GTFOBins: A Curated List of Unix Binaries for Bypassing Local Security Restrictions
By
StefanBatory
Pure flour-power. Hearty enough to carry you through lunch.
Summary
GTFOBins is a curated list of Unix-like binaries that can be exploited to bypass local security restrictions in misconfigured systems. The list catalogs executables (like 7z, aa-exec, ab, etc.) and their potential for abuse, such as file read, shell access, file upload, file download, and command execution. It serves as a security reference for penetration testers and system administrators to identify and mitigate privilege escalation vectors.
Key quotes
· 5 pulledGTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
7z - File read
aa-exec - Shell
ab - Upload, Download
acr - Command
You might also wanna read
SSH Authentication Configuration and Key Management Documentation
This appears to be technical documentation or configuration data related to SSH (Secure Shell) authentication and security. The content incl
Suspicious hidden message discovered in jqwik testing library 1.10.0
A developer reports discovering a suspicious string in the jqwik testing library (version 1.10.0) that appears during Maven test runs. The s
Anthropic Releases Free Security Plugin for Claude Code Terminal to Detect Vulnerabilities
Anthropic has released a free security-guidance plugin for its Claude Code terminal tool that autonomously reviews code edits, model outputs
cybersecuritynews.com·14h agowolfCOSE: A Lightweight COSE + CBOR Library for Embedded Systems with PQC and FIPS 140-3 Support
wolfCOSE is a lightweight C library implementing CBOR (RFC 8949) and COSE (RFC 9052/9053) for embedded systems, using wolfSSL as the crypto
Anthropic launches Claude Security beta for codebase vulnerability scanning
Anthropic has released Claude Security, a defensive security tool within Claude Code on the web, from closed preview to beta for Claude Ente
thenewstack.io·1d agoHow LinkedIn's 2012 Breach Exposed the Dangers of Unsalted Password Hashes
This article examines the 2012 LinkedIn breach where attackers cracked millions of passwords using fast, unsalted hashes like MD5 and SHA-1.
hendryadrian.com·2d ago