본문 바로가기

꿀팁!

모의침투맛보기

find / -type f -perm -4000 -user root 2>/dev/null후

 

나온문자열이 아래 url의 목록중 포함되어있다면 세부내역을 통해 활용

 

https://gtfobins.org/

 

GTFOBins

GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems. The project collects legitimate functions of Unix-like executables that can be abused to get the f**k break out restricted

gtfobins.org

목록에 있는지 확인후 활용