Notas
  • Introduction
  • Active Directory
    • BloodHound
    • Bypassing
    • Enumeration
    • Groups
    • Methodology
    • Msfvenom
    • Pivoting
    • Privesc
  • CMS
    • Jenkins
    • wordpress
  • CVEs
    • CVE-2017-0199
    • CVE-2019-1414
    • CVE-2021-42287
    • CVE-2021-44228
  • Common Ports
    • DNS - 53
    • LDAP - 389
    • MSSQL - 1433
    • NFS - 2049
    • RPC - 135
    • SMB - 445
    • VNC - 5900
    • ftp-21
    • kerberos-88
    • msrpc-5722
    • mysql-3306
    • rdp-3389
    • redis-6379
    • smtp-25
    • snmp-161
    • squid-3128
    • winrm-5985
  • EXTRA
    • BruteForce
    • Criptography
    • Extra
    • Fuzzing
    • Mounts
    • RevShells
  • Pentesting Android
    • Basic
  • Pentesting Web
    • IIS
    • LFI
    • OWASP TOP 10
    • Padding Oracle Attack
    • SSRF
    • SSTI
    • XSS
  • Pivoting
    • Remote Port Fowarding
    • Remote commands
  • SQLi
    • Conditional-based
    • Enumeration
    • Error-based
    • SQLite
    • Time-based
  • linux
    • Escalada
    • common-vulns
    • docker-breakout
    • ip-tables
    • port-forwarding
    • port-knocking
    • privesc
    • reversing
    • samba
  • scripting
    • Bash
    • PHP
    • Powershell
    • Python
Powered by GitBook
On this page
  • Pseudocurl
  • HostDiscovery
  • PortDiscovery
  1. scripting

Bash

Pseudocurl

function __curl() {  read proto server path <<<$(echo ${1//// })  DOC=/${path// //}  HOST=${server//:*}  PORT=${server//*:}  [[ x"${HOST}" == x"${PORT}" ]] && PORT=80  exec 3<>/dev/tcp/${HOST}/$PORT  echo -en "GET ${DOC} HTTP/1.0\r\nHost: ${HOST}\r\n\r\n" >&3  (while read line; do   [[ "$line" == $'\r' ]] && break  done && cat) <&3  exec 3>&-}

HostDiscovery

#!/bin/bashfunction ctrl_c(){  exit 1}# Ctrl+Ctrap ctrl_c INTnetworks=(172.18.0 172.19.0)for network in ${networks[@]};do  for i in $(seq 1 254); do    timeout 1 bash -c "ping -c 1 $network.$i" &>/dev/null && echo "[+] HOST $network.$i - ACTIVE" &  done; waitdone

PortDiscovery

#!/bin/bashfunction ctrl_c(){  exit 1}# Ctrl+Ctrap ctrl_c INTnetworks=(172.18.0.2 172.18.0.1 172.19.0.4 172.19.0.3 172.19.0.2 172.19.0.1)for network in ${networks[@]};do  for port in $(seq 1 65535); do    timeout 1 bash -c "echo '' > /dev/tcp/$network/$port" &>/dev/null && echo "[+] HOST $network:$port - ACTIVE" &  done; waitdone
PreviousscriptingNextPHP

Last updated 1 year ago