srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/data/packs/hacking.json
diff options
context:
space:
mode:
Diffstat (limited to 'data/packs/hacking.json')
-rw-r--r--data/packs/hacking.json58
1 files changed, 57 insertions, 1 deletions
diff --git a/data/packs/hacking.json b/data/packs/hacking.json
index 9bc3b04..da02dc7 100644
--- a/data/packs/hacking.json
+++ b/data/packs/hacking.json
@@ -209,5 +209,61 @@
"attribution": "Defence",
"explanation": "Parameterised queries send the values separately from the statement, so nothing the user types can become SQL.",
"content": "cur.execute('SELECT * FROM users WHERE name = %s AND active = %s', (name, True))"
+ },
+ {
+ "category": "hacking",
+ "content": "nmap -sV -sC -p- --min-rate 1000 -oA scan 10.0.0.0/24",
+ "attribution": "nmap",
+ "explanation": "-p- covers all 65535 ports rather than the usual thousand. -oA writes all three output formats at once, which matters because a scan is slow to repeat.",
+ "language": "shell"
+ },
+ {
+ "category": "hacking",
+ "content": "gobuster dir -u https://target -w /usr/share/wordlists/dirb/common.txt -x php,txt -t 40",
+ "attribution": "gobuster",
+ "explanation": "-x appends extensions to every word, so one wordlist tests several file types. Authorised testing only: this is noisy and appears plainly in any access log.",
+ "language": "shell"
+ },
+ {
+ "category": "hacking",
+ "content": "hashcat -m 1000 -a 0 hashes.txt rockyou.txt -r rules/best64.rule",
+ "attribution": "hashcat",
+ "explanation": "-m selects the hash type and -a 0 is a straight dictionary attack. A rule file mutates each candidate, which covers far more of the search space than the raw list.",
+ "language": "shell"
+ },
+ {
+ "category": "hacking",
+ "content": "openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -text",
+ "attribution": "openssl",
+ "explanation": "-servername sends the SNI field, without which a shared host returns the wrong certificate. Redirecting standard input stops the client waiting for something to send.",
+ "language": "shell"
+ },
+ {
+ "category": "hacking",
+ "content": "tcpdump -i eth0 -nn -s0 -w capture.pcap 'tcp port 80 and host 10.0.0.5'",
+ "attribution": "tcpdump",
+ "explanation": "-s0 captures whole packets rather than the first bytes. The quoted expression is a BPF filter, applied in the kernel, so unmatched traffic is never copied.",
+ "language": "shell"
+ },
+ {
+ "category": "hacking",
+ "content": "ffuf -w params.txt -u 'https://target/api?FUZZ=1' -fs 1234 -mc all",
+ "attribution": "ffuf",
+ "explanation": "-fs hides responses of one exact size, which is how a uniform wall of not-found pages is removed. -mc all then keeps every remaining status code for inspection.",
+ "language": "shell"
+ },
+ {
+ "category": "hacking",
+ "content": "john --wordlist=rockyou.txt --rules=Jumbo --format=sha512crypt shadow.txt",
+ "attribution": "john",
+ "explanation": "Rules generate variations of each word: capitalisation, appended digits, common substitutions. Naming the format skips John's guess, which is often wrong on mixed files.",
+ "language": "shell"
+ },
+ {
+ "category": "hacking",
+ "content": "sqlmap -u 'https://target/item?id=1' --batch --level 3 --risk 2 --dbs",
+ "attribution": "sqlmap",
+ "explanation": "--batch answers prompts with the default so it runs unattended. Level and risk widen the payloads tried, at the cost of a much noisier and slower test.",
+ "language": "shell"
}
-] \ No newline at end of file
+]