HN Hall of Fame Weekly email

GTFOBins

gtfobins.github.io Reference Curated collections & archives Security & privacy Class of 2021-10 Hall of Fame
Screenshot of gtfobins.github.io captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 7 calendar years, with breakout response in 3 of them.

submissions
10
submitters
10
observed span
2018–2026
peak thread · 99 comments
324 pts
latest 20+ return · 2023-07-07
201 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

Kind of weird to list every program that reads an input file with higher privleges under sudo or suid. That's like almost every program, and kind of the entire point of sudo/suid.

bawolff·324-point thread·

Most of them by very far rely on sudo. I've got a system without sudo. The only way to execute something as root on my system is to log in, using a U2F security key, from a second system (typically a small laptop sitting next to my workstation). That second system is connected to my workstation on a dedicated LAN only used by these two machines. Firewalls on both (for example my workstation only allow SSH in from that one…

I find a lot of these to be really contrived and not actually exploits. For example, the first "issue" for yum[0] shows that you can create a RPM that will run arbitrary commands when installed, and then shows the example install command, which requires root access. So, sure, if someone tricks you into running arbitrary commands as root, you're hosed. I don't find this particularly novel or interesting. Then there are several supposed "SUID issues", like the second one for…

kelnos·163-point thread·

What I get from reading this is, "never sudo <bin> anything you don't absolutely need to". Or in other words, always adhere to the Principle of Least Privilege. As a sysadmin, we often just give ourselves ALL:ALL in sudo, but we shouldn't. We definitely shouldn't give it to other users.

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
3

100+ points or 50+ comments

Total points
702

reference only — not used in Hall rules or ranking

Total comments
189

reference only — not used in Hall rules or ranking

Every submission

DateTitle as submittedByPointsComments
2018-05-23Show HN: GTFOBins – Curated list of Unix binaries to bypass security controlscyrusand20
2018-09-05Exploitable Unix binaries to bypass local security restrictionsntrischi10
2019-02-24Show HN: GTFOBins – Lolbas for Unixd0bby10
2019-08-08Living Off the Land in LinuxFirst breakoutDyslexicAtheist16335
2020-12-01Curated list of Unix binaries that can be exploited by an attackervarbhat30
2021-01-20GTFOBins: List of Unix binaries that can bypass local security restrictionsbryanrasmussen21
2021-10-13GTFOBinsHall induction · Best threadmatthberg32454
2023-07-07List of Unix binaries that can be used to bypass local security restrictionsLatest 20+ point returnjanisz20199
2025-04-04GTFOBinsbsilvereagle20
2026-01-14GTFOBinstosh30