Wildcard Injection

Privilege escalation via wildcard/glob argument injection. Use this skill whenever you need to exploit unquoted wildcards in privileged scripts, or when analyzing binaries like tar, rsync, zip, 7z, tcpdump, chown, chmod for argument injection vulnerabilities. Trigger this skill for any privilege escalation scenario involving file operations, backup scripts, or sudoers rules with wildcards. Make sure to use this skill when you see patterns like `tar *`, `rsync *`, `zip *`, `chown *`, or any privileged command with unquoted globs.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/linux-hardening/privilege-escalation/wildcards-spare-tricks commit 3249198eef

Frequently asked questions

npx skillmds@latest add abelrguezr/wildcard-injection