wrote:
> (of course, this attack can be prevented using mount options to
> disable setgid executables on all filesystems where users have write
> access)

In which case they just keep a filehandle open and use that later on.
You could also simply start a screen session while you still have the
group and attach to that later.


