Advertisement
Guest User

GTFOBins Cross Ref with local bins with SUID Bit Set

a guest
Jul 18th, 2018
247
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.34 KB | None | 0 0
  1. echo;echo;echo "Getting suid bins from GTFOBins, please standby..."; for path in $(curl -s https://github.com/GTFOBins/GTFOBins.github.io/tree/master/_gtfobins | grep md | se
  2. d "s/.* title=\"\(.*\)\".*/\1/" | cut -d " " -f3 | cut -d '"' -f2); do result=$(curl -s https://github.com/$path)|grep -i suid; if [ "$result" != "" ] ; then command=$(echo $path | cut -d "/" -f7 | cut -
  3. d "." -f1); echo Adding Command To List: $command; echo $command >> commands ;fi ; done ; timeout 30s find / -perm -4000 2> /dev/null > localsuids; echo;echo "Possible SUID Vuln Bins:"; for command in $(
  4. cat commands); do grep $command localsuids ; done ; echo "cleaning up..."; rm commands; rm localsuids; echo "That's it! Thanks for playing!";
  5.  
  6. OUTPUT:
  7. Getting suid bins from GTFOBins, please standby ...
  8. Adding Command To List: ash
  9. Adding Command To List: awk
  10. Adding Command To List: base64
  11. Adding Command To List: bash
  12. Adding Command To List: busybox
  13. Adding Command To List: cat
  14. Adding Command To List: crontab
  15. Adding Command To List: csh
  16. Adding Command To List: curl
  17. Adding Command To List: cut
  18. Adding Command To List: dash
  19. Adding Command To List: dd
  20. Adding Command To List: diff
  21. Adding Command To List: ed
  22. Adding Command To List: emacs
  23. Adding Command To List: env
  24. Adding Command To List: expand
  25. Adding Command To List: expect
  26. Adding Command To List: find
  27. Adding Command To List: flock
  28. Adding Command To List: fmt
  29. Adding Command To List: fold
  30. Adding Command To List: ftp
  31. Adding Command To List: gdb
  32. Adding Command To List: head
  33. Adding Command To List: ionice
  34. Adding Command To List: jq
  35. Adding Command To List: ksh
  36. Adding Command To List: ld
  37. Adding Command To List: less
  38. Adding Command To List: ltrace
  39. Adding Command To List: mail
  40. Adding Command To List: make
  41. Adding Command To List: man
  42. Adding Command To List: more
  43. Adding Command To List: mount
  44. Adding Command To List: nano
  45. Adding Command To List: nc
  46. Adding Command To List: nl
  47. Adding Command To List: node
  48. Adding Command To List: od
  49. Adding Command To List: perl
  50. Adding Command To List: php
  51. Adding Command To List: pico
  52. Adding Command To List: puppet
  53. Adding Command To List: python2
  54. Adding Command To List: python3
  55. Adding Command To List: rlwrap
  56. Adding Command To List: rpm
  57. Adding Command To List: rpmquery
  58. Adding Command To List: ruby
  59. Adding Command To List: scp
  60. Adding Command To List: sed
  61. Adding Command To List: setarch
  62. Adding Command To List: sftp
  63. Adding Command To List: shuf
  64. Adding Command To List: socat
  65. Adding Command To List: sort
  66. Adding Command To List: sqlite3
  67. Adding Command To List: ssh
  68. Adding Command To List: stdbuf
  69. Adding Command To List: strace
  70. Adding Command To List: tail
  71. Adding Command To List: tar
  72. Adding Command To List: taskset
  73. Adding Command To List: tclsh
  74. Adding Command To List: tee
  75. Adding Command To List: telnet
  76. Adding Command To List: tftp
  77. Adding Command To List: time
  78. Adding Command To List: timeout
  79. Adding Command To List: ul
  80. Adding Command To List: unexpand
  81. Adding Command To List: uniq
  82. Adding Command To List: unshare
  83. Adding Command To List: vi
  84. Adding Command To List: watch
  85. Adding Command To List: wget
  86. Adding Command To List: whois
  87. Adding Command To List: wish
  88. Adding Command To List: xargs
  89. Adding Command To List: xxd
  90. Adding Command To List: zsh
  91.  
  92. Possible SUID Vuln Bins:
  93. /bin/fusermount
  94. /bin/mount
  95. /bin/umount
  96. cleaning up...
  97. That's it! Thanks for playing!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement