Skip to main content

pentest-tooling

Pentest: nmap, nuclei, sqlmap, ffuf, subfinder, Sploitus CVE lookup — tool usage playbooks.

Zur Installation springen

Quellinformationen

Repository
aurict/aurict
Letzte Quellaktivität
24. Juni 2026 um 19:34
Erkannte Sprache von SKILL.md
Englisch
Sterne
33
Forks
2

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
pentest-tooling
description
Pentest: nmap, nuclei, sqlmap, ffuf, subfinder, Sploitus CVE lookup — tool usage playbooks.
triggers
{"keywords":["nmap","nuclei","sqlmap","ffuf","subfinder","sploitus","pentest","exploit","scan","vulnerability scan","cve lookup"]}
auto_load_when
Active security testing or vulnerability scanning with CLI tools
agent
pentest
tools
["Read","Bash","WebFetch","WebSearch"]
# Penetration Testing Tooling Playbooks > ⚠ These tools require Linux or macOS. On Windows use WSL2. > Install: `apt install nmap nuclei sqlmap ffuf subfinder` or use `go install` for Go tools. --- ## 1. nmap — Service & Port Scanning ```bash # Quick top-1000 ports with service detection nmap -sV -sC -T4 TARGET # Full port scan (slow but complete) nmap -p- --min-rate 5000 TARGET # Save output for later analysis nmap -sV -sC -oN nmap_scan.txt -oX nmap_scan.xml TARGET # Specific port range nmap -p 80,443,8080,8443 -sV TARGET # UDP scan (requires root) sudo nmap -sU --top-ports 20 TARGET ``` **Read output for:** - Open ports + service versions → match against CVE databases - Default scripts (`-sC`) detect: HTTP headers, SSL certs, SMB info, FTP banners --- ## 2. nuclei — Template-Based Vulnerability Scanning ```bash # Scan with all severity levels nuclei -u https://TARGET -severity critical,high,medium,low # Scan specific template category nuclei -u https://TARGET -tags cve,sqli,xss,ssrf # Scan from file with multiple targets nuclei -l targets.txt -severity critical,high # Update templates first (always do this) nuclei -update-templates # Save findings to file nuclei -u https://TARGET -o nuclei_findings.txt -severity critical,high ``` **Good for:** mass CVE detection, misconfigurations, exposed panels, default credentials --- ## 3. sqlmap — SQL Injection Testing ```bash # Basic injection test on GET parameter sqlmap -u "https://TARGET/page?id=1" --batch # POST parameter injection sqlmap -u "https://TARGET/login" --data="username=admin&password=test" --batch # Enumerate databases (after injection confirmed) sqlmap -u "URL" --batch --dbs # Dump specific database sqlmap -u "URL" --batch -D database_name --tables sqlmap -u "URL" --batch -D database_name -T users --dump # With session cookie (authenticated) sqlmap -u "URL" --cookie="session=VALUE" --batch # Bypass WAF with tamper scripts sqlmap -u "URL" --batch --tamper=space2comment,charencode ``` --- ## 4. ffuf — Web Fuzzing ```bash # Directory/path discovery ffuf -w /usr/share/wordlists/dirb/common.txt -u https://TARGET/FUZZ # Subdomain enumeration via DNS ffuf -w subdomains.txt -u https://FUZZ.TARGET -H "Host: FUZZ.TARGET" # Parameter fuzzing (GET) ffuf -w params.txt -u "https://TARGET/page?FUZZ=test" # POST body fuzzing ffuf -w payloads.txt -u https://TARGET/login -X POST \ -d "username=admin&password=FUZZ" -fc 401 # Filter by response size or status code ffuf -w wordlist.txt -u https://TARGET/FUZZ -fc 404 -fs 1234 ``` **Wordlists:** `/usr/share/wordlists/dirb/common.txt`, SecLists (`/usr/share/seclists/`) --- ## 5. subfinder — Subdomain Enumeration ```bash # Basic subdomain discovery subfinder -d target.com -o subdomains.txt # With all sources (slower but more complete) subfinder -d target.com -all -o subdomains.txt # Silent mode (output only) subfinder -d target.com -silent # Feed into nuclei subfinder -d target.com -silent | nuclei -severity critical,high ``` --- ## 6. Sploitus — CVE & Exploit Lookup ``` # Search by product/component name webfetch https://sploitus.com/search?query=PRODUCT+VERSION&type=exploits # Search by CVE ID webfetch https://sploitus.com/search?query=CVE-2024-XXXXX # Search by technology webfetch https://sploitus.com/search?query=apache+log4j ``` **Also useful:** ``` websearch "CVE-XXXX-XXXXX exploit github" websearch "PRODUCT VERSION remote code execution poc" ``` --- ## 7. Dependency Audit ```bash # Node.js npm audit --json | jq '.vulnerabilities | to_entries[] | select(.value.severity == "critical" or .value.severity == "high")' # Python pip audit --format json # Rust cargo audit # Go govulncheck ./... ``` --- ## Quick Decision Matrix | Goal | Tool | |---|---| | What ports/services are open? | nmap | | Known CVEs for this version? | nuclei + Sploitus | | Is this endpoint SQLi vulnerable? | sqlmap | | What endpoints/dirs exist? | ffuf | | What subdomains exist? | subfinder | | Is this dependency CVE'd? | npm audit / cargo audit |
Auf GitHub ansehen