Commit Graph

720 Commits

Author SHA1 Message Date
Andrea Cardaci
0c87e670b4
Add npm 2021-01-21 15:11:28 +01:00
Andrea Cardaci
2ce5e831b7
Fix npm 2021-01-21 15:04:27 +01:00
Andrea Cardaci
717acf4b14
Fix openvt 2021-01-21 14:49:32 +01:00
Hardeep Singh
f8ff5eddc7
Added npm.md 2021-01-19 23:52:33 +05:30
Mohit Khemchandani
4347f58f55 Added openvt.md 2021-01-19 23:07:21 +05:30
Andrea Cardaci
eba354eda0
Minor fixes to SUID mainly 2021-01-18 09:23:50 +01:00
Andrea Cardaci
c85513d5a6
Fix hping3 SUID 2021-01-18 09:19:35 +01:00
Nick Blekherman
d6d3563e5d
Add SUID category to nawk as file read 2021-01-18 09:49:07 +02:00
Nick Blekherman
c293ed20f7
Add SUID category to mawk as file read 2021-01-18 09:48:12 +02:00
Nick Blekherman
31b69cfeed
Add SUID category to gawk as file read 2021-01-18 09:46:51 +02:00
Nick Blekherman
085e72a971
Add ./ to SUID category in awk.md 2021-01-18 09:44:34 +02:00
Nick Blekherman
3065294305
Add ./ to SUID category in ed.md 2021-01-18 09:41:36 +02:00
Nick Blekherman
646ea8132e
Revert limited-suid to suid and add -p in hping3 2021-01-18 09:40:50 +02:00
Nick Blekherman
b43f418ddb
Add ./ to SUID category in nohup.mp 2021-01-18 09:36:35 +02:00
Andrea Cardaci
5c4ec744cb
Merge pull request #160 from xmpf/adiff_ar_bridge
Add ar and bridge file-read
2021-01-17 23:42:42 +01:00
Andrea Cardaci
0d5c457233
Fix YAML in ar 2021-01-17 23:40:41 +01:00
Andrea Cardaci
7da8627262
Remove adiff since is ar that actually reads here 2021-01-17 23:38:07 +01:00
Andrea Cardaci
bed198068f
Fix ar and add suid and sudo 2021-01-17 23:32:44 +01:00
Andrea Cardaci
f7ff2ea852
Add suid and sudo to bridge 2021-01-17 23:25:31 +01:00
Andrea Cardaci
629501ccc7
Improve bridge 2021-01-17 23:22:33 +01:00
Michalis Papadopoullos
4f11ca6a15
Add atobm 2021-01-17 23:11:43 +01:00
Andrea Cardaci
da85e84b60
Add at 2021-01-15 20:39:32 +01:00
Andrea Cardaci
013bf5a0c9 Fix newlines in at 2021-01-15 20:38:33 +01:00
Andrea Cardaci
578f951c76 Improve at and add the shell function 2021-01-15 20:34:57 +01:00
Aman Rawat
e241cd3aa7 added at 2021-01-15 20:34:57 +01:00
Shikata
561a5b2c9a Remove trailing space in awk.md line 31 2021-01-13 11:22:26 +02:00
Andrea Cardaci
47db2fa431 Make cupsfilter more general 2021-01-12 18:03:46 +01:00
Michalis Papadopoullos
46bbaaf6d6 cupsfilter (package: cups) 2021-01-12 18:03:46 +01:00
Shikata
28cc7ff7da Add SUID [file read] category to sqlite3 2021-01-12 13:57:34 +02:00
Shikata
ae8271292a Add SUID [file read] category to lua 2021-01-12 13:50:43 +02:00
Shikata
47698d0cfb Add SUID [file read] category to ed 2021-01-12 13:44:19 +02:00
Shikata
fd719bb4b6 Add SUID category to awk 2021-01-12 13:39:52 +02:00
Shikata
a48303c2b9 Remove redundant sudo from SUID category in nohup 2021-01-11 16:18:18 +02:00
Michalis Papadopoullos
513909c38c Added adiff, ar, bridge file_read 2021-01-11 13:59:30 +02:00
Shikata
211edf746b Switch SUID to Limited SUID in aria2c 2021-01-11 13:45:21 +02:00
Shikata
c09b95053f Fixed order of Limited SUID category in lwp-request 2021-01-11 13:02:54 +02:00
Shikata
05a9ae111b Switch SUID to Limited SUID in hping3 2021-01-11 13:02:11 +02:00
Shikata
9d1b86e9d3 Switch SUID to Limited SUID in lwp-request 2021-01-11 12:56:13 +02:00
Shikata
c4f93b87d5 Remove redundant lua -e from File Write and File Read categories in nmap 2021-01-11 12:37:37 +02:00
Shikata
db40142ea7 Remove redundant sudo from SUID category 2021-01-11 12:31:54 +02:00
Andrea Cardaci
bb4050810e Fix rpm[query] SUID 2021-01-10 18:27:30 +01:00
Andrea Cardaci
33fb39a183 Fix wrong nano and pico SUID 2021-01-10 18:16:30 +01:00
ritiksahni
01d4de40d2
Add dig 2021-01-10 12:31:51 +01:00
ritiksahni
9069b0c903
Add exiftool 2021-01-09 15:03:35 +01:00
Andrea Cardaci
5b2d89b99a Fix nmap SUID file-write 2021-01-04 09:05:21 +01:00
Syed Umar Arfeen
edc8a2d03d
Adding another usage of Nmap's SUID
I came along with this method on stackoverflow while trying to execute commands using a SUID nmap binary, though `--script` failed me but this works. Could be enough to demonstrate effect of using SUID on Nmap. 

I've yet to come up with a way to over-write the contents of the system file according to what we want, with this we can only over-write files with nmap output.

```bash
sudo touch /etc/filecantbetouched
nmap 127.0.0.1 -oN=/etc/filecantbetouched
cat /etc/filecantbetouched
```
2021-01-04 12:16:29 +05:00
makikvues
1c07880178
Add hping3 2020-12-30 08:47:47 +01:00
Eblazquez
4de8e04e4b
Add virsh 2020-12-25 21:04:07 +01:00
Andrea Cardaci
65857d486b
Merge pull request #147 from mindfuckup/master 2020-12-20 21:31:05 +01:00
Andrea Cardaci
c80e83c3c5 Make install similar to chmod 2020-12-20 21:24:10 +01:00
Andrea Cardaci
fbe4b42890 Improve split 2020-12-20 21:15:58 +01:00
Andrea Cardaci
2475ea0a5a Improve pr 2020-12-20 21:09:50 +01:00
Andrea Cardaci
c6502e8ddc Use base64 in basenc 2020-12-20 20:59:40 +01:00
Andrea Cardaci
7cfac08921 Improve the description of nroff 2020-12-20 20:54:05 +01:00
Andrea Cardaci
b05a84474b Improve the description of troff 2020-12-20 20:48:00 +01:00
Andrea Cardaci
dd16d538ce Improve the description of ssh-keyscan 2020-12-20 20:44:24 +01:00
Andrea Cardaci
54c20a1349 Improve the description of ss 2020-12-20 20:41:49 +01:00
Andrea Cardaci
5102eccdfc Fix psql shell path and remove suid 2020-12-20 20:36:55 +01:00
Andrea Cardaci
6a6485c44b Fix ex shell path and remove suid 2020-12-20 20:36:47 +01:00
Andrea Cardaci
dc3de20e84 Add note about column 2020-12-20 20:36:47 +01:00
Andrea Cardaci
4b2100bfae Fix check_log 2020-12-20 19:53:16 +01:00
Andrea Cardaci
ee8cce63f9 Replace command with shell in check_by_ssh 2020-12-20 19:32:15 +01:00
Yash Saxena
a38ccf2621
Add capsh 2020-11-27 14:22:31 +01:00
Andrea Cardaci
22899a5159 Improve update-alternatives 2020-11-17 18:54:53 +01:00
Michael Gisbers
e212f23455 Create update-alternatives.md
Use update-alternatives with sudo to replace system binaries
2020-11-17 18:54:53 +01:00
Emanuel Duss
286775860a Fixed syntax error 2020-11-13 12:46:01 +01:00
Emanuel Duss
de10e4761e Added missing shell file 2020-11-13 12:09:04 +01:00
Emanuel Duss
cb7cb672f2 New command: split 2020-11-13 11:59:14 +01:00
Emanuel Duss
c88e461484 New command: pr 2020-11-13 11:59:14 +01:00
Emanuel Duss
28b67bdfd5 New command: paste 2020-11-13 11:59:14 +01:00
Emanuel Duss
9e593b6ac0 New command: join 2020-11-13 11:59:14 +01:00
Emanuel Duss
146b146cd3 New command: install 2020-11-13 11:59:14 +01:00
Emanuel Duss
5a3e672d23 New command: csplit 2020-11-13 11:59:14 +01:00
Emanuel Duss
55b7296d8e New command: comm 2020-11-13 11:59:14 +01:00
Emanuel Duss
2ee9d7a934 New command: basenc 2020-11-13 11:58:00 +01:00
Emanuel Duss
f3dfd7a50c Added nroff file read 2020-11-13 11:57:13 +01:00
Emanuel Duss
764b2685bc Syntax cleanup, removed some non-working SUID entries 2020-11-13 11:56:48 +01:00
Emanuel Duss
bd1e3ce65d Fixed indentation 2020-11-12 21:36:18 +01:00
Emanuel Duss
64b4b9de1f Fixed wrong filename 2020-11-12 14:33:06 +01:00
Emanuel Duss
66cc5dd512 New command: xmodmap 2020-11-12 14:21:00 +01:00
Emanuel Duss
f9043b2f14 New command: troff 2020-11-12 14:21:00 +01:00
Emanuel Duss
5a58f6a3c3 New command: tbl 2020-11-12 14:21:00 +01:00
Emanuel Duss
0a110bb044 New command: ssh-keygen 2020-11-12 14:21:00 +01:00
Emanuel Duss
bde35dc4c7 New command: ss 2020-11-12 14:21:00 +01:00
Emanuel Duss
a8458733ea New command: rev 2020-11-12 14:21:00 +01:00
Emanuel Duss
3d776d1ea8 New command: psql 2020-11-12 14:21:00 +01:00
Emanuel Duss
324e0e672a New command: ex 2020-11-12 14:21:00 +01:00
Emanuel Duss
ff997ac104 New command: column 2020-11-12 14:21:00 +01:00
Emanuel Duss
00902fc035 New command: check_statusfile 2020-11-12 14:21:00 +01:00
Emanuel Duss
e7c1b630ad New command: check_ssl_cert 2020-11-12 14:21:00 +01:00
Emanuel Duss
846a613121 New command: check_raid 2020-11-12 14:21:00 +01:00
Emanuel Duss
d0bbdb69cf New command: check_memory 2020-11-12 14:21:00 +01:00
Emanuel Duss
ea9dd24d59 New command: check_log 2020-11-12 14:21:00 +01:00
Emanuel Duss
722f9bc605 New command: check_cups 2020-11-12 14:21:00 +01:00
Emanuel Duss
127738e927 New command: check_by_ssh 2020-11-12 14:21:00 +01:00
Andrea Cardaci
cbfec71fa5 Add cowsay and cowthink 2020-11-12 01:02:28 +01:00
bcoles
e242e92634
Create slsh.md 2020-11-10 20:06:53 +01:00
Andrea Cardaci
03c30e9944 Update composer
- align to the GTFOBins conventions
- avoid Python
- use limited SUID instead of just SUID
2020-11-08 10:39:10 +01:00
clubby789
deaf47943f Add entry for composer 2020-11-08 10:39:10 +01:00
Andrea Cardaci
3409aa0949 Enforce conventions 2020-10-24 12:46:42 +02:00
Ryan Saridar
373f57fc18 Add ghci binary 2020-10-24 12:46:42 +02:00
Ryan Saridar
106dede9da Add ghc binary 2020-10-24 12:46:42 +02:00
Andrea Cardaci
a49cccf7da Add missing git shell example 2020-10-03 12:12:30 +02:00
Andrea Cardaci
87a0bb6a9f Make the new Git shell follow the conventions 2020-10-03 12:03:20 +02:00
PaulSaladin
ef2ebf9d30 Add new sudo git function #Yaml_fix 2020-10-03 12:03:20 +02:00
Roman Mueller
b8dc2aa817
Add file-download to yum 2020-10-02 20:22:06 +02:00
Roman Mueller
1a5b396744
Add file read to git 2020-10-02 14:50:08 +02:00
Andrea Cardaci
81fafc83f3 Add view and rview
Close #137.
2020-09-27 11:45:49 +02:00
Andrea Cardaci
04b29456a6 Add gcc file read
This is an improved version with respect to #138.

Close #138.
2020-09-27 11:29:28 +02:00
Ian Thorne
78eae09003
Added entry for the su command 2020-06-17 18:18:01 +02:00
Andrea Cardaci
a8cdd4728d Fix and polish sysctl 2020-06-11 18:25:45 +02:00
Fabrizio
8ab57da5c7 Create sysctl.md 2020-06-11 18:25:45 +02:00
Andrea Cardaci
45308d4f58 Remove some useless instances of export 2020-06-10 23:04:59 +02:00
Andrea Cardaci
9aa7ec842e Use the sudo VAR=... syntax instead of using -E 2020-06-10 22:56:05 +02:00
Andrea Cardaci
b92d9e0ec2 Fix sudo zypper
`PATH` is a forbidden variable that is not preserved by -E anyway.
2020-06-10 22:54:20 +02:00
Andrea Cardaci
9cd6849b8e Remove useless instances of sudo -E 2020-06-10 22:53:45 +02:00
Aj Dumanhug
fbd887e91a
Remove -E option of sudo for more
Note added by @cyrus-and: this only works because `sudo` preserves `TERM` nevertheless (unless explicitly blacklisted).
2020-06-10 22:48:48 +02:00
T3cH_W1z4rD
1600e05fef
Add pkexec 2020-06-07 01:16:30 +02:00
CraftyDH
d3a218db04 Add XZ 2020-05-25 13:43:36 +02:00
Andrea Cardaci
42fa84a08a Add note about socat shell 2020-05-13 19:41:46 +02:00
Andrea Cardaci
3d9370b1e4 Improve socat 2020-05-13 19:36:45 +02:00
JayDee Raymaker
0d98790312
Add socat shell 2020-05-13 19:33:13 +02:00
Andrea Cardaci
ed2fa545ca Fix bash revshell 2020-05-03 13:13:43 +02:00
Andrea Cardaci
c82955d93c Fix socat invocation 2020-04-25 19:39:14 +02:00
Andrea Cardaci
b56bd683c9 Fix socat so that the victim always connects to the attacker 2020-04-25 19:32:52 +02:00
Maciej Piechota
1f6d44f7a0 Update socat.md 2020-04-25 19:32:52 +02:00
Andrea Cardaci
89b1753a0d Improve dpkg 2020-04-25 19:29:59 +02:00
Maciej Piechota
f6ccddda5c Update dpkg.md
dpkg uses system less pager to list the installed packages.
2020-04-25 19:29:59 +02:00
Andrea Cardaci
361c198d27
Add restic 2020-04-12 13:26:36 +02:00
Andrea Cardaci
7f6221646b Fix and improve restic 2020-04-12 13:22:13 +02:00
Andrea Cardaci
9ec96219a3 Fix line termination 2020-04-12 13:22:13 +02:00
PreethamBomma
b2a2b3a5f0 Add restic.md 2020-04-12 13:22:13 +02:00
d0zer
041110d54d
Add library load section to OpenSSL 2020-04-12 11:20:11 +02:00
Andrea Cardaci
3310197fbc Remove -no_ign_eof from openssl
As discussed in #121.
2020-03-28 14:51:58 +01:00
Andrea Cardaci
ad919ba28b Improve tac and add sudo and suid 2020-03-23 19:54:53 +01:00
Dhiraj Mishra
bd77f4fb71 Create tac.md 2020-03-23 19:54:53 +01:00
Andrea Cardaci
2e55528e82 Add cp file-write
Along the lines of #122.
2020-03-21 19:24:30 +01:00
Andrea Cardaci
834cae88be Refactor cp 2020-03-21 19:14:56 +01:00
Dhiraj Mishra
b6f1947354
Add cp file-read 2020-03-21 19:12:58 +01:00
Andrea Cardaci
662994aca8 Add limited-suid to pry 2020-03-17 20:48:08 +01:00
Andrea Cardaci
ec91e7b417 Improve lwp-download 2020-03-17 20:41:52 +01:00
bcoles
279824d588 Create lwp-download.md 2020-03-17 20:41:52 +01:00
bcoles
a0132156fc Create lwp-request.md 2020-03-17 20:40:08 +01:00
bcoles
15fa8e72d7
Create eqn.md 2020-03-17 20:38:21 +01:00
Andrea Cardaci
e4cd54418c Upgrade gtester to proper shell and add SUID
Related to #108.
2020-03-17 20:33:15 +01:00
bcoles
ee1093fc7b
Create gtester.md 2020-03-17 20:32:25 +01:00
Andrea Cardaci
813d1bebca Improve busctl 2020-03-17 20:19:45 +01:00
bcoles
20efe0d022 Create busctl.md 2020-03-17 20:19:45 +01:00
bcoles
efb956a7b1
Create byebug.md 2020-03-17 20:12:46 +01:00
Andrea Cardaci
5decf3493a Upgrade rake to proper interactive shell 2020-03-17 20:06:27 +01:00
bcoles
9956127653 Create rake.md 2020-03-17 20:06:27 +01:00
bcoles
cc74dd22d8 Create pry.md 2020-03-17 19:51:35 +01:00
bcoles
5f31fe4292
Create dialog.md 2020-03-17 19:46:32 +01:00
bcoles
2eadcc4082 Create nroff.md 2020-03-17 19:38:41 +01:00
bcoles
9eb6538bef Create nsenter.md 2020-03-17 19:33:32 +01:00
Andrea Cardaci
38d7e65264 Fix redcarpet 2020-03-17 19:32:17 +01:00
bcoles
cf9b07bf7b Create redcarpet.md 2020-03-17 19:32:17 +01:00
bcoles
f1b42310a2 Create valgrind.md 2020-03-17 19:28:20 +01:00
bcoles
8e41380863 Create highlight.md 2020-03-17 19:27:49 +01:00
bcoles
67a562d2aa Update shuf.md 2020-03-17 19:22:50 +01:00
Andrea Cardaci
696b9aa173 Add hd.md 2020-03-17 14:38:20 +01:00
Andrea Cardaci
4e22118f35 Add description to hexdump 2020-03-17 14:38:20 +01:00
bcoles
96ddab6cb8 Create hexdump.md 2020-03-17 14:38:20 +01:00
bcoles
0e78ab8010 Create soelim.md 2020-03-17 14:26:37 +01:00
bcoles
4cb792888c
Create strings.md 2020-03-17 14:25:54 +01:00
Andrea Cardaci
03c2183f51 Clarify the genisoimage description
Thanks to #94.
2020-03-15 15:09:25 +01:00
Andrea Cardaci
bd07d8d725 Document and fix zsoelim 2020-03-15 13:33:15 +01:00
bcoles
dce8b357fb Create zsoelim.md 2020-03-15 13:33:15 +01:00
Andrea Cardaci
3361f8a51d Fix and document genisoimage
The SUID function has been removed as it appears to drop privileges (at least on
Debian).
2020-03-15 13:20:45 +01:00
bcoles
d2bbf8b8c9 Create genisoimage.md 2020-03-15 13:20:45 +01:00
bcoles
da60e6e253 Create ksshell.md 2020-03-15 13:11:37 +01:00
bcoles
bbb7db7d63
Create crash.md 2020-03-15 13:10:31 +01:00
Andrea Cardaci
2e6fa047e9 Improve and document dmesg file read 2020-03-15 12:51:02 +01:00
bcoles
32887085bf Update dmesg.md 2020-03-15 12:51:02 +01:00
Andrea Cardaci
041cb2fb7b Link back python from pdb 2020-03-15 12:35:00 +01:00
Andrea Cardaci
1342a7b981 Avoid temp directory in pdb 2020-03-15 12:35:00 +01:00
bcoles
41124f24c2 Create pdb.md 2020-03-15 12:35:00 +01:00
Emilio Pinna
3e6ac9bcf3 Add uudecode 2020-03-15 11:25:35 +00:00
bcoles
d27860b2df Create chroot.md 2020-03-15 12:24:03 +01:00
Andrea Cardaci
8b41830d0b Add (suid) shell for nohup 2020-03-15 12:18:08 +01:00
Andrea Cardaci
8eaeb29c18 Remove export from nohup 2020-03-15 12:18:08 +01:00
bcoles
dfbe9e8bef Create nohup.md 2020-03-15 12:18:08 +01:00
Andrea Cardaci
256794389d Use latin-1 as encoding for iconv 2020-03-15 12:05:17 +01:00
Andrea Cardaci
aca4fbe67b Fix iconv bin name 2020-03-15 12:05:17 +01:00
bcoles
7aa5510f29 Create iconv.md 2020-03-15 12:05:17 +01:00
bcoles
5bde37ec38
Create uuencode.md (#92) 2020-03-15 10:46:04 +00:00
bcoles
fa2f04ba4d
Create base32.md (#90)
Thanks!
2020-03-15 10:44:26 +00:00
Andrea Cardaci
eb37b4ae29 Add another bundler shell example
Related to #88.
2020-03-14 13:20:54 +01:00
bcoles
3104f1d971
Create bundler.md 2020-03-14 13:17:09 +01:00
Andrea Cardaci
0bd4ab2b27 Use rdoc instead of json in gem 2020-03-14 13:08:13 +01:00
Andrea Cardaci
7e12bf7799 Clarify that man uses the default pager 2020-03-14 12:58:28 +01:00
Andrea Cardaci
ddd6c2e304 Fix typo in gem 2020-03-14 12:56:21 +01:00
Andrea Cardaci
48892aad60 Improve and document yelp 2020-03-14 12:45:57 +01:00
Dhiraj Mishra
8f797d3d19 Create yelp.md 2020-03-14 12:45:57 +01:00
Andrea Cardaci
dfb01a4c3b Simplify gcc shell 2020-03-14 12:20:07 +01:00
bcoles
dec4a7f928 Create gcc.md 2020-03-14 12:20:07 +01:00
bcoles
0adf67ca2f
Create gem.md 2020-03-14 11:56:23 +01:00
bcoles
b94b01477c Create cobc.md 2020-03-14 11:53:05 +01:00
Andrea Cardaci
d8a1e55782 Add look 2020-03-11 12:21:03 +01:00
Andrea Cardaci
1b4e4ab15e
Add eb 2020-03-04 20:24:29 +01:00