Commit Graph

668 Commits

Author SHA1 Message Date
LinuxSploit
4469fdc662
Add lwp-download file-read/write 2021-04-13 08:59:10 +02:00
LinuxSploit
1ceca200b6
Add another gzip file-read 2021-04-11 17:44:26 +02:00
Andrea Cardaci
7e1ac22fa0 Polish and simplify php file-read/write 2021-04-11 12:12:53 +02:00
LinuxSploit
6ba729e1de Update php.md
FILE READ & FILE WRITE ADDED
2021-04-11 12:12:53 +02:00
LinuxSploit
41d9312c53
Add curl file-write 2021-04-11 12:10:42 +02:00
godylockz
c790928248 Initial commit of freebsd pkg GTFO 2021-04-09 14:32:44 +02:00
godylockz
39027eb0c1
Add snap 2021-04-09 08:57:02 +02:00
Andrea Cardaci
9800048833
Upgrade to shell 2021-04-08 07:56:49 +02:00
M4x
ecb1840df3
add command for rpm and delete unnecessary prefix
remove trailing spaces
2021-04-07 17:31:05 +08:00
M4x
565ebae880
add command for rpm and delete unnecessary prefix 2021-04-07 16:30:36 +08:00
Andrea Cardaci
c3f37d9e09 Fix and simplify gcc file delete 2021-04-06 09:45:44 +02:00
LinuxSploit
51e8892fec Update gcc.md
delete a file with gcc
2021-04-06 09:45:44 +02:00
iilegacyyii
33d93b2bcd
Document the --parents option of GNU cp 2021-04-05 13:58:35 +02:00
Andrea Cardaci
a02e1a1194 Promote certbot command to shell 2021-04-03 12:04:09 +02:00
Emanuel Duss
160e8d5dcd New: certbot 2021-04-03 12:04:09 +02:00
Andrea Cardaci
03b57fab4a Fix csvtool 2021-03-17 23:55:52 +01:00
F.Romero
9431dd9daf
Add csvtool 2021-03-17 22:50:42 +01:00
Emilio Pinna
b9ef170f4c Fix trailing spaces 2021-03-12 21:38:27 +00:00
Emilio Pinna
685c1412db Polish virsh 2021-03-07 14:42:30 +00:00
Emilio Pinna
80d2b5cb26 Fix virsh 2021-03-07 14:33:12 +00:00
Emilio Pinna
a4b1293072 Merge branch 'master' of github.com-epinna:GTFOBins/GTFOBins.github.io 2021-03-07 14:30:23 +00:00
Emilio Pinna
b3f1a8e1c4 Add virsh 2021-03-07 14:29:57 +00:00
Andrea Cardaci
62a32ea9de Fix cpio file extension 2021-03-07 12:39:34 +01:00
Emilio Pinna
6722cff3fd Merge branch 'master' of git://github.com/Eblazquez/GTFOBins.github.io into Eblazquez-master 2021-03-07 11:27:52 +00:00
Andrea Cardaci
d63982dea9
Simplify and add file-write and shell 2021-03-07 12:24:02 +01:00
kiranghimire
6f2c001687 Added cpio 2021-03-06 21:51:42 +05:45
joaogmauricio
2db67eefb9
Add ssh-keygen 2021-03-05 09:12:09 +01:00
Andrea Cardaci
af562d63cb Clean up and add gzip description about aux utilities
As suggested in #176 by Kiran Ghimire (Cimihan123).
2021-03-02 17:49:45 +01:00
Kiran Ghimire
161512c6e2
Add gzip 2021-03-02 17:26:14 +01:00
remiflavien1
320ed40277 fix iftop version 2021-03-02 17:10:53 +01:00
Andrea Cardaci
eda1cde6a1
Improve the alternative shell function 2021-02-27 17:09:41 +01:00
nightshiba
a3b63dae9e
Improved man.md shell function
Replaced a command requiring interactive actions with a one-liner
2021-02-27 12:39:48 +01:00
AssassinUKG
c20963cfd6
Add cpulimit SUID 2021-02-27 12:06:40 +01:00
Andrea Cardaci
eca7899007 Add Node.js file-{read,write,upload,download}
Close #172.
2021-02-20 12:17:28 +01:00
Andrea Cardaci
af95091e60 Remove useless require in Node.js 2021-02-20 11:58:47 +01:00
Andrea Cardaci
c299dc3a52 Allow unprivileged shell in openvpn by using a null device
Related #171.
2021-02-20 00:56:32 +01:00
Andrea Cardaci
7bf1608cd5 Remove leftover line from openvpn 2021-02-20 00:56:32 +01:00
Andrea Cardaci
daf9b43e80 Add openvpn file-read
Related #171.
2021-02-20 00:56:22 +01:00
Emanuel Duss
ad35aaa5d8
Add openvpn 2021-02-20 00:33:43 +01:00
Andrea Cardaci
09c2605f84
Simplify sg 2021-02-16 09:01:05 +01:00
SleestakOverflow
ec7633d6bc
Update sg.md 2021-02-15 21:57:15 -06:00
SleestakOverflow
99a572b7d9
Create sg.md
Adding the "sg" binary which allows command execution under a "different" group ID. However, it can be used to break out of restricted environments by using a user's own group ID.
2021-02-15 21:49:13 -06:00
Andrea Cardaci
aa018b04c4 Fix pager links 2021-02-05 13:41:12 +01:00
Andrea Cardaci
a3f2107360 Clone vipw to vigr as it is just a symlink 2021-02-05 13:38:30 +01:00
Andrea Cardaci
4f4207be13 Cleanup and clarify vipw 2021-02-05 13:37:16 +01:00
sk3l10x1ng
72c489bffa Add vipw 2021-02-05 13:34:29 +01:00
eblazquez
e1b99dd03e Fix virsh 2021-01-31 19:49:31 +01:00
Prudhv!
6763f4b692
Add vimdiff 2021-01-29 22:12:00 +01:00
Andrea Cardaci
0c87e670b4
Add npm 2021-01-21 15:11:28 +01:00
Andrea Cardaci
2ce5e831b7
Fix npm 2021-01-21 15:04:27 +01:00
Andrea Cardaci
717acf4b14
Fix openvt 2021-01-21 14:49:32 +01:00
Hardeep Singh
f8ff5eddc7
Added npm.md 2021-01-19 23:52:33 +05:30
Mohit Khemchandani
4347f58f55 Added openvt.md 2021-01-19 23:07:21 +05:30
Andrea Cardaci
eba354eda0
Minor fixes to SUID mainly 2021-01-18 09:23:50 +01:00
Andrea Cardaci
c85513d5a6
Fix hping3 SUID 2021-01-18 09:19:35 +01:00
Nick Blekherman
d6d3563e5d
Add SUID category to nawk as file read 2021-01-18 09:49:07 +02:00
Nick Blekherman
c293ed20f7
Add SUID category to mawk as file read 2021-01-18 09:48:12 +02:00
Nick Blekherman
31b69cfeed
Add SUID category to gawk as file read 2021-01-18 09:46:51 +02:00
Nick Blekherman
085e72a971
Add ./ to SUID category in awk.md 2021-01-18 09:44:34 +02:00
Nick Blekherman
3065294305
Add ./ to SUID category in ed.md 2021-01-18 09:41:36 +02:00
Nick Blekherman
646ea8132e
Revert limited-suid to suid and add -p in hping3 2021-01-18 09:40:50 +02:00
Nick Blekherman
b43f418ddb
Add ./ to SUID category in nohup.mp 2021-01-18 09:36:35 +02:00
Andrea Cardaci
5c4ec744cb
Merge pull request #160 from xmpf/adiff_ar_bridge
Add ar and bridge file-read
2021-01-17 23:42:42 +01:00
Andrea Cardaci
0d5c457233
Fix YAML in ar 2021-01-17 23:40:41 +01:00
Andrea Cardaci
7da8627262
Remove adiff since is ar that actually reads here 2021-01-17 23:38:07 +01:00
Andrea Cardaci
bed198068f
Fix ar and add suid and sudo 2021-01-17 23:32:44 +01:00
Andrea Cardaci
f7ff2ea852
Add suid and sudo to bridge 2021-01-17 23:25:31 +01:00
Andrea Cardaci
629501ccc7
Improve bridge 2021-01-17 23:22:33 +01:00
Michalis Papadopoullos
4f11ca6a15
Add atobm 2021-01-17 23:11:43 +01:00
Andrea Cardaci
da85e84b60
Add at 2021-01-15 20:39:32 +01:00
Andrea Cardaci
013bf5a0c9 Fix newlines in at 2021-01-15 20:38:33 +01:00
Andrea Cardaci
578f951c76 Improve at and add the shell function 2021-01-15 20:34:57 +01:00
Aman Rawat
e241cd3aa7 added at 2021-01-15 20:34:57 +01:00
Shikata
561a5b2c9a Remove trailing space in awk.md line 31 2021-01-13 11:22:26 +02:00
Andrea Cardaci
47db2fa431 Make cupsfilter more general 2021-01-12 18:03:46 +01:00
Michalis Papadopoullos
46bbaaf6d6 cupsfilter (package: cups) 2021-01-12 18:03:46 +01:00
Shikata
28cc7ff7da Add SUID [file read] category to sqlite3 2021-01-12 13:57:34 +02:00
Shikata
ae8271292a Add SUID [file read] category to lua 2021-01-12 13:50:43 +02:00
Shikata
47698d0cfb Add SUID [file read] category to ed 2021-01-12 13:44:19 +02:00
Shikata
fd719bb4b6 Add SUID category to awk 2021-01-12 13:39:52 +02:00
Shikata
a48303c2b9 Remove redundant sudo from SUID category in nohup 2021-01-11 16:18:18 +02:00
Michalis Papadopoullos
513909c38c Added adiff, ar, bridge file_read 2021-01-11 13:59:30 +02:00
Shikata
211edf746b Switch SUID to Limited SUID in aria2c 2021-01-11 13:45:21 +02:00
Shikata
c09b95053f Fixed order of Limited SUID category in lwp-request 2021-01-11 13:02:54 +02:00
Shikata
05a9ae111b Switch SUID to Limited SUID in hping3 2021-01-11 13:02:11 +02:00
Shikata
9d1b86e9d3 Switch SUID to Limited SUID in lwp-request 2021-01-11 12:56:13 +02:00
Shikata
c4f93b87d5 Remove redundant lua -e from File Write and File Read categories in nmap 2021-01-11 12:37:37 +02:00
Shikata
db40142ea7 Remove redundant sudo from SUID category 2021-01-11 12:31:54 +02:00
Andrea Cardaci
bb4050810e Fix rpm[query] SUID 2021-01-10 18:27:30 +01:00
Andrea Cardaci
33fb39a183 Fix wrong nano and pico SUID 2021-01-10 18:16:30 +01:00
ritiksahni
01d4de40d2
Add dig 2021-01-10 12:31:51 +01:00
ritiksahni
9069b0c903
Add exiftool 2021-01-09 15:03:35 +01:00
Andrea Cardaci
5b2d89b99a Fix nmap SUID file-write 2021-01-04 09:05:21 +01:00
Syed Umar Arfeen
edc8a2d03d
Adding another usage of Nmap's SUID
I came along with this method on stackoverflow while trying to execute commands using a SUID nmap binary, though `--script` failed me but this works. Could be enough to demonstrate effect of using SUID on Nmap. 

I've yet to come up with a way to over-write the contents of the system file according to what we want, with this we can only over-write files with nmap output.

```bash
sudo touch /etc/filecantbetouched
nmap 127.0.0.1 -oN=/etc/filecantbetouched
cat /etc/filecantbetouched
```
2021-01-04 12:16:29 +05:00
makikvues
1c07880178
Add hping3 2020-12-30 08:47:47 +01:00
Eblazquez
4de8e04e4b
Add virsh 2020-12-25 21:04:07 +01:00
Andrea Cardaci
65857d486b
Merge pull request #147 from mindfuckup/master 2020-12-20 21:31:05 +01:00
Andrea Cardaci
c80e83c3c5 Make install similar to chmod 2020-12-20 21:24:10 +01:00
Andrea Cardaci
fbe4b42890 Improve split 2020-12-20 21:15:58 +01:00
Andrea Cardaci
2475ea0a5a Improve pr 2020-12-20 21:09:50 +01:00