diff options
Diffstat (limited to 'data/packs/hacking.json')
| -rw-r--r-- | data/packs/hacking.json | 58 |
1 files changed, 57 insertions, 1 deletions
diff --git a/data/packs/hacking.json b/data/packs/hacking.json index 9bc3b04..da02dc7 100644 --- a/data/packs/hacking.json +++ b/data/packs/hacking.json @@ -209,5 +209,61 @@ "attribution": "Defence", "explanation": "Parameterised queries send the values separately from the statement, so nothing the user types can become SQL.", "content": "cur.execute('SELECT * FROM users WHERE name = %s AND active = %s', (name, True))" + }, + { + "category": "hacking", + "content": "nmap -sV -sC -p- --min-rate 1000 -oA scan 10.0.0.0/24", + "attribution": "nmap", + "explanation": "-p- covers all 65535 ports rather than the usual thousand. -oA writes all three output formats at once, which matters because a scan is slow to repeat.", + "language": "shell" + }, + { + "category": "hacking", + "content": "gobuster dir -u https://target -w /usr/share/wordlists/dirb/common.txt -x php,txt -t 40", + "attribution": "gobuster", + "explanation": "-x appends extensions to every word, so one wordlist tests several file types. Authorised testing only: this is noisy and appears plainly in any access log.", + "language": "shell" + }, + { + "category": "hacking", + "content": "hashcat -m 1000 -a 0 hashes.txt rockyou.txt -r rules/best64.rule", + "attribution": "hashcat", + "explanation": "-m selects the hash type and -a 0 is a straight dictionary attack. A rule file mutates each candidate, which covers far more of the search space than the raw list.", + "language": "shell" + }, + { + "category": "hacking", + "content": "openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -text", + "attribution": "openssl", + "explanation": "-servername sends the SNI field, without which a shared host returns the wrong certificate. Redirecting standard input stops the client waiting for something to send.", + "language": "shell" + }, + { + "category": "hacking", + "content": "tcpdump -i eth0 -nn -s0 -w capture.pcap 'tcp port 80 and host 10.0.0.5'", + "attribution": "tcpdump", + "explanation": "-s0 captures whole packets rather than the first bytes. The quoted expression is a BPF filter, applied in the kernel, so unmatched traffic is never copied.", + "language": "shell" + }, + { + "category": "hacking", + "content": "ffuf -w params.txt -u 'https://target/api?FUZZ=1' -fs 1234 -mc all", + "attribution": "ffuf", + "explanation": "-fs hides responses of one exact size, which is how a uniform wall of not-found pages is removed. -mc all then keeps every remaining status code for inspection.", + "language": "shell" + }, + { + "category": "hacking", + "content": "john --wordlist=rockyou.txt --rules=Jumbo --format=sha512crypt shadow.txt", + "attribution": "john", + "explanation": "Rules generate variations of each word: capitalisation, appended digits, common substitutions. Naming the format skips John's guess, which is often wrong on mixed files.", + "language": "shell" + }, + { + "category": "hacking", + "content": "sqlmap -u 'https://target/item?id=1' --batch --level 3 --risk 2 --dbs", + "attribution": "sqlmap", + "explanation": "--batch answers prompts with the default so it runs unattended. Level and risk widen the payloads tried, at the cost of a much noisier and slower test.", + "language": "shell" } -]
\ No newline at end of file +] |