mirror of
https://github.com/carlospolop/hacktricks
synced 2024-11-15 01:17:36 +00:00
GitBook: [#3031] No subject
This commit is contained in:
parent
0048bea4ee
commit
df0522161a
1 changed files with 21 additions and 20 deletions
|
@ -2,7 +2,7 @@
|
|||
|
||||
## BlueTeam
|
||||
|
||||
* [https://github.com/yarox24/attack\_monitor](https://github.com/yarox24/attack_monitor)
|
||||
* [https://github.com/yarox24/attack\_monitor](https://github.com/yarox24/attack\_monitor)
|
||||
* [https://capsule8.com/blog/dont-get-kicked-out-a-tale-of-rootkits-and-other-backdoors/](https://capsule8.com/blog/dont-get-kicked-out-a-tale-of-rootkits-and-other-backdoors/)
|
||||
* [https://github.com/ION28/BLUESPAWN](https://github.com/ION28/BLUESPAWN)
|
||||
* [https://github.com/PaperMtn/lil-pwny](https://github.com/PaperMtn/lil-pwny) : Check disclosed accounts
|
||||
|
@ -11,10 +11,10 @@
|
|||
## OSINT
|
||||
|
||||
* [https://github.com/3vangel1st/kamerka](https://github.com/3vangel1st/kamerka)
|
||||
* [https://github.com/BullsEye0/google\_dork\_list](https://github.com/BullsEye0/google_dork_list)
|
||||
* [https://github.com/BullsEye0/google\_dork\_list](https://github.com/BullsEye0/google\_dork\_list)
|
||||
* [https://github.com/highmeh/lure](https://github.com/highmeh/lure)
|
||||
* [https://www.shodan.io/](https://www.shodan.io/)
|
||||
* [https://censys.io/](https://censys.io/)
|
||||
* [https://www.shodan.io/](https://www.shodan.io)
|
||||
* [https://censys.io/](https://censys.io)
|
||||
* [https://viz.greynoise.io/table](https://viz.greynoise.io/table)
|
||||
* [https://www.zoomeye.org](https://www.zoomeye.org)
|
||||
* [https://fofa.so](https://fofa.so)
|
||||
|
@ -23,9 +23,9 @@
|
|||
* [https://hunter.io](https://hunter.io)
|
||||
* [https://wigle.net](https://wigle.net)
|
||||
* [https://ghostproject.fr](https://ghostproject.fr)
|
||||
* [https://www.oshadan.com/](https://www.oshadan.com/)
|
||||
* [https://builtwith.com/](https://builtwith.com/)
|
||||
* [https://www.spiderfoot.net/](https://www.spiderfoot.net/)
|
||||
* [https://www.oshadan.com/](https://www.oshadan.com)
|
||||
* [https://builtwith.com/](https://builtwith.com)
|
||||
* [https://www.spiderfoot.net/](https://www.spiderfoot.net)
|
||||
* [https://github.com/zricethezav/gitleaks](https://github.com/zricethezav/gitleaks)
|
||||
* [https://www.nmmapper.com/sys/tools/subdomainfinder/](https://www.nmmapper.com/sys/tools/subdomainfinder/) : 8 Subdomain finder tools, sublist3r, amass and more
|
||||
|
||||
|
@ -47,22 +47,22 @@
|
|||
* [https://github.com/TypeError/Bookmarks/blob/master/README.md](https://github.com/TypeError/Bookmarks/blob/master/README.md) : BurpExtension to avoid dozens repeater tabs
|
||||
* [https://github.com/hakluke/hakrawler](https://github.com/hakluke/hakrawler) : Obtain assets
|
||||
* [https://github.com/izo30/google-dorker](https://github.com/izo30/google-dorker) : Google dorks
|
||||
* [https://github.com/sehno/Bug-bounty/blob/master/bugbounty\_checklist.md](https://github.com/sehno/Bug-bounty/blob/master/bugbounty_checklist.md) : Web BugBounty checklist
|
||||
* [https://github.com/sehno/Bug-bounty/blob/master/bugbounty\_checklist.md](https://github.com/sehno/Bug-bounty/blob/master/bugbounty\_checklist.md) : Web BugBounty checklist
|
||||
* [https://github.com/Naategh/dom-red](https://github.com/Naategh/dom-red) : Check a list of domain against Open Redirection
|
||||
* [https://github.com/prodigysml/Dr.-Watson](https://github.com/prodigysml/Dr.-Watson) : Burp plugin, offline analysis to discover domains, subdomains and IPs
|
||||
* [https://github.com/hahwul/WebHackersWeapons](https://github.com/hahwul/WebHackersWeapons): List of different tools
|
||||
* [https://github.com/gauravnarwani97/Trishul](https://github.com/gauravnarwani97/Trishul) : BurpSuite Plugingto find vulns \(SQLi, XSS, SSTI\)
|
||||
* [https://github.com/gauravnarwani97/Trishul](https://github.com/gauravnarwani97/Trishul) : BurpSuite Plugingto find vulns (SQLi, XSS, SSTI)
|
||||
* [https://github.com/fransr/postMessage-tracker](https://github.com/fransr/postMessage-tracker) : Chrome extension for tracking post-messages functions
|
||||
* [https://github.com/Quitten/Autorize](https://github.com/Quitten/Autorize) : Automatic authentication tests \(remove cookies and try to send the request\)
|
||||
* [https://github.com/pikpikcu/xrcross](https://github.com/pikpikcu/xrcross): XRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test \(XSS\|SSRF\|CORS\|SSTI\|IDOR\|RCE\|LFI\|SQLI\) vulnerabilities
|
||||
* [https://github.com/Quitten/Autorize](https://github.com/Quitten/Autorize) : Automatic authentication tests (remove cookies and try to send the request)
|
||||
* [https://github.com/pikpikcu/xrcross](https://github.com/pikpikcu/xrcross): XRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test (XSS|SSRF|CORS|SSTI|IDOR|RCE|LFI|SQLI) vulnerabilities
|
||||
|
||||
## Windows
|
||||
|
||||
* [https://github.com/Mr-Un1k0d3r/PoisonHandler](https://github.com/Mr-Un1k0d3r/PoisonHandler) : Lateral movements
|
||||
* [https://freddiebarrsmith.com/trix/trix.html](https://freddiebarrsmith.com/trix/trix.html) : LOL bins
|
||||
* [https://gist.github.com/netbiosX/ee35fcd3722e401a38136cff7b751d79](https://gist.github.com/netbiosX/ee35fcd3722e401a38136cff7b751d79) \([https://pentestlab.blog/2020/01/13/persistence-image-file-execution-options-injection/](https://pentestlab.blog/2020/01/13/persistence-image-file-execution-options-injection/)\): Persistence
|
||||
* [https://github.com/odzhan/injection](https://github.com/odzhan/injection) : Windows Process Injection techniques
|
||||
* [https://github.com/BankSecurity/Red\_Team](https://github.com/BankSecurity/Red_Team) : Red Team scripts
|
||||
* [https://gist.github.com/netbiosX/ee35fcd3722e401a38136cff7b751d79](https://gist.github.com/netbiosX/ee35fcd3722e401a38136cff7b751d79) ([https://pentestlab.blog/2020/01/13/persistence-image-file-execution-options-injection/](https://pentestlab.blog/2020/01/13/persistence-image-file-execution-options-injection/)): Persistence
|
||||
* [https://github.com/odzhan/injection](https://github.com/odzhan/injection) : Windows Process Injection techniques 
|
||||
* [https://github.com/BankSecurity/Red\_Team](https://github.com/BankSecurity/Red\_Team) : Red Team scripts
|
||||
* [https://github.com/l0ss/Grouper2](https://github.com/l0ss/Grouper2) : find security-related misconfigurations in Active Directory Group Policy.
|
||||
* [https://www.wietzebeukema.nl/blog/powershell-obfuscation-using-securestring](https://www.wietzebeukema.nl/blog/powershell-obfuscation-using-securestring) : Securestring obfuscation
|
||||
* [https://pentestlab.blog/2020/02/24/parent-pid-spoofing/](https://pentestlab.blog/2020/02/24/parent-pid-spoofing/) : Parent PID Spoofing
|
||||
|
@ -74,10 +74,10 @@
|
|||
|
||||
## Firmware
|
||||
|
||||
Tools q veo q pueden molar para analizar firmares \(automaticas\):
|
||||
Tools q veo q pueden molar para analizar firmares (automaticas):
|
||||
|
||||
* [https://github.com/craigz28/firmwalker](https://github.com/craigz28/firmwalker)
|
||||
* [https://github.com/fkie-cad/FACT\_core](https://github.com/fkie-cad/FACT_core)
|
||||
* [https://github.com/fkie-cad/FACT\_core](https://github.com/fkie-cad/FACT\_core)
|
||||
* [https://gitlab.com/bytesweep/bytesweep-go](https://gitlab.com/bytesweep/bytesweep-go)
|
||||
|
||||
Post-crema:
|
||||
|
@ -91,6 +91,8 @@ Aqui un firware con vulnerabilidades para analizar: [https://github.com/scriptin
|
|||
|
||||
y por aqui la metodologia owasp para analizar firmware: [https://github.com/scriptingxss/owasp-fstm](https://github.com/scriptingxss/owasp-fstm)
|
||||
|
||||
Firmware emulation: FIRMADYNE (https://github.com/firmadyne/firmadyne/) is a platform for automating the emulation and dynamic analysis of Linux-based firmware.
|
||||
|
||||
## OTHER
|
||||
|
||||
* [https://twitter.com/HackAndDo/status/1202695084543791117](https://twitter.com/HackAndDo/status/1202695084543791117)
|
||||
|
@ -101,15 +103,14 @@ y por aqui la metodologia owasp para analizar firmware: [https://github.com/scri
|
|||
* [https://www.hackerdecabecera.com/2019/12/blectf-capture-flag-en-formato-hardware.html](https://www.hackerdecabecera.com/2019/12/blectf-capture-flag-en-formato-hardware.html) : Bluetooth LE CTF
|
||||
* [https://github.com/skeeto/endlessh](https://github.com/skeeto/endlessh) : SSH tarpit that slowly sends an endless banner.
|
||||
* AWS and Cloud tools: [https://github.com/toniblyx/my-arsenal-of-aws-security-tools](https://github.com/toniblyx/my-arsenal-of-aws-security-tools)
|
||||
* IFS \(Interplanetary File System\) for phising: [https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/using-the-interplanetary-file-system-for-offensive-operations/](https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/using-the-interplanetary-file-system-for-offensive-operations/)
|
||||
* IFS (Interplanetary File System) for phising: [https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/using-the-interplanetary-file-system-for-offensive-operations/](https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/using-the-interplanetary-file-system-for-offensive-operations/)
|
||||
* IP rotation services: [https://medium.com/@lokeshdlk77/how-to-rotate-ip-address-in-brute-force-attack-e66407259212](https://medium.com/@lokeshdlk77/how-to-rotate-ip-address-in-brute-force-attack-e66407259212)
|
||||
* Linux rootkit: [https://github.com/aesophor/satanic-rootkit](https://github.com/aesophor/satanic-rootkit)
|
||||
* [https://theia-ide.org/](https://theia-ide.org/) : Online IDE
|
||||
* [https://theia-ide.org/](https://theia-ide.org) : Online IDE
|
||||
* [https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters/](https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters/) : Resources for starting on BugBounties
|
||||
* [https://medium.com/macoclock/jailbreak-and-stuff-kickstart-tools-and-techniques-for-ios-application-pentesting-6fa53a3987ab](https://medium.com/macoclock/jailbreak-and-stuff-kickstart-tools-and-techniques-for-ios-application-pentesting-6fa53a3987ab) : IOS pentesting tools
|
||||
* [https://github.com/random-robbie/keywords/blob/master/keywords.txt](https://github.com/random-robbie/keywords/blob/master/keywords.txt) : Keywords
|
||||
* [https://github.com/ElevenPaths/HomePWN](https://github.com/ElevenPaths/HomePWN) : Hacking IoT \(Wifi, BLE, SSDP, MDNS\)
|
||||
* [https://github.com/ElevenPaths/HomePWN](https://github.com/ElevenPaths/HomePWN) : Hacking IoT (Wifi, BLE, SSDP, MDNS)
|
||||
* [https://github.com/rackerlabs/scantron](https://github.com/rackerlabs/scantron) : automating scanning
|
||||
* [https://github.com/doyensec/awesome-electronjs-hacking](https://github.com/doyensec/awesome-electronjs-hacking) : This list aims to cover Electron.js security related topics.
|
||||
* [https://github.com/serain/bbrecon](https://github.com/serain/bbrecon) : Info about BB programs
|
||||
|
||||
|
|
Loading…
Reference in a new issue