mirror of
https://github.com/anotherhadi/sec-notes.git
synced 2026-10-05 15:48:25 +02:00
init
This commit is contained in:
@@ -0,0 +1,10 @@
|
|||||||
|
# Contributing
|
||||||
|
|
||||||
|
Everybody is invited and welcome to contribute. There is a lot to do... Check the issues!
|
||||||
|
|
||||||
|
The process is straight-forward.
|
||||||
|
|
||||||
|
- Read [How to get faster PR reviews](https://github.com/kubernetes/community/blob/master/contributors/guide/pull-requests.md#best-practices-for-faster-reviews) by Kubernetes (but skip step 0 and 1)
|
||||||
|
- Fork this git repository
|
||||||
|
- Write your changes (bug fixes, new features, ...).
|
||||||
|
- Create a Pull Request against the main branch.
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
ko_fi: anotherhadi
|
||||||
Executable
+39
@@ -0,0 +1,39 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
import re
|
||||||
|
import subprocess
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
REPO_ROOT = Path(__file__).resolve().parents[2]
|
||||||
|
SKIP_DIRS = {".git", ".direnv", ".github"}
|
||||||
|
|
||||||
|
TOC_PLACEHOLDER_RE = re.compile(r"\[toc\]", re.IGNORECASE)
|
||||||
|
TOC_START = "<!-- START doctoc generated TOC please keep comment here to allow auto update -->"
|
||||||
|
TOC_END = "<!-- END doctoc generated TOC please keep comment here to allow auto update -->"
|
||||||
|
|
||||||
|
|
||||||
|
def find_markdown_files():
|
||||||
|
for path in sorted(REPO_ROOT.rglob("*.md")):
|
||||||
|
if not SKIP_DIRS.isdisjoint(path.relative_to(REPO_ROOT).parts):
|
||||||
|
continue
|
||||||
|
yield path
|
||||||
|
|
||||||
|
|
||||||
|
def has_toc_markers(path):
|
||||||
|
text = path.read_text()
|
||||||
|
if TOC_START in text:
|
||||||
|
return True
|
||||||
|
if TOC_PLACEHOLDER_RE.search(text):
|
||||||
|
text = TOC_PLACEHOLDER_RE.sub(f"{TOC_START}\n{TOC_END}", text, count=1)
|
||||||
|
path.write_text(text)
|
||||||
|
return True
|
||||||
|
return False
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
for md_file in find_markdown_files():
|
||||||
|
if has_toc_markers(md_file):
|
||||||
|
subprocess.run(["doctoc", "--notitle", str(md_file)], check=True)
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
Executable
+75
@@ -0,0 +1,75 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
import re
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
REPO_ROOT = Path(__file__).resolve().parents[2]
|
||||||
|
README = REPO_ROOT / "README.md"
|
||||||
|
SKIP_DIRS = {".git", ".github", ".direnv"}
|
||||||
|
SECTION_TITLE_OVERRIDES = {"osint": "OSINT"}
|
||||||
|
|
||||||
|
FRONTMATTER_RE = re.compile(r"^---\n(.*?\n)---\n", re.DOTALL)
|
||||||
|
FIELD_RE = re.compile(r'^(\w+):\s*"?(.*?)"?\s*$')
|
||||||
|
TOC_START = "<!-- START doctoc generated TOC please keep comment here to allow auto update -->"
|
||||||
|
TOC_END = "<!-- END doctoc generated TOC please keep comment here to allow auto update -->"
|
||||||
|
|
||||||
|
|
||||||
|
def existing_toc_block():
|
||||||
|
if README.exists():
|
||||||
|
text = README.read_text()
|
||||||
|
if TOC_START in text and TOC_END in text:
|
||||||
|
start = text.index(TOC_START)
|
||||||
|
end = text.index(TOC_END) + len(TOC_END)
|
||||||
|
return text[start:end]
|
||||||
|
return "[toc]"
|
||||||
|
|
||||||
|
|
||||||
|
def parse_frontmatter(path):
|
||||||
|
text = path.read_text()
|
||||||
|
match = FRONTMATTER_RE.match(text)
|
||||||
|
if not match:
|
||||||
|
return {}
|
||||||
|
fields = {}
|
||||||
|
for line in match.group(1).splitlines():
|
||||||
|
field_match = FIELD_RE.match(line)
|
||||||
|
if field_match:
|
||||||
|
fields[field_match.group(1)] = field_match.group(2)
|
||||||
|
return fields
|
||||||
|
|
||||||
|
|
||||||
|
def section_title(dirname):
|
||||||
|
return SECTION_TITLE_OVERRIDES.get(dirname, dirname.capitalize())
|
||||||
|
|
||||||
|
|
||||||
|
def build_section(directory):
|
||||||
|
lines = [f"## {section_title(directory.name)}", ""]
|
||||||
|
for md_file in sorted(directory.glob("*.md")):
|
||||||
|
fields = parse_frontmatter(md_file)
|
||||||
|
title = fields.get("title", md_file.stem)
|
||||||
|
description = fields.get("description", "")
|
||||||
|
rel_path = f"./{directory.name}/{md_file.name}"
|
||||||
|
lines.append(f"- [{title}]({rel_path}): {description}")
|
||||||
|
lines.append("")
|
||||||
|
return lines
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
directories = sorted(
|
||||||
|
d
|
||||||
|
for d in REPO_ROOT.iterdir()
|
||||||
|
if d.is_dir() and d.name not in SKIP_DIRS and any(d.glob("*.md"))
|
||||||
|
)
|
||||||
|
|
||||||
|
lines = [
|
||||||
|
"# Sec Notes",
|
||||||
|
"",
|
||||||
|
existing_toc_block(),
|
||||||
|
"",
|
||||||
|
]
|
||||||
|
for directory in directories:
|
||||||
|
lines.extend(build_section(directory))
|
||||||
|
|
||||||
|
README.write_text("\n".join(lines).rstrip("\n") + "\n")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
.pre-commit-config.yaml
|
||||||
|
.direnv/
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
MIT License
|
||||||
|
|
||||||
|
Copyright (c) 2026 Hadi
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||||
|
of this software and associated documentation files (the "Software"), to deal
|
||||||
|
in the Software without restriction, including without limitation the rights
|
||||||
|
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||||
|
copies of the Software, and to permit persons to whom the Software is
|
||||||
|
furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
The above copyright notice and this permission notice shall be included in all
|
||||||
|
copies or substantial portions of the Software.
|
||||||
|
|
||||||
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||||
|
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||||
|
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||||
|
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||||
|
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||||
|
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||||
|
SOFTWARE.
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
# Sec Notes
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Blog](#blog)
|
||||||
|
- [Linux](#linux)
|
||||||
|
- [Network](#network)
|
||||||
|
- [OSINT](#osint)
|
||||||
|
- [Web](#web)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
## Blog
|
||||||
|
|
||||||
|
- [The Password is 'admin': Why Default Credentials Are Still Breaking the Internet](./blog/default-passwords.md): Default credentials like admin:admin remain one of the most exploited vulnerabilities on the internet. Learn why they're dangerous, how the Mirai botnet took down half the web with just 62 passwords, and how to protect your infrastructure: plus introducing default-creds, an open-source database to look up factory-set credentials in seconds.
|
||||||
|
- [Unmasking Github Users: How to Identify the Person Behind Any Github Profile](./blog/github-users-osint.md): Ever wondered who is behind a specific Github username? This guide covers advanced OSINT techniques to deanonymize users, find hidden email addresses, and link Github accounts to real-world identities.
|
||||||
|
|
||||||
|
## Linux
|
||||||
|
|
||||||
|
- [GRUB Boot Bypass](./linux/grub-bypass.md): Physical access techniques to get a root shell by editing GRUB boot parameters.
|
||||||
|
- [Linux Privilege Escalation](./linux/privesc.md): Common misconfigurations and weaknesses to check when escalating privileges on Linux.
|
||||||
|
|
||||||
|
## Network
|
||||||
|
|
||||||
|
- [FTP](./network/ftp.md): Enumeration, exploitation and post-exploitation techniques for FTP servers.
|
||||||
|
- [NFS](./network/nfs.md): Enumeration, mounting and privilege escalation techniques for NFS shares.
|
||||||
|
- [Nmap](./network/nmap.md): Host discovery, port scanning, service detection and NSE scripting
|
||||||
|
- [RDP](./network/rdp.md): Enumeration, exploitation and post-exploitation techniques for RDP servers.
|
||||||
|
- [SSH](./network/ssh.md): Enumeration, exploitation and post-exploitation techniques for SSH servers.
|
||||||
|
- [Telnet](./network/telnet.md): Enumeration, exploitation and post-exploitation techniques for Telnet servers.
|
||||||
|
|
||||||
|
## OSINT
|
||||||
|
|
||||||
|
- [Bluesky](./osint/bluesky.md): Enumeration, search operators, API endpoints and tools for investigating Bluesky accounts.
|
||||||
|
- [Information Gathering](./osint/information-gathering.md): Essential cybersecurity cheatsheet for Information Gathering and Open Source Intelligence (OSINT). Discover data related to emails, domains, usernames, and images using both command line and online tools.
|
||||||
|
- [Sock Puppets](./osint/sock-puppets.md): Essential cheatsheet on creating and managing Sock Puppets (fake identities) for ethical security research and Open Source Intelligence (OSINT), focusing on maintaining separation from personal data and bypassing common verification.
|
||||||
|
- [Tips](./osint/tips.md): A cheatsheet of practical tips and unconventional methods for Open Source Intelligence (OSINT), focusing on advanced data visualization, information leakage detection, and utilizing web archives for historical data.
|
||||||
|
- [X / Twitter](./osint/twitter-x.md): Enumeration, search operators, deleted content recovery and tools for investigating X accounts.
|
||||||
|
|
||||||
|
## Web
|
||||||
|
|
||||||
|
- [Directory Discovery](./web/directory-discovery.md): Techniques and tools for discovering hidden directories and files on web servers.
|
||||||
|
- [FFUF](./web/ffuf.md): Reference and usage examples for ffuf, a fast web fuzzer for directories, endpoints and subdomains.
|
||||||
|
- [Subdomains Discovery](./web/subdomains-discovery.md): Methods and tools for enumerating subdomains of a target domain.
|
||||||
@@ -0,0 +1,69 @@
|
|||||||
|
---
|
||||||
|
title: "The Password is 'admin': Why Default Credentials Are Still Breaking the Internet"
|
||||||
|
description: "Default credentials like admin:admin remain one of the most exploited vulnerabilities on the internet. Learn why they're dangerous, how the Mirai botnet took down half the web with just 62 passwords, and how to protect your infrastructure: plus introducing default-creds, an open-source database to look up factory-set credentials in seconds."
|
||||||
|
image: "../../../public/images/blog/default-passwords.png"
|
||||||
|
tags: ["botnet", "passwords", "cybersecurity"]
|
||||||
|
publishDate: "2026-03-13"
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [What are default credentials?](#what-are-default-credentials)
|
||||||
|
- [Real-world impact](#real-world-impact)
|
||||||
|
- [Best practices & solutions](#best-practices--solutions)
|
||||||
|
- [For users & sysadmins](#for-users--sysadmins)
|
||||||
|
- [For developers](#for-developers)
|
||||||
|
- [How to contribute](#how-to-contribute)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
## What are default credentials?
|
||||||
|
|
||||||
|
When a manufacturer ships a router, a camera, or a piece of software, it needs to be accessible out of the box. To make **setup easier**, they pre-configure it with a username and password, often something simple like admin/admin or root/password. These are called **default credentials**.
|
||||||
|
|
||||||
|
_The problem?_ Most users never change them. Whether out of convenience, lack of awareness, or simply because the service "works fine as-is", these factory-set credentials often remain active long after deployment.. turning a minor convenience into a serious **security hole**.
|
||||||
|
|
||||||
|
To help security researchers and pentesters quickly identify these exposure points, I built **[default-creds](https://default-creds.hadi.icu)**. It's an open-source, community-driven database of default credentials. Just search for a device or service, and you'll instantly get its known factory-set username and password. It also comes with a public API, documented at [default-creds.hadi.icu/api-docs](https://default-creds.hadi.icu/api-docs).
|
||||||
|
|
||||||
|
## Real-world impact
|
||||||
|
|
||||||
|
The consequences of unchanged default credentials aren't theoretical: they've already broken the internet, literally.
|
||||||
|
|
||||||
|
In the fall of 2016, a piece of malware called **Mirai** quietly scanned the internet for IoT devices still running their factory-set credentials. Using a list of just 62 common default username/password combinations like `admin:admin` or `root:password`, it managed to enslave over 380,000 devices (mostly routers, IP cameras, DVRs, ...) and turning them into an army.
|
||||||
|
|
||||||
|
On September 20, 2016, Brian Krebs' security blog was hit with a DDoS attack exceeding 620 Gbps, one of the largest ever recorded at the time. Then came the attack on French web host OVH, which broke that record. And then, in October 2016, Mirai took down **Dyn** (a major DNS provider) causing disruptions to Twitter, Spotify, Amazon, Netflix, GitHub, and PayPal, among others, with attacks reportedly peaking at 1 Tbps.
|
||||||
|
|
||||||
|
All of this, enabled by `admin:admin`.
|
||||||
|
|
||||||
|
Mirai wasn't a sophisticated zero-day exploit. It was a dictionary of 62 passwords. The attack surface wasn't a vulnerability in the code; it was human laziness at scale.
|
||||||
|
|
||||||
|
The original Mirai and its early variants launched approximately 20,000 DDoS attacks between late 2016 and early 2017. And even though its creators were eventually arrested, the source code lives on, having spawned numerous variants that continue to operate today.
|
||||||
|
|
||||||
|
Default credentials aren't just a consumer problem. Enterprises, developers, and sysadmins are equally exposed; From home routers and IP cameras to network switches, firewalls, and self-hosted services like Grafana, Redis, or Jenkins. If it has a login screen and was deployed without changing the defaults, it's a target.
|
||||||
|
|
||||||
|
## Best practices & solutions
|
||||||
|
|
||||||
|
### For users & sysadmins
|
||||||
|
|
||||||
|
1. **Change default credentials immediately.** The moment you deploy a new device or service, changing the default username and password should be the first thing you do; before it ever touches a production network.
|
||||||
|
2. **Use strong, unique passwords.** Replacing `admin:admin` with `admin:admin123` doesn't count. Use a password manager to generate and store proper credentials for each service.
|
||||||
|
3. **Audit your infrastructure.** You can't fix what you don't know about. Regularly scan your own systems for services still running on default credentials: this is exactly the kind of task [default-creds](https://default-creds.hadi.icu/) is built for.
|
||||||
|
|
||||||
|
### For developers
|
||||||
|
|
||||||
|
1. **Never ship with hardcoded default credentials.** A default password baked into your codebase is a vulnerability waiting to be exploited (and it will end up in databases like [default-creds](https://default-creds.hadi.icu) :p )
|
||||||
|
2. **Force a password change on first launch.** If your software needs a default to function, make it temporary. Block access until the user has set their own credentials.
|
||||||
|
3. **Generate a random password instead.** Even better: skip the default entirely. Generate a strong, unique password at install time and print it once in the console or the setup logs. The user still should change this password.
|
||||||
|
|
||||||
|
## How to contribute
|
||||||
|
|
||||||
|
**default-creds** is only as useful as its data. If you know a device or service that's missing from the database, contributing is straightforward. The project is open-source on [GitHub](https://github.com/anotherhadi/default-creds) under the MIT license, and contributions are made via Pull Requests by adding simple YAML definitions.
|
||||||
|
|
||||||
|
The full contribution guide is available in the [CONTRIBUTING.md](https://github.com/anotherhadi/default-creds/blob/main/CONTRIBUTING.md).
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
If you enjoyed this guide, please like and share it! Your support helps me create more infosec & OSINT content.
|
||||||
|
|
||||||
|
Have questions or feedback? Feel free to reach out: anotherhadi.clapped234[at]passmail.net
|
||||||
@@ -0,0 +1,154 @@
|
|||||||
|
---
|
||||||
|
title: "Unmasking Github Users: How to Identify the Person Behind Any Github Profile"
|
||||||
|
description: "Ever wondered who is behind a specific Github username? This guide covers advanced OSINT techniques to deanonymize users, find hidden email addresses, and link Github accounts to real-world identities."
|
||||||
|
image: "../../../public/images/blog/github-osint-users.png"
|
||||||
|
tags: ["osint", "github", "cybersecurity"]
|
||||||
|
publishDate: "2026-01-01"
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Level 1: The Low-Hanging Fruit](#level-1-the-low-hanging-fruit)
|
||||||
|
- [Level 2: Digging into Commits](#level-2-digging-into-commits)
|
||||||
|
- [The `.patch` Method](#the-patch-method)
|
||||||
|
- [The API Events Method](#the-api-events-method)
|
||||||
|
- [The Verification Loop: Linking Email to Account](#the-verification-loop-linking-email-to-account)
|
||||||
|
- [The Email Spoofing Method](#the-email-spoofing-method)
|
||||||
|
- [The Search Index: Finding Hidden Contributions](#the-search-index-finding-hidden-contributions)
|
||||||
|
- [Level 3: Technical Metadata](#level-3-technical-metadata)
|
||||||
|
- [SSH Keys](#ssh-keys)
|
||||||
|
- [GPG Keys](#gpg-keys)
|
||||||
|
- [Level 4: Connecting the Dots](#level-4-connecting-the-dots)
|
||||||
|
- [Automating the Hunt: Github-Recon](#automating-the-hunt-github-recon)
|
||||||
|
- [Conclusion and Protection: How to Stay Anonymous](#conclusion-and-protection-how-to-stay-anonymous)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
In the world of Open-Source Intelligence (OSINT), we often focus on social media platforms like Twitter or LinkedIn. However, developers frequently leave behind much more detailed personal information on **Github**.
|
||||||
|
|
||||||
|
Whether you are a recruiter, a security researcher, or a digital investigator, Github is a goldmine. Why? Because while a user might choose a cryptic handle like `anotherhadi`, their Git configuration often reveals their real name and email address.
|
||||||
|
|
||||||
|
## Level 1: The Low-Hanging Fruit
|
||||||
|
|
||||||
|
Before diving into technical exploits, start with the obvious. Many users forget how much they have shared in their profile settings.
|
||||||
|
|
||||||
|
- **The Bio & Location**: Even a vague location like "Montpellier, France," combined with a niche tech stack (e.g., "COBOL expert"), significantly narrows down the search.
|
||||||
|
- **External Links**: Check the personal website or blog link. Run a WHOIS lookup on that domain to find registration details. Use other OSINT tools and techniques on those websites to pivot further.
|
||||||
|
- **The Profile Picture**: Right-click the avatar and use Google Reverse Image Search, Yandex, or other reverse image engines. Developers often use the same professional headshot on Github as they do on LinkedIn.
|
||||||
|
|
||||||
|
## Level 2: Digging into Commits
|
||||||
|
|
||||||
|
This is the **most effective OSINT** method. While Github masks author names and emails in the web view, this information is permanently embedded in the commit metadata.
|
||||||
|
|
||||||
|
### The `.patch` Method
|
||||||
|
|
||||||
|
Find a repository where the target has contributed. Open any commit they made, and simply add `.patch` to the end of the URL.
|
||||||
|
|
||||||
|
- **URL**: `https://github.com/{username}/{repo}/commit/{commit_hash}.patch`
|
||||||
|
- Look at the `From:` line. It should look like this: `From: John Doe <[email protected]>`
|
||||||
|
|
||||||
|
For example, check: [github.com/anotherhadi/nixy/commit/e6873e8caae491073d8ab7daad9d2e50a04490ce.patch](https://github.com/anotherhadi/nixy/commit/e6873e8caae491073d8ab7daad9d2e50a04490ce.patch)
|
||||||
|
|
||||||
|
### The API Events Method
|
||||||
|
|
||||||
|
If you cannot find a recent commit, check their **public activity** stream via the Github API.
|
||||||
|
|
||||||
|
- **Go to**: `https://api.github.com/users/{target_username}/events/public`
|
||||||
|
- Search (Ctrl+F) for the word `email`. You will often find the **email address** associated with their `PushEvent` headers, even if they have "Keep my email addresses private" enabled in their current settings.
|
||||||
|
|
||||||
|
## The Verification Loop: Linking Email to Account
|
||||||
|
|
||||||
|
If you have found an email address and want to be 100% sure it belongs to a specific Github profile, you can use Github’s own attribution engine against itself.
|
||||||
|
|
||||||
|
### The Email Spoofing Method
|
||||||
|
|
||||||
|
While the previous methods help you find an email _from_ a profile, this technique does the opposite: it identifies which Github account is linked to a specific email address.
|
||||||
|
|
||||||
|
**How it works:**
|
||||||
|
Github attributes commits based on the email address found in the Git metadata. If you push a commit using a specific email, Github will automatically link that commit to the account associated with that address as its **primary email**.
|
||||||
|
|
||||||
|
**The Process:**
|
||||||
|
|
||||||
|
1. **Initialize a local repo:** `git init investigation`
|
||||||
|
2. **Configure the target email:** `git config user.email "[email protected]"` and `git config user.name "A Username"`
|
||||||
|
3. **Create a dummy commit:** `echo "test" > probe.txt && git add . && git commit -m "Probe"`
|
||||||
|
4. **Push to a repo you own:** Create a new empty repository on your Github account and push the code there.
|
||||||
|
5. **Observe the result:** Go to the commit history on the Github web interface. The avatar and username of the account linked to that email will appear as the author of the commit.
|
||||||
|
|
||||||
|
> **Note:** This method only works if the target email is set as the **Primary Email** on the user's account. It is a foolproof way to confirm if an email address you found elsewhere belongs to a specific Github user.
|
||||||
|
|
||||||
|
### The Search Index: Finding Hidden Contributions
|
||||||
|
|
||||||
|
Even if an email address is not listed on a user's profile, it may still be indexed within Github's global search.
|
||||||
|
Github allows you to filter search results by the metadata fields of a commit.
|
||||||
|
This is particularly useful if the target has **contributed to public repositories** using their real email.
|
||||||
|
|
||||||
|
You can use these specific qualifiers in the **Github search bar** (select the "Commits" tab):
|
||||||
|
|
||||||
|
- `author-email:[email protected]`: Finds commits where the target is the original author.
|
||||||
|
- `committer-email:[email protected]`: Finds commits where the target was the one who committed the code (sometimes different from the author).
|
||||||
|
|
||||||
|
## Level 3: Technical Metadata
|
||||||
|
|
||||||
|
If the email is masked or missing, we can look at the **cryptographic keys** the user uses to communicate with Github.
|
||||||
|
|
||||||
|
### SSH Keys
|
||||||
|
|
||||||
|
Every user’s public **SSH keys are public**.
|
||||||
|
|
||||||
|
- **URL**: `https://github.com/{username}.keys`
|
||||||
|
- **The Pivot**: You can take the key string and search for it on platforms like **Censys** or **Shodan**. If that same key is authorized on a specific server IP, you have successfully located the user’s infrastructure.
|
||||||
|
|
||||||
|
### GPG Keys
|
||||||
|
|
||||||
|
If a user signs their commits, their **GPG key** is available at:
|
||||||
|
|
||||||
|
- **URL**: `https://github.com/{username}.gpg`
|
||||||
|
- **The Reveal**: Import this key into your local GPG tool (`gpg --import`). It will often reveal the **Verified Identity** and the primary email address linked to the encryption key.
|
||||||
|
|
||||||
|
## Level 4: Connecting the Dots
|
||||||
|
|
||||||
|
Once you have a **name**, an **email**, or a **unique username**, it’s time to _pivot_.
|
||||||
|
|
||||||
|
- **Username Pivoting**: Use tools like [Sherlock](https://github.com/sherlock-project/sherlock) or [Maigret](https://github.com/soxoj/maigret/) to search for the same username across hundreds of other platforms. Developers are creatures of habit; they likely use the same handle on Stack Overflow, Reddit, or even old gaming forums.
|
||||||
|
- **Email Pivoting**: Use tools like [holehe](https://github.com/megadose/holehe) to find other accounts registered with the email addresses you just uncovered.
|
||||||
|
|
||||||
|
## Automating the Hunt: Github-Recon
|
||||||
|
|
||||||
|
If you want to move from manual investigation to automated intelligence, check out [Github-Recon](https://github.com/anotherhadi/github-recon).
|
||||||
|
Written in Go, this powerful CLI tool aggregates public OSINT data by automating the techniques mentioned above and more. Whether you start with a username or a single email address, it can retrieve SSH/GPG keys, enumerate social accounts, and find "close friends" based on interactions.
|
||||||
|
Its standout features include a **Deep Scan** mode-which clones repositories to perform regex searches and TruffleHog secret detection—and an automated **Email Spoofing** engine that instantly identifies the account linked to any primary email address.
|
||||||
|
|
||||||
|
## Conclusion and Protection: How to Stay Anonymous
|
||||||
|
|
||||||
|
If you are a developer reading this, you might be feeling exposed.
|
||||||
|
Understanding what information about you is publicly visible is the **first step to managing your online presence**. This guide and tools like [github-recon](https://github.com/anotherhadi/github-recon) can help you identify your own publicly available data on Github. Here’s how you can take steps to protect your privacy and security:
|
||||||
|
|
||||||
|
- **Review your public profile**: Regularly check your Github profile and
|
||||||
|
repositories to ensure that you are not unintentionally exposing sensitive
|
||||||
|
information.
|
||||||
|
- **Manage email exposure**: Use Github's settings to control which email
|
||||||
|
addresses are visible on your profile and in commit history. You can also **use
|
||||||
|
a no-reply email** address for commits, and an
|
||||||
|
[alias email](https://proton.me/support/addresses-and-aliases) for your
|
||||||
|
account. Delete/modify any sensitive information in your commit history.
|
||||||
|
- **Be Mindful of Repository Content**: **Avoid including sensitive information** in
|
||||||
|
your repositories, such as API keys, passwords, emails or personal data. Use
|
||||||
|
`.gitignore` to exclude files that contain sensitive information.
|
||||||
|
|
||||||
|
You can also use a tool like [TruffleHog](github.com/trufflesecurity/trufflehog)
|
||||||
|
to scan your repositories specifically for exposed secrets and tokens.
|
||||||
|
|
||||||
|
**Useful links:**
|
||||||
|
|
||||||
|
- [Blocking command line pushes that expose your personal email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/blocking-command-line-pushes-that-expose-your-personal-email-address)
|
||||||
|
- [No-reply email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/setting-your-commit-email-address)
|
||||||
|
|
||||||
|
In OSINT, the best hidden secrets are the ones we forget we ever shared. Happy hunting!
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
If you enjoyed this guide, please like and share it! Your support helps me create more infosec & OSINT content.
|
||||||
|
|
||||||
|
Have questions or feedback? Feel free to reach out: anotherhadi.clapped234[at]passmail.net
|
||||||
Generated
+65
@@ -0,0 +1,65 @@
|
|||||||
|
{
|
||||||
|
"nodes": {
|
||||||
|
"flake-compat": {
|
||||||
|
"flake": false,
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1767039857,
|
||||||
|
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "flake-compat",
|
||||||
|
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "flake-compat",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"git-hooks": {
|
||||||
|
"inputs": {
|
||||||
|
"flake-compat": "flake-compat",
|
||||||
|
"nixpkgs": [
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1787424939,
|
||||||
|
"narHash": "sha256-O2tBn84NNuHrnqNVxx/XqsXwfYvS1YwBh+7CBnbCYsk=",
|
||||||
|
"owner": "cachix",
|
||||||
|
"repo": "git-hooks.nix",
|
||||||
|
"rev": "809414f0cdadf82cf11b06c2b29ba9b3168b3297",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "cachix",
|
||||||
|
"repo": "git-hooks.nix",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nixpkgs": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1787736819,
|
||||||
|
"narHash": "sha256-cV5xEJJK3BvhU8rEd4mC9UsmDi5qscv/kzGPhBRC5WA=",
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "9fbb54b33e91ee4ca368e35a78e0613c720600b3",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "NixOS",
|
||||||
|
"ref": "nixos-unstable",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"root": {
|
||||||
|
"inputs": {
|
||||||
|
"git-hooks": "git-hooks",
|
||||||
|
"nixpkgs": "nixpkgs"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"root": "root",
|
||||||
|
"version": 7
|
||||||
|
}
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
{
|
||||||
|
description = "";
|
||||||
|
|
||||||
|
inputs = {
|
||||||
|
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
|
||||||
|
git-hooks = {
|
||||||
|
url = "github:cachix/git-hooks.nix";
|
||||||
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
outputs = {
|
||||||
|
self,
|
||||||
|
nixpkgs,
|
||||||
|
git-hooks,
|
||||||
|
}: let
|
||||||
|
supportedSystems = ["x86_64-linux" "aarch64-linux"];
|
||||||
|
|
||||||
|
forAllSystems = f:
|
||||||
|
nixpkgs.lib.genAttrs supportedSystems
|
||||||
|
(system: f system (import nixpkgs {inherit system;}));
|
||||||
|
in {
|
||||||
|
devShells = forAllSystems (system: pkgs: let
|
||||||
|
hooks = git-hooks.lib.${system}.run {
|
||||||
|
src = ./.;
|
||||||
|
hooks = {
|
||||||
|
gen-readme = {
|
||||||
|
enable = true;
|
||||||
|
name = "gen-readme";
|
||||||
|
entry = "python3 .github/scripts/gen-readme.py";
|
||||||
|
language = "system";
|
||||||
|
files = "\\.md$";
|
||||||
|
excludes = ["^\\.github/" "^README\\.md$"];
|
||||||
|
pass_filenames = false;
|
||||||
|
before = ["doctoc"];
|
||||||
|
};
|
||||||
|
|
||||||
|
doctoc = {
|
||||||
|
enable = true;
|
||||||
|
name = "doctoc";
|
||||||
|
entry = "python3 .github/scripts/doctoc-all.py";
|
||||||
|
language = "system";
|
||||||
|
files = "\\.md$";
|
||||||
|
excludes = ["^\\.github/"];
|
||||||
|
pass_filenames = false;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
in {
|
||||||
|
default = pkgs.mkShell {
|
||||||
|
packages = with pkgs; [doctoc] ++ hooks.enabledPackages;
|
||||||
|
|
||||||
|
shellHook = hooks.shellHook;
|
||||||
|
};
|
||||||
|
});
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,79 @@
|
|||||||
|
---
|
||||||
|
title: "GRUB Boot Bypass"
|
||||||
|
description: "Physical access techniques to get a root shell by editing GRUB boot parameters."
|
||||||
|
tags: ["linux", "grub", "physical-access", "privesc"]
|
||||||
|
publishDate: 2026-05-18
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Techniques](#techniques)
|
||||||
|
- [init=/bin/sh](#initbinsh)
|
||||||
|
- [init=/bin/bash](#initbinbash)
|
||||||
|
- [rd.break (systemd)](#rdbreak-systemd)
|
||||||
|
- [single (single-user mode)](#single-single-user-mode)
|
||||||
|
- [systemd.unit=rescue.target](#systemdunitrescuetarget)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
When GRUB is not password-protected, anyone with physical access can edit boot parameters and bypass authentication entirely.
|
||||||
|
|
||||||
|
At the GRUB menu, press **`e`** to edit the selected entry. Modify the line starting with `linux`, then press **`F10`** to boot.
|
||||||
|
|
||||||
|
## Techniques
|
||||||
|
|
||||||
|
### init=/bin/sh
|
||||||
|
|
||||||
|
Replaces the init process with a shell; drops directly into a root shell before any login prompt.
|
||||||
|
|
||||||
|
```
|
||||||
|
linux ... init=/bin/sh
|
||||||
|
```
|
||||||
|
|
||||||
|
Filesystem is mounted read-only by default. Remount to make changes:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
mount -o remount,rw /
|
||||||
|
```
|
||||||
|
|
||||||
|
### init=/bin/bash
|
||||||
|
|
||||||
|
Same as above but uses bash. Add `rw` on the `linux` line to mount read-write from the start:
|
||||||
|
|
||||||
|
```
|
||||||
|
linux ... rw init=/bin/bash
|
||||||
|
```
|
||||||
|
|
||||||
|
### rd.break (systemd)
|
||||||
|
|
||||||
|
Interrupts the boot process in the initramfs, before the real root filesystem is mounted. Useful for resetting the root password.
|
||||||
|
|
||||||
|
```
|
||||||
|
linux ... rd.break
|
||||||
|
```
|
||||||
|
|
||||||
|
From the initramfs shell:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
mount -o remount,rw /sysroot
|
||||||
|
chroot /sysroot
|
||||||
|
passwd root
|
||||||
|
exit
|
||||||
|
```
|
||||||
|
|
||||||
|
### single (single-user mode)
|
||||||
|
|
||||||
|
Boots into maintenance mode. On some distros this drops to a root shell without a password prompt (not Debian/Ubuntu).
|
||||||
|
|
||||||
|
```
|
||||||
|
linux ... single
|
||||||
|
```
|
||||||
|
|
||||||
|
### systemd.unit=rescue.target
|
||||||
|
|
||||||
|
systemd equivalent of single-user mode: minimal services, root shell.
|
||||||
|
|
||||||
|
```
|
||||||
|
linux ... systemd.unit=rescue.target
|
||||||
|
```
|
||||||
@@ -0,0 +1,93 @@
|
|||||||
|
---
|
||||||
|
title: "Linux Privilege Escalation"
|
||||||
|
description: "Common misconfigurations and weaknesses to check when escalating privileges on Linux."
|
||||||
|
tags: ["linux", "privesc", "post-exploitation"]
|
||||||
|
publishDate: 2026-05-18
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Sudo](#sudo)
|
||||||
|
- [SUID / SGID](#suid--sgid)
|
||||||
|
- [Misconfiguration](#misconfiguration)
|
||||||
|
- [Cron Jobs](#cron-jobs)
|
||||||
|
- [Capabilities](#capabilities)
|
||||||
|
- [Kernel Exploits](#kernel-exploits)
|
||||||
|
- [LinPEAS / WinPEAS](#linpeas--winpeas)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
## Sudo
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo -l
|
||||||
|
```
|
||||||
|
|
||||||
|
Check [GTFOBins](https://gtfobins.github.io) for any listed binary.
|
||||||
|
|
||||||
|
If `env_keep+=LD_PRELOAD` is set:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# compile a shared lib that spawns a shell
|
||||||
|
gcc -fPIC -shared -o /tmp/shell.so shell.c -nostartfiles
|
||||||
|
sudo LD_PRELOAD=/tmp/shell.so <allowed_binary>
|
||||||
|
```
|
||||||
|
|
||||||
|
## SUID / SGID
|
||||||
|
|
||||||
|
```bash
|
||||||
|
find / -user root -perm -4000 -ls 2>/dev/null # SUID
|
||||||
|
find / -group root -perm -2000 -ls 2>/dev/null # SGID
|
||||||
|
```
|
||||||
|
|
||||||
|
Check any non-standard binary on GTFOBins.
|
||||||
|
|
||||||
|
## Misconfiguration
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# World-writable directories
|
||||||
|
find / -type d -perm -2 -ls 2>/dev/null
|
||||||
|
|
||||||
|
# World-writable files owned by root
|
||||||
|
find / -user root -perm -2 ! -type l -ls 2>/dev/null
|
||||||
|
```
|
||||||
|
|
||||||
|
## Cron Jobs
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cat /etc/crontab
|
||||||
|
ls -la /etc/cron.*
|
||||||
|
crontab -l
|
||||||
|
```
|
||||||
|
|
||||||
|
If a cron runs a script you can write to, replace its content:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
echo 'chmod +s /bin/bash' >> /path/to/script.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
If the cron uses a relative PATH and a directory is writable, drop a malicious binary earlier in `$PATH`.
|
||||||
|
|
||||||
|
## Capabilities
|
||||||
|
|
||||||
|
```bash
|
||||||
|
getcap -r / 2>/dev/null
|
||||||
|
```
|
||||||
|
|
||||||
|
Dangerous capabilities: `cap_setuid`, `cap_net_raw`, `cap_dac_override`.
|
||||||
|
Check [GTFOBins](https://gtfobins.github.io) for exploitation.
|
||||||
|
|
||||||
|
## Kernel Exploits
|
||||||
|
|
||||||
|
```bash
|
||||||
|
uname -r
|
||||||
|
searchsploit linux kernel $(uname -r)
|
||||||
|
```
|
||||||
|
|
||||||
|
## LinPEAS / WinPEAS
|
||||||
|
|
||||||
|
Automated enumeration scripts to surface privesc vectors quickly.
|
||||||
|
|
||||||
|
- [LinPEAS (linux)](https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS)
|
||||||
|
- [WinPEAS (windows)](https://github.com/peass-ng/PEASS-ng/tree/master/winPEAS)
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
---
|
||||||
|
title: "FTP"
|
||||||
|
description: "Enumeration, exploitation and post-exploitation techniques for FTP servers."
|
||||||
|
tags: ["ftp", "network", "service"]
|
||||||
|
publishDate: 2026-04-29
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Enumeration](#enumeration)
|
||||||
|
- [Banner grabbing](#banner-grabbing)
|
||||||
|
- [Nmap](#nmap)
|
||||||
|
- [Anonymous Login](#anonymous-login)
|
||||||
|
- [Brute Force](#brute-force)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
FTP runs on **port 21** (control) and uses a secondary data channel (port 20 for active, ephemeral port for passive).
|
||||||
|
Common implementations: vsftpd, ProFTPD, Pure-FTPd, FileZilla Server, IIS FTP.
|
||||||
|
|
||||||
|
## Enumeration
|
||||||
|
|
||||||
|
### Banner grabbing
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nc -nv $IP 21
|
||||||
|
ftp $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
The banner often reveals the software version: cross-reference with CVE databases.
|
||||||
|
|
||||||
|
### Nmap
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -sV -p 21 $IP
|
||||||
|
nmap -p 21 --script ftp-* $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
Key scripts:
|
||||||
|
|
||||||
|
- `ftp-anon`: checks anonymous login
|
||||||
|
- `ftp-bounce`: tests for FTP bounce attack
|
||||||
|
- `ftp-brute`: brute-force credentials
|
||||||
|
- `ftp-syst`: retrieves system info
|
||||||
|
|
||||||
|
## Anonymous Login
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ftp $IP
|
||||||
|
# Username: anonymous
|
||||||
|
# Password: <empty> or anonymous@
|
||||||
|
```
|
||||||
|
|
||||||
|
If allowed, list and download everything:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ls -la
|
||||||
|
mget *
|
||||||
|
```
|
||||||
|
|
||||||
|
Check for writable directories: you may be able to upload a webshell if FTP root overlaps with a web root.
|
||||||
|
|
||||||
|
## Brute Force
|
||||||
|
|
||||||
|
```bash
|
||||||
|
hydra -l $user -P ~/wordlists/rockyou.txt ftp://$IP
|
||||||
|
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M ftp
|
||||||
|
```
|
||||||
|
|
||||||
|
Try default credentials first: `admin:admin`, `ftp:ftp`, `user:password`.
|
||||||
@@ -0,0 +1,92 @@
|
|||||||
|
---
|
||||||
|
title: "NFS"
|
||||||
|
description: "Enumeration, mounting and privilege escalation techniques for NFS shares."
|
||||||
|
tags: ["nfs", "network", "service"]
|
||||||
|
publishDate: 2026-05-18
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Enumeration](#enumeration)
|
||||||
|
- [Nmap](#nmap)
|
||||||
|
- [List shares](#list-shares)
|
||||||
|
- [Mount](#mount)
|
||||||
|
- [Privilege Escalation](#privilege-escalation)
|
||||||
|
- [no_root_squash](#no_root_squash)
|
||||||
|
- [UID spoofing](#uid-spoofing)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
NFS (Network File System) runs on **port 2049** and allows remote filesystem mounting over the network.
|
||||||
|
Common on Linux/Unix environments. Access control is defined in `/etc/exports` on the server.
|
||||||
|
|
||||||
|
## Enumeration
|
||||||
|
|
||||||
|
### Nmap
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -sV -p 111,2049 $IP
|
||||||
|
nmap -p 111,2049 --script nfs-* $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
Key scripts:
|
||||||
|
|
||||||
|
- `nfs-showmount`: lists exported shares
|
||||||
|
- `nfs-ls`: lists files in shares
|
||||||
|
- `nfs-statfs`: retrieves disk stats
|
||||||
|
|
||||||
|
### List shares
|
||||||
|
|
||||||
|
```bash
|
||||||
|
showmount -e $IP
|
||||||
|
rpcinfo -p $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
## Mount
|
||||||
|
|
||||||
|
```bash
|
||||||
|
mkdir /mnt/nfs
|
||||||
|
mount -t nfs $IP:/share /mnt/nfs
|
||||||
|
mount -t nfs -o vers=2 $IP:/share /mnt/nfs # force NFSv2
|
||||||
|
umount /mnt/nfs
|
||||||
|
```
|
||||||
|
|
||||||
|
## Privilege Escalation
|
||||||
|
|
||||||
|
### no_root_squash
|
||||||
|
|
||||||
|
If the share is exported with `no_root_squash`, the remote root user keeps root privileges on the share.
|
||||||
|
|
||||||
|
Check `/etc/exports` on the server (if readable):
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cat /etc/exports
|
||||||
|
```
|
||||||
|
|
||||||
|
Look for:
|
||||||
|
|
||||||
|
```
|
||||||
|
/share *(rw,no_root_squash)
|
||||||
|
```
|
||||||
|
|
||||||
|
If present, copy a SUID binary onto the share as root from your attacker machine:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cp /bin/bash /mnt/nfs/bash
|
||||||
|
chmod +s /mnt/nfs/bash
|
||||||
|
```
|
||||||
|
|
||||||
|
Then execute it on the target with `-p` to keep the SUID effective UID:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
/tmp/nfs/bash -p
|
||||||
|
```
|
||||||
|
|
||||||
|
### UID spoofing
|
||||||
|
|
||||||
|
NFS authenticates by UID. If you know a file is owned by UID 1001 on the server, impersonate it directly:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
python3 -c "import os; os.setuid(1001); os.system('/bin/bash')"
|
||||||
|
```
|
||||||
+123
@@ -0,0 +1,123 @@
|
|||||||
|
---
|
||||||
|
title: "Nmap"
|
||||||
|
description: "Host discovery, port scanning, service detection and NSE scripting"
|
||||||
|
tags: ["nmap", "network", "enumeration"]
|
||||||
|
publishDate: 2026-05-18
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Host Discovery](#host-discovery)
|
||||||
|
- [Port Scanning](#port-scanning)
|
||||||
|
- [Service & Version Detection](#service--version-detection)
|
||||||
|
- [OS Detection](#os-detection)
|
||||||
|
- [Aggressive Scan](#aggressive-scan)
|
||||||
|
- [Timing Templates](#timing-templates)
|
||||||
|
- [NSE Scripts](#nse-scripts)
|
||||||
|
- [Output Formats](#output-formats)
|
||||||
|
- [Common Profiles](#common-profiles)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
Nmap is a network scanner used for host discovery, port scanning, service/version detection, OS fingerprinting, and vulnerability scripting via NSE.
|
||||||
|
|
||||||
|
## Host Discovery
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -sn 192.168.1.0/24 # ping sweep, no port scan
|
||||||
|
nmap -sn -PR 192.168.1.0/24 # ARP ping (local network)
|
||||||
|
nmap -Pn $IP # skip host discovery, treat as up
|
||||||
|
```
|
||||||
|
|
||||||
|
## Port Scanning
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap $IP # top 1000 ports (SYN scan if root)
|
||||||
|
nmap -p 80,443,8080 $IP # specific ports
|
||||||
|
nmap -p 1-65535 $IP # all ports
|
||||||
|
nmap -p- $IP # shorthand for all ports
|
||||||
|
nmap -sU $IP # UDP scan
|
||||||
|
nmap -sU -sS $IP # UDP + SYN together
|
||||||
|
```
|
||||||
|
|
||||||
|
Scan types:
|
||||||
|
|
||||||
|
- `-sS`: SYN scan (stealth, requires root)
|
||||||
|
- `-sT`: TCP connect scan (no root needed)
|
||||||
|
- `-sU`: UDP scan
|
||||||
|
- `-sA`: ACK scan (firewall rule mapping)
|
||||||
|
- `-sN/sF/sX`: Null, FIN, Xmas (evasion, unreliable on Windows)
|
||||||
|
|
||||||
|
## Service & Version Detection
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -sV $IP
|
||||||
|
nmap -sV --version-intensity 9 $IP # more aggressive probing
|
||||||
|
```
|
||||||
|
|
||||||
|
## OS Detection
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -O $IP
|
||||||
|
nmap -O --osscan-guess $IP # guess if not confident
|
||||||
|
```
|
||||||
|
|
||||||
|
## Aggressive Scan
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -A $IP # -sV -O --script=default --traceroute
|
||||||
|
```
|
||||||
|
|
||||||
|
## Timing Templates
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -T0 $IP # paranoid (IDS evasion, very slow)
|
||||||
|
nmap -T1 $IP # sneaky
|
||||||
|
nmap -T3 $IP # normal (default)
|
||||||
|
nmap -T4 $IP # aggressive (faster, good for CTFs)
|
||||||
|
nmap -T5 $IP # insane (may miss results)
|
||||||
|
```
|
||||||
|
|
||||||
|
## NSE Scripts
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap --script default $IP
|
||||||
|
nmap --script vuln $IP
|
||||||
|
nmap --script "ftp-*" $IP
|
||||||
|
nmap --script safe $IP
|
||||||
|
nmap --script $script --script-args user=$user,pass=$password $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
Common script categories: `auth`, `brute`, `default`, `discovery`, `dos`, `exploit`, `intrusive`, `safe`, `version`, `vuln`.
|
||||||
|
|
||||||
|
Scripts are located in `/usr/share/nmap/scripts/`.
|
||||||
|
|
||||||
|
## Output Formats
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -oN output.txt $IP # normal
|
||||||
|
nmap -oX output.xml $IP # XML
|
||||||
|
nmap -oG output.gnmap $IP # grepable
|
||||||
|
nmap -oA output $IP # all three at once
|
||||||
|
```
|
||||||
|
|
||||||
|
## Common Profiles
|
||||||
|
|
||||||
|
Quick full scan:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -p- -T4 --min-rate 5000 -sV -sC -oA full $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
CTF/lab initial recon:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -sV -sC -p- --open $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
UDP top ports:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -sU --top-ports 100 $IP
|
||||||
|
```
|
||||||
@@ -0,0 +1,54 @@
|
|||||||
|
---
|
||||||
|
title: "RDP"
|
||||||
|
description: "Enumeration, exploitation and post-exploitation techniques for RDP servers."
|
||||||
|
tags: ["rdp", "network", "service"]
|
||||||
|
publishDate: 2026-05-04
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Enumeration](#enumeration)
|
||||||
|
- [Banner grabbing](#banner-grabbing)
|
||||||
|
- [Connect](#connect)
|
||||||
|
- [Brute Force](#brute-force)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
RDP (Remote Desktop Protocol) runs on **port 3389** and provides a graphical remote session.
|
||||||
|
Common on Windows servers and workstations.
|
||||||
|
|
||||||
|
## Enumeration
|
||||||
|
|
||||||
|
### Banner grabbing
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -sV -p 3389 $IP
|
||||||
|
nmap -p 3389 --script rdp-* $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
Key scripts:
|
||||||
|
|
||||||
|
- `rdp-enum-encryption`: checks encryption level
|
||||||
|
- `rdp-vuln-ms12-020`: tests for MS12-020 DoS vulnerability
|
||||||
|
|
||||||
|
## Connect
|
||||||
|
|
||||||
|
```bash
|
||||||
|
xfreerdp /u:$user /p:$password /v:$IP
|
||||||
|
xfreerdp /u:$user /p:$password /v:$IP /cert:ignore
|
||||||
|
rdesktop $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
Pass the hash directly (no plaintext password needed):
|
||||||
|
|
||||||
|
```bash
|
||||||
|
xfreerdp /u:$user /pth:$hash /v:$IP
|
||||||
|
```
|
||||||
|
|
||||||
|
## Brute Force
|
||||||
|
|
||||||
|
```bash
|
||||||
|
hydra -l $user -P ~/wordlists/rockyou.txt rdp://$IP
|
||||||
|
crowbar -b rdp -s $IP/32 -u $user -C ~/wordlists/rockyou.txt
|
||||||
|
```
|
||||||
@@ -0,0 +1,85 @@
|
|||||||
|
---
|
||||||
|
title: "SSH"
|
||||||
|
description: "Enumeration, exploitation and post-exploitation techniques for SSH servers."
|
||||||
|
tags: ["ssh", "network", "service"]
|
||||||
|
publishDate: 2026-05-04
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Enumeration](#enumeration)
|
||||||
|
- [Banner grabbing](#banner-grabbing)
|
||||||
|
- [Nmap](#nmap)
|
||||||
|
- [Connect](#connect)
|
||||||
|
- [Brute Force](#brute-force)
|
||||||
|
- [Key-Based Auth](#key-based-auth)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
SSH runs on **port 22** and provides an encrypted remote shell.
|
||||||
|
Common implementations: OpenSSH, Dropbear, Bitvise.
|
||||||
|
|
||||||
|
## Enumeration
|
||||||
|
|
||||||
|
### Banner grabbing
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nc -nv $IP 22
|
||||||
|
ssh $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
The banner reveals the software and version (e.g. `OpenSSH_9.2`).
|
||||||
|
|
||||||
|
### Nmap
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -sV -p 22 $IP
|
||||||
|
nmap -p 22 --script ssh-* $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
Key scripts:
|
||||||
|
|
||||||
|
- `ssh-hostkey`: retrieves the server's public key
|
||||||
|
- `ssh-auth-methods`: lists accepted authentication methods
|
||||||
|
- `ssh-brute`: brute-force credentials
|
||||||
|
|
||||||
|
## Connect
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh $user@$IP
|
||||||
|
ssh -p 2222 $user@$IP
|
||||||
|
ssh -i id_rsa $user@$IP
|
||||||
|
```
|
||||||
|
|
||||||
|
## Brute Force
|
||||||
|
|
||||||
|
```bash
|
||||||
|
hydra -l $user -P ~/wordlists/rockyou.txt ssh://$IP
|
||||||
|
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M ssh
|
||||||
|
```
|
||||||
|
|
||||||
|
Only viable if password auth is enabled. Check with:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh -v $user@$IP
|
||||||
|
```
|
||||||
|
|
||||||
|
Look for `publickey,password` in the output.
|
||||||
|
|
||||||
|
## Key-Based Auth
|
||||||
|
|
||||||
|
If you find a private key (`id_rsa`), set permissions and connect:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
chmod 600 id_rsa
|
||||||
|
ssh -i id_rsa $user@$IP
|
||||||
|
```
|
||||||
|
|
||||||
|
If the key is encrypted, crack the passphrase:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh2john id_rsa > hash.txt
|
||||||
|
john hash.txt --wordlist=~/wordlists/rockyou.txt
|
||||||
|
hashcat -m 22921 hash.txt ~/wordlists/rockyou.txt
|
||||||
|
```
|
||||||
@@ -0,0 +1,61 @@
|
|||||||
|
---
|
||||||
|
title: "Telnet"
|
||||||
|
description: "Enumeration, exploitation and post-exploitation techniques for Telnet servers."
|
||||||
|
tags: ["telnet", "network", "service"]
|
||||||
|
publishDate: 2026-05-04
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Enumeration](#enumeration)
|
||||||
|
- [Banner grabbing](#banner-grabbing)
|
||||||
|
- [Nmap](#nmap)
|
||||||
|
- [Connect](#connect)
|
||||||
|
- [Brute Force](#brute-force)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
Telnet runs on **port 23** and transmits all data (including credentials) in **cleartext**.
|
||||||
|
Common on embedded devices, legacy systems, routers, and IoT equipment.
|
||||||
|
|
||||||
|
## Enumeration
|
||||||
|
|
||||||
|
### Banner grabbing
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nc -nv $IP 23
|
||||||
|
telnet $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
The banner often reveals the OS, hostname, or device type.
|
||||||
|
|
||||||
|
### Nmap
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmap -sV -p 23 $IP
|
||||||
|
nmap -p 23 --script telnet-* $IP
|
||||||
|
```
|
||||||
|
|
||||||
|
Key scripts:
|
||||||
|
|
||||||
|
- `telnet-ntlm-info`: extracts NTLM info (Windows targets)
|
||||||
|
- `telnet-brute`: brute-force credentials
|
||||||
|
|
||||||
|
## Connect
|
||||||
|
|
||||||
|
```bash
|
||||||
|
telnet $IP
|
||||||
|
telnet $IP 23
|
||||||
|
```
|
||||||
|
|
||||||
|
Login with `user` / `password`. Session is fully interactive once authenticated.
|
||||||
|
|
||||||
|
## Brute Force
|
||||||
|
|
||||||
|
```bash
|
||||||
|
hydra -l $user -P ~/wordlists/rockyou.txt telnet://$IP
|
||||||
|
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M telnet
|
||||||
|
```
|
||||||
|
|
||||||
|
Try default credentials first. Routers and embedded devices commonly ship with `admin:admin`, `root:root`, or blank passwords.
|
||||||
@@ -0,0 +1,116 @@
|
|||||||
|
---
|
||||||
|
title: "Bluesky"
|
||||||
|
description: "Enumeration, search operators, API endpoints and tools for investigating Bluesky accounts."
|
||||||
|
tags: ["osint", "bluesky", "social-media", "enumeration"]
|
||||||
|
publishDate: 2026-04-29
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Key Concepts](#key-concepts)
|
||||||
|
- [Account Enumeration](#account-enumeration)
|
||||||
|
- [Resolve handle → DID](#resolve-handle-%E2%86%92-did)
|
||||||
|
- [Resolve DID → history (all past handles, keys, creation date)](#resolve-did-%E2%86%92-history-all-past-handles-keys-creation-date)
|
||||||
|
- [Get profile metadata](#get-profile-metadata)
|
||||||
|
- [Followers / following](#followers--following)
|
||||||
|
- [Search Operators](#search-operators)
|
||||||
|
- [API equivalent](#api-equivalent)
|
||||||
|
- [Google Dorks](#google-dorks)
|
||||||
|
- [Tools](#tools)
|
||||||
|
- [BlueSkyNet](#blueskynet)
|
||||||
|
- [ClearSky](#clearsky)
|
||||||
|
- [plc.directory](#plcdirectory)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
## Key Concepts
|
||||||
|
|
||||||
|
Bluesky is built on the **AT Protocol**. Every account has two identifiers:
|
||||||
|
|
||||||
|
- **Handle**: `user.bsky.social` or a custom domain (can change)
|
||||||
|
- **DID**: `did:plc:ewvi7nxzyoun6zhxrhs64oiz` (permanent, survives handle changes)
|
||||||
|
|
||||||
|
All public content is accessible **without an account**. Follower/following lists are also public by default.
|
||||||
|
|
||||||
|
## Account Enumeration
|
||||||
|
|
||||||
|
### Resolve handle → DID
|
||||||
|
|
||||||
|
```
|
||||||
|
https://bsky.social/xrpc/com.atproto.identity.resolveHandle?handle=$HANDLE
|
||||||
|
```
|
||||||
|
|
||||||
|
### Resolve DID → history (all past handles, keys, creation date)
|
||||||
|
|
||||||
|
```
|
||||||
|
https://plc.directory/$DID
|
||||||
|
```
|
||||||
|
|
||||||
|
### Get profile metadata
|
||||||
|
|
||||||
|
```
|
||||||
|
https://public.api.bsky.app/xrpc/app.bsky.actor.getProfile?actor=$HANDLE
|
||||||
|
```
|
||||||
|
|
||||||
|
Returns: DID, display name, description, follower/following count, creation date, avatar URL.
|
||||||
|
|
||||||
|
### Followers / following
|
||||||
|
|
||||||
|
```
|
||||||
|
https://public.api.bsky.app/xrpc/app.bsky.graph.getFollowers?actor=$HANDLE&limit=100
|
||||||
|
https://public.api.bsky.app/xrpc/app.bsky.graph.getFollows?actor=$HANDLE&limit=100
|
||||||
|
```
|
||||||
|
|
||||||
|
Paginate with the `cursor` field from the response.
|
||||||
|
|
||||||
|
## Search Operators
|
||||||
|
|
||||||
|
Bluesky's full-text search supports these operators (combinable):
|
||||||
|
|
||||||
|
| Operator | Example | Effect |
|
||||||
|
| ----------- | ----------------------------- | ----------------------------- |
|
||||||
|
| `"..."` | `"exact phrase"` | Exact match |
|
||||||
|
| `from:` | `from:handle.bsky.social` | Posts by user |
|
||||||
|
| `mentions:` | `mentions:handle.bsky.social` | Posts mentioning user |
|
||||||
|
| `since:` | `since:2024-01-01` | After date (UTC, YYYY-MM-DD) |
|
||||||
|
| `until:` | `until:2024-06-30` | Before date (UTC, YYYY-MM-DD) |
|
||||||
|
| `lang:` | `lang:fr` | Language (ISO 639-1) |
|
||||||
|
| `domain:` | `domain:github.com` | Posts linking to domain |
|
||||||
|
| `#tag` | `#osint` | Hashtag |
|
||||||
|
|
||||||
|
#### API equivalent
|
||||||
|
|
||||||
|
```
|
||||||
|
https://public.api.bsky.app/xrpc/app.bsky.feed.searchPosts?q={QUERY}&author={HANDLE}&since=2024-01-01&until=2024-12-31&lang=en&limit=25
|
||||||
|
```
|
||||||
|
|
||||||
|
## Google Dorks
|
||||||
|
|
||||||
|
Bluesky is heavily indexed by Google. Useful for finding profiles and posts without touching the platform:
|
||||||
|
|
||||||
|
```
|
||||||
|
site:bsky.app "$TARGET_NAME"
|
||||||
|
site:bsky.app "$TARGET_NAME" inurl:profile
|
||||||
|
site:bsky.app "$KEYWORD" since:2024-01-01
|
||||||
|
```
|
||||||
|
|
||||||
|
## Tools
|
||||||
|
|
||||||
|
### BlueSkyNet
|
||||||
|
|
||||||
|
Web app for searching and exporting Bluesky data to CSV. Wraps the public API with a UI for advanced search filters.
|
||||||
|
|
||||||
|
- [github.com/jakecreps/blueskynet](https://github.com/jakecreps/blueskynet)
|
||||||
|
|
||||||
|
### ClearSky
|
||||||
|
|
||||||
|
Shows block lists, blocking history, and who blocked a given account. Useful for mapping relationships and adversarial clusters.
|
||||||
|
|
||||||
|
- [clearsky.app](https://clearsky.app)
|
||||||
|
|
||||||
|
### plc.directory
|
||||||
|
|
||||||
|
Official DID PLC directory. Lookup a DID to get full account history: creation date, all past handles, key rotations.
|
||||||
|
|
||||||
|
- [plc.directory](https://plc.directory)
|
||||||
@@ -0,0 +1,79 @@
|
|||||||
|
---
|
||||||
|
title: "Information Gathering"
|
||||||
|
description: "Essential cybersecurity cheatsheet for Information Gathering and Open Source Intelligence (OSINT). Discover data related to emails, domains, usernames, and images using both command line and online tools."
|
||||||
|
tags: ["osint", "enumeration", "information-gathering"]
|
||||||
|
publishDate: 2026-05-03
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [IKnowYou](#iknowyou)
|
||||||
|
- [Command line tools](#command-line-tools)
|
||||||
|
- [Online tools](#online-tools)
|
||||||
|
- [OSINT Aggregation Tool](#osint-aggregation-tool)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
**Information Gathering**, often referred to as **Open Source Intelligence (OSINT)** in the context of ethical hacking, is the systematic collection and analysis of publicly available data about a target, providing the foundational knowledge necessary to identify potential vulnerabilities and craft targeted security assessments.
|
||||||
|
|
||||||
|
## Command line tools
|
||||||
|
|
||||||
|
| **From** | **Use** |
|
||||||
|
| --------- | ----------------------------------------------------------------------------------------------- |
|
||||||
|
| Email | `holehe $email` |
|
||||||
|
| | `ghunt email $email` (for google account) |
|
||||||
|
| | `github-recon $email` ([link](http://github.com/anotherhadi/github-recon/), for github account) |
|
||||||
|
| Domain | `theHarvester -d $domain -l 100` |
|
||||||
|
| | `theHarvester -d $domain -l 100 -b all` (full) |
|
||||||
|
| Username | `sherlock $username` |
|
||||||
|
| Image | `exiftool $imagePath` |
|
||||||
|
| Instagram | `instaloader profile $username` |
|
||||||
|
| Github | `trufflehog github --org=$usernameOrOrg` |
|
||||||
|
| | `github-recon $username` ([link](http://github.com/anotherhadi/github-recon/)) |
|
||||||
|
|
||||||
|
## Online tools
|
||||||
|
|
||||||
|
| **For** | **Use** |
|
||||||
|
| ---------- | ------------------------------------------------------ |
|
||||||
|
| Visualiser | [OSINTracker](https://www.osintracker.com/) |
|
||||||
|
| IP | [Shodan](https://www.shodan.io/) |
|
||||||
|
| | [Censys](https://search.censys.io/) |
|
||||||
|
| Domain | [Whois](https://www.whois.com/whois/) |
|
||||||
|
| | [crt.sh](https://crt.sh/) (certificate transparency) |
|
||||||
|
| Name | [Webmii](https://webmii.com/) |
|
||||||
|
| | [BreachDirectory](https://breachdirectory.org/) |
|
||||||
|
| | [LeakLookup](https://leak-lookup.com/search) |
|
||||||
|
| | [IntelX](https://intelx.io/) |
|
||||||
|
| | [Genealogic.review](https://genealogic.review/) |
|
||||||
|
| SSID | [Wigle](https://wigle.net/) |
|
||||||
|
| Image | [PimEyes (faces)](https://pimeyes.com/) |
|
||||||
|
| | [Lenso (faces)](https://lenso.ai) |
|
||||||
|
| | [TinEye](https://tineye.com) |
|
||||||
|
| | [Pic2Map (exif geolocation)](https://www.pic2map.com/) |
|
||||||
|
| Username | [DeHashed](https://dehashed.com/search) |
|
||||||
|
| | [BreachDirectory](https://breachdirectory.org/) |
|
||||||
|
| | [IntelX](https://intelx.io/) |
|
||||||
|
| | [LeakLookup](https://leak-lookup.com/search) |
|
||||||
|
| | [Oathnet](https://oathnet.org/) |
|
||||||
|
| Email | [DeHashed](https://dehashed.com/search) |
|
||||||
|
| | [Hunter](https://hunter.io/) |
|
||||||
|
| | [HaveIBeenPwned](https://haveibeenpwned.com/) |
|
||||||
|
| | [BreachDirectory](https://breachdirectory.org/) |
|
||||||
|
| | [LeakLookup](https://leak-lookup.com/search) |
|
||||||
|
| | [IntelX](https://intelx.io/) |
|
||||||
|
| | [Oathnet](https://oathnet.org/) |
|
||||||
|
| Phone | [Epieos](https://epieos.com/) |
|
||||||
|
| Instagram | [Dumpor](https://dumpor.io/) |
|
||||||
|
| Misc | [Goosint](https://goosint.com/) |
|
||||||
|
| | [OSINT Framework](https://osintframework.com/) |
|
||||||
|
| | [OSINT Dojo](https://osintdojo.com/) |
|
||||||
|
|
||||||
|
## OSINT Aggregation Tool
|
||||||
|
|
||||||
|
<a href="https://iknowyou.hadi.icu" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>IKnowYou</h4>
|
||||||
|
<p>Self-hosted OSINT aggregation platform: Run dozens of open-source intelligence tools against a single target in parallel; all from one clean web interface.</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
---
|
||||||
|
title: "Sock Puppets"
|
||||||
|
description: "Essential cheatsheet on creating and managing Sock Puppets (fake identities) for ethical security research and Open Source Intelligence (OSINT), focusing on maintaining separation from personal data and bypassing common verification."
|
||||||
|
tags: ["osint", "sock-puppets"]
|
||||||
|
publishDate: 2026-05-03
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Sms 4 Sats (Onion)](#sms-4-sats-onion)
|
||||||
|
- [Faker](#faker)
|
||||||
|
- [Fake Name](#fake-name)
|
||||||
|
- [This Person Does Not Exist](#this-person-does-not-exist)
|
||||||
|
- [SMSPool](#smspool)
|
||||||
|
- [Receive Sms Online](#receive-sms-online)
|
||||||
|
- [Receive Free Sms](#receive-free-sms)
|
||||||
|
- [Receive Free Sms](#receive-free-sms-1)
|
||||||
|
- [Online Sim](#online-sim)
|
||||||
|
- [Sms 4 Sats](#sms-4-sats)
|
||||||
|
- [Information generation](#information-generation)
|
||||||
|
- [Bypass phone verification](#bypass-phone-verification)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
Sock puppets are fake identities use to gather information from a target.
|
||||||
|
The sock puppet should have no link between your personal information and the fakes ones. (No ip address, mail, follow, etc..)
|
||||||
|
|
||||||
|
## Information generation
|
||||||
|
|
||||||
|
<a href="https://fakerjs.dev" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>Faker</h4>
|
||||||
|
<p>Generate massive amounts of fake data</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
|
|
||||||
|
<a href="https://fakenamegenerator.com/" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>Fake Name</h4>
|
||||||
|
<p>Personal informations</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
|
|
||||||
|
<a href="https://www.thispersondoesnotexist.com/" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>This Person Does Not Exist</h4>
|
||||||
|
<p>Generate fake image</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
|
|
||||||
|
## Bypass phone verification
|
||||||
|
|
||||||
|
<a href="https://www.smspool.net/" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>SMSPool</h4>
|
||||||
|
<p>Cheapest and Fastest Online SMS verification</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
|
|
||||||
|
<a href="https://receive-sms-online.info" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>Receive Sms Online</h4>
|
||||||
|
<p>Free SMS verification</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
|
|
||||||
|
<a href="https://receivefreesms.net" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>Receive Free Sms</h4>
|
||||||
|
<p>Free SMS verification</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
|
|
||||||
|
<a href="https://receive-smss.com" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>Receive Free Sms</h4>
|
||||||
|
<p>Free SMS verification</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
|
|
||||||
|
<a href="https://onlinesim.io/" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>Online Sim</h4>
|
||||||
|
<p>SMS verification with free tier</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
|
|
||||||
|
<a href="https://sms4stats.com/" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>Sms 4 Sats</h4>
|
||||||
|
<p>Paid SMS verification</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
|
|
||||||
|
<a href="http://sms4sat6y7lkq4vscloomatwyj33cfeddukkvujo2hkdqtmyi465spid.onion" class="link-card not-prose" target="_blank">
|
||||||
|
<span>
|
||||||
|
<h4>Sms 4 Sats (Onion)</h4>
|
||||||
|
<p>Paid SMS verification. Tor version</p>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
@@ -0,0 +1,54 @@
|
|||||||
|
---
|
||||||
|
title: "Tips"
|
||||||
|
description: "A cheatsheet of practical tips and unconventional methods for Open Source Intelligence (OSINT), focusing on advanced data visualization, information leakage detection, and utilizing web archives for historical data."
|
||||||
|
tags: ["osint"]
|
||||||
|
publishDate: 2026-05-03
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Visualisation](#visualisation)
|
||||||
|
- [Forgotten passwords](#forgotten-passwords)
|
||||||
|
- [Archive Search](#archive-search)
|
||||||
|
- [Google Cache](#google-cache)
|
||||||
|
- [Domain History](#domain-history)
|
||||||
|
- [Bookmarklets](#bookmarklets)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
## Visualisation
|
||||||
|
|
||||||
|
Use [OSINTracker](https://app.osintracker.com/) to visualise your findings.
|
||||||
|
It allows you to create a graph of your findings, which can help you see connections and relationships between different pieces of information.
|
||||||
|
|
||||||
|
## Forgotten passwords
|
||||||
|
|
||||||
|
To find email addresses and phone numbers associated with an account, you can click on "Forgot password?" on the login page of a website. Be careful, though, this creates notifications and can be detected by the target, and often gives your information away.
|
||||||
|
|
||||||
|
## Archive Search
|
||||||
|
|
||||||
|
- [Wayback Machine](https://web.archive.org) stores over 618 billion web captures
|
||||||
|
- [Archive.ph](https://archive.ph) creates on-demand snapshots, including for JS-heavy sites, with both a functional page and screenshot version
|
||||||
|
|
||||||
|
## Google Cache
|
||||||
|
|
||||||
|
Google keeps a cached version of most indexed pages. Access it with the `cache:` operator:
|
||||||
|
|
||||||
|
```
|
||||||
|
cache:example.com
|
||||||
|
cache:example.com/page
|
||||||
|
```
|
||||||
|
|
||||||
|
If the page has been taken down or modified, the cached version may still show the original content.
|
||||||
|
|
||||||
|
## Domain History
|
||||||
|
|
||||||
|
[VirusTotal](https://www.virustotal.com) shows the historical DNS records, subdomains, and associated IPs for any domaint useful when a site has moved or been taken down.
|
||||||
|
|
||||||
|
[ViewDNS.info](https://viewdns.info) covers WHOIS history, reverse IP, reverse MX, and port scans from a single interface.
|
||||||
|
|
||||||
|
## Bookmarklets
|
||||||
|
|
||||||
|
- [K2SOsint/Bookmarklets](https://github.com/K2SOsint/Bookmarklets)
|
||||||
|
- [tools.myosint.training](https://tools.myosint.training/)
|
||||||
@@ -0,0 +1,157 @@
|
|||||||
|
---
|
||||||
|
title: "X / Twitter"
|
||||||
|
description: "Enumeration, search operators, deleted content recovery and tools for investigating X accounts."
|
||||||
|
tags: ["osint", "twitter", "x", "social-media", "enumeration"]
|
||||||
|
publishDate: 2026-04-29
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [Key Concepts](#key-concepts)
|
||||||
|
- [Account Enumeration](#account-enumeration)
|
||||||
|
- [Handle to User ID](#handle-to-user-id)
|
||||||
|
- [Banner last update time](#banner-last-update-time)
|
||||||
|
- [Timestamp from ID (Snowflake)](#timestamp-from-id-snowflake)
|
||||||
|
- [Direct profile URL by ID](#direct-profile-url-by-id)
|
||||||
|
- [Search Operators](#search-operators)
|
||||||
|
- [Direct search URL](#direct-search-url)
|
||||||
|
- [Google Dorks](#google-dorks)
|
||||||
|
- [Deleted and Archived Content](#deleted-and-archived-content)
|
||||||
|
- [Wayback Machine](#wayback-machine)
|
||||||
|
- [Twayback](#twayback)
|
||||||
|
- [Profile history](#profile-history)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
## Key Concepts
|
||||||
|
|
||||||
|
Every account has two identifiers:
|
||||||
|
|
||||||
|
- **Handle**: `@username` (can change)
|
||||||
|
- **User ID**: numeric, permanent (survives handle changes and suspensions)
|
||||||
|
|
||||||
|
Unlike [Bluesky](/notes/osint/bluesky), X now requires a login to browse most content in the browser. The free API tier (v2) is severely limited. Most open-source scraping tools that bypassed the API (Twint, snscrape, GetOldTweets3) are broken since the 2023 API lockdown.
|
||||||
|
|
||||||
|
## Account Enumeration
|
||||||
|
|
||||||
|
### Handle to User ID
|
||||||
|
|
||||||
|
The user ID stays constant when someone changes their handle or gets suspended. Several web tools resolve it:
|
||||||
|
|
||||||
|
- [tweeterid.com](https://tweeterid.com/)
|
||||||
|
- [commentpicker.com/twitter-id.php](https://commentpicker.com/twitter-id.php)
|
||||||
|
|
||||||
|
Or via the profile page source: look for `"id_str"` in the page JSON.
|
||||||
|
|
||||||
|
### Banner last update time
|
||||||
|
|
||||||
|
The profile banner URL contains a Unix timestamp indicating when the banner was last changed:
|
||||||
|
|
||||||
|
```
|
||||||
|
https://pbs.twimg.com/profile_banners/{user_id}/{unix_timestamp}/600x200
|
||||||
|
```
|
||||||
|
|
||||||
|
Right-click the banner image and copy the URL, or inspect the page source. Convert the timestamp at [unixtimestamp.com](https://www.unixtimestamp.com/).
|
||||||
|
|
||||||
|
### Timestamp from ID (Snowflake)
|
||||||
|
|
||||||
|
Twitter IDs are Snowflake IDs: the numeric value encodes the exact creation time of a tweet or account. Extract it with:
|
||||||
|
|
||||||
|
```python
|
||||||
|
tweet_id = 1234567890123456789
|
||||||
|
timestamp_ms = (tweet_id >> 22) + 1288834974657
|
||||||
|
```
|
||||||
|
|
||||||
|
`1288834974657` is Twitter's custom epoch (Nov 4, 2010). Works on both tweet IDs and user IDs: useful to confirm account creation date without needing profile metadata.
|
||||||
|
|
||||||
|
Several online converters exist if you don't want to do it manually: search "snowflake id decoder".
|
||||||
|
|
||||||
|
### Direct profile URL by ID
|
||||||
|
|
||||||
|
Old tweet/profile URLs using numeric IDs still resolve even after handle changes:
|
||||||
|
|
||||||
|
```
|
||||||
|
https://x.com/i/user/$USER_ID
|
||||||
|
```
|
||||||
|
|
||||||
|
## Search Operators
|
||||||
|
|
||||||
|
Accessible at `x.com/search`. Operators are combinable.
|
||||||
|
|
||||||
|
| Operator | Example | Effect |
|
||||||
|
| ----------------- | -------------------------- | ------------------------ |
|
||||||
|
| `"..."` | `"exact phrase"` | Exact match |
|
||||||
|
| `from:` | `from:handle` | Posts by user |
|
||||||
|
| `to:` | `to:handle` | Posts directed at user |
|
||||||
|
| `since:` | `since:2024-01-01` | After date (YYYY-MM-DD) |
|
||||||
|
| `until:` | `until:2024-06-30` | Before date (YYYY-MM-DD) |
|
||||||
|
| `lang:` | `lang:fr` | Language (ISO 639-1) |
|
||||||
|
| `near:` | `near:"Paris" within:10km` | Geo (web only, not API) |
|
||||||
|
| `geocode:` | `geocode:48.85,2.35,5km` | Geo by coordinates |
|
||||||
|
| `filter:images` | | Posts with images |
|
||||||
|
| `filter:videos` | | Posts with videos |
|
||||||
|
| `filter:links` | | Posts with URLs |
|
||||||
|
| `filter:verified` | | Verified accounts only |
|
||||||
|
| `-filter:replies` | | Exclude replies |
|
||||||
|
| `min_retweets:` | `min_retweets:100` | Engagement threshold |
|
||||||
|
| `min_faves:` | `min_faves:500` | Engagement threshold |
|
||||||
|
| `#tag` | `#osint` | Hashtag |
|
||||||
|
| `-term` | `-spam` | Exclude term |
|
||||||
|
|
||||||
|
Boolean: spaces imply AND, use uppercase `OR` for alternatives, parentheses for grouping.
|
||||||
|
|
||||||
|
#### Direct search URL
|
||||||
|
|
||||||
|
```
|
||||||
|
https://x.com/search?q=from%3A$HANDLE+since%3A2024-01-01&f=live
|
||||||
|
```
|
||||||
|
|
||||||
|
`f=live` returns chronological results instead of relevance-ranked.
|
||||||
|
|
||||||
|
## Google Dorks
|
||||||
|
|
||||||
|
```
|
||||||
|
site:x.com "$TARGET"
|
||||||
|
site:twitter.com "$TARGET"
|
||||||
|
site:x.com/i/status "$KEYWORD"
|
||||||
|
"twitter.com/$HANDLE" OR "x.com/$HANDLE"
|
||||||
|
```
|
||||||
|
|
||||||
|
Old `twitter.com` URLs are still indexed separately from `x.com`, search both.
|
||||||
|
|
||||||
|
## Deleted and Archived Content
|
||||||
|
|
||||||
|
### Wayback Machine
|
||||||
|
|
||||||
|
```
|
||||||
|
https://web.archive.org/web/*/twitter.com/$HANDLE/status/*
|
||||||
|
https://web.archive.org/web/*/x.com/$HANDLE/status/*
|
||||||
|
```
|
||||||
|
|
||||||
|
Manually browse snapshots, or use [waybacktweets](https://github.com/claromes/waybacktweets) to batch-retrieve CDX data:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
pip install waybacktweets
|
||||||
|
waybacktweets $HANDLE
|
||||||
|
```
|
||||||
|
|
||||||
|
Outputs CSV/JSON with archived tweet URLs. Useful for deleted posts and suspended accounts.
|
||||||
|
|
||||||
|
### Twayback
|
||||||
|
|
||||||
|
Web tool wrapping the same Wayback CDX API with a UI:
|
||||||
|
|
||||||
|
```
|
||||||
|
https://twayback.space/
|
||||||
|
```
|
||||||
|
|
||||||
|
Note: only works if the tweet was crawled before deletion.
|
||||||
|
|
||||||
|
### Profile history
|
||||||
|
|
||||||
|
The Wayback Machine also archives profile pages: past bios, display names, profile photos, header images. Check snapshots at:
|
||||||
|
|
||||||
|
```
|
||||||
|
https://web.archive.org/web/*/twitter.com/$HANDLE
|
||||||
|
```
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
---
|
||||||
|
title: "Directory Discovery"
|
||||||
|
description: "Techniques and tools for discovering hidden directories and files on web servers."
|
||||||
|
tags: ["web", "enumeration", "discovery", "directory"]
|
||||||
|
publishDate: 2026-06-01
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [FFUF](#ffuf)
|
||||||
|
- [Robots.txt](#robotstxt)
|
||||||
|
- [Sitemap.xml](#sitemapxml)
|
||||||
|
- [Dirb](#dirb)
|
||||||
|
- [Spider - Katana](#spider---katana)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
## FFUF
|
||||||
|
|
||||||
|
See also [FFUF](/notes/web/ffuf) for fuzzing-based directory discovery.
|
||||||
|
|
||||||
|
## Robots.txt
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -s $url/robots.txt
|
||||||
|
```
|
||||||
|
|
||||||
|
## Sitemap.xml
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -s $url/sitemap.xml
|
||||||
|
```
|
||||||
|
|
||||||
|
## Dirb
|
||||||
|
|
||||||
|
```bash
|
||||||
|
dirb $url
|
||||||
|
```
|
||||||
|
|
||||||
|
## Spider - Katana
|
||||||
|
|
||||||
|
A spider is a tool that crawls a website and collects information about its
|
||||||
|
structure and content. It can be used to find hidden directories, files, and
|
||||||
|
parameters.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
katana -c 15 -p 15 -u $url > output
|
||||||
|
```
|
||||||
+33
@@ -0,0 +1,33 @@
|
|||||||
|
---
|
||||||
|
title: "FFUF"
|
||||||
|
description: "Reference and usage examples for ffuf, a fast web fuzzer for directories, endpoints and subdomains."
|
||||||
|
tags:
|
||||||
|
["web", "enumeration", "discovery", "subdomain", "directory", "bruteforce"]
|
||||||
|
publishDate: 2026-06-01
|
||||||
|
---
|
||||||
|
|
||||||
|
**Fuff (or ffuf)** is a fast web fuzzer written in Go, mainly used in
|
||||||
|
cybersecurity to discover hidden directories, files, API endpoints, subdomains,
|
||||||
|
vhosts and more. Its speed and flexibility make it a must-have for pentesters
|
||||||
|
and bug bounty hunters.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Flags:
|
||||||
|
# -rate 50 -t 50 # Limit requests to 50 per second with 50 concurrent threads
|
||||||
|
# -X POST|GET|PUT # Set method
|
||||||
|
# -e .php,.asp,.bak,.db # Set the extension
|
||||||
|
# -recursion -recursion-depth 3 # Recursive fuzzing up to 3 levels deep
|
||||||
|
# -fc 404,500 # Exclude responses with status codes 404 and 500
|
||||||
|
|
||||||
|
# Examples:
|
||||||
|
ffuf -w wordlist.txt -u $url/FUZZ # Basic directory/file fuzzing using a wordlist
|
||||||
|
ffuf -w subdomains.txt -u https://FUZZ.$url # Subdomain fuzzing
|
||||||
|
ffuf -w vhosts.txt -u $url -H "Host: https://FUZZ.$url" # Virtual host fuzzing by modifying the Host header
|
||||||
|
ffuf -w wordlist.txt -u $url/page.php?FUZZ=value # GET parameter fuzzing in the query string
|
||||||
|
ffuf -w wordlist.txt -u $url/api -X POST -d 'FUZZ=value' # POST body parameter fuzzing
|
||||||
|
ffuf -w wordlist.txt -u $url/FUZZ -b 'session=abcdef' # Use a session cookie during fuzzing
|
||||||
|
ffuf -w headers.txt -u $url -H "X-Custom-Header: FUZZ" # HTTP header fuzzing
|
||||||
|
ffuf -w passwords.txt -X POST -u $url/login -d "username=admin&password=FUZZ" # Password brute-forcing for user "admin"
|
||||||
|
ffuf -w users.txt:USER -w passwords.txt:PASS -u "$url/login?username=USER&password=PASS" -mode pitchfork # Pitchfork mode: matches each line from both wordlists (USER[i], PASS[i])
|
||||||
|
ffuf -w users.txt:USER -w passwords.txt:PASS -u "$url/login?username=USER&password=PASS" -mode clusterbomb # Clusterbomb mode: tests every user with every password combination
|
||||||
|
```
|
||||||
@@ -0,0 +1,98 @@
|
|||||||
|
---
|
||||||
|
title: "Subdomains Discovery"
|
||||||
|
description: "Methods and tools for enumerating subdomains of a target domain."
|
||||||
|
tags: ["web", "enumeration", "discovery", "subdomain"]
|
||||||
|
publishDate: 2026-06-01
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||||
|
|
||||||
|
- [FFUF](#ffuf)
|
||||||
|
- [Google Dorking](#google-dorking)
|
||||||
|
- [Certificate Transparency](#certificate-transparency)
|
||||||
|
- [Passive DNS](#passive-dns)
|
||||||
|
- [DMARC](#dmarc)
|
||||||
|
- [ASN & IP Ranges](#asn--ip-ranges)
|
||||||
|
- [Favicon Hash](#favicon-hash)
|
||||||
|
|
||||||
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||||
|
|
||||||
|
## FFUF
|
||||||
|
|
||||||
|
See also [FFUF](/notes/web/ffuf) for fuzzing-based subdomain discovery.
|
||||||
|
|
||||||
|
## Google Dorking
|
||||||
|
|
||||||
|
Google dorks can surface subdomains indexed by Google without any active scanning.
|
||||||
|
|
||||||
|
```
|
||||||
|
site:*.$domain
|
||||||
|
site:*.$domain -www
|
||||||
|
site:*.$domain inurl:admin
|
||||||
|
site:*.$domain ext:php | ext:json | ext:xml
|
||||||
|
```
|
||||||
|
|
||||||
|
## Certificate Transparency
|
||||||
|
|
||||||
|
CT logs record every TLS certificate ever issued for a domain. Querying them is
|
||||||
|
passive and reliable.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -s "https://crt.sh/?q=%25.$domain&output=json" | jq '.[].name_value' | sort -u
|
||||||
|
```
|
||||||
|
|
||||||
|
Tools that aggregate CT logs:
|
||||||
|
|
||||||
|
- [crt.sh](https://crt.sh)
|
||||||
|
- [censys.io](https://search.censys.io)
|
||||||
|
|
||||||
|
## Passive DNS
|
||||||
|
|
||||||
|
Passive DNS databases store historical DNS resolutions collected from resolvers
|
||||||
|
worldwide; useful for finding subdomains that no longer resolve but once did.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Amass (passive mode, no active scanning)
|
||||||
|
amass enum -passive -d $domain
|
||||||
|
|
||||||
|
# subfinder (uses many passive sources)
|
||||||
|
subfinder -d $domain -silent
|
||||||
|
```
|
||||||
|
|
||||||
|
## DMARC
|
||||||
|
|
||||||
|
DMARC can reveal more domains associated with a target.
|
||||||
|
|
||||||
|
Go to `dmarc.live/info/$domain`, it allows you to find domains using the
|
||||||
|
same DMARC record.
|
||||||
|
|
||||||
|
## ASN & IP Ranges
|
||||||
|
|
||||||
|
Finding the ASN of a target exposes its entire IP range, which may contain
|
||||||
|
undiscovered subdomains or related infrastructure.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Get ASN from an IP
|
||||||
|
whois $ip | grep -i "asn\|orgname\|origin"
|
||||||
|
|
||||||
|
# Get IP ranges from ASN
|
||||||
|
whois -h whois.radb.net -- '-i origin AS12345' | grep route
|
||||||
|
```
|
||||||
|
|
||||||
|
## Favicon Hash
|
||||||
|
|
||||||
|
A unique favicon can be fingerprinted to find other domains hosted by the same
|
||||||
|
organisation, including subdomains on non-standard ports.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Compute the MMH3 hash of the favicon
|
||||||
|
python3 -c "
|
||||||
|
import requests, mmh3, base64
|
||||||
|
r = requests.get('https://$domain/favicon.ico')
|
||||||
|
h = mmh3.hash(base64.encodebytes(r.content))
|
||||||
|
print(h)
|
||||||
|
"
|
||||||
|
```
|
||||||
|
|
||||||
|
Then search the hash on [Shodan](https://shodan.io): `http.favicon.hash:<hash>`
|
||||||
Reference in New Issue
Block a user