This commit is contained in:
Hadi
2026-08-28 11:45:23 +02:00
commit 54fed22b8b
28 changed files with 1884 additions and 0 deletions
+1
View File
@@ -0,0 +1 @@
use flake
+10
View File
@@ -0,0 +1,10 @@
# Contributing
Everybody is invited and welcome to contribute. There is a lot to do... Check the issues!
The process is straight-forward.
- Read [How to get faster PR reviews](https://github.com/kubernetes/community/blob/master/contributors/guide/pull-requests.md#best-practices-for-faster-reviews) by Kubernetes (but skip step 0 and 1)
- Fork this git repository
- Write your changes (bug fixes, new features, ...).
- Create a Pull Request against the main branch.
+1
View File
@@ -0,0 +1 @@
ko_fi: anotherhadi
+39
View File
@@ -0,0 +1,39 @@
#!/usr/bin/env python3
import re
import subprocess
from pathlib import Path
REPO_ROOT = Path(__file__).resolve().parents[2]
SKIP_DIRS = {".git", ".direnv", ".github"}
TOC_PLACEHOLDER_RE = re.compile(r"\[toc\]", re.IGNORECASE)
TOC_START = "<!-- START doctoc generated TOC please keep comment here to allow auto update -->"
TOC_END = "<!-- END doctoc generated TOC please keep comment here to allow auto update -->"
def find_markdown_files():
for path in sorted(REPO_ROOT.rglob("*.md")):
if not SKIP_DIRS.isdisjoint(path.relative_to(REPO_ROOT).parts):
continue
yield path
def has_toc_markers(path):
text = path.read_text()
if TOC_START in text:
return True
if TOC_PLACEHOLDER_RE.search(text):
text = TOC_PLACEHOLDER_RE.sub(f"{TOC_START}\n{TOC_END}", text, count=1)
path.write_text(text)
return True
return False
def main():
for md_file in find_markdown_files():
if has_toc_markers(md_file):
subprocess.run(["doctoc", "--notitle", str(md_file)], check=True)
if __name__ == "__main__":
main()
+75
View File
@@ -0,0 +1,75 @@
#!/usr/bin/env python3
import re
from pathlib import Path
REPO_ROOT = Path(__file__).resolve().parents[2]
README = REPO_ROOT / "README.md"
SKIP_DIRS = {".git", ".github", ".direnv"}
SECTION_TITLE_OVERRIDES = {"osint": "OSINT"}
FRONTMATTER_RE = re.compile(r"^---\n(.*?\n)---\n", re.DOTALL)
FIELD_RE = re.compile(r'^(\w+):\s*"?(.*?)"?\s*$')
TOC_START = "<!-- START doctoc generated TOC please keep comment here to allow auto update -->"
TOC_END = "<!-- END doctoc generated TOC please keep comment here to allow auto update -->"
def existing_toc_block():
if README.exists():
text = README.read_text()
if TOC_START in text and TOC_END in text:
start = text.index(TOC_START)
end = text.index(TOC_END) + len(TOC_END)
return text[start:end]
return "[toc]"
def parse_frontmatter(path):
text = path.read_text()
match = FRONTMATTER_RE.match(text)
if not match:
return {}
fields = {}
for line in match.group(1).splitlines():
field_match = FIELD_RE.match(line)
if field_match:
fields[field_match.group(1)] = field_match.group(2)
return fields
def section_title(dirname):
return SECTION_TITLE_OVERRIDES.get(dirname, dirname.capitalize())
def build_section(directory):
lines = [f"## {section_title(directory.name)}", ""]
for md_file in sorted(directory.glob("*.md")):
fields = parse_frontmatter(md_file)
title = fields.get("title", md_file.stem)
description = fields.get("description", "")
rel_path = f"./{directory.name}/{md_file.name}"
lines.append(f"- [{title}]({rel_path}): {description}")
lines.append("")
return lines
def main():
directories = sorted(
d
for d in REPO_ROOT.iterdir()
if d.is_dir() and d.name not in SKIP_DIRS and any(d.glob("*.md"))
)
lines = [
"# Sec Notes",
"",
existing_toc_block(),
"",
]
for directory in directories:
lines.extend(build_section(directory))
README.write_text("\n".join(lines).rstrip("\n") + "\n")
if __name__ == "__main__":
main()
+2
View File
@@ -0,0 +1,2 @@
.pre-commit-config.yaml
.direnv/
+21
View File
@@ -0,0 +1,21 @@
MIT License
Copyright (c) 2026 Hadi
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
+45
View File
@@ -0,0 +1,45 @@
# Sec Notes
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Blog](#blog)
- [Linux](#linux)
- [Network](#network)
- [OSINT](#osint)
- [Web](#web)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
## Blog
- [The Password is 'admin': Why Default Credentials Are Still Breaking the Internet](./blog/default-passwords.md): Default credentials like admin:admin remain one of the most exploited vulnerabilities on the internet. Learn why they're dangerous, how the Mirai botnet took down half the web with just 62 passwords, and how to protect your infrastructure: plus introducing default-creds, an open-source database to look up factory-set credentials in seconds.
- [Unmasking Github Users: How to Identify the Person Behind Any Github Profile](./blog/github-users-osint.md): Ever wondered who is behind a specific Github username? This guide covers advanced OSINT techniques to deanonymize users, find hidden email addresses, and link Github accounts to real-world identities.
## Linux
- [GRUB Boot Bypass](./linux/grub-bypass.md): Physical access techniques to get a root shell by editing GRUB boot parameters.
- [Linux Privilege Escalation](./linux/privesc.md): Common misconfigurations and weaknesses to check when escalating privileges on Linux.
## Network
- [FTP](./network/ftp.md): Enumeration, exploitation and post-exploitation techniques for FTP servers.
- [NFS](./network/nfs.md): Enumeration, mounting and privilege escalation techniques for NFS shares.
- [Nmap](./network/nmap.md): Host discovery, port scanning, service detection and NSE scripting
- [RDP](./network/rdp.md): Enumeration, exploitation and post-exploitation techniques for RDP servers.
- [SSH](./network/ssh.md): Enumeration, exploitation and post-exploitation techniques for SSH servers.
- [Telnet](./network/telnet.md): Enumeration, exploitation and post-exploitation techniques for Telnet servers.
## OSINT
- [Bluesky](./osint/bluesky.md): Enumeration, search operators, API endpoints and tools for investigating Bluesky accounts.
- [Information Gathering](./osint/information-gathering.md): Essential cybersecurity cheatsheet for Information Gathering and Open Source Intelligence (OSINT). Discover data related to emails, domains, usernames, and images using both command line and online tools.
- [Sock Puppets](./osint/sock-puppets.md): Essential cheatsheet on creating and managing Sock Puppets (fake identities) for ethical security research and Open Source Intelligence (OSINT), focusing on maintaining separation from personal data and bypassing common verification.
- [Tips](./osint/tips.md): A cheatsheet of practical tips and unconventional methods for Open Source Intelligence (OSINT), focusing on advanced data visualization, information leakage detection, and utilizing web archives for historical data.
- [X / Twitter](./osint/twitter-x.md): Enumeration, search operators, deleted content recovery and tools for investigating X accounts.
## Web
- [Directory Discovery](./web/directory-discovery.md): Techniques and tools for discovering hidden directories and files on web servers.
- [FFUF](./web/ffuf.md): Reference and usage examples for ffuf, a fast web fuzzer for directories, endpoints and subdomains.
- [Subdomains Discovery](./web/subdomains-discovery.md): Methods and tools for enumerating subdomains of a target domain.
+69
View File
@@ -0,0 +1,69 @@
---
title: "The Password is 'admin': Why Default Credentials Are Still Breaking the Internet"
description: "Default credentials like admin:admin remain one of the most exploited vulnerabilities on the internet. Learn why they're dangerous, how the Mirai botnet took down half the web with just 62 passwords, and how to protect your infrastructure: plus introducing default-creds, an open-source database to look up factory-set credentials in seconds."
image: "../../../public/images/blog/default-passwords.png"
tags: ["botnet", "passwords", "cybersecurity"]
publishDate: "2026-03-13"
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [What are default credentials?](#what-are-default-credentials)
- [Real-world impact](#real-world-impact)
- [Best practices & solutions](#best-practices--solutions)
- [For users & sysadmins](#for-users--sysadmins)
- [For developers](#for-developers)
- [How to contribute](#how-to-contribute)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
## What are default credentials?
When a manufacturer ships a router, a camera, or a piece of software, it needs to be accessible out of the box. To make **setup easier**, they pre-configure it with a username and password, often something simple like admin/admin or root/password. These are called **default credentials**.
_The problem?_ Most users never change them. Whether out of convenience, lack of awareness, or simply because the service "works fine as-is", these factory-set credentials often remain active long after deployment.. turning a minor convenience into a serious **security hole**.
To help security researchers and pentesters quickly identify these exposure points, I built **[default-creds](https://default-creds.hadi.icu)**. It's an open-source, community-driven database of default credentials. Just search for a device or service, and you'll instantly get its known factory-set username and password. It also comes with a public API, documented at [default-creds.hadi.icu/api-docs](https://default-creds.hadi.icu/api-docs).
## Real-world impact
The consequences of unchanged default credentials aren't theoretical: they've already broken the internet, literally.
In the fall of 2016, a piece of malware called **Mirai** quietly scanned the internet for IoT devices still running their factory-set credentials. Using a list of just 62 common default username/password combinations like `admin:admin` or `root:password`, it managed to enslave over 380,000 devices (mostly routers, IP cameras, DVRs, ...) and turning them into an army.
On September 20, 2016, Brian Krebs' security blog was hit with a DDoS attack exceeding 620 Gbps, one of the largest ever recorded at the time. Then came the attack on French web host OVH, which broke that record. And then, in October 2016, Mirai took down **Dyn** (a major DNS provider) causing disruptions to Twitter, Spotify, Amazon, Netflix, GitHub, and PayPal, among others, with attacks reportedly peaking at 1 Tbps.
All of this, enabled by `admin:admin`.
Mirai wasn't a sophisticated zero-day exploit. It was a dictionary of 62 passwords. The attack surface wasn't a vulnerability in the code; it was human laziness at scale.
The original Mirai and its early variants launched approximately 20,000 DDoS attacks between late 2016 and early 2017. And even though its creators were eventually arrested, the source code lives on, having spawned numerous variants that continue to operate today.
Default credentials aren't just a consumer problem. Enterprises, developers, and sysadmins are equally exposed; From home routers and IP cameras to network switches, firewalls, and self-hosted services like Grafana, Redis, or Jenkins. If it has a login screen and was deployed without changing the defaults, it's a target.
## Best practices & solutions
### For users & sysadmins
1. **Change default credentials immediately.** The moment you deploy a new device or service, changing the default username and password should be the first thing you do; before it ever touches a production network.
2. **Use strong, unique passwords.** Replacing `admin:admin` with `admin:admin123` doesn't count. Use a password manager to generate and store proper credentials for each service.
3. **Audit your infrastructure.** You can't fix what you don't know about. Regularly scan your own systems for services still running on default credentials: this is exactly the kind of task [default-creds](https://default-creds.hadi.icu/) is built for.
### For developers
1. **Never ship with hardcoded default credentials.** A default password baked into your codebase is a vulnerability waiting to be exploited (and it will end up in databases like [default-creds](https://default-creds.hadi.icu) :p )
2. **Force a password change on first launch.** If your software needs a default to function, make it temporary. Block access until the user has set their own credentials.
3. **Generate a random password instead.** Even better: skip the default entirely. Generate a strong, unique password at install time and print it once in the console or the setup logs. The user still should change this password.
## How to contribute
**default-creds** is only as useful as its data. If you know a device or service that's missing from the database, contributing is straightforward. The project is open-source on [GitHub](https://github.com/anotherhadi/default-creds) under the MIT license, and contributions are made via Pull Requests by adding simple YAML definitions.
The full contribution guide is available in the [CONTRIBUTING.md](https://github.com/anotherhadi/default-creds/blob/main/CONTRIBUTING.md).
---
If you enjoyed this guide, please like and share it! Your support helps me create more infosec & OSINT content.
Have questions or feedback? Feel free to reach out: anotherhadi.clapped234[at]passmail.net
+154
View File
@@ -0,0 +1,154 @@
---
title: "Unmasking Github Users: How to Identify the Person Behind Any Github Profile"
description: "Ever wondered who is behind a specific Github username? This guide covers advanced OSINT techniques to deanonymize users, find hidden email addresses, and link Github accounts to real-world identities."
image: "../../../public/images/blog/github-osint-users.png"
tags: ["osint", "github", "cybersecurity"]
publishDate: "2026-01-01"
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Level 1: The Low-Hanging Fruit](#level-1-the-low-hanging-fruit)
- [Level 2: Digging into Commits](#level-2-digging-into-commits)
- [The `.patch` Method](#the-patch-method)
- [The API Events Method](#the-api-events-method)
- [The Verification Loop: Linking Email to Account](#the-verification-loop-linking-email-to-account)
- [The Email Spoofing Method](#the-email-spoofing-method)
- [The Search Index: Finding Hidden Contributions](#the-search-index-finding-hidden-contributions)
- [Level 3: Technical Metadata](#level-3-technical-metadata)
- [SSH Keys](#ssh-keys)
- [GPG Keys](#gpg-keys)
- [Level 4: Connecting the Dots](#level-4-connecting-the-dots)
- [Automating the Hunt: Github-Recon](#automating-the-hunt-github-recon)
- [Conclusion and Protection: How to Stay Anonymous](#conclusion-and-protection-how-to-stay-anonymous)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
In the world of Open-Source Intelligence (OSINT), we often focus on social media platforms like Twitter or LinkedIn. However, developers frequently leave behind much more detailed personal information on **Github**.
Whether you are a recruiter, a security researcher, or a digital investigator, Github is a goldmine. Why? Because while a user might choose a cryptic handle like `anotherhadi`, their Git configuration often reveals their real name and email address.
## Level 1: The Low-Hanging Fruit
Before diving into technical exploits, start with the obvious. Many users forget how much they have shared in their profile settings.
- **The Bio & Location**: Even a vague location like "Montpellier, France," combined with a niche tech stack (e.g., "COBOL expert"), significantly narrows down the search.
- **External Links**: Check the personal website or blog link. Run a WHOIS lookup on that domain to find registration details. Use other OSINT tools and techniques on those websites to pivot further.
- **The Profile Picture**: Right-click the avatar and use Google Reverse Image Search, Yandex, or other reverse image engines. Developers often use the same professional headshot on Github as they do on LinkedIn.
## Level 2: Digging into Commits
This is the **most effective OSINT** method. While Github masks author names and emails in the web view, this information is permanently embedded in the commit metadata.
### The `.patch` Method
Find a repository where the target has contributed. Open any commit they made, and simply add `.patch` to the end of the URL.
- **URL**: `https://github.com/{username}/{repo}/commit/{commit_hash}.patch`
- Look at the `From:` line. It should look like this: `From: John Doe <[email protected]>`
For example, check: [github.com/anotherhadi/nixy/commit/e6873e8caae491073d8ab7daad9d2e50a04490ce.patch](https://github.com/anotherhadi/nixy/commit/e6873e8caae491073d8ab7daad9d2e50a04490ce.patch)
### The API Events Method
If you cannot find a recent commit, check their **public activity** stream via the Github API.
- **Go to**: `https://api.github.com/users/{target_username}/events/public`
- Search (Ctrl+F) for the word `email`. You will often find the **email address** associated with their `PushEvent` headers, even if they have "Keep my email addresses private" enabled in their current settings.
## The Verification Loop: Linking Email to Account
If you have found an email address and want to be 100% sure it belongs to a specific Github profile, you can use Github’s own attribution engine against itself.
### The Email Spoofing Method
While the previous methods help you find an email _from_ a profile, this technique does the opposite: it identifies which Github account is linked to a specific email address.
**How it works:**
Github attributes commits based on the email address found in the Git metadata. If you push a commit using a specific email, Github will automatically link that commit to the account associated with that address as its **primary email**.
**The Process:**
1. **Initialize a local repo:** `git init investigation`
2. **Configure the target email:** `git config user.email "[email protected]"` and `git config user.name "A Username"`
3. **Create a dummy commit:** `echo "test" > probe.txt && git add . && git commit -m "Probe"`
4. **Push to a repo you own:** Create a new empty repository on your Github account and push the code there.
5. **Observe the result:** Go to the commit history on the Github web interface. The avatar and username of the account linked to that email will appear as the author of the commit.
> **Note:** This method only works if the target email is set as the **Primary Email** on the user's account. It is a foolproof way to confirm if an email address you found elsewhere belongs to a specific Github user.
### The Search Index: Finding Hidden Contributions
Even if an email address is not listed on a user's profile, it may still be indexed within Github's global search.
Github allows you to filter search results by the metadata fields of a commit.
This is particularly useful if the target has **contributed to public repositories** using their real email.
You can use these specific qualifiers in the **Github search bar** (select the "Commits" tab):
- `author-email:[email protected]`: Finds commits where the target is the original author.
- `committer-email:[email protected]`: Finds commits where the target was the one who committed the code (sometimes different from the author).
## Level 3: Technical Metadata
If the email is masked or missing, we can look at the **cryptographic keys** the user uses to communicate with Github.
### SSH Keys
Every user’s public **SSH keys are public**.
- **URL**: `https://github.com/{username}.keys`
- **The Pivot**: You can take the key string and search for it on platforms like **Censys** or **Shodan**. If that same key is authorized on a specific server IP, you have successfully located the user’s infrastructure.
### GPG Keys
If a user signs their commits, their **GPG key** is available at:
- **URL**: `https://github.com/{username}.gpg`
- **The Reveal**: Import this key into your local GPG tool (`gpg --import`). It will often reveal the **Verified Identity** and the primary email address linked to the encryption key.
## Level 4: Connecting the Dots
Once you have a **name**, an **email**, or a **unique username**, it’s time to _pivot_.
- **Username Pivoting**: Use tools like [Sherlock](https://github.com/sherlock-project/sherlock) or [Maigret](https://github.com/soxoj/maigret/) to search for the same username across hundreds of other platforms. Developers are creatures of habit; they likely use the same handle on Stack Overflow, Reddit, or even old gaming forums.
- **Email Pivoting**: Use tools like [holehe](https://github.com/megadose/holehe) to find other accounts registered with the email addresses you just uncovered.
## Automating the Hunt: Github-Recon
If you want to move from manual investigation to automated intelligence, check out [Github-Recon](https://github.com/anotherhadi/github-recon).
Written in Go, this powerful CLI tool aggregates public OSINT data by automating the techniques mentioned above and more. Whether you start with a username or a single email address, it can retrieve SSH/GPG keys, enumerate social accounts, and find "close friends" based on interactions.
Its standout features include a **Deep Scan** mode-which clones repositories to perform regex searches and TruffleHog secret detection—and an automated **Email Spoofing** engine that instantly identifies the account linked to any primary email address.
## Conclusion and Protection: How to Stay Anonymous
If you are a developer reading this, you might be feeling exposed.
Understanding what information about you is publicly visible is the **first step to managing your online presence**. This guide and tools like [github-recon](https://github.com/anotherhadi/github-recon) can help you identify your own publicly available data on Github. Here’s how you can take steps to protect your privacy and security:
- **Review your public profile**: Regularly check your Github profile and
repositories to ensure that you are not unintentionally exposing sensitive
information.
- **Manage email exposure**: Use Github's settings to control which email
addresses are visible on your profile and in commit history. You can also **use
a no-reply email** address for commits, and an
[alias email](https://proton.me/support/addresses-and-aliases) for your
account. Delete/modify any sensitive information in your commit history.
- **Be Mindful of Repository Content**: **Avoid including sensitive information** in
your repositories, such as API keys, passwords, emails or personal data. Use
`.gitignore` to exclude files that contain sensitive information.
You can also use a tool like [TruffleHog](github.com/trufflesecurity/trufflehog)
to scan your repositories specifically for exposed secrets and tokens.
**Useful links:**
- [Blocking command line pushes that expose your personal email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/blocking-command-line-pushes-that-expose-your-personal-email-address)
- [No-reply email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/setting-your-commit-email-address)
In OSINT, the best hidden secrets are the ones we forget we ever shared. Happy hunting!
---
If you enjoyed this guide, please like and share it! Your support helps me create more infosec & OSINT content.
Have questions or feedback? Feel free to reach out: anotherhadi.clapped234[at]passmail.net
Generated
+65
View File
@@ -0,0 +1,65 @@
{
"nodes": {
"flake-compat": {
"flake": false,
"locked": {
"lastModified": 1767039857,
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "NixOS",
"repo": "flake-compat",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "flake-compat",
"type": "github"
}
},
"git-hooks": {
"inputs": {
"flake-compat": "flake-compat",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1787424939,
"narHash": "sha256-O2tBn84NNuHrnqNVxx/XqsXwfYvS1YwBh+7CBnbCYsk=",
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "809414f0cdadf82cf11b06c2b29ba9b3168b3297",
"type": "github"
},
"original": {
"owner": "cachix",
"repo": "git-hooks.nix",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1787736819,
"narHash": "sha256-cV5xEJJK3BvhU8rEd4mC9UsmDi5qscv/kzGPhBRC5WA=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "9fbb54b33e91ee4ca368e35a78e0613c720600b3",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"root": {
"inputs": {
"git-hooks": "git-hooks",
"nixpkgs": "nixpkgs"
}
}
},
"root": "root",
"version": 7
}
+57
View File
@@ -0,0 +1,57 @@
{
description = "";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
git-hooks = {
url = "github:cachix/git-hooks.nix";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = {
self,
nixpkgs,
git-hooks,
}: let
supportedSystems = ["x86_64-linux" "aarch64-linux"];
forAllSystems = f:
nixpkgs.lib.genAttrs supportedSystems
(system: f system (import nixpkgs {inherit system;}));
in {
devShells = forAllSystems (system: pkgs: let
hooks = git-hooks.lib.${system}.run {
src = ./.;
hooks = {
gen-readme = {
enable = true;
name = "gen-readme";
entry = "python3 .github/scripts/gen-readme.py";
language = "system";
files = "\\.md$";
excludes = ["^\\.github/" "^README\\.md$"];
pass_filenames = false;
before = ["doctoc"];
};
doctoc = {
enable = true;
name = "doctoc";
entry = "python3 .github/scripts/doctoc-all.py";
language = "system";
files = "\\.md$";
excludes = ["^\\.github/"];
pass_filenames = false;
};
};
};
in {
default = pkgs.mkShell {
packages = with pkgs; [doctoc] ++ hooks.enabledPackages;
shellHook = hooks.shellHook;
};
});
};
}
+79
View File
@@ -0,0 +1,79 @@
---
title: "GRUB Boot Bypass"
description: "Physical access techniques to get a root shell by editing GRUB boot parameters."
tags: ["linux", "grub", "physical-access", "privesc"]
publishDate: 2026-05-18
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Techniques](#techniques)
- [init=/bin/sh](#initbinsh)
- [init=/bin/bash](#initbinbash)
- [rd.break (systemd)](#rdbreak-systemd)
- [single (single-user mode)](#single-single-user-mode)
- [systemd.unit=rescue.target](#systemdunitrescuetarget)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
When GRUB is not password-protected, anyone with physical access can edit boot parameters and bypass authentication entirely.
At the GRUB menu, press **`e`** to edit the selected entry. Modify the line starting with `linux`, then press **`F10`** to boot.
## Techniques
### init=/bin/sh
Replaces the init process with a shell; drops directly into a root shell before any login prompt.
```
linux ... init=/bin/sh
```
Filesystem is mounted read-only by default. Remount to make changes:
```bash
mount -o remount,rw /
```
### init=/bin/bash
Same as above but uses bash. Add `rw` on the `linux` line to mount read-write from the start:
```
linux ... rw init=/bin/bash
```
### rd.break (systemd)
Interrupts the boot process in the initramfs, before the real root filesystem is mounted. Useful for resetting the root password.
```
linux ... rd.break
```
From the initramfs shell:
```bash
mount -o remount,rw /sysroot
chroot /sysroot
passwd root
exit
```
### single (single-user mode)
Boots into maintenance mode. On some distros this drops to a root shell without a password prompt (not Debian/Ubuntu).
```
linux ... single
```
### systemd.unit=rescue.target
systemd equivalent of single-user mode: minimal services, root shell.
```
linux ... systemd.unit=rescue.target
```
+93
View File
@@ -0,0 +1,93 @@
---
title: "Linux Privilege Escalation"
description: "Common misconfigurations and weaknesses to check when escalating privileges on Linux."
tags: ["linux", "privesc", "post-exploitation"]
publishDate: 2026-05-18
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Sudo](#sudo)
- [SUID / SGID](#suid--sgid)
- [Misconfiguration](#misconfiguration)
- [Cron Jobs](#cron-jobs)
- [Capabilities](#capabilities)
- [Kernel Exploits](#kernel-exploits)
- [LinPEAS / WinPEAS](#linpeas--winpeas)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
## Sudo
```bash
sudo -l
```
Check [GTFOBins](https://gtfobins.github.io) for any listed binary.
If `env_keep+=LD_PRELOAD` is set:
```bash
# compile a shared lib that spawns a shell
gcc -fPIC -shared -o /tmp/shell.so shell.c -nostartfiles
sudo LD_PRELOAD=/tmp/shell.so <allowed_binary>
```
## SUID / SGID
```bash
find / -user root -perm -4000 -ls 2>/dev/null # SUID
find / -group root -perm -2000 -ls 2>/dev/null # SGID
```
Check any non-standard binary on GTFOBins.
## Misconfiguration
```bash
# World-writable directories
find / -type d -perm -2 -ls 2>/dev/null
# World-writable files owned by root
find / -user root -perm -2 ! -type l -ls 2>/dev/null
```
## Cron Jobs
```bash
cat /etc/crontab
ls -la /etc/cron.*
crontab -l
```
If a cron runs a script you can write to, replace its content:
```bash
echo 'chmod +s /bin/bash' >> /path/to/script.sh
```
If the cron uses a relative PATH and a directory is writable, drop a malicious binary earlier in `$PATH`.
## Capabilities
```bash
getcap -r / 2>/dev/null
```
Dangerous capabilities: `cap_setuid`, `cap_net_raw`, `cap_dac_override`.
Check [GTFOBins](https://gtfobins.github.io) for exploitation.
## Kernel Exploits
```bash
uname -r
searchsploit linux kernel $(uname -r)
```
## LinPEAS / WinPEAS
Automated enumeration scripts to surface privesc vectors quickly.
- [LinPEAS (linux)](https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS)
- [WinPEAS (windows)](https://github.com/peass-ng/PEASS-ng/tree/master/winPEAS)
+71
View File
@@ -0,0 +1,71 @@
---
title: "FTP"
description: "Enumeration, exploitation and post-exploitation techniques for FTP servers."
tags: ["ftp", "network", "service"]
publishDate: 2026-04-29
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Enumeration](#enumeration)
- [Banner grabbing](#banner-grabbing)
- [Nmap](#nmap)
- [Anonymous Login](#anonymous-login)
- [Brute Force](#brute-force)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
FTP runs on **port 21** (control) and uses a secondary data channel (port 20 for active, ephemeral port for passive).
Common implementations: vsftpd, ProFTPD, Pure-FTPd, FileZilla Server, IIS FTP.
## Enumeration
### Banner grabbing
```bash
nc -nv $IP 21
ftp $IP
```
The banner often reveals the software version: cross-reference with CVE databases.
### Nmap
```bash
nmap -sV -p 21 $IP
nmap -p 21 --script ftp-* $IP
```
Key scripts:
- `ftp-anon`: checks anonymous login
- `ftp-bounce`: tests for FTP bounce attack
- `ftp-brute`: brute-force credentials
- `ftp-syst`: retrieves system info
## Anonymous Login
```bash
ftp $IP
# Username: anonymous
# Password: <empty> or anonymous@
```
If allowed, list and download everything:
```bash
ls -la
mget *
```
Check for writable directories: you may be able to upload a webshell if FTP root overlaps with a web root.
## Brute Force
```bash
hydra -l $user -P ~/wordlists/rockyou.txt ftp://$IP
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M ftp
```
Try default credentials first: `admin:admin`, `ftp:ftp`, `user:password`.
+92
View File
@@ -0,0 +1,92 @@
---
title: "NFS"
description: "Enumeration, mounting and privilege escalation techniques for NFS shares."
tags: ["nfs", "network", "service"]
publishDate: 2026-05-18
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Enumeration](#enumeration)
- [Nmap](#nmap)
- [List shares](#list-shares)
- [Mount](#mount)
- [Privilege Escalation](#privilege-escalation)
- [no_root_squash](#no_root_squash)
- [UID spoofing](#uid-spoofing)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
NFS (Network File System) runs on **port 2049** and allows remote filesystem mounting over the network.
Common on Linux/Unix environments. Access control is defined in `/etc/exports` on the server.
## Enumeration
### Nmap
```bash
nmap -sV -p 111,2049 $IP
nmap -p 111,2049 --script nfs-* $IP
```
Key scripts:
- `nfs-showmount`: lists exported shares
- `nfs-ls`: lists files in shares
- `nfs-statfs`: retrieves disk stats
### List shares
```bash
showmount -e $IP
rpcinfo -p $IP
```
## Mount
```bash
mkdir /mnt/nfs
mount -t nfs $IP:/share /mnt/nfs
mount -t nfs -o vers=2 $IP:/share /mnt/nfs # force NFSv2
umount /mnt/nfs
```
## Privilege Escalation
### no_root_squash
If the share is exported with `no_root_squash`, the remote root user keeps root privileges on the share.
Check `/etc/exports` on the server (if readable):
```bash
cat /etc/exports
```
Look for:
```
/share *(rw,no_root_squash)
```
If present, copy a SUID binary onto the share as root from your attacker machine:
```bash
cp /bin/bash /mnt/nfs/bash
chmod +s /mnt/nfs/bash
```
Then execute it on the target with `-p` to keep the SUID effective UID:
```bash
/tmp/nfs/bash -p
```
### UID spoofing
NFS authenticates by UID. If you know a file is owned by UID 1001 on the server, impersonate it directly:
```bash
python3 -c "import os; os.setuid(1001); os.system('/bin/bash')"
```
+123
View File
@@ -0,0 +1,123 @@
---
title: "Nmap"
description: "Host discovery, port scanning, service detection and NSE scripting"
tags: ["nmap", "network", "enumeration"]
publishDate: 2026-05-18
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Host Discovery](#host-discovery)
- [Port Scanning](#port-scanning)
- [Service & Version Detection](#service--version-detection)
- [OS Detection](#os-detection)
- [Aggressive Scan](#aggressive-scan)
- [Timing Templates](#timing-templates)
- [NSE Scripts](#nse-scripts)
- [Output Formats](#output-formats)
- [Common Profiles](#common-profiles)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
Nmap is a network scanner used for host discovery, port scanning, service/version detection, OS fingerprinting, and vulnerability scripting via NSE.
## Host Discovery
```bash
nmap -sn 192.168.1.0/24 # ping sweep, no port scan
nmap -sn -PR 192.168.1.0/24 # ARP ping (local network)
nmap -Pn $IP # skip host discovery, treat as up
```
## Port Scanning
```bash
nmap $IP # top 1000 ports (SYN scan if root)
nmap -p 80,443,8080 $IP # specific ports
nmap -p 1-65535 $IP # all ports
nmap -p- $IP # shorthand for all ports
nmap -sU $IP # UDP scan
nmap -sU -sS $IP # UDP + SYN together
```
Scan types:
- `-sS`: SYN scan (stealth, requires root)
- `-sT`: TCP connect scan (no root needed)
- `-sU`: UDP scan
- `-sA`: ACK scan (firewall rule mapping)
- `-sN/sF/sX`: Null, FIN, Xmas (evasion, unreliable on Windows)
## Service & Version Detection
```bash
nmap -sV $IP
nmap -sV --version-intensity 9 $IP # more aggressive probing
```
## OS Detection
```bash
nmap -O $IP
nmap -O --osscan-guess $IP # guess if not confident
```
## Aggressive Scan
```bash
nmap -A $IP # -sV -O --script=default --traceroute
```
## Timing Templates
```bash
nmap -T0 $IP # paranoid (IDS evasion, very slow)
nmap -T1 $IP # sneaky
nmap -T3 $IP # normal (default)
nmap -T4 $IP # aggressive (faster, good for CTFs)
nmap -T5 $IP # insane (may miss results)
```
## NSE Scripts
```bash
nmap --script default $IP
nmap --script vuln $IP
nmap --script "ftp-*" $IP
nmap --script safe $IP
nmap --script $script --script-args user=$user,pass=$password $IP
```
Common script categories: `auth`, `brute`, `default`, `discovery`, `dos`, `exploit`, `intrusive`, `safe`, `version`, `vuln`.
Scripts are located in `/usr/share/nmap/scripts/`.
## Output Formats
```bash
nmap -oN output.txt $IP # normal
nmap -oX output.xml $IP # XML
nmap -oG output.gnmap $IP # grepable
nmap -oA output $IP # all three at once
```
## Common Profiles
Quick full scan:
```bash
nmap -p- -T4 --min-rate 5000 -sV -sC -oA full $IP
```
CTF/lab initial recon:
```bash
nmap -sV -sC -p- --open $IP
```
UDP top ports:
```bash
nmap -sU --top-ports 100 $IP
```
+54
View File
@@ -0,0 +1,54 @@
---
title: "RDP"
description: "Enumeration, exploitation and post-exploitation techniques for RDP servers."
tags: ["rdp", "network", "service"]
publishDate: 2026-05-04
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Enumeration](#enumeration)
- [Banner grabbing](#banner-grabbing)
- [Connect](#connect)
- [Brute Force](#brute-force)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
RDP (Remote Desktop Protocol) runs on **port 3389** and provides a graphical remote session.
Common on Windows servers and workstations.
## Enumeration
### Banner grabbing
```bash
nmap -sV -p 3389 $IP
nmap -p 3389 --script rdp-* $IP
```
Key scripts:
- `rdp-enum-encryption`: checks encryption level
- `rdp-vuln-ms12-020`: tests for MS12-020 DoS vulnerability
## Connect
```bash
xfreerdp /u:$user /p:$password /v:$IP
xfreerdp /u:$user /p:$password /v:$IP /cert:ignore
rdesktop $IP
```
Pass the hash directly (no plaintext password needed):
```bash
xfreerdp /u:$user /pth:$hash /v:$IP
```
## Brute Force
```bash
hydra -l $user -P ~/wordlists/rockyou.txt rdp://$IP
crowbar -b rdp -s $IP/32 -u $user -C ~/wordlists/rockyou.txt
```
+85
View File
@@ -0,0 +1,85 @@
---
title: "SSH"
description: "Enumeration, exploitation and post-exploitation techniques for SSH servers."
tags: ["ssh", "network", "service"]
publishDate: 2026-05-04
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Enumeration](#enumeration)
- [Banner grabbing](#banner-grabbing)
- [Nmap](#nmap)
- [Connect](#connect)
- [Brute Force](#brute-force)
- [Key-Based Auth](#key-based-auth)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
SSH runs on **port 22** and provides an encrypted remote shell.
Common implementations: OpenSSH, Dropbear, Bitvise.
## Enumeration
### Banner grabbing
```bash
nc -nv $IP 22
ssh $IP
```
The banner reveals the software and version (e.g. `OpenSSH_9.2`).
### Nmap
```bash
nmap -sV -p 22 $IP
nmap -p 22 --script ssh-* $IP
```
Key scripts:
- `ssh-hostkey`: retrieves the server's public key
- `ssh-auth-methods`: lists accepted authentication methods
- `ssh-brute`: brute-force credentials
## Connect
```bash
ssh $user@$IP
ssh -p 2222 $user@$IP
ssh -i id_rsa $user@$IP
```
## Brute Force
```bash
hydra -l $user -P ~/wordlists/rockyou.txt ssh://$IP
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M ssh
```
Only viable if password auth is enabled. Check with:
```bash
ssh -v $user@$IP
```
Look for `publickey,password` in the output.
## Key-Based Auth
If you find a private key (`id_rsa`), set permissions and connect:
```bash
chmod 600 id_rsa
ssh -i id_rsa $user@$IP
```
If the key is encrypted, crack the passphrase:
```bash
ssh2john id_rsa > hash.txt
john hash.txt --wordlist=~/wordlists/rockyou.txt
hashcat -m 22921 hash.txt ~/wordlists/rockyou.txt
```
+61
View File
@@ -0,0 +1,61 @@
---
title: "Telnet"
description: "Enumeration, exploitation and post-exploitation techniques for Telnet servers."
tags: ["telnet", "network", "service"]
publishDate: 2026-05-04
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Enumeration](#enumeration)
- [Banner grabbing](#banner-grabbing)
- [Nmap](#nmap)
- [Connect](#connect)
- [Brute Force](#brute-force)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
Telnet runs on **port 23** and transmits all data (including credentials) in **cleartext**.
Common on embedded devices, legacy systems, routers, and IoT equipment.
## Enumeration
### Banner grabbing
```bash
nc -nv $IP 23
telnet $IP
```
The banner often reveals the OS, hostname, or device type.
### Nmap
```bash
nmap -sV -p 23 $IP
nmap -p 23 --script telnet-* $IP
```
Key scripts:
- `telnet-ntlm-info`: extracts NTLM info (Windows targets)
- `telnet-brute`: brute-force credentials
## Connect
```bash
telnet $IP
telnet $IP 23
```
Login with `user` / `password`. Session is fully interactive once authenticated.
## Brute Force
```bash
hydra -l $user -P ~/wordlists/rockyou.txt telnet://$IP
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M telnet
```
Try default credentials first. Routers and embedded devices commonly ship with `admin:admin`, `root:root`, or blank passwords.
+116
View File
@@ -0,0 +1,116 @@
---
title: "Bluesky"
description: "Enumeration, search operators, API endpoints and tools for investigating Bluesky accounts."
tags: ["osint", "bluesky", "social-media", "enumeration"]
publishDate: 2026-04-29
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Key Concepts](#key-concepts)
- [Account Enumeration](#account-enumeration)
- [Resolve handle → DID](#resolve-handle-%E2%86%92-did)
- [Resolve DID → history (all past handles, keys, creation date)](#resolve-did-%E2%86%92-history-all-past-handles-keys-creation-date)
- [Get profile metadata](#get-profile-metadata)
- [Followers / following](#followers--following)
- [Search Operators](#search-operators)
- [API equivalent](#api-equivalent)
- [Google Dorks](#google-dorks)
- [Tools](#tools)
- [BlueSkyNet](#blueskynet)
- [ClearSky](#clearsky)
- [plc.directory](#plcdirectory)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
## Key Concepts
Bluesky is built on the **AT Protocol**. Every account has two identifiers:
- **Handle**: `user.bsky.social` or a custom domain (can change)
- **DID**: `did:plc:ewvi7nxzyoun6zhxrhs64oiz` (permanent, survives handle changes)
All public content is accessible **without an account**. Follower/following lists are also public by default.
## Account Enumeration
### Resolve handle → DID
```
https://bsky.social/xrpc/com.atproto.identity.resolveHandle?handle=$HANDLE
```
### Resolve DID → history (all past handles, keys, creation date)
```
https://plc.directory/$DID
```
### Get profile metadata
```
https://public.api.bsky.app/xrpc/app.bsky.actor.getProfile?actor=$HANDLE
```
Returns: DID, display name, description, follower/following count, creation date, avatar URL.
### Followers / following
```
https://public.api.bsky.app/xrpc/app.bsky.graph.getFollowers?actor=$HANDLE&limit=100
https://public.api.bsky.app/xrpc/app.bsky.graph.getFollows?actor=$HANDLE&limit=100
```
Paginate with the `cursor` field from the response.
## Search Operators
Bluesky's full-text search supports these operators (combinable):
| Operator | Example | Effect |
| ----------- | ----------------------------- | ----------------------------- |
| `"..."` | `"exact phrase"` | Exact match |
| `from:` | `from:handle.bsky.social` | Posts by user |
| `mentions:` | `mentions:handle.bsky.social` | Posts mentioning user |
| `since:` | `since:2024-01-01` | After date (UTC, YYYY-MM-DD) |
| `until:` | `until:2024-06-30` | Before date (UTC, YYYY-MM-DD) |
| `lang:` | `lang:fr` | Language (ISO 639-1) |
| `domain:` | `domain:github.com` | Posts linking to domain |
| `#tag` | `#osint` | Hashtag |
#### API equivalent
```
https://public.api.bsky.app/xrpc/app.bsky.feed.searchPosts?q={QUERY}&author={HANDLE}&since=2024-01-01&until=2024-12-31&lang=en&limit=25
```
## Google Dorks
Bluesky is heavily indexed by Google. Useful for finding profiles and posts without touching the platform:
```
site:bsky.app "$TARGET_NAME"
site:bsky.app "$TARGET_NAME" inurl:profile
site:bsky.app "$KEYWORD" since:2024-01-01
```
## Tools
### BlueSkyNet
Web app for searching and exporting Bluesky data to CSV. Wraps the public API with a UI for advanced search filters.
- [github.com/jakecreps/blueskynet](https://github.com/jakecreps/blueskynet)
### ClearSky
Shows block lists, blocking history, and who blocked a given account. Useful for mapping relationships and adversarial clusters.
- [clearsky.app](https://clearsky.app)
### plc.directory
Official DID PLC directory. Lookup a DID to get full account history: creation date, all past handles, key rotations.
- [plc.directory](https://plc.directory)
+79
View File
@@ -0,0 +1,79 @@
---
title: "Information Gathering"
description: "Essential cybersecurity cheatsheet for Information Gathering and Open Source Intelligence (OSINT). Discover data related to emails, domains, usernames, and images using both command line and online tools."
tags: ["osint", "enumeration", "information-gathering"]
publishDate: 2026-05-03
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [IKnowYou](#iknowyou)
- [Command line tools](#command-line-tools)
- [Online tools](#online-tools)
- [OSINT Aggregation Tool](#osint-aggregation-tool)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
**Information Gathering**, often referred to as **Open Source Intelligence (OSINT)** in the context of ethical hacking, is the systematic collection and analysis of publicly available data about a target, providing the foundational knowledge necessary to identify potential vulnerabilities and craft targeted security assessments.
## Command line tools
| **From** | **Use** |
| --------- | ----------------------------------------------------------------------------------------------- |
| Email | `holehe $email` |
| | `ghunt email $email` (for google account) |
| | `github-recon $email` ([link](http://github.com/anotherhadi/github-recon/), for github account) |
| Domain | `theHarvester -d $domain -l 100` |
| | `theHarvester -d $domain -l 100 -b all` (full) |
| Username | `sherlock $username` |
| Image | `exiftool $imagePath` |
| Instagram | `instaloader profile $username` |
| Github | `trufflehog github --org=$usernameOrOrg` |
| | `github-recon $username` ([link](http://github.com/anotherhadi/github-recon/)) |
## Online tools
| **For** | **Use** |
| ---------- | ------------------------------------------------------ |
| Visualiser | [OSINTracker](https://www.osintracker.com/) |
| IP | [Shodan](https://www.shodan.io/) |
| | [Censys](https://search.censys.io/) |
| Domain | [Whois](https://www.whois.com/whois/) |
| | [crt.sh](https://crt.sh/) (certificate transparency) |
| Name | [Webmii](https://webmii.com/) |
| | [BreachDirectory](https://breachdirectory.org/) |
| | [LeakLookup](https://leak-lookup.com/search) |
| | [IntelX](https://intelx.io/) |
| | [Genealogic.review](https://genealogic.review/) |
| SSID | [Wigle](https://wigle.net/) |
| Image | [PimEyes (faces)](https://pimeyes.com/) |
| | [Lenso (faces)](https://lenso.ai) |
| | [TinEye](https://tineye.com) |
| | [Pic2Map (exif geolocation)](https://www.pic2map.com/) |
| Username | [DeHashed](https://dehashed.com/search) |
| | [BreachDirectory](https://breachdirectory.org/) |
| | [IntelX](https://intelx.io/) |
| | [LeakLookup](https://leak-lookup.com/search) |
| | [Oathnet](https://oathnet.org/) |
| Email | [DeHashed](https://dehashed.com/search) |
| | [Hunter](https://hunter.io/) |
| | [HaveIBeenPwned](https://haveibeenpwned.com/) |
| | [BreachDirectory](https://breachdirectory.org/) |
| | [LeakLookup](https://leak-lookup.com/search) |
| | [IntelX](https://intelx.io/) |
| | [Oathnet](https://oathnet.org/) |
| Phone | [Epieos](https://epieos.com/) |
| Instagram | [Dumpor](https://dumpor.io/) |
| Misc | [Goosint](https://goosint.com/) |
| | [OSINT Framework](https://osintframework.com/) |
| | [OSINT Dojo](https://osintdojo.com/) |
## OSINT Aggregation Tool
<a href="https://iknowyou.hadi.icu" class="link-card not-prose" target="_blank">
<span>
<h4>IKnowYou</h4>
<p>Self-hosted OSINT aggregation platform: Run dozens of open-source intelligence tools against a single target in parallel; all from one clean web interface.</p>
</span>
</a>
+101
View File
@@ -0,0 +1,101 @@
---
title: "Sock Puppets"
description: "Essential cheatsheet on creating and managing Sock Puppets (fake identities) for ethical security research and Open Source Intelligence (OSINT), focusing on maintaining separation from personal data and bypassing common verification."
tags: ["osint", "sock-puppets"]
publishDate: 2026-05-03
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Sms 4 Sats (Onion)](#sms-4-sats-onion)
- [Faker](#faker)
- [Fake Name](#fake-name)
- [This Person Does Not Exist](#this-person-does-not-exist)
- [SMSPool](#smspool)
- [Receive Sms Online](#receive-sms-online)
- [Receive Free Sms](#receive-free-sms)
- [Receive Free Sms](#receive-free-sms-1)
- [Online Sim](#online-sim)
- [Sms 4 Sats](#sms-4-sats)
- [Information generation](#information-generation)
- [Bypass phone verification](#bypass-phone-verification)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
Sock puppets are fake identities use to gather information from a target.
The sock puppet should have no link between your personal information and the fakes ones. (No ip address, mail, follow, etc..)
## Information generation
<a href="https://fakerjs.dev" class="link-card not-prose" target="_blank">
<span>
<h4>Faker</h4>
<p>Generate massive amounts of fake data</p>
</span>
</a>
<a href="https://fakenamegenerator.com/" class="link-card not-prose" target="_blank">
<span>
<h4>Fake Name</h4>
<p>Personal informations</p>
</span>
</a>
<a href="https://www.thispersondoesnotexist.com/" class="link-card not-prose" target="_blank">
<span>
<h4>This Person Does Not Exist</h4>
<p>Generate fake image</p>
</span>
</a>
## Bypass phone verification
<a href="https://www.smspool.net/" class="link-card not-prose" target="_blank">
<span>
<h4>SMSPool</h4>
<p>Cheapest and Fastest Online SMS verification</p>
</span>
</a>
<a href="https://receive-sms-online.info" class="link-card not-prose" target="_blank">
<span>
<h4>Receive Sms Online</h4>
<p>Free SMS verification</p>
</span>
</a>
<a href="https://receivefreesms.net" class="link-card not-prose" target="_blank">
<span>
<h4>Receive Free Sms</h4>
<p>Free SMS verification</p>
</span>
</a>
<a href="https://receive-smss.com" class="link-card not-prose" target="_blank">
<span>
<h4>Receive Free Sms</h4>
<p>Free SMS verification</p>
</span>
</a>
<a href="https://onlinesim.io/" class="link-card not-prose" target="_blank">
<span>
<h4>Online Sim</h4>
<p>SMS verification with free tier</p>
</span>
</a>
<a href="https://sms4stats.com/" class="link-card not-prose" target="_blank">
<span>
<h4>Sms 4 Sats</h4>
<p>Paid SMS verification</p>
</span>
</a>
<a href="http://sms4sat6y7lkq4vscloomatwyj33cfeddukkvujo2hkdqtmyi465spid.onion" class="link-card not-prose" target="_blank">
<span>
<h4>Sms 4 Sats (Onion)</h4>
<p>Paid SMS verification. Tor version</p>
</span>
</a>
+54
View File
@@ -0,0 +1,54 @@
---
title: "Tips"
description: "A cheatsheet of practical tips and unconventional methods for Open Source Intelligence (OSINT), focusing on advanced data visualization, information leakage detection, and utilizing web archives for historical data."
tags: ["osint"]
publishDate: 2026-05-03
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Visualisation](#visualisation)
- [Forgotten passwords](#forgotten-passwords)
- [Archive Search](#archive-search)
- [Google Cache](#google-cache)
- [Domain History](#domain-history)
- [Bookmarklets](#bookmarklets)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
## Visualisation
Use [OSINTracker](https://app.osintracker.com/) to visualise your findings.
It allows you to create a graph of your findings, which can help you see connections and relationships between different pieces of information.
## Forgotten passwords
To find email addresses and phone numbers associated with an account, you can click on "Forgot password?" on the login page of a website. Be careful, though, this creates notifications and can be detected by the target, and often gives your information away.
## Archive Search
- [Wayback Machine](https://web.archive.org) stores over 618 billion web captures
- [Archive.ph](https://archive.ph) creates on-demand snapshots, including for JS-heavy sites, with both a functional page and screenshot version
## Google Cache
Google keeps a cached version of most indexed pages. Access it with the `cache:` operator:
```
cache:example.com
cache:example.com/page
```
If the page has been taken down or modified, the cached version may still show the original content.
## Domain History
[VirusTotal](https://www.virustotal.com) shows the historical DNS records, subdomains, and associated IPs for any domaint useful when a site has moved or been taken down.
[ViewDNS.info](https://viewdns.info) covers WHOIS history, reverse IP, reverse MX, and port scans from a single interface.
## Bookmarklets
- [K2SOsint/Bookmarklets](https://github.com/K2SOsint/Bookmarklets)
- [tools.myosint.training](https://tools.myosint.training/)
+157
View File
@@ -0,0 +1,157 @@
---
title: "X / Twitter"
description: "Enumeration, search operators, deleted content recovery and tools for investigating X accounts."
tags: ["osint", "twitter", "x", "social-media", "enumeration"]
publishDate: 2026-04-29
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Key Concepts](#key-concepts)
- [Account Enumeration](#account-enumeration)
- [Handle to User ID](#handle-to-user-id)
- [Banner last update time](#banner-last-update-time)
- [Timestamp from ID (Snowflake)](#timestamp-from-id-snowflake)
- [Direct profile URL by ID](#direct-profile-url-by-id)
- [Search Operators](#search-operators)
- [Direct search URL](#direct-search-url)
- [Google Dorks](#google-dorks)
- [Deleted and Archived Content](#deleted-and-archived-content)
- [Wayback Machine](#wayback-machine)
- [Twayback](#twayback)
- [Profile history](#profile-history)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
## Key Concepts
Every account has two identifiers:
- **Handle**: `@username` (can change)
- **User ID**: numeric, permanent (survives handle changes and suspensions)
Unlike [Bluesky](/notes/osint/bluesky), X now requires a login to browse most content in the browser. The free API tier (v2) is severely limited. Most open-source scraping tools that bypassed the API (Twint, snscrape, GetOldTweets3) are broken since the 2023 API lockdown.
## Account Enumeration
### Handle to User ID
The user ID stays constant when someone changes their handle or gets suspended. Several web tools resolve it:
- [tweeterid.com](https://tweeterid.com/)
- [commentpicker.com/twitter-id.php](https://commentpicker.com/twitter-id.php)
Or via the profile page source: look for `"id_str"` in the page JSON.
### Banner last update time
The profile banner URL contains a Unix timestamp indicating when the banner was last changed:
```
https://pbs.twimg.com/profile_banners/{user_id}/{unix_timestamp}/600x200
```
Right-click the banner image and copy the URL, or inspect the page source. Convert the timestamp at [unixtimestamp.com](https://www.unixtimestamp.com/).
### Timestamp from ID (Snowflake)
Twitter IDs are Snowflake IDs: the numeric value encodes the exact creation time of a tweet or account. Extract it with:
```python
tweet_id = 1234567890123456789
timestamp_ms = (tweet_id >> 22) + 1288834974657
```
`1288834974657` is Twitter's custom epoch (Nov 4, 2010). Works on both tweet IDs and user IDs: useful to confirm account creation date without needing profile metadata.
Several online converters exist if you don't want to do it manually: search "snowflake id decoder".
### Direct profile URL by ID
Old tweet/profile URLs using numeric IDs still resolve even after handle changes:
```
https://x.com/i/user/$USER_ID
```
## Search Operators
Accessible at `x.com/search`. Operators are combinable.
| Operator | Example | Effect |
| ----------------- | -------------------------- | ------------------------ |
| `"..."` | `"exact phrase"` | Exact match |
| `from:` | `from:handle` | Posts by user |
| `to:` | `to:handle` | Posts directed at user |
| `since:` | `since:2024-01-01` | After date (YYYY-MM-DD) |
| `until:` | `until:2024-06-30` | Before date (YYYY-MM-DD) |
| `lang:` | `lang:fr` | Language (ISO 639-1) |
| `near:` | `near:"Paris" within:10km` | Geo (web only, not API) |
| `geocode:` | `geocode:48.85,2.35,5km` | Geo by coordinates |
| `filter:images` | | Posts with images |
| `filter:videos` | | Posts with videos |
| `filter:links` | | Posts with URLs |
| `filter:verified` | | Verified accounts only |
| `-filter:replies` | | Exclude replies |
| `min_retweets:` | `min_retweets:100` | Engagement threshold |
| `min_faves:` | `min_faves:500` | Engagement threshold |
| `#tag` | `#osint` | Hashtag |
| `-term` | `-spam` | Exclude term |
Boolean: spaces imply AND, use uppercase `OR` for alternatives, parentheses for grouping.
#### Direct search URL
```
https://x.com/search?q=from%3A$HANDLE+since%3A2024-01-01&f=live
```
`f=live` returns chronological results instead of relevance-ranked.
## Google Dorks
```
site:x.com "$TARGET"
site:twitter.com "$TARGET"
site:x.com/i/status "$KEYWORD"
"twitter.com/$HANDLE" OR "x.com/$HANDLE"
```
Old `twitter.com` URLs are still indexed separately from `x.com`, search both.
## Deleted and Archived Content
### Wayback Machine
```
https://web.archive.org/web/*/twitter.com/$HANDLE/status/*
https://web.archive.org/web/*/x.com/$HANDLE/status/*
```
Manually browse snapshots, or use [waybacktweets](https://github.com/claromes/waybacktweets) to batch-retrieve CDX data:
```bash
pip install waybacktweets
waybacktweets $HANDLE
```
Outputs CSV/JSON with archived tweet URLs. Useful for deleted posts and suspended accounts.
### Twayback
Web tool wrapping the same Wayback CDX API with a UI:
```
https://twayback.space/
```
Note: only works if the tweet was crawled before deletion.
### Profile history
The Wayback Machine also archives profile pages: past bios, display names, profile photos, header images. Check snapshots at:
```
https://web.archive.org/web/*/twitter.com/$HANDLE
```
+49
View File
@@ -0,0 +1,49 @@
---
title: "Directory Discovery"
description: "Techniques and tools for discovering hidden directories and files on web servers."
tags: ["web", "enumeration", "discovery", "directory"]
publishDate: 2026-06-01
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [FFUF](#ffuf)
- [Robots.txt](#robotstxt)
- [Sitemap.xml](#sitemapxml)
- [Dirb](#dirb)
- [Spider - Katana](#spider---katana)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
## FFUF
See also [FFUF](/notes/web/ffuf) for fuzzing-based directory discovery.
## Robots.txt
```bash
curl -s $url/robots.txt
```
## Sitemap.xml
```bash
curl -s $url/sitemap.xml
```
## Dirb
```bash
dirb $url
```
## Spider - Katana
A spider is a tool that crawls a website and collects information about its
structure and content. It can be used to find hidden directories, files, and
parameters.
```bash
katana -c 15 -p 15 -u $url > output
```
+33
View File
@@ -0,0 +1,33 @@
---
title: "FFUF"
description: "Reference and usage examples for ffuf, a fast web fuzzer for directories, endpoints and subdomains."
tags:
["web", "enumeration", "discovery", "subdomain", "directory", "bruteforce"]
publishDate: 2026-06-01
---
**Fuff (or ffuf)** is a fast web fuzzer written in Go, mainly used in
cybersecurity to discover hidden directories, files, API endpoints, subdomains,
vhosts and more. Its speed and flexibility make it a must-have for pentesters
and bug bounty hunters.
```bash
# Flags:
# -rate 50 -t 50 # Limit requests to 50 per second with 50 concurrent threads
# -X POST|GET|PUT # Set method
# -e .php,.asp,.bak,.db # Set the extension
# -recursion -recursion-depth 3 # Recursive fuzzing up to 3 levels deep
# -fc 404,500 # Exclude responses with status codes 404 and 500
# Examples:
ffuf -w wordlist.txt -u $url/FUZZ # Basic directory/file fuzzing using a wordlist
ffuf -w subdomains.txt -u https://FUZZ.$url # Subdomain fuzzing
ffuf -w vhosts.txt -u $url -H "Host: https://FUZZ.$url" # Virtual host fuzzing by modifying the Host header
ffuf -w wordlist.txt -u $url/page.php?FUZZ=value # GET parameter fuzzing in the query string
ffuf -w wordlist.txt -u $url/api -X POST -d 'FUZZ=value' # POST body parameter fuzzing
ffuf -w wordlist.txt -u $url/FUZZ -b 'session=abcdef' # Use a session cookie during fuzzing
ffuf -w headers.txt -u $url -H "X-Custom-Header: FUZZ" # HTTP header fuzzing
ffuf -w passwords.txt -X POST -u $url/login -d "username=admin&password=FUZZ" # Password brute-forcing for user "admin"
ffuf -w users.txt:USER -w passwords.txt:PASS -u "$url/login?username=USER&password=PASS" -mode pitchfork # Pitchfork mode: matches each line from both wordlists (USER[i], PASS[i])
ffuf -w users.txt:USER -w passwords.txt:PASS -u "$url/login?username=USER&password=PASS" -mode clusterbomb # Clusterbomb mode: tests every user with every password combination
```
+98
View File
@@ -0,0 +1,98 @@
---
title: "Subdomains Discovery"
description: "Methods and tools for enumerating subdomains of a target domain."
tags: ["web", "enumeration", "discovery", "subdomain"]
publishDate: 2026-06-01
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [FFUF](#ffuf)
- [Google Dorking](#google-dorking)
- [Certificate Transparency](#certificate-transparency)
- [Passive DNS](#passive-dns)
- [DMARC](#dmarc)
- [ASN & IP Ranges](#asn--ip-ranges)
- [Favicon Hash](#favicon-hash)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
## FFUF
See also [FFUF](/notes/web/ffuf) for fuzzing-based subdomain discovery.
## Google Dorking
Google dorks can surface subdomains indexed by Google without any active scanning.
```
site:*.$domain
site:*.$domain -www
site:*.$domain inurl:admin
site:*.$domain ext:php | ext:json | ext:xml
```
## Certificate Transparency
CT logs record every TLS certificate ever issued for a domain. Querying them is
passive and reliable.
```bash
curl -s "https://crt.sh/?q=%25.$domain&output=json" | jq '.[].name_value' | sort -u
```
Tools that aggregate CT logs:
- [crt.sh](https://crt.sh)
- [censys.io](https://search.censys.io)
## Passive DNS
Passive DNS databases store historical DNS resolutions collected from resolvers
worldwide; useful for finding subdomains that no longer resolve but once did.
```bash
# Amass (passive mode, no active scanning)
amass enum -passive -d $domain
# subfinder (uses many passive sources)
subfinder -d $domain -silent
```
## DMARC
DMARC can reveal more domains associated with a target.
Go to `dmarc.live/info/$domain`, it allows you to find domains using the
same DMARC record.
## ASN & IP Ranges
Finding the ASN of a target exposes its entire IP range, which may contain
undiscovered subdomains or related infrastructure.
```bash
# Get ASN from an IP
whois $ip | grep -i "asn\|orgname\|origin"
# Get IP ranges from ASN
whois -h whois.radb.net -- '-i origin AS12345' | grep route
```
## Favicon Hash
A unique favicon can be fingerprinted to find other domains hosted by the same
organisation, including subdomains on non-standard ports.
```bash
# Compute the MMH3 hash of the favicon
python3 -c "
import requests, mmh3, base64
r = requests.get('https://$domain/favicon.ico')
h = mmh3.hash(base64.encodebytes(r.content))
print(h)
"
```
Then search the hash on [Shodan](https://shodan.io): `http.favicon.hash:<hash>`