HackTricks
HackTricks
HackTricks
HackTricks
HackTricks
Pentesting Methodology
External Recon Methodology
Phishing Methodology
About the author
Exfiltration
Tunneling and Port Forwarding
Brute Force - CheatSheet
Search Exploits
Shells
Shells (Linux, Windows, MSFVenom)
Linux/Unix
Checklist - Linux Privilege Escalation
Linux Privilege Escalation
Useful Linux Commands
Linux Environment Variables
Windows
Checklist - Local Windows Privilege Escalation
Windows Local Privilege Escalation
Active Directory Methodology
NTLM
Stealing Credentials
Authentication, Credentials, UAC and EFS
Basic CMD for Pentesters
Basic PowerShell for Pentesters
AV Bypass
Mobile Apps Pentesting
Android APK Checklist
Android Applications Pentesting
Pentesting
Pentesting Network
Pentesting JDWP - Java Debug Wire Protocol
Pentesting Printers
Pentesting SAP
7/tcp/udp - Pentesting Echo
21 - Pentesting FTP
22 - Pentesting SSH/SFTP
23 - Pentesting Telnet
25,465,587 - Pentesting SMTP/s
43 - Pentesting WHOIS
53 - Pentesting DNS
69/UDP TFTP/Bittorrent-tracker
79 - Pentesting Finger
80,443 - Pentesting Web Methodology
Uncovering CloudFlare
Laravel
Code Review Tools
Symphony
XSS to RCE Electron Desktop Apps
Spring Actuators
Artifactory Hacking guide
Apache
JSP
API Pentesting
Buckets
CGI
Drupal
Flask
Git
GraphQL
H2 - Java SQL database
IIS - Internet Information Services
JBOSS
Jenkins
JIRA
Joomla
Nginx
PHP Tricks (SPA)
Python
SpEL - Spring Expression Language
Tomcat
VMWare (ESX, VCenter...)
WebDav
werkzeug
Wordpress
88tcp/udp - Pentesting Kerberos
110,995 - Pentesting POP
111/TCP/UDP - Pentesting Portmapper
113 - Pentesting Ident
123/udp - Pentesting NTP
135, 593 - Pentesting MSRPC
137,138,139 - Pentesting NetBios
139,445 - Pentesting SMB
143,993 - Pentesting IMAP
161,162,10161,10162/udp - Pentesting SNMP
194,6667,6660-7000 - Pentesting IRC
264 - Pentesting Check Point FireWall-1
389, 636, 3268, 3269 - Pentesting LDAP
500/udp - Pentesting IPsec/IKE VPN
502 - Pentesting Modbus
512 - Pentesting Rexec
513 - Pentesting Rlogin
514 - Pentesting Rsh
515 - Pentesting Line Printer Daemon (LPD)
548 - Pentesting Apple Filing Protocol (AFP)
554,8554 - Pentesting RTSP
623/UDP/TCP - IPMI
631 - Internet Printing Protocol(IPP)
873 - Pentesting Rsync
1026 - Pentesting Rusersd
1098/1099 - Pentesting Java RMI
1433 - Pentesting MSSQL - Microsoft SQL Server
1521,1522-1529 - Pentesting Oracle TNS Listener
1723 - Pentesting PPTP
1883 - Pentesting MQTT (Mosquitto)
2049 - Pentesting NFS Service
2301,2381 - Pentesting Compaq/HP Insight Manager
2375, 2376 Pentesting Docker
3260 - Pentesting ISCSI
3299 - Pentesting SAPRouter
3306 - Pentesting Mysql
3389 - Pentesting RDP
3632 - Pentesting distcc
4369 - Pentesting Erlang Port Mapper Daemon (epmd)
5000 - Pentesting Docker Registry
5353/UDP Multicast DNS (mDNS)
5432,5433 - Pentesting Postgresql
5671,5672 - Pentesting AMQP
5800,5801,5900,5901 - Pentesting VNC
5984,6984 - Pentesting CouchDB
5985,5986 - Pentesting WinRM
6000 - Pentesting X11
6379 - Pentesting Redis
8009 - Pentesting Apache JServ Protocol (AJP)
8089 - Splunkd
9000 - Pentesting FastCGI
9001 - Pentesting HSQLDB
9042/9160 - Pentesting Cassandra
9100 - Pentesting Raw Printing (JetDirect, AppSocket, PDL-datastream)
9200 - Pentesting Elasticsearch
10000 - Pentesting Network Data Management Protocol (ndmp)
11211 - Pentesting Memcache
15672 - Pentesting RabbitMQ Management
27017,27018 - Pentesting MongoDB
44818/UDP/TCP - Pentesting EthernetIP
47808/udp - Pentesting BACNet
50030,50060,50070,50075,50090 - Pentesting Hadoop
Pentesting Web
2FA/OTP Bypass
Abusing hop-by-hop headers
Bypass Payment Process
Captcha Bypass
Cache Poisoning and Cache Deception
Clickjacking
Client Side Template Injection (CSTI)
Command Injection
Content Security Policy (CSP) Bypass
Cookies Hacking
CORS - Misconfigurations & Bypass
CRLF (%0D%0A) Injection
Cross-site WebSocket hijacking (CSWSH)
CSRF (Cross Site Request Forgery)
Dangling Markup - HTML scriptless injection
Deserialization
Domain/Subdomain takeover
Email Header Injection
File Inclusion/Path traversal
File Upload
Formula Injection
HTTP Request Smuggling / HTTP Desync Attack
IDOR
JWT Vulnerabilities (Json Web Tokens)
NoSQL injection
LDAP Injection
OAuth to Account takeover
Open Redirect
Parameter Pollution
PostMessage Vulnerabilities
Race Condition
Rate Limit Bypass
SQL Injection
SSRF (Server Side Request Forgery)
SSTI (Server Side Template Injection)
Unicode Normalization vulnerability
Web Tool - WFuzz
XPATH injection
XSLT Server Side Injection (Extensible Stylesheet Languaje Transformations)
XXE - XEE - XML External Entity
XSS (Cross Site Scripting)
XSSI (Cross-Site Script Inclusion)
XS-Search
Physical attacks
Physical Attacks
Escaping from KIOSKs
Reversing
Common API used in Malware
Reversing Tools
Cryptographic/Compression Algorithms
Word Macros
Exploiting
Linux Exploiting (Basic) (SPA)
Exploiting Tools
Windows Exploiting (Basic Guide - OSCP lvl)
Forensics
Malware Analysis
Memory dump analysis
Pcaps analysis
Volatility - CheatSheet
Basic Forensics (ESP)
Crypto
Certificates
Electronic Code Book (ECB)
Cipher Block Chaining CBC-MAC
Padding Oracle
RC4 - Encrypt&Decrypt
Crypto CTFs Tricks
BACKDOORS
Merlin
Empire
Salseo
ICMPsh
Stego
Stego Tricks
Esoteric languages
MISC
Basic Python
Other Big References
TODO
More Tools
MISC
Pentesting DNS
Burp Suite
Other Web Tricks
Interesting HTTP
Emails Vulnerabilities
Cloud security review
Android Forensics
TR-069
6881/udp - Pentesting BitTorrent
CTF Write-ups
1911 - Pentesting fox
Online Platforms with API
Reset/Forgoten Password Bypass
Stealing Sensitive Information Disclosure from a Web
XSS to RCE Electron Desktop Apps
Recommended read:
https://mksben.l0.cm/2020/10/discord-desktop-rce.html?m=1
​
Previous
Symphony
Next
Spring Actuators
Last updated
2 months ago
Edit on GitHub