HackTricks
Searchโ€ฆ
๐Ÿ‘ฝ
Network Services Pentesting
Search Exploits
Support HackTricks and get benefits!

Browser

Always search in "google" or others: <service_name> [version] exploit
You should also try the shodan exploit search from https://exploits.shodan.io/.

Searchsploit

Useful to search exploits for services in exploitdb from the console.
1
#Searchsploit tricks
2
searchsploit "linux Kernel" #Example
3
searchsploit apache mod_ssl #Other example
4
searchsploit -m 7618 #Paste the exploit in current directory
5
searchsploit -p 7618[.c] #Show complete path
6
searchsploit -x 7618[.c] #Open vi to inspect the exploit
7
searchsploit --nmap file.xml #Search vulns inside an nmap xml result
Copied!

Pompem

โ€‹https://github.com/rfunix/Pompem is another tool to search for exploits
1
msf> search platform:windows port:135 target:XP type:exploit
Copied!

PacketStorm

If nothing is found, try to search the used technology inside https://packetstormsecurity.com/โ€‹

Vulners

You can also search in vulners database: https://vulners.com/โ€‹

Sploitus

This search exploits in other databases: https://sploitus.com/โ€‹
Support HackTricks and get benefits!