Cristian Cornea
Notes
JScript (.js) Dropper
HTML Smuggling (download automatically malicious file through JavaScript
Special XSS Payload (obfuscated)
Cross-Site Websocket Hijacking
Host Header Injection to Manipulate Forgot Password
Localhost (especially for SSRF) bypass blacklist
WAF Bypass
x86 Msfvenom Encoders (good ones!)
TMUX Hijacking
Hidden Windows Text Stream
DirtyCOW Exploit (Linux Kernel version from 2.6.22 to 3.9)
Oracle Enumeration TNS Listener (port 1521)
Buffer Overflow Bad Chars
JS Meterpreter Payload
Compile on Linux for Windows x86
From MSSQL Injection to RCE
Windows Kernel Vulnerabilities Finder - Sherlock (PowerShell)
PowerShell one-liners (incl. file transfers)
Much Better PowerShell Reverse Shell One-Liner
Post-Exploitation Enumerate all users of Domain
Windows XP SP0/SP1 Privilege Escalation:
SUID Flag on /usr/bin/cp command Privilege Escalation
Writable /etc/passwd Privilege Escalation
Bypass robots.txt "You are not a search engine. Permission denied."
ShellShock PHP < 5.6.2
Privilege Escalation through SeImpersonatePrivilege permission (JuicyPotato)
Memcached Pentest & Enumeration
Tunneling Post-Exploitation (PortForwarding) through Chisel
Active Directory Users & Groups Enumeration
Tunelling on Windows
Windows Architecture and Version
Windows Service Start Mode
Windows check permissions over a file/executable with 'icacls'
Powershell Running Services
Client-Side .hta (HTML-based Internet Explorer only) Code Execution
Fingerprinting Client-Side Victim
Scan Security Headers
PowerShell to retrieve Active Directory objects (including deleted)
Decode LDAP Passwords
mysql command line alternative
TTY Shell that works almost every time on Linux
Kerberos check for valid usernames or bruteforce user/pass with kerbrute
Crawls web pages for keywords
TeamViewer Privilege Escalation -> CVE-2019-189888
PowerShell Reverse Shell
Wget Alternative for Windows in PowerShell
CVE-2019-10-15 Sudo < 1.2.28 Privilege Escalation
Adminer Database Management Tool Exploit Bypass Login
Alternate data streams of empty or incomplete file on SMB
SMB Recursively List Files
Telnet > Netcat
/etc/update-motd.d Privilege Escalation
SSH into Victim without password
Really Good Privilege Escalation Scripts
XMPP Authentication Crack
CTF Docs
Test for LDAP NULL BIND
Extract VBA Script from document
Decode Rubber Ducky USB .bin payloads
Crack Android lockscreen from system files (gesture.key)
XOR Analysis
Cryptanalysis
RSA Cracking Tools
Morse Code Audio Decode
Text to 21 Common Ciphers
Crypto Example Challs
Shift in Python
Predict encoding type
Get data, process and respond over a socket
Extract domain names & hosts from PCAP
Manual UNION SQLite Injection
SQL Injection Little Tips
Manual UNION SQL Injection
Known Plaintext ZIP
Python Functions
PHP Functions
PHP Jail Escape
XPATH Dump
LFI Retrieve File without executing it
Useful PCAP Reader
ZIP Format Signatures
JWT KID Value Exploitation
Blind XXE to SSRF
Hidden terminal input history
Search file by name pattern
Search string
Check SUDO privileges/rights
Last updated