Commit Graph

829 Commits

Author SHA1 Message Date
tirefire
f4914f6dcb
Add tic 2021-08-18 14:10:58 +02:00
LinuxSploit
508f493cd1
Add csplit file-write
Co-authored-by: Andrea Cardaci <cyrus.and@gmail.com>
2021-07-31 12:50:05 +02:00
LinuxSploit
0b196471f8
Add rake file-read
Co-authored-by: Andrea Cardaci <cyrus.and@gmail.com>
2021-07-17 08:42:47 +02:00
Andrea Cardaci
9b402581ce Add cp sudo example similar to #235 2021-07-15 14:24:17 +02:00
ARZ
fcde0d9160
Add ln sudo 2021-07-15 14:23:51 +02:00
Nasef
ee3eb38ee4
Add knife and ansible-playbook
Co-authored-by: Andrea Cardaci <cyrus.and@gmail.com>
2021-07-13 18:38:09 +02:00
Andrea Cardaci
b1a33432e9 Simplify cmp 2021-07-13 08:53:44 +02:00
LinuxSploit
a9313397a0 Create cmp.md 2021-07-13 08:53:44 +02:00
godylockz
d6accb1ca3
Add dmidecode 2021-07-13 08:41:23 +02:00
Andrea Cardaci
8f1cde5d35 Fix gtester 2021-06-26 11:34:55 +02:00
Andrea Cardaci
074adc3ae3 Add arj
Close #221.
2021-06-26 11:32:21 +02:00
Andrea Cardaci
23a082d1e3 Update ar 2021-06-26 11:14:15 +02:00
LinuxSploit
fe7b3d797f
Add gtester file-write
Co-authored-by: Andrea Cardaci <cyrus.and@gmail.com>
2021-06-24 08:53:52 +02:00
LinuxSploit
d6fdf6e633
Add tmux file-read 2021-06-24 08:48:20 +02:00
LinuxSploit
ed0922ee57
Add expect file-read
Co-authored-by: Andrea Cardaci <cyrus.and@gmail.com>
2021-06-23 09:01:37 +02:00
LinuxSploit
dab2e88a30
Add pic file-read
Co-authored-by: Andrea Cardaci <cyrus.and@gmail.com>
2021-06-23 08:57:40 +02:00
Andrea Cardaci
fd476e08c2 Update yarn and npm shells
Mention an additional way to run scripts as suggested in #224.
2021-06-22 22:11:05 +02:00
Jacco van Buuren
390c49394a Added timedatectl and loginctl 2021-06-18 15:14:55 +02:00
Andrea Cardaci
3466212c5d Update yarn and npm 2021-06-18 14:16:48 +02:00
Andrea Cardaci
ff4e89470d Add tshark shell 2021-06-18 14:12:25 +02:00
b33lz3bub
1405b4dce5
Add yarn 2021-06-18 14:06:46 +02:00
Renato Almeida de Oliveira
cfe0a0c300
Add cp suid 2021-06-04 14:02:15 +02:00
Michalis Papadopoullos
7c9c505542
Add c89 and c99 2021-06-04 13:54:33 +02:00
Michalis Papadopoullos
49086c50ca
Add msgmerge file-read 2021-06-04 13:50:44 +02:00
Michalis Papadopoullos
54929fab15
Add msgcat file-read 2021-06-04 13:47:55 +02:00
Michalis Papadopoullos
87cfb706fe
Add msguniq file-read 2021-06-04 13:46:03 +02:00
Andrea Cardaci
c014314b83 Add msgfilter shell 2021-06-04 13:43:15 +02:00
Michalis Papadopoullos
8612fb0b86
Add msgfilter file-read 2021-06-04 09:23:53 +02:00
Michalis Papadopoullos
b04b2af68b
Add msgattrib file-read 2021-05-25 09:00:36 +02:00
Michalis Papadopoullos
a18f48d0f6
Add msgconv file-read 2021-05-25 08:57:15 +02:00
LinuxSploit
be0ff3ade6
Add wget file-read/write 2021-05-15 19:21:30 +02:00
LinuxSploit
d4f9fa6622
Add ltrace file-read/write 2021-05-09 17:31:28 +02:00
Kiran Ghimire
379a19bf32
Add xmore 2021-05-07 14:13:06 +02:00
Andrea Cardaci
254db17d9c Simplify strace file-read 2021-05-03 20:05:47 +02:00
LinuxSploit
6f9d02501e add file-write 2021-05-03 20:05:47 +02:00
Andrea Cardaci
77b3b0a06f Add split file-write GNU variant 2021-04-28 09:01:24 +02:00
Andrea Cardaci
afd946b0c8 Fix typo in split 2021-04-28 09:01:12 +02:00
Andrea Cardaci
bc5783fb5b Use a longer package name for snap
Close #203.
2021-04-28 08:51:13 +02:00
LinuxSploit
9745f89ea4
Add split file-write 2021-04-28 08:48:47 +02:00
Andrea Cardaci
a9b046f74b Add perl file-read 2021-04-26 16:11:44 +02:00
Andrea Cardaci
d81463fb82 Fix YAML style 2021-04-26 16:11:33 +02:00
Andrea Cardaci
162f586eb8
Add TeX binaries and GNU Octave 2021-04-26 16:10:21 +02:00
Andrea Cardaci
21b641911e Fix and improve TeX binaries and GNU Octave 2021-04-26 16:07:59 +02:00
SynackCerv
806c8054eb
Create lualatex.md
Add lualatex.
2021-04-22 22:16:14 +02:00
SynackCerv
fd30994f8a
Create luatex.md
Add luatex.
2021-04-22 22:15:59 +02:00
SynackCerv
ff22bbda93
Create latexmk.tex
Add latexmk.
2021-04-22 22:15:40 +02:00
SynackCerv
2972d25e23
Create xetex.md
xetex
2021-04-22 22:15:18 +02:00
SynackCerv
1e3f00a04f
Create xelatex.md
Add xelatex.
2021-04-22 22:15:02 +02:00
SynackCerv
4017773b69
Create latex.md
Add latex.
2021-04-22 22:14:40 +02:00
SynackCerv
012b5e92d1
Create pdflatex.md
Add pdflatex.
2021-04-22 22:13:51 +02:00
SynackCerv
f0d733ef91
Create pdftex.md
Add pdftex.
2021-04-22 22:13:29 +02:00
SynackCerv
8c08101fed
Create tex.md
Add tex.
2021-04-22 22:13:08 +02:00
SynackCerv
85010470b2
Create dvips.md
Add dvips.
2021-04-22 22:12:52 +02:00
SynackCerv
dbb2e24ff0
Create octave.md
Add GNU Octave
2021-04-22 22:12:26 +02:00
Andrea Cardaci
832d69e6c8
Drop SUID for lwp-request as it's Perl script 2021-04-19 13:13:56 +02:00
LinuxSploit
c51b90a1bb
Add csvtool file-read/write 2021-04-18 11:17:49 +02:00
Andrea Cardaci
5255ea1846 Cleanup 2021-04-17 21:03:54 +02:00
LinuxSploit
65900862c5 Update zip.md
add file-read
2021-04-17 21:03:54 +02:00
LinuxSploit
313a49d9f7 Update lwp-download.md
lwp-download drop the elevated privileges
2021-04-17 20:56:12 +02:00
LinuxSploit
494ea89794
Add zsh file-read/write 2021-04-13 14:08:39 +02:00
LinuxSploit
69be6785a9
Add wc 2021-04-13 14:00:51 +02:00
LinuxSploit
4469fdc662
Add lwp-download file-read/write 2021-04-13 08:59:10 +02:00
LinuxSploit
1ceca200b6
Add another gzip file-read 2021-04-11 17:44:26 +02:00
Andrea Cardaci
7e1ac22fa0 Polish and simplify php file-read/write 2021-04-11 12:12:53 +02:00
LinuxSploit
6ba729e1de Update php.md
FILE READ & FILE WRITE ADDED
2021-04-11 12:12:53 +02:00
LinuxSploit
41d9312c53
Add curl file-write 2021-04-11 12:10:42 +02:00
godylockz
c790928248 Initial commit of freebsd pkg GTFO 2021-04-09 14:32:44 +02:00
godylockz
39027eb0c1
Add snap 2021-04-09 08:57:02 +02:00
Andrea Cardaci
9800048833
Upgrade to shell 2021-04-08 07:56:49 +02:00
M4x
ecb1840df3
add command for rpm and delete unnecessary prefix
remove trailing spaces
2021-04-07 17:31:05 +08:00
M4x
565ebae880
add command for rpm and delete unnecessary prefix 2021-04-07 16:30:36 +08:00
Andrea Cardaci
c3f37d9e09 Fix and simplify gcc file delete 2021-04-06 09:45:44 +02:00
LinuxSploit
51e8892fec Update gcc.md
delete a file with gcc
2021-04-06 09:45:44 +02:00
iilegacyyii
33d93b2bcd
Document the --parents option of GNU cp 2021-04-05 13:58:35 +02:00
Andrea Cardaci
a02e1a1194 Promote certbot command to shell 2021-04-03 12:04:09 +02:00
Emanuel Duss
160e8d5dcd New: certbot 2021-04-03 12:04:09 +02:00
Andrea Cardaci
03b57fab4a Fix csvtool 2021-03-17 23:55:52 +01:00
F.Romero
9431dd9daf
Add csvtool 2021-03-17 22:50:42 +01:00
Emilio Pinna
b9ef170f4c Fix trailing spaces 2021-03-12 21:38:27 +00:00
Emilio Pinna
685c1412db Polish virsh 2021-03-07 14:42:30 +00:00
Emilio Pinna
80d2b5cb26 Fix virsh 2021-03-07 14:33:12 +00:00
Emilio Pinna
a4b1293072 Merge branch 'master' of github.com-epinna:GTFOBins/GTFOBins.github.io 2021-03-07 14:30:23 +00:00
Emilio Pinna
b3f1a8e1c4 Add virsh 2021-03-07 14:29:57 +00:00
Andrea Cardaci
62a32ea9de Fix cpio file extension 2021-03-07 12:39:34 +01:00
Emilio Pinna
6722cff3fd Merge branch 'master' of git://github.com/Eblazquez/GTFOBins.github.io into Eblazquez-master 2021-03-07 11:27:52 +00:00
Andrea Cardaci
d63982dea9
Simplify and add file-write and shell 2021-03-07 12:24:02 +01:00
kiranghimire
6f2c001687 Added cpio 2021-03-06 21:51:42 +05:45
joaogmauricio
2db67eefb9
Add ssh-keygen 2021-03-05 09:12:09 +01:00
Andrea Cardaci
af562d63cb Clean up and add gzip description about aux utilities
As suggested in #176 by Kiran Ghimire (Cimihan123).
2021-03-02 17:49:45 +01:00
Kiran Ghimire
161512c6e2
Add gzip 2021-03-02 17:26:14 +01:00
remiflavien1
320ed40277 fix iftop version 2021-03-02 17:10:53 +01:00
Andrea Cardaci
eda1cde6a1
Improve the alternative shell function 2021-02-27 17:09:41 +01:00
nightshiba
a3b63dae9e
Improved man.md shell function
Replaced a command requiring interactive actions with a one-liner
2021-02-27 12:39:48 +01:00
AssassinUKG
c20963cfd6
Add cpulimit SUID 2021-02-27 12:06:40 +01:00
Andrea Cardaci
eca7899007 Add Node.js file-{read,write,upload,download}
Close #172.
2021-02-20 12:17:28 +01:00
Andrea Cardaci
af95091e60 Remove useless require in Node.js 2021-02-20 11:58:47 +01:00
Andrea Cardaci
c299dc3a52 Allow unprivileged shell in openvpn by using a null device
Related #171.
2021-02-20 00:56:32 +01:00
Andrea Cardaci
7bf1608cd5 Remove leftover line from openvpn 2021-02-20 00:56:32 +01:00
Andrea Cardaci
daf9b43e80 Add openvpn file-read
Related #171.
2021-02-20 00:56:22 +01:00
Emanuel Duss
ad35aaa5d8
Add openvpn 2021-02-20 00:33:43 +01:00
Andrea Cardaci
09c2605f84
Simplify sg 2021-02-16 09:01:05 +01:00
SleestakOverflow
ec7633d6bc
Update sg.md 2021-02-15 21:57:15 -06:00
SleestakOverflow
99a572b7d9
Create sg.md
Adding the "sg" binary which allows command execution under a "different" group ID. However, it can be used to break out of restricted environments by using a user's own group ID.
2021-02-15 21:49:13 -06:00
Andrea Cardaci
aa018b04c4 Fix pager links 2021-02-05 13:41:12 +01:00
Andrea Cardaci
a3f2107360 Clone vipw to vigr as it is just a symlink 2021-02-05 13:38:30 +01:00
Andrea Cardaci
4f4207be13 Cleanup and clarify vipw 2021-02-05 13:37:16 +01:00
sk3l10x1ng
72c489bffa Add vipw 2021-02-05 13:34:29 +01:00
eblazquez
e1b99dd03e Fix virsh 2021-01-31 19:49:31 +01:00
Prudhv!
6763f4b692
Add vimdiff 2021-01-29 22:12:00 +01:00
Andrea Cardaci
0c87e670b4
Add npm 2021-01-21 15:11:28 +01:00
Andrea Cardaci
2ce5e831b7
Fix npm 2021-01-21 15:04:27 +01:00
Andrea Cardaci
717acf4b14
Fix openvt 2021-01-21 14:49:32 +01:00
Hardeep Singh
f8ff5eddc7
Added npm.md 2021-01-19 23:52:33 +05:30
Mohit Khemchandani
4347f58f55 Added openvt.md 2021-01-19 23:07:21 +05:30
Andrea Cardaci
eba354eda0
Minor fixes to SUID mainly 2021-01-18 09:23:50 +01:00
Andrea Cardaci
c85513d5a6
Fix hping3 SUID 2021-01-18 09:19:35 +01:00
Nick Blekherman
d6d3563e5d
Add SUID category to nawk as file read 2021-01-18 09:49:07 +02:00
Nick Blekherman
c293ed20f7
Add SUID category to mawk as file read 2021-01-18 09:48:12 +02:00
Nick Blekherman
31b69cfeed
Add SUID category to gawk as file read 2021-01-18 09:46:51 +02:00
Nick Blekherman
085e72a971
Add ./ to SUID category in awk.md 2021-01-18 09:44:34 +02:00
Nick Blekherman
3065294305
Add ./ to SUID category in ed.md 2021-01-18 09:41:36 +02:00
Nick Blekherman
646ea8132e
Revert limited-suid to suid and add -p in hping3 2021-01-18 09:40:50 +02:00
Nick Blekherman
b43f418ddb
Add ./ to SUID category in nohup.mp 2021-01-18 09:36:35 +02:00
Andrea Cardaci
5c4ec744cb
Merge pull request #160 from xmpf/adiff_ar_bridge
Add ar and bridge file-read
2021-01-17 23:42:42 +01:00
Andrea Cardaci
0d5c457233
Fix YAML in ar 2021-01-17 23:40:41 +01:00
Andrea Cardaci
7da8627262
Remove adiff since is ar that actually reads here 2021-01-17 23:38:07 +01:00
Andrea Cardaci
bed198068f
Fix ar and add suid and sudo 2021-01-17 23:32:44 +01:00
Andrea Cardaci
f7ff2ea852
Add suid and sudo to bridge 2021-01-17 23:25:31 +01:00
Andrea Cardaci
629501ccc7
Improve bridge 2021-01-17 23:22:33 +01:00
Michalis Papadopoullos
4f11ca6a15
Add atobm 2021-01-17 23:11:43 +01:00
Andrea Cardaci
da85e84b60
Add at 2021-01-15 20:39:32 +01:00
Andrea Cardaci
013bf5a0c9 Fix newlines in at 2021-01-15 20:38:33 +01:00
Andrea Cardaci
578f951c76 Improve at and add the shell function 2021-01-15 20:34:57 +01:00
Aman Rawat
e241cd3aa7 added at 2021-01-15 20:34:57 +01:00
Shikata
561a5b2c9a Remove trailing space in awk.md line 31 2021-01-13 11:22:26 +02:00
Andrea Cardaci
47db2fa431 Make cupsfilter more general 2021-01-12 18:03:46 +01:00
Michalis Papadopoullos
46bbaaf6d6 cupsfilter (package: cups) 2021-01-12 18:03:46 +01:00
Shikata
28cc7ff7da Add SUID [file read] category to sqlite3 2021-01-12 13:57:34 +02:00
Shikata
ae8271292a Add SUID [file read] category to lua 2021-01-12 13:50:43 +02:00
Shikata
47698d0cfb Add SUID [file read] category to ed 2021-01-12 13:44:19 +02:00
Shikata
fd719bb4b6 Add SUID category to awk 2021-01-12 13:39:52 +02:00
Shikata
a48303c2b9 Remove redundant sudo from SUID category in nohup 2021-01-11 16:18:18 +02:00
Michalis Papadopoullos
513909c38c Added adiff, ar, bridge file_read 2021-01-11 13:59:30 +02:00
Shikata
211edf746b Switch SUID to Limited SUID in aria2c 2021-01-11 13:45:21 +02:00
Shikata
c09b95053f Fixed order of Limited SUID category in lwp-request 2021-01-11 13:02:54 +02:00
Shikata
05a9ae111b Switch SUID to Limited SUID in hping3 2021-01-11 13:02:11 +02:00
Shikata
9d1b86e9d3 Switch SUID to Limited SUID in lwp-request 2021-01-11 12:56:13 +02:00
Shikata
c4f93b87d5 Remove redundant lua -e from File Write and File Read categories in nmap 2021-01-11 12:37:37 +02:00
Shikata
db40142ea7 Remove redundant sudo from SUID category 2021-01-11 12:31:54 +02:00
Andrea Cardaci
bb4050810e Fix rpm[query] SUID 2021-01-10 18:27:30 +01:00
Andrea Cardaci
33fb39a183 Fix wrong nano and pico SUID 2021-01-10 18:16:30 +01:00
ritiksahni
01d4de40d2
Add dig 2021-01-10 12:31:51 +01:00
ritiksahni
9069b0c903
Add exiftool 2021-01-09 15:03:35 +01:00
Andrea Cardaci
5b2d89b99a Fix nmap SUID file-write 2021-01-04 09:05:21 +01:00
Syed Umar Arfeen
edc8a2d03d
Adding another usage of Nmap's SUID
I came along with this method on stackoverflow while trying to execute commands using a SUID nmap binary, though `--script` failed me but this works. Could be enough to demonstrate effect of using SUID on Nmap. 

I've yet to come up with a way to over-write the contents of the system file according to what we want, with this we can only over-write files with nmap output.

```bash
sudo touch /etc/filecantbetouched
nmap 127.0.0.1 -oN=/etc/filecantbetouched
cat /etc/filecantbetouched
```
2021-01-04 12:16:29 +05:00
makikvues
1c07880178
Add hping3 2020-12-30 08:47:47 +01:00
Eblazquez
4de8e04e4b
Add virsh 2020-12-25 21:04:07 +01:00
Andrea Cardaci
65857d486b
Merge pull request #147 from mindfuckup/master 2020-12-20 21:31:05 +01:00
Andrea Cardaci
c80e83c3c5 Make install similar to chmod 2020-12-20 21:24:10 +01:00
Andrea Cardaci
fbe4b42890 Improve split 2020-12-20 21:15:58 +01:00
Andrea Cardaci
2475ea0a5a Improve pr 2020-12-20 21:09:50 +01:00
Andrea Cardaci
c6502e8ddc Use base64 in basenc 2020-12-20 20:59:40 +01:00
Andrea Cardaci
7cfac08921 Improve the description of nroff 2020-12-20 20:54:05 +01:00
Andrea Cardaci
b05a84474b Improve the description of troff 2020-12-20 20:48:00 +01:00
Andrea Cardaci
dd16d538ce Improve the description of ssh-keyscan 2020-12-20 20:44:24 +01:00
Andrea Cardaci
54c20a1349 Improve the description of ss 2020-12-20 20:41:49 +01:00
Andrea Cardaci
5102eccdfc Fix psql shell path and remove suid 2020-12-20 20:36:55 +01:00
Andrea Cardaci
6a6485c44b Fix ex shell path and remove suid 2020-12-20 20:36:47 +01:00
Andrea Cardaci
dc3de20e84 Add note about column 2020-12-20 20:36:47 +01:00
Andrea Cardaci
4b2100bfae Fix check_log 2020-12-20 19:53:16 +01:00
Andrea Cardaci
ee8cce63f9 Replace command with shell in check_by_ssh 2020-12-20 19:32:15 +01:00
Yash Saxena
a38ccf2621
Add capsh 2020-11-27 14:22:31 +01:00
Andrea Cardaci
22899a5159 Improve update-alternatives 2020-11-17 18:54:53 +01:00
Michael Gisbers
e212f23455 Create update-alternatives.md
Use update-alternatives with sudo to replace system binaries
2020-11-17 18:54:53 +01:00
Emanuel Duss
286775860a Fixed syntax error 2020-11-13 12:46:01 +01:00
Emanuel Duss
de10e4761e Added missing shell file 2020-11-13 12:09:04 +01:00
Emanuel Duss
cb7cb672f2 New command: split 2020-11-13 11:59:14 +01:00
Emanuel Duss
c88e461484 New command: pr 2020-11-13 11:59:14 +01:00
Emanuel Duss
28b67bdfd5 New command: paste 2020-11-13 11:59:14 +01:00
Emanuel Duss
9e593b6ac0 New command: join 2020-11-13 11:59:14 +01:00
Emanuel Duss
146b146cd3 New command: install 2020-11-13 11:59:14 +01:00
Emanuel Duss
5a3e672d23 New command: csplit 2020-11-13 11:59:14 +01:00
Emanuel Duss
55b7296d8e New command: comm 2020-11-13 11:59:14 +01:00
Emanuel Duss
2ee9d7a934 New command: basenc 2020-11-13 11:58:00 +01:00
Emanuel Duss
f3dfd7a50c Added nroff file read 2020-11-13 11:57:13 +01:00
Emanuel Duss
764b2685bc Syntax cleanup, removed some non-working SUID entries 2020-11-13 11:56:48 +01:00
Emanuel Duss
bd1e3ce65d Fixed indentation 2020-11-12 21:36:18 +01:00
Emanuel Duss
64b4b9de1f Fixed wrong filename 2020-11-12 14:33:06 +01:00
Emanuel Duss
66cc5dd512 New command: xmodmap 2020-11-12 14:21:00 +01:00
Emanuel Duss
f9043b2f14 New command: troff 2020-11-12 14:21:00 +01:00
Emanuel Duss
5a58f6a3c3 New command: tbl 2020-11-12 14:21:00 +01:00
Emanuel Duss
0a110bb044 New command: ssh-keygen 2020-11-12 14:21:00 +01:00
Emanuel Duss
bde35dc4c7 New command: ss 2020-11-12 14:21:00 +01:00
Emanuel Duss
a8458733ea New command: rev 2020-11-12 14:21:00 +01:00
Emanuel Duss
3d776d1ea8 New command: psql 2020-11-12 14:21:00 +01:00
Emanuel Duss
324e0e672a New command: ex 2020-11-12 14:21:00 +01:00
Emanuel Duss
ff997ac104 New command: column 2020-11-12 14:21:00 +01:00
Emanuel Duss
00902fc035 New command: check_statusfile 2020-11-12 14:21:00 +01:00
Emanuel Duss
e7c1b630ad New command: check_ssl_cert 2020-11-12 14:21:00 +01:00
Emanuel Duss
846a613121 New command: check_raid 2020-11-12 14:21:00 +01:00