Shell

This executable can spawn an interactive system shell.
  1. Version requirements2.02 to 5.21
    This function can be performed by any unprivileged user.
    nmap --interactive
    !/bin/sh
    This function is performed by the privileged user if executed via sudo because the acquired privileges are not dropped.
    RemarksIf there are environment variables involved, they must be passed via sudo VAR=value ... or exported then sudo -E ....
    nmap --interactive
    !/bin/sh
    This function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.
    RemarksThis executable runs commands using the system shell, e.g., via functions like system, so it only works for distributions where the shell does not drop SUID privileges.
    nmap --interactive
    !/bin/sh

File write

This executable can write data to local files.
  1. CommentThe payload appears inside the regular nmap output.
    This function can be performed by any unprivileged user.
    nmap -oG=/path/to/output-file DATA
    This function is performed by the privileged user if executed via sudo because the acquired privileges are not dropped.
    RemarksIf there are environment variables involved, they must be passed via sudo VAR=value ... or exported then sudo -E ....
    nmap -oG=/path/to/output-file DATA
    This function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.
    nmap -oG=/path/to/output-file DATA

File read

This executable can read data from local files.
  1. CommentThe file is actually parsed as a list of hosts/networks, lines are leaked through error messages.
    This function can be performed by any unprivileged user.
    nmap -iL /path/to/input-file
    This function is performed by the privileged user if executed via sudo because the acquired privileges are not dropped.
    RemarksIf there are environment variables involved, they must be passed via sudo VAR=value ... or exported then sudo -E ....
    nmap -iL /path/to/input-file
    This function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.
    nmap -iL /path/to/input-file
    RemarksThe content is corrupted or otherwise altered by the process, thus it might not be suitable for handling arbitrary binary data.

Inherit

This executable can inherit functions from another.
  1. CommentThis allows to run Lua code (...).
    This function can be performed by any unprivileged user.
    echo '...' >/path/to/temp-file
    nmap --script=/path/to/temp-file
    This function is performed by the privileged user if executed via sudo because the acquired privileges are not dropped.
    RemarksIf there are environment variables involved, they must be passed via sudo VAR=value ... or exported then sudo -E ....
    echo '...' >/path/to/temp-file
    nmap --script=/path/to/temp-file
    This function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.
    echo '...' >/path/to/temp-file
    nmap --script=/path/to/temp-file
    Functions

    Inherits from lua, thus possibly granting its functions.