Emanuel Duss
d0bbdb69cf
New command: check_memory
2020-11-12 14:21:00 +01:00
Emanuel Duss
ea9dd24d59
New command: check_log
2020-11-12 14:21:00 +01:00
Emanuel Duss
722f9bc605
New command: check_cups
2020-11-12 14:21:00 +01:00
Emanuel Duss
127738e927
New command: check_by_ssh
2020-11-12 14:21:00 +01:00
Andrea Cardaci
cbfec71fa5
Add cowsay and cowthink
2020-11-12 01:02:28 +01:00
bcoles
e242e92634
Create slsh.md
2020-11-10 20:06:53 +01:00
Andrea Cardaci
03c30e9944
Update composer
...
- align to the GTFOBins conventions
- avoid Python
- use limited SUID instead of just SUID
2020-11-08 10:39:10 +01:00
clubby789
deaf47943f
Add entry for composer
2020-11-08 10:39:10 +01:00
Andrea Cardaci
3409aa0949
Enforce conventions
2020-10-24 12:46:42 +02:00
Ryan Saridar
373f57fc18
Add ghci binary
2020-10-24 12:46:42 +02:00
Ryan Saridar
106dede9da
Add ghc binary
2020-10-24 12:46:42 +02:00
Andrea Cardaci
a49cccf7da
Add missing git shell example
2020-10-03 12:12:30 +02:00
Andrea Cardaci
87a0bb6a9f
Make the new Git shell follow the conventions
2020-10-03 12:03:20 +02:00
PaulSaladin
ef2ebf9d30
Add new sudo git function #Yaml_fix
2020-10-03 12:03:20 +02:00
Roman Mueller
b8dc2aa817
Add file-download to yum
2020-10-02 20:22:06 +02:00
Roman Mueller
1a5b396744
Add file read to git
2020-10-02 14:50:08 +02:00
Andrea Cardaci
81fafc83f3
Add view and rview
...
Close #137 .
2020-09-27 11:45:49 +02:00
Andrea Cardaci
04b29456a6
Add gcc file read
...
This is an improved version with respect to #138 .
Close #138 .
2020-09-27 11:29:28 +02:00
Ian Thorne
78eae09003
Added entry for the su command
2020-06-17 18:18:01 +02:00
Andrea Cardaci
a8cdd4728d
Fix and polish sysctl
2020-06-11 18:25:45 +02:00
Fabrizio
8ab57da5c7
Create sysctl.md
2020-06-11 18:25:45 +02:00
Andrea Cardaci
45308d4f58
Remove some useless instances of export
2020-06-10 23:04:59 +02:00
Andrea Cardaci
9aa7ec842e
Use the sudo VAR=... syntax instead of using -E
2020-06-10 22:56:05 +02:00
Andrea Cardaci
b92d9e0ec2
Fix sudo zypper
...
`PATH` is a forbidden variable that is not preserved by -E anyway.
2020-06-10 22:54:20 +02:00
Andrea Cardaci
9cd6849b8e
Remove useless instances of sudo -E
2020-06-10 22:53:45 +02:00
Aj Dumanhug
fbd887e91a
Remove -E option of sudo for more
...
Note added by @cyrus-and: this only works because `sudo` preserves `TERM` nevertheless (unless explicitly blacklisted).
2020-06-10 22:48:48 +02:00
T3cH_W1z4rD
1600e05fef
Add pkexec
2020-06-07 01:16:30 +02:00
CraftyDH
d3a218db04
Add XZ
2020-05-25 13:43:36 +02:00
Andrea Cardaci
42fa84a08a
Add note about socat shell
2020-05-13 19:41:46 +02:00
Andrea Cardaci
3d9370b1e4
Improve socat
2020-05-13 19:36:45 +02:00
JayDee Raymaker
0d98790312
Add socat shell
2020-05-13 19:33:13 +02:00
Andrea Cardaci
ed2fa545ca
Fix bash revshell
2020-05-03 13:13:43 +02:00
Andrea Cardaci
c82955d93c
Fix socat invocation
2020-04-25 19:39:14 +02:00
Andrea Cardaci
b56bd683c9
Fix socat so that the victim always connects to the attacker
2020-04-25 19:32:52 +02:00
Maciej Piechota
1f6d44f7a0
Update socat.md
2020-04-25 19:32:52 +02:00
Andrea Cardaci
89b1753a0d
Improve dpkg
2020-04-25 19:29:59 +02:00
Maciej Piechota
f6ccddda5c
Update dpkg.md
...
dpkg uses system less pager to list the installed packages.
2020-04-25 19:29:59 +02:00
Andrea Cardaci
361c198d27
Add restic
2020-04-12 13:26:36 +02:00
Andrea Cardaci
7f6221646b
Fix and improve restic
2020-04-12 13:22:13 +02:00
Andrea Cardaci
9ec96219a3
Fix line termination
2020-04-12 13:22:13 +02:00
PreethamBomma
b2a2b3a5f0
Add restic.md
2020-04-12 13:22:13 +02:00
d0zer
041110d54d
Add library load section to OpenSSL
2020-04-12 11:20:11 +02:00
Andrea Cardaci
3310197fbc
Remove -no_ign_eof from openssl
...
As discussed in #121 .
2020-03-28 14:51:58 +01:00
Andrea Cardaci
ad919ba28b
Improve tac and add sudo and suid
2020-03-23 19:54:53 +01:00
Dhiraj Mishra
bd77f4fb71
Create tac.md
2020-03-23 19:54:53 +01:00
Andrea Cardaci
2e55528e82
Add cp file-write
...
Along the lines of #122 .
2020-03-21 19:24:30 +01:00
Andrea Cardaci
834cae88be
Refactor cp
2020-03-21 19:14:56 +01:00
Dhiraj Mishra
b6f1947354
Add cp file-read
2020-03-21 19:12:58 +01:00
Andrea Cardaci
662994aca8
Add limited-suid to pry
2020-03-17 20:48:08 +01:00
Andrea Cardaci
ec91e7b417
Improve lwp-download
2020-03-17 20:41:52 +01:00
bcoles
279824d588
Create lwp-download.md
2020-03-17 20:41:52 +01:00
bcoles
a0132156fc
Create lwp-request.md
2020-03-17 20:40:08 +01:00
bcoles
15fa8e72d7
Create eqn.md
2020-03-17 20:38:21 +01:00
Andrea Cardaci
e4cd54418c
Upgrade gtester to proper shell and add SUID
...
Related to #108 .
2020-03-17 20:33:15 +01:00
bcoles
ee1093fc7b
Create gtester.md
2020-03-17 20:32:25 +01:00
Andrea Cardaci
813d1bebca
Improve busctl
2020-03-17 20:19:45 +01:00
bcoles
20efe0d022
Create busctl.md
2020-03-17 20:19:45 +01:00
bcoles
efb956a7b1
Create byebug.md
2020-03-17 20:12:46 +01:00
Andrea Cardaci
5decf3493a
Upgrade rake to proper interactive shell
2020-03-17 20:06:27 +01:00
bcoles
9956127653
Create rake.md
2020-03-17 20:06:27 +01:00
bcoles
cc74dd22d8
Create pry.md
2020-03-17 19:51:35 +01:00
bcoles
5f31fe4292
Create dialog.md
2020-03-17 19:46:32 +01:00
bcoles
2eadcc4082
Create nroff.md
2020-03-17 19:38:41 +01:00
bcoles
9eb6538bef
Create nsenter.md
2020-03-17 19:33:32 +01:00
Andrea Cardaci
38d7e65264
Fix redcarpet
2020-03-17 19:32:17 +01:00
bcoles
cf9b07bf7b
Create redcarpet.md
2020-03-17 19:32:17 +01:00
bcoles
f1b42310a2
Create valgrind.md
2020-03-17 19:28:20 +01:00
bcoles
8e41380863
Create highlight.md
2020-03-17 19:27:49 +01:00
bcoles
67a562d2aa
Update shuf.md
2020-03-17 19:22:50 +01:00
Andrea Cardaci
696b9aa173
Add hd.md
2020-03-17 14:38:20 +01:00
Andrea Cardaci
4e22118f35
Add description to hexdump
2020-03-17 14:38:20 +01:00
bcoles
96ddab6cb8
Create hexdump.md
2020-03-17 14:38:20 +01:00
bcoles
0e78ab8010
Create soelim.md
2020-03-17 14:26:37 +01:00
bcoles
4cb792888c
Create strings.md
2020-03-17 14:25:54 +01:00
Andrea Cardaci
03c2183f51
Clarify the genisoimage description
...
Thanks to #94 .
2020-03-15 15:09:25 +01:00
Andrea Cardaci
bd07d8d725
Document and fix zsoelim
2020-03-15 13:33:15 +01:00
bcoles
dce8b357fb
Create zsoelim.md
2020-03-15 13:33:15 +01:00
Andrea Cardaci
3361f8a51d
Fix and document genisoimage
...
The SUID function has been removed as it appears to drop privileges (at least on
Debian).
2020-03-15 13:20:45 +01:00
bcoles
d2bbf8b8c9
Create genisoimage.md
2020-03-15 13:20:45 +01:00
bcoles
da60e6e253
Create ksshell.md
2020-03-15 13:11:37 +01:00
bcoles
bbb7db7d63
Create crash.md
2020-03-15 13:10:31 +01:00
Andrea Cardaci
2e6fa047e9
Improve and document dmesg file read
2020-03-15 12:51:02 +01:00
bcoles
32887085bf
Update dmesg.md
2020-03-15 12:51:02 +01:00
Andrea Cardaci
041cb2fb7b
Link back python from pdb
2020-03-15 12:35:00 +01:00
Andrea Cardaci
1342a7b981
Avoid temp directory in pdb
2020-03-15 12:35:00 +01:00
bcoles
41124f24c2
Create pdb.md
2020-03-15 12:35:00 +01:00
Emilio Pinna
3e6ac9bcf3
Add uudecode
2020-03-15 11:25:35 +00:00
bcoles
d27860b2df
Create chroot.md
2020-03-15 12:24:03 +01:00
Andrea Cardaci
8b41830d0b
Add (suid) shell for nohup
2020-03-15 12:18:08 +01:00
Andrea Cardaci
8eaeb29c18
Remove export from nohup
2020-03-15 12:18:08 +01:00
bcoles
dfbe9e8bef
Create nohup.md
2020-03-15 12:18:08 +01:00
Andrea Cardaci
256794389d
Use latin-1 as encoding for iconv
2020-03-15 12:05:17 +01:00
Andrea Cardaci
aca4fbe67b
Fix iconv bin name
2020-03-15 12:05:17 +01:00
bcoles
7aa5510f29
Create iconv.md
2020-03-15 12:05:17 +01:00
bcoles
5bde37ec38
Create uuencode.md ( #92 )
2020-03-15 10:46:04 +00:00
bcoles
fa2f04ba4d
Create base32.md ( #90 )
...
Thanks!
2020-03-15 10:44:26 +00:00
Andrea Cardaci
eb37b4ae29
Add another bundler shell example
...
Related to #88 .
2020-03-14 13:20:54 +01:00
bcoles
3104f1d971
Create bundler.md
2020-03-14 13:17:09 +01:00
Andrea Cardaci
0bd4ab2b27
Use rdoc instead of json in gem
2020-03-14 13:08:13 +01:00
Andrea Cardaci
7e12bf7799
Clarify that man uses the default pager
2020-03-14 12:58:28 +01:00
Andrea Cardaci
ddd6c2e304
Fix typo in gem
2020-03-14 12:56:21 +01:00
Andrea Cardaci
48892aad60
Improve and document yelp
2020-03-14 12:45:57 +01:00
Dhiraj Mishra
8f797d3d19
Create yelp.md
2020-03-14 12:45:57 +01:00
Andrea Cardaci
dfb01a4c3b
Simplify gcc shell
2020-03-14 12:20:07 +01:00
bcoles
dec4a7f928
Create gcc.md
2020-03-14 12:20:07 +01:00
bcoles
0adf67ca2f
Create gem.md
2020-03-14 11:56:23 +01:00
bcoles
b94b01477c
Create cobc.md
2020-03-14 11:53:05 +01:00
Andrea Cardaci
d8a1e55782
Add look
2020-03-11 12:21:03 +01:00
Andrea Cardaci
1b4e4ab15e
Add eb
2020-03-04 20:24:29 +01:00
Emanuel Duss
b19420d1fd
Added file -f for reading files
2020-02-09 11:44:34 +01:00
Andrea Cardaci
236f88cd34
Fix and clarify sudo for top
...
Related #81 .
2020-01-28 22:33:55 +01:00
Andrea Cardaci
51d7b541dc
Add shell and sudo for top
...
This closes #81 .
Thanks to Chris McCoy (https://github.com/chris-mccoy ) for the idea.
2020-01-28 22:18:36 +01:00
Mr. Robot
304e338c2f
Add macOS file read for fmt
2020-01-08 15:50:13 +01:00
Mr. Robot
4c3636900c
fix typo in shell name
2020-01-08 00:49:11 +01:00
Andrea Cardaci
1f9dbbf6eb
Improve bpftrace sudo shell
2020-01-03 14:11:37 +01:00
Andrea Cardaci
6b4c7c12c9
Add bpftrace sudo shell
2020-01-03 14:02:32 +01:00
Emilio
a9c3dc58fa
Fix sudo script
2019-12-31 16:46:25 +01:00
Andrea Cardaci
15b465d937
Add git hooks shell
...
Closes #77 as it provides a working example and a possibly better hook. Thanks
to jivex5k <wgehalo@gmail.com> for the initial proposal.
2019-12-18 14:38:35 +01:00
Andrea Cardaci
740fa3a44f
Reword screen and use echo instead of tail with user interaction
...
Based on an example provided by #76 .
2019-12-04 02:25:49 +01:00
Andrea Cardaci
15a2bbafe5
Add bash library-load
2019-11-29 13:49:37 +01:00
Tobias
09fdfe5f5d
Adding sub commands sudo for git
2019-10-25 14:19:18 +02:00
Roman Mueller
3a0179306c
Add file-download and file-upload to tar
2019-10-01 13:16:50 +02:00
Syed Umar Arfeen
26ea00d78a
Add iftop
2019-09-28 11:41:05 +02:00
Syed Umar Arfeen
c37da57373
Providing user as argument using -Z
...
For certain distributions running tcpdump without providing -Z (user) argument
causes the provided command to be executed as the `tcpdump` user which has low
privileges by default.
2019-09-23 04:04:05 +02:00
Andrea Cardaci
47f4fb064c
Add note about AppArmor in tcpdump
2019-09-22 12:01:15 +02:00
Andrea Cardaci
b5444fba6e
Remove network shell functions from mawk as not supported
2019-08-30 15:48:07 +02:00
AlessandroZ
977232c45c
adding gawk, nawk, mawk
2019-08-30 15:40:42 +02:00
Andrea Cardaci
391d436fc5
Add ldconfig
...
Close #68 .
2019-08-14 13:14:57 +02:00
Emilio
f68a3ce009
Fix rvim file-write description
2019-08-07 08:39:28 +01:00
Andrea Cardaci
e969daf111
Reword file upload/download descriptions
2019-07-29 16:41:49 +02:00
Andrea Cardaci
a7798bcfe2
Add alternative nmap file upload/download
...
Close #67 .
2019-07-29 16:32:49 +02:00
Andrea Cardaci
205e922b9b
Fix Markdown line break
2019-07-29 15:17:37 +02:00
Léo Meira Vital
bd1d10bd03
Updating git sudo to not drop capabilities
...
Close #66
2019-07-09 20:55:47 +02:00
Miles Whittaker
aa08187718
Add systemctl example using SYSTEMD_EDITOR
...
Close #65 .
2019-07-02 18:14:29 +02:00
Andrea Cardaci
ce031a0d95
Allow to create new containers in docker file read and write
2019-07-02 16:15:39 +02:00
Andrea Cardaci
01f6117248
Improve and generalize docker file read and write
2019-07-02 16:11:15 +02:00
Dominic Breuker
dcbf66329a
Add file read and write as per #64 (temporary solution)
2019-07-02 15:53:28 +02:00
Andrea Cardaci
40ecb11b2e
Simplify the docker example by using chroot
...
Also make it available for non-root users.
The previous SUID example had the problem that the loaders between host and
containers must match, for example, copying `sh` from alpine to debian doesn't
directly work.
2019-07-02 15:47:29 +02:00
Andrea Cardaci
f4a3fc9af3
Add notice about Git sudo capabilities
2019-06-23 17:24:38 +02:00
Syed Umar Arfeen
b8493f916d
Increase the probability that the pager is called by Git
...
`git help config` produces a much longer output, hopefully longer than the
terminal window.
Close #62
2019-06-23 17:17:59 +02:00
Andrea Cardaci
ac68a5864a
Update SUID in nano and pico
2019-04-16 19:11:31 +02:00
Andrea Cardaci
f7baa8aee6
Fix sed quotes
2019-04-16 15:50:36 +02:00
Andrea Cardaci
f088906051
Fix sed file write
2019-04-16 15:49:49 +02:00
Rich Mirch
f79b10a5f8
Add systemctl sudo shell usingpager
2019-04-16 15:41:32 +02:00
Rich Mirch
20607b9b3c
Add sed shell alternative example
2019-04-16 15:37:14 +02:00
Andrea Cardaci
3bc83dcbde
Add alternative file read and write to less
2019-04-08 11:26:10 +02:00
Rich Mirch
3702ec4d53
Update sudo yum by loading a custom plugin ( #58 )
2019-04-06 21:51:33 +01:00
Emilio
b9a262c600
Fix nano shell, suid, and sudo
2019-03-31 12:44:50 +01:00
Emilio
c20ccf4af2
Fix pico shell, suid, and sudo
2019-03-31 12:43:08 +01:00
Emilio
75eff93c50
Improve pico shell, suid, and sudo
2019-03-31 12:19:11 +01:00
Emilio
260b024c74
Add tmux
2019-03-31 11:03:55 +01:00
Emilio
08f5b33651
Add functions with default pager in git
2019-03-31 11:03:34 +01:00
Andrea Cardaci
336abc79bb
Add service shell
2019-03-25 19:54:58 +01:00
Andrea Cardaci
13ab3596bb
Add MySQL library-load
2019-03-25 19:40:48 +01:00
Emilio
73b18859d5
Add screen
2019-03-12 17:44:03 +00:00
S. Sauvin
383db60b02
Update ip with sudo and SUID ( #56 )
...
* Update ip with sudo and SUID
2019-03-12 11:51:10 +00:00
Emilio
fec4b52281
Add smbclient upload and download
2019-03-10 19:08:17 +00:00
Andrea Cardaci
58e517563c
Add suid/sudo accordingly to openssl
2019-03-06 14:08:42 +01:00
Andrea Cardaci
60af774288
Add -no_ign_eof to exit nicely when possible to openssl
2019-03-06 13:54:16 +01:00
Andrea Cardaci
e1a02558ec
Refactor openssl descriptions
2019-03-06 13:53:52 +01:00
Roman Mueller
cdb4576c85
Add reverse-shell, file-upload and file-download.
2019-03-05 09:37:52 +01:00
the-remmer
8c03983ab8
Add zypper
...
Close #52 .
2019-02-22 12:51:30 +01:00
Jonathan Siegel
dd9f4269ed
Add the GNU version of mail
...
Close #54 .
2019-02-19 11:27:35 +01:00
Emilio Pinna
2650be9c68
Add new shell and sudo payload to nano
...
Thanks to https://twitter.com/TheKnapsy/status/1093137518780854273 .
2019-02-15 20:10:32 +00:00
brian
3bd955e8cc
Use os.execute instead of posix.exec in rpm
...
From rpm versions 4.9.0 and on, posix.exec() will return an error unless called
from a child process created with posix.fork(). os.execute() may be used
instead.
This change is documented in these two resources:
- http://rpm.org/user_doc/lua.html
- https://rpm-packaging-guide.github.io/
Close #53 .
2019-02-14 12:32:18 +01:00
Emilio
52a2f4cdc7
Add Lua payloads to rvim
2019-02-03 10:21:45 +00:00
Emilio
d111e78b45
Add Lua payloads to vim
2019-02-03 10:15:53 +00:00
Emilio
9dc5fa2128
Add dnf thanks to https://lsdsecurity.com/2019/01/linux-privilege-escalation-using-apt-get-apt-dpkg-to-abuse-sudo-nopasswd-misconfiguration/ as in #51
2019-02-02 16:15:49 +00:00
Emilio
a0674eb8f0
Add other sudo to rpm thanks to https://lsdsecurity.com/2019/01/linux-privilege-escalation-using-apt-get-apt-dpkg-to-abuse-sudo-nopasswd-misconfiguration/ as in #51
2019-02-02 15:54:57 +00:00
Emilio
b330297943
Add yum thanks to https://lsdsecurity.com/2019/01/linux-privilege-escalation-using-apt-get-apt-dpkg-to-abuse-sudo-nopasswd-misconfiguration/ as in #51
2019-02-02 15:46:01 +00:00
Emilio
7a3ae6e05a
Add dpkg thanks to https://lsdsecurity.com/2019/01/linux-privilege-escalation-using-apt-get-apt-dpkg-to-abuse-sudo-nopasswd-misconfiguration/ as in #51
2019-02-02 15:13:28 +00:00
Emilio
3166a321c0
Add script
2019-02-02 10:02:14 +00:00
Emilio Pinna
fc59ef546f
Add arp and mtr. Thanks to https://twitter.com/insecurity_ltd/status/1087727178295529473
2019-01-30 23:07:40 +00:00
Andrea Cardaci
d0464d7ce8
Drop useless echo indentation
2019-01-29 14:25:16 +01:00
bstapes
a2886b643d
Add systemctl
2019-01-29 14:12:29 +01:00
Andrea Cardaci
0109792b7e
Clarify bash reverse shell
2019-01-25 16:41:15 +01:00
in.security
3a53c6339e
Add ip
2019-01-25 16:40:42 +01:00
Emilio Pinna
1719c4ffda
Polish gimp description
2019-01-22 20:21:20 +00:00
Emilio Pinna
8782ccb96b
Fix gimp description
2019-01-22 20:19:39 +00:00
Emilio Pinna
ee7b68232f
Add gimp description
2019-01-22 20:17:00 +00:00
Emilio Pinna
69b8eb1056
Fix gimp file write
2019-01-22 20:13:34 +00:00
Emilio
9180d550e7
Add gimp thanks to https://twitter.com/Geluchat/status/1083743529388687361
2019-01-21 20:53:48 +00:00
Andrea Cardaci
bab4250775
Fix apt sudo shell
2019-01-21 16:41:17 +01:00
Andrea Cardaci
21f760676c
Add alternative apt* shell technique
...
Thanks to
https://lsdsecurity.com/2019/01/linux-privilege-escalation-using-apt-get-apt-dpkg-to-abuse-sudo-nopasswd-misconfiguration/
Also related to #38 .
2019-01-21 16:28:20 +01:00
Andrea Cardaci
4fdaada820
Fix apt* shell
...
The Bash process substitution doesn't work (anymore?).
2019-01-21 15:40:28 +01:00
Andrea Cardaci
f6b29ce958
Mention the SPELL environment variable in nano
2019-01-21 14:07:14 +01:00
egre55
3e103b2f28
Add logsave
2019-01-15 12:22:21 +01:00
Emilio
732e4f9ae4
Add missing description to gdb sudo
2019-01-05 11:28:25 +00:00
Emilio
31be45fbde
Add sudo to red
2019-01-05 11:24:49 +00:00
Emilio
76f0b9cf45
Adjust and add file-write, file-read, and library-load to irb
2019-01-01 23:06:00 +00:00
Shaksham Jaiswal
1cbe81b195
Add irb ( #44 )
2019-01-03 20:17:38 +00:00
Emilio
9047ee345c
Use shorten ruby file download from #44
2019-01-02 15:28:13 +00:00
Andrea Cardaci
c156f48e5f
Fix SUID and document readelf
2019-01-02 13:41:10 +01:00
0rbz
6ebfcef36c
Create readelf.md
2018-12-31 14:58:24 -05:00
Andrea Cardaci
9652aee337
Add comments to rlogin
...
Close #45 .
2018-12-31 13:35:36 +01:00
0rbz
c1ea5f2b41
Create rlogin.md
2018-12-31 13:35:36 +01:00
Emilio Pinna
bbfcb5b633
Keep cancel description consistent
2018-12-31 09:40:49 +01:00
0rbz
63147892c4
Create cancel.md ( #43 )
...
* Add cancel.md
2018-12-31 09:38:20 +01:00
Qazeer
809b60ef97
Add nmap interactive mode
2018-12-24 18:39:24 +01:00
Emilio Pinna
e404981c2e
Add reverse-shell, file-upload, file-download, library-load, and capabilities to rvim
2018-12-18 15:19:41 +01:00
Emilio Pinna
6befd62430
Add reverse-shell, file-upload, file-download, library-load, and capabilities to vim
2018-12-18 15:11:03 +01:00
Emilio Pinna
d3ef67aa3a
Remove suid from vim
2018-12-18 14:28:09 +01:00
Emilio Pinna
4910c32409
Skim wrong functions from original vi
2018-12-18 14:04:05 +01:00
Emilio Pinna
9432a6ce3c
Add Python 3 comment in vim and rvim
2018-12-18 13:31:22 +01:00
Chris Frederick
cda1654809
Add openssl-enc commands ( #41 )
2018-12-17 14:46:30 +01:00
s3krit
a659ed5d5f
Add file
2018-12-12 18:08:22 +01:00
Andrea Cardaci
32b113b003
Fix and add SUID to other vi
...
Related to #39 .
2018-12-03 16:00:11 +01:00
Andrea Cardaci
e066c22c1f
Fix YAML format in vi
2018-12-03 16:00:01 +01:00
Andrea Cardaci
ed9363fe2d
Fix broken shells in vi
...
Related to #39 .
2018-12-03 15:59:37 +01:00
Emilio Pinna
279381cf3c
Polish rvim, vi, and vim
2018-12-03 13:15:57 +00:00
Hugo DELVAL
bd0cad0433
Add vi(m) commands ( #39 )
2018-12-03 13:06:41 +00:00
Andrea Cardaci
46fd726c5a
Improve 'apt-* install' entries
...
Improve description, enforce standards and make sure that the package will not
be installed.
Related #38 .
2018-11-29 14:25:49 +01:00
HugoDelval
736f3482d3
Add apt(-get) entries
2018-11-29 13:51:39 +01:00
g0tmi1k
2d3071ef55
Typo: LFILE -> $LFILE (DD command)
2018-11-20 13:40:19 +01:00
Andrea Cardaci
f111f3e261
Split run-mailcap into functions
...
Close #34 .
2018-11-19 14:04:01 +01:00
egre55
892949d4af
Add run-mailcap
2018-11-19 13:30:43 +01:00
Andrea Cardaci
df1efb0437
Fix cpan YAML
2018-11-12 15:48:31 +01:00
egre55
d5405933d1
Add run-parts
2018-11-12 15:45:29 +01:00
Andrea Cardaci
3cbfa05169
Add dmesg
...
Close #32 .
2018-11-12 15:11:50 +01:00
Andrea Cardaci
23dae5406e
Minor fixes on cpan
2018-11-12 15:11:50 +01:00
egre55
a448ed5c25
Add dmsetup ( #31 )
...
* Add dmsetup
* fixes
2018-11-10 18:39:18 +00:00
Emilio Pinna
27c1c56577
Polish cpan
2018-11-08 20:01:40 +00:00
Shaksham Jaiswal
754e5e0f95
variable fix
2018-11-08 20:00:23 +00:00
Shaksham Jaiswal
f6d6019515
added environment variables
2018-11-08 20:00:23 +00:00
Shaksham Jaiswal
b78d64c236
made fixes, thanks to egre55
2018-11-08 20:00:23 +00:00
Shaksham Jaiswal
e600a4e610
indentation fixes
2018-11-08 20:00:23 +00:00
Shaksham Jaiswal
b3a6e93b78
Add cpan
2018-11-08 20:00:23 +00:00
Andrea Cardaci
66844f9cc4
Fix YAML format in start-stop-daemon
2018-11-05 16:41:04 +01:00
egre55
86e249e812
Add start-stop-daemon
2018-11-05 16:34:57 +01:00
Andrea Cardaci
ae79cfa550
Add limited suid to pic
...
Related to #28 .
2018-11-02 23:47:20 +01:00
egre55
0b62b20891
Add pic
2018-11-02 23:45:58 +01:00
Andrea Cardaci
3cd9494b9b
Remove limited-suid from man
2018-10-23 13:55:21 +02:00
Andrea Cardaci
0c8a06246b
Add --to-command interactive shell to tar
...
Close #27
2018-10-21 12:13:17 +02:00
Andrea Cardaci
a7818d5f16
Promote tar command to interactive shell
2018-10-21 12:13:17 +02:00
Emilio Pinna
fdda727eb1
Add jjs
2018-10-14 21:01:33 +01:00
Emilio Pinna
7ad0233b33
Add description to jrunscript reverse-shell
2018-10-14 21:01:24 +01:00
Emilio Pinna
46e293e444
Describe jrunscript suid limitations
2018-10-13 13:36:24 +01:00
Emilio Pinna
26151d0c44
Add jrunscript
2018-10-12 18:39:39 +01:00
Emilio Pinna
d7d463ee0c
Add missing SUID in gdb
2018-10-08 22:51:52 +01:00
Emilio Pinna
2377be5a55
Fix suid in PHP
2018-10-08 20:56:51 +01:00
Emilio Pinna
f14e511218
Fix python SUID
2018-10-08 20:14:25 +01:00
Emilio Pinna
dd337b5ddf
Adopt new function names
2018-10-05 18:55:38 +01:00
Andrea Cardaci
1dfb03b013
Add description about grep flavors
...
Related to #26 .
2018-10-03 14:44:55 +02:00
Roman Mueller
0bca156294
Add grep
2018-10-03 14:22:27 +02:00
Andrea Cardaci
fbb0ccefa4
Add info about pager in journalctl
...
Close #25 .
2018-10-02 22:52:08 +02:00
Roman Mueller
7d3a6ddd9d
Add journalctl
2018-10-02 22:52:05 +02:00
Emilio Pinna
9514d41a80
Remove capabilities-enabled from pip
2018-09-29 10:54:33 +01:00
Emilio Pinna
a156e10996
Use LFILE in easy_install and pip file-write function
2018-09-29 10:51:00 +01:00
Emilio Pinna
f8dab26569
Rephrase easy_install descriptions
2018-09-29 10:47:19 +01:00
Emilio Pinna
9dc6a93e5b
Add download to easy_install
2018-09-29 10:46:03 +01:00
Emilio Pinna
c2224a6b49
Add easy_install file-write
2018-09-28 17:57:23 +01:00
Emilio Pinna
0e639583d6
Add easy_install
2018-09-27 22:53:55 +01:00
Emilio Pinna
5087fa15ef
Remove pip description
2018-09-27 22:00:56 +01:00
Emilio Pinna
be7f7b87a0
Remove capabilities-enabled and sudo-enabled from pip
2018-09-27 21:54:50 +01:00
Emilio Pinna
1321a330a5
Fix pip setcap
2018-09-27 21:43:28 +01:00
Emilio Pinna
ce111369f3
Try add python payloads to pip
2018-09-27 21:34:49 +01:00
Andrea Cardaci
0db7fe5f32
Fix pip to work in both Linux and macOS
2018-09-27 12:58:29 +02:00
Emilio Pinna
3c59b1c2fc
Add python functions to gdb
2018-09-25 22:44:12 +01:00
Emilio Pinna
12aa95cf2f
Fix pip description
2018-09-25 22:16:12 +01:00
Emilio Pinna
0ec8e7d99d
Fix gdb description
2018-09-25 22:02:25 +01:00
Emilio Pinna
1222c37802
Merge python2 and python3
2018-09-25 21:41:31 +01:00
Emilio Pinna
ebb9fd00be
Fix python3 upload
2018-09-25 20:37:38 +01:00
Emilio Pinna
d3659b5cc6
Fix python2 upload
2018-09-25 20:37:38 +01:00
Andrea Cardaci
689e00461d
Get rid of base64 for curl and wget and make descriptions similar
...
Close #24 .
2018-09-25 19:56:27 +02:00
Roman Mueller
9bac306503
Add history file read/write to bash
...
Close #21 .
2018-09-13 18:51:28 +02:00
Andrea Cardaci
b10791a840
Add download to finger
2018-09-13 15:42:45 +02:00
Andrea Cardaci
2e477b25de
Add the capabilities-enabled function
...
This exploits `setcap` to persist root privileges on Linux.
2018-09-13 14:49:51 +02:00
Andrea Cardaci
aed737131c
Add capabilities to gdb
2018-09-13 14:48:40 +02:00
Emilio Pinna
3125617475
Add finger
2018-09-12 22:35:41 +01:00
Emilio Pinna
7314987800
Add capabilities to node
2018-09-12 22:02:05 +01:00
Emilio Pinna
c7375411b7
Add capabilities to perl, php, python3, and ruby
2018-09-12 21:57:04 +01:00
Emilio Pinna
e72d7e3d19
Reorder functions
2018-09-12 21:56:42 +01:00
Emilio Pinna
1afd9ec9ec
Drafting capabilities
2018-09-12 21:29:53 +01:00
Andrea Cardaci
2e6968e883
Clarify aria2c --allow-overwrite
...
As discussed in #22 .
2018-09-07 13:46:22 +02:00
Andrea Cardaci
e5d5f2e2c6
Clarify tcpdump subprocess
2018-09-07 13:33:30 +02:00
Andrea Cardaci
17c3e974a7
Add a full local version of aria2c and add --allow-overwrite
...
Close #22
2018-09-07 13:30:55 +02:00
HugoDelval
65b762ca80
Add aria2c
...
Taken from https://github.com/InsecurityAsso/inshack-2018/blob/master/web/curler/exploit/exploit
2018-09-07 13:30:10 +02:00
Andrea Cardaci
8eaf595fe6
Make interactive execute whenever possible
...
Here the trick is to restore those file descriptors (0, 1, 2) that have been
redirected (`dup2`) by the parent process.
First we need to determine which one has been redirected, for example by looking
at `ls -l /proc/$$/fd/`. Then we can use `0<&x`, `1>&x` or `2>&x` to restore 0,
1 or 2 respectively, where `x` is any file descriptor number that points to the
TTY.
It may happen that no file descriptor is unchanged, in that case we can use
`tty` to perform the redirection: sh <$(tty) >$(tty) 2>$(tty)
2018-09-07 01:11:06 +02:00
Andrea Cardaci
5b79154cf1
Avoid output file for tcpdump
2018-09-07 00:29:58 +02:00
Andrea Cardaci
ab62d024b1
Make xargs execute-interactive
2018-09-06 23:35:27 +02:00
Andrea Cardaci
7c0fa85a66
Make nano/pico execute-interactive by using exec
2018-09-06 21:36:20 +02:00
Andrea Cardaci
65c3d3409f
Fix ssh execute
2018-09-06 20:40:36 +02:00
Andrea Cardaci
14ea39d22f
Fix description long lines
2018-09-06 19:18:22 +02:00
Andrea Cardaci
d180391d7e
Fix Python link in pip
2018-09-06 19:18:12 +02:00
Andrea Cardaci
7d9465bd6a
Add pip
...
As suggested by #20 .
2018-09-06 18:46:22 +02:00
Andrea Cardaci
9c96140f1d
Add date
...
Thanks to #20 .
2018-09-06 17:08:01 +02:00
Emilio Pinna
cb695abfa6
Add chmod and chown as suggested in #20
2018-09-05 17:59:07 +01:00
Emilio Pinna
f2ab6a6283
Remove file-read and file-write from cp and mv
2018-09-05 17:38:32 +01:00
Andrea Cardaci
aab8e783ec
Add facter
...
Thanks to #20 .
2018-09-04 13:42:37 +02:00
Emilio Pinna
d5f546b67d
Polish cp and mv descriptions
2018-09-03 21:40:09 +01:00
Emilio Pinna
08a82c913a
Add mv as suggested in #20
2018-09-03 21:38:22 +01:00
Emilio Pinna
508a06c14a
Add cp as suggested in #20
2018-09-03 21:33:24 +01:00
Andrea Cardaci
8f4b085807
Fix shuf YAML
2018-08-31 15:51:14 +02:00
Andrea Cardaci
6bfc58daab
Add notice about tcpdump traffic requirements
2018-08-31 11:29:36 +02:00
Andrea Cardaci
09564b427f
Add apt, apt-get, mysql and smbclient
...
Thanks to #20 .
2018-08-31 11:09:19 +02:00
Andrea Cardaci
5b18d9340a
Fix red YAML
2018-08-31 10:17:36 +02:00
George O
cbab8b803a
Add red
...
Close #17 .
2018-08-27 16:27:12 +02:00
Emilio Pinna
51acc5bc9b
Fix tcpdump sudo-enabled
2018-08-24 17:59:16 +01:00
Andrea Cardaci
1bff7d1525
Fix SUID for less and pg
2018-08-24 13:30:23 +02:00
Andrea Cardaci
38a5860d48
Add file-write to less
2018-08-24 12:32:06 +02:00
Andrea Cardaci
41bd75145c
Fix SUID for less and pg
...
Only file access is possible in that case.
2018-08-24 12:25:57 +02:00
Andrea Cardaci
e310b1f565
Fix more YAML
2018-08-24 12:08:37 +02:00
pshem
2b16dd52e8
Add nice, cpulimit and pg
2018-08-24 11:33:15 +02:00
Emilio Pinna
e84ec807a1
Fix nmap suid-limited
2018-08-23 23:45:07 +01:00
Emilio Pinna
8fb329ca92
Fix nmap suid-limited
2018-08-23 23:44:27 +01:00
Emilio Pinna
0681eacca5
Add reverse and bind shell and file transfer functions to nmap
2018-08-23 18:29:50 +01:00
Andrea Cardaci
97c54f9b22
Fix nmap descriptions
2018-08-23 18:11:27 +02:00
Andrea Cardaci
d4b50275bb
Use DATA as a placeholder for file-write operations
2018-08-20 15:00:34 +02:00
Andrea Cardaci
866ca2e404
Fix other editors file write
2018-08-20 15:00:34 +02:00
Andrea Cardaci
b4b67ff10b
Fix ed file read/write
2018-08-20 15:00:34 +02:00
Emilio Pinna
0ba5df0cb9
Use temporary files in zip functions
2018-08-19 11:32:48 +01:00
Emilio Pinna
a68ef39e30
Standardize tcpdump temporary file creation
2018-08-19 11:24:13 +01:00
Emilio Pinna
14c8781f2d
Fix nmap description and temporary file
2018-08-19 11:20:37 +01:00
Emilio Pinna
f34aa31334
Remove docker interactive-execute
2018-08-19 11:14:16 +01:00
Andrea Cardaci
f740b410cc
Simplify zip and add suid-limited
2018-08-19 11:43:26 +02:00
Andrea Cardaci
2ff760e560
Fix and simplify tcpdump
2018-08-19 11:43:26 +02:00
Andrea Cardaci
acf29564cb
Simplify rsync and add interactive execute
2018-08-19 11:43:26 +02:00
Andrea Cardaci
7822ec33e8
Add suid, description and YAML fixes to nmap
2018-08-19 11:43:26 +02:00
Andrea Cardaci
c20ade4551
Make docker disposable, use sh instead of bash and add description
2018-08-19 11:43:26 +02:00
AlessandroZ
7219385a05
add new ways
2018-08-17 17:16:09 +02:00
Andrea Cardaci
6b73dcf283
Use the portable -u option for mktemp instead of removing the file
...
Close #15 .
2018-07-31 12:44:16 +02:00
Emilio Pinna
53ad35fb10
Add suid-enabled and sudo-enabled to tftp
2018-07-22 18:24:39 +01:00
Emilio Pinna
3469b03e78
Add sudo-enabled and suid-limited to socat
2018-07-22 15:49:15 +01:00
Emilio Pinna
0f422cdd6a
Reorder functions in git, lua, and nc
2018-07-22 15:42:43 +01:00
Emilio Pinna
38cd886b36
Describe which functions work with netcat traditional
2018-07-22 15:35:26 +01:00
Emilio Pinna
fbd8a68cae
Add suid-limited and sudo-enabled to nc
2018-07-22 15:34:05 +01:00
Emilio Pinna
4de0246992
Use double backtick for inline code
2018-07-22 15:22:03 +01:00
Emilio Pinna
b016b7b9dd
Add suid-enabled and sudo-enabled to curl, dd, and wget
2018-07-22 14:30:03 +01:00
Emilio Pinna
00a06edb07
Fix lua descriptions
2018-07-22 14:12:20 +01:00
Emilio Pinna
ef92163d03
Add git
2018-07-22 14:06:54 +01:00
Emilio Pinna
bfd61e93fc
Add lua
2018-07-22 12:47:57 +01:00
Emilio Pinna
94f43fb943
Fix nc download description
2018-07-22 12:47:43 +01:00
Andrea Cardaci
e1cd3aed68
Fix YAMLs according to YAMLlint
2018-07-16 15:01:50 +02:00
Andrea Cardaci
a00f689760
Improve mount
2018-07-16 13:47:09 +02:00
Andrea Cardaci
e50f44521e
Improve crontab
2018-07-16 13:37:17 +02:00
kk
85b99ce89f
added crontab and mount
2018-07-16 10:00:14 +02:00
Emilio Pinna
d6895f367d
Reorder functions in binaries
2018-07-04 19:26:52 +01:00
Emilio Pinna
80b20b6991
Add ruby download
2018-06-17 20:16:43 +01:00
Emilio Pinna
401c469b26
Add versions requirements on PHP and ruby
2018-06-17 20:08:02 +01:00
Emilio Pinna
50ffed4210
Replace more suid-limited execution with a suid-enabled read example
2018-06-17 11:39:42 +01:00
Emilio Pinna
7fa5b1e16e
Use valid Mbox file for mail
2018-06-17 11:28:23 +01:00
Emilio Pinna
06966c8cd4
Remove mail suid-limited
2018-06-17 11:27:03 +01:00
Emilio Pinna
fce5a22341
Add sudo-enabled to cut
2018-06-16 16:13:16 +01:00
Roman Mueller
659002adef
Add cut
2018-06-16 14:28:28 +01:00
Andrea Cardaci
b3fc53a9d3
Remove invalid SUID execute from sed
2018-06-13 16:42:02 +02:00
Andrea Cardaci
2da69686ac
Fix sed execute and file write, also enforce standards
2018-06-13 16:05:57 +02:00
Roman Mueller
3c0e0bf1e3
Add execute-interactive & file-write to sed
2018-06-13 12:01:25 +02:00
Andrea Cardaci
0d786940c4
Add tar execute-non-interactive and file-read
2018-06-13 10:35:26 +02:00
Dov Murik
69465eb338
Add expand, unexpand
2018-06-12 19:29:34 +01:00
Andrea Cardaci
4b11771fec
Avoid cat in bash
2018-06-12 16:17:34 +02:00
Andrea Cardaci
3b59c85656
Fix bash file read
2018-06-11 13:12:15 +02:00
Roman Mueller
7660674537
Add file-read to curl
2018-06-10 21:59:08 +01:00
Andrea Cardaci
2696bc3cde
Fix make compatibility issues
2018-06-04 20:00:09 +02:00
Emilio Pinna
7e5bcab249
Replace where_to_save with file_to_save
2018-06-04 18:53:35 +01:00
Emilio Pinna
6a747b0920
Fix PHP interactive functions
2018-06-04 18:40:46 +01:00
Andrea Cardaci
b2731c2c91
Fix make suid shell
2018-06-04 19:13:16 +02:00
Andrea Cardaci
564dbe28fa
Add base64, ltrace, make, sqlite3, time
2018-06-04 19:05:55 +02:00
Andrea Cardaci
81f12399fe
Add compatibility notice in make
2018-06-04 18:59:07 +02:00
Andrea Cardaci
c31a8a1b6b
Simplify make
2018-06-04 18:28:58 +02:00
Andrea Cardaci
4eff8b534f
Fix time description
2018-06-04 17:23:26 +02:00
Andrea Cardaci
b2a2dccc82
Add execute-interactive to sqlite3
2018-06-04 17:16:57 +02:00
Andrea Cardaci
323553f4b0
Make base64 portable
2018-06-04 14:59:57 +02:00
Andrea Cardaci
0785f116d3
Clarify echo command in rlwrap file-write
2018-06-04 13:16:24 +02:00
Andrea Cardaci
3cc3be5aa5
Use /dev/null as history for rlwrap
2018-06-04 13:09:55 +02:00
Andrea Cardaci
069e7da89d
Add sudo and suid to od
2018-06-04 13:01:44 +02:00
Andrea Cardaci
467e4e875d
Fix od YAML
2018-06-04 13:01:25 +02:00
Andrea Cardaci
669f8f0373
Inhibit actual locking in flock
2018-06-04 12:46:28 +02:00
Dov Murik
5fa7efbc1c
Add base64, ltrace, make, sqlite3, time
2018-06-04 10:21:53 +00:00
Dov Murik
3f8a62a253
Add flock, od, rlwrap
2018-06-03 20:22:08 +00:00
Roman Mueller
6e6cbb66a7
Remove non-interactive versions
2018-06-03 13:09:03 +01:00
Roman Mueller
1e443710a2
Add ProxyCommand executions to ssh
2018-06-03 13:09:03 +01:00
Andrea Cardaci
de8d657479
Fix typo in xargs
2018-06-03 12:30:34 +02:00
Andrea Cardaci
2463f9477a
Add xargs file-read even though it uses the external echo command
2018-06-03 11:51:44 +02:00
Andrea Cardaci
d14b69c12f
Add comment to puppet about diff
2018-06-03 11:41:27 +02:00
Andrea Cardaci
77edd09b07
Add output to puppet execute functions
2018-06-03 10:58:39 +02:00
Andrea Cardaci
6843fe84b5
Use consistent shell variable style in puppet
2018-06-03 10:30:07 +02:00
Andrea Cardaci
42997519e1
Fix sort file-read to avoid actually sorting lines
...
Thanks to @dubek.
2018-06-03 10:01:46 +02:00
Emilio Pinna
b6dfe3e083
Add diff
2018-06-02 16:02:38 +01:00
Emilio Pinna
234cfc0ebb
Add puppet description
2018-06-02 15:55:12 +01:00
Roman Mueller
144e51b165
Add puppet
2018-06-02 14:29:54 +02:00
Andrea Cardaci
b3c405e2d5
Add sudo and suid to nl
2018-06-01 13:30:32 +02:00
Andrea Cardaci
5a1c87e7c5
Fix YAML literal blocks
2018-06-01 12:44:34 +02:00
Andrea Cardaci
b96f6e9a49
Fix YAMLs format
2018-06-01 00:22:34 +02:00
Emilio Pinna
bdf78c5e99
Add busybox
2018-05-31 20:09:44 +01:00
Andrea Cardaci
3a619c7777
Add whois
...
Thanks to https://twitter.com/info_dox/status/1001985728342102017
2018-05-31 20:24:56 +02:00
Andrea Cardaci
d95bc8a8dc
Fix coherence in nc YAML
2018-05-31 20:24:56 +02:00
Andrea Cardaci
ce034dd7b0
Clarify ul corruption
2018-05-31 12:37:44 +02:00
Emilio Pinna
401486648a
Add sort, ul, uniq
2018-05-30 19:15:29 +01:00
Emilio Pinna
1b5f2aedae
Rephrase ssh read
2018-05-30 19:07:49 +01:00
Andrea Cardaci
852407bb02
Add tee
2018-05-30 19:20:51 +02:00
Andrea Cardaci
5aee2ec17e
Add cat
2018-05-30 19:20:43 +02:00
Andrea Cardaci
66f60d7ef6
Use variables in dd
2018-05-30 12:56:08 +02:00
Andrea Cardaci
d937f2ba52
Use id as non-interactive command in php
2018-05-30 12:56:08 +02:00
Andrea Cardaci
bb001f1b8a
Add xargs, nl and unshare
2018-05-30 12:55:36 +02:00
Andrea Cardaci
ab481fa4a5
Reduce the number of leading spaces in nl and comment about it
2018-05-30 12:54:05 +02:00
Andrea Cardaci
4c3c73a4b6
Add variables to nl
2018-05-30 12:45:42 +02:00
Andrea Cardaci
fa60f30f5a
Remove suid-limited as it is superseded by suid-enabled
2018-05-30 12:26:29 +02:00
Andrea Cardaci
6563f19914
Remove xargs file-read as it relies on an external program
2018-05-30 11:53:20 +02:00
Andrea Cardaci
d3b3c390a4
Simplify xargs invocation
2018-05-30 11:53:20 +02:00
Dov Murik
d1906b7fdd
Add unshare
2018-05-30 08:17:06 +00:00