offsec
SUDO_KILLER
offsec | SUDO_KILLER | |
---|---|---|
1 | 8 | |
40 | 2,098 | |
- | - | |
4.3 | 8.8 | |
about 1 year ago | 2 months ago | |
PowerShell | Shell | |
- | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
offsec
-
Passed OSCP (2nd attempt)
I made a GitHub repository with a list of machines I did for preparation for the OSCP exam, and also the write-up of TJnull's OSCP prep HackTheBox machines... - the-robot/offsec
SUDO_KILLER
- cve-2023-22809
-
CVE-2023-22809
this project https://github.com/TH3xACE/SUDO_KILLER can be used to detect and exploit this CVE.
-
Sudoedit can edit arbitrary files (CVE-2023-22809)
check the project https://github.com/TH3xACE/SUDO_KILLER ... there is a docker and the tool within it to play with the described scenario and there is a video also...showing the exploitation :)
- TH3xACE/SUDO_KILLER - A tool to identify and exploit sudo rules' misconfigurations and vulnerabilities within sudo for linux privilege escalation.
- Some of the latest CVEs like CVE-2014-0106, CVE-2015-5602, CVE-2017-1000367, CVE-2019-14287, CVE-2019-18634, CVE-2021-3156 and CVE-2021-23240 are detected by the tool and much more. If you like the project, don't forget to give a +1 star on github. Thanks
- How to detect sudo’s CVE-2021-3156 using Falco
-
Baron Samedit: Heap-based buffer overflow in Sudo (CVE-2021-3156)
Detection and checks for CVE-2021-3156 and CVE-2021-23240 were added to https://github.com/TH3xACE/SUDO_KILLER . Please give a +1 star on github if you appreciate the project.
What are some alternatives?
OSCP-Exam-Report-Template - Modified template for the OSCP Exam and Labs. Used during my passing attempt
linux-smart-enumeration - Linux enumeration tool for pentesting and CTFs with verbosity levels
EZEA - EZEA (EaZy Enum Automator), made for OSCP. This tool uses bash to automate most of the enumeration proces
linux-exploit-suggester - Linux privilege escalation auditing tool
CTF-Difficulty - This cheasheet is aimed at the CTF Players and Beginners to help them sort the CTF Challenges on the basis of Difficulties.
CVE-2021-4034 - PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
OSCP-BoF - This is a walkthrough about understanding the #BoF machine present in the #OSCP exam.
please
zsh-toggle-command-prefix - Zsh widget to toggle a prefix on a command
awesome-oscp - A curated list of awesome OSCP resources
please - Really tiny sudo replacement
MacDirtyCow - Example of CVE-2022-46689 aka MacDirtyCow.