vosNET - Cyber's new GitHub repository now online! Here you can find any custom code that may get written up and all of the Hack The Box write-ups will be put here in handy Markdown format.
#GitHub#HTB#hacking#CyberSecurity#infosec#CyberKnowledge
Linux users can use bracket expansion in BASH to speed up tasks, such as moving different types of files from one place to another. For example:
mv {<source>} <destination>
mv {*.exe,*.pdf,file1,file2} ../
#CyberKnowledge#TipOfTheWeek#CyberSecurity#Hacking
Windows has its own packet capture software built in. If you want to view the capture in Wireshark convert the output with the following command:
pktmon etl2pcap <filename.etl> --out <filename.pcap>
#CyberKnowledge#TipOfTheWeek#CyberSecurity#Hacking
Windows has its own packet capture software built in but by default it only captures the first 128 bytes. To record the whole packet use the following command:
pktmon start -c --pkt-size 0
#CyberKnowledge#TipOfTheWeek#CyberSecurity#Hacking
When using BurpSuite web HTTP proxy to inspect your web traffic, you can easily send a request to the repeater function with the shortcut 'ctrl+r'. Jump straight to the repeater tab with the shortcut 'shift+ctrl+r'
#CyberKnowledge#TipOfTheWeek#CyberSecurity#Hacking
When querying a MySQL database on the command line, you can make the out put of your query easier to read using the \G flag at the end of the query string. For example:
select * from users\G
#CyberKnowledge#TipOfTheWeek#CyberSecurity#Hacking
Found a host exposing a Network File System (NFS) endpoint on a network?
Linux users can list the exported shares using the showmount command:
showmount -e <host IP addr>
#CyberKnowledge#TipOfTheWeek#CyberSecurity#Hacking
When enumerating a Linux host sometimes it's a good idea to check all permissions on a file or directory for hidden permissions. Do this with the following:
getfacl <dir/filename>
#CyberKnowledge#TipOfTheWeek#CyberSecurity#Hacking
Linux users can transfer files quickly using NetCat by directing files into and out of the command.
On receiving host:
nc -lnvp [port #] > filename
On sending host:
nc [ip receiving host]:[port #] < filename
#CyberKnowledge#TipOfTheWeek#CyberSecurity#Hacking
Ever needed to download multiple files from a webserver using a command line tool such as WGET and had to make a request per file? Speed this up by including each file in a single command:
wget <URL>/{<file1>,<file2>}
#CyberKnowledge#TipOfTheWeek#CyberSecurity#Hacking
I just pwned Horizontall in Hack The Box! Another "Easy" box completed. I'll release my walk-through when the box retires. If you need any tips or hints drop me a message.
https://t.co/eseVYcCrZL #hackthebox#htb#cybersecurity
After gaining a foothold on a Linux attackers will want to look through the .bash_history file for any sensitive data. Prevent this from happening by permanently directing history to /dev/null with the following command: ln /dev/null ~/.bash_history -sf
#CyberKnowledge#Hacking
I just pwned BountyHunter in Hack The Box! Another "Easy" box to complete. I'll release my walkthrough when the box retires. If you need any tips or hint drop me a message. https://t.co/fZNf6usmiU #hackthebox#htb#cybersecurity
Ever needed to compare the contents of two similar files for where they differ? Linux users can use 'Diff' on the command line to do just that:
diff -y <filename 1> <filename 2>
Use the -y flag to view the file contents in two columns.
#TipOfTheWeek#CyberSecurity#Hacking
I just pwned Knife in Hack The Box!
Another easy box completed. This one isn't too hard to complete, full walkthrough will be posted at https://t.co/YtcllV7bh6 when the box is retired. https://t.co/ARV4GpewUT #hackthebox#htb#cybersecurity
Sometimes you need to spin up a webserver that can execute PHP. Not a problem for Linux users. Use the following command:
php -S <listen address>:<port number>
e.g. sudo php -S 0.0.0.0:80
#CyberKnowledge#TipOfTheWeek#CyberSecurity#Hacking