Skip to main content

このリポジトリの skills

abelrguezr/hacktricks-skills - 13ページ

SkillsMP は abelrguezr/hacktricks-skills から 908 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

abelrguezr/hacktricks-skills

収集済み skill 908 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

How to identify, test, and document echo services (port 7 TCP/UDP) during network security assessments. Use this skill whenever you're scanning networks, analyzing open ports, or investigating unusual service behavior. Trigger this skill when you see port 7…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest EPP (Extensible Provisioning Protocol) servers used for domain name management. Use this skill whenever the user mentions EPP, domain registrar testing, port 700, TLD security, registry vulnerabilities, or wants to assess domain name system…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest Apache JServ Protocol (AJP) services on port 8009. Use this skill whenever the user mentions AJP, Tomcat port 8009, Ghostcat vulnerability, or needs to enumerate/exploit AJP endpoints. This skill covers AJP protocol enumeration, CVE-2020-1938 Ghostcat…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest InfluxDB time-series databases on port 8086. Use this skill whenever you need to enumerate, test authentication, or extract data from InfluxDB instances. Trigger for any InfluxDB assessment, time-series database testing, port 8086 enumeration, or when…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to pentest Splunkd services (port 8089) for vulnerability assessment and exploitation. Use this skill whenever the user mentions Splunk, port 8089, Splunkd, log analytics security testing, or needs to assess Splunk installations for vulnerabilities…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to enumerate and assess Bitcoin nodes during security assessments. Use this skill whenever the user mentions Bitcoin nodes, cryptocurrency pentesting, ports 8333/18333/38333/18444, or wants to enumerate Bitcoin network infrastructure. This skill covers…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest rsync file sharing services on port 873. Use this skill whenever you need to enumerate, access, or exploit rsync services. Trigger this skill for any rsync-related tasks including module enumeration, authentication testing, file transfer, brute force…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest FastCGI services (typically port 9000) for enumeration, RCE, and SSRF exploitation. Use this skill whenever you need to test FastCGI/PHP-FPM services, probe for misconfigurations, craft FastCGI payloads for RCE, or leverage SSRF to reach internal…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to pentest HSQLDB (HyperSQL Database) services on port 9001. Use this skill whenever the user mentions HSQLDB, port 9001, Java database exploitation, JDBC attacks, or needs to interact with HSQLDB during security assessments. This skill covers connection…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest network printers via PJL (Printer Job Language) on port 9100/tcp. Use this skill whenever the user mentions printer security, port 9100, JetDirect, AppSocket, PJL commands, printer enumeration, printer exploitation, PRET tool, or any printer-related…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest and enumerate Elasticsearch instances (port 9200). Use this skill whenever the user mentions Elasticsearch, elastic, port 9200, ELK stack, or needs to enumerate/search/dump data from an Elasticsearch server. This includes checking authentication,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest Apache Cassandra databases. Use this skill whenever you need to enumerate, assess, or test Cassandra instances on ports 9042 or 9160. Trigger this skill for any Cassandra security assessment, database enumeration, credential discovery, or when you…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest IPsec/IKE VPN services on UDP ports 500 and 4500. Use this skill whenever the user mentions VPN pentesting, IPsec testing, IKE vulnerability assessment, or needs to enumerate and exploit IPsec/IKE VPN gateways. Trigger for any task involving VPN…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest NFS (Network File System) services on port 2049. Use this skill whenever the user mentions NFS, network file sharing, port 2049, showmount, nfs exports, or needs to enumerate/mount/exploit NFS shares. This skill helps with NFS enumeration, mounting…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Reconnaissance and vulnerability assessment for Check Point Firewall-1 systems. Use this skill whenever the user needs to enumerate Check Point firewalls, discover firewall/management station hostnames via port 264, or assess HTTP Security Server format…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Internet Printing Protocol (IPP) security assessment and pentesting. Use this skill whenever the user mentions IPP, CUPS, port 631, printer security, network printing vulnerabilities, or needs to enumerate/test printing services. This skill covers…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to pentest Compaq/HP Insight Manager services. Use this skill whenever the user mentions HP Insight Manager, Compaq Insight Manager, port 2301, port 2381, or any HP server management service enumeration. Trigger for any reconnaissance, vulnerability…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform DNS security assessments and enumeration. Use this skill whenever the user needs to enumerate DNS servers, check for zone transfers, discover subdomains, validate DNSSEC configuration, or assess DNS security posture. Trigger on requests involving DNS…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to enumerate and exploit the Finger protocol (port 79) during security assessments. Use this skill whenever you need to enumerate users on a target system, check for finger service vulnerabilities, perform banner grabbing on port 79, or test for command…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform FTP bounce attacks to scan ports on internal or otherwise inaccessible networks. Use this skill whenever the user needs to scan ports through an FTP server, mentions FTP bounce, PORT/EPRT commands, or wants to check if ports are open on a target that…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Use FTP bounce attacks to download files from a victim FTP server through a vulnerable middle FTP server. Use this skill whenever you have FTP credentials for a middle server and need to access files on another FTP server that the middle server can reach but…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform FTP server pentesting including enumeration, authentication testing, anonymous access checks, FTP bounce attacks, and post-exploitation. Use this skill whenever the user mentions FTP, port 21, file transfer protocol, FTP servers, anonymous FTP, FTP…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest IMAP email servers for vulnerabilities, information disclosure, and credential testing. Use this skill whenever the user mentions IMAP, email server testing, port 143, port 993, email enumeration, or wants to assess email service security. Trigger for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform IRC (Internet Relay Chat) security testing and enumeration. Use this skill whenever the user mentions IRC, IRC servers, port 6667, IRC channels, IRC operators, or wants to enumerate/test IRC services. Trigger for any IRC-related security assessment,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit exposed Java Debug Wire Protocol (JDWP) services for remote code execution. Use this skill whenever you need to test JDWP vulnerabilities, enumerate Java debug services, or gain access to Java applications with debug ports exposed. Trigger on mentions…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Harvest Kerberos tickets from Linux systems during post-exploitation. Use this skill whenever you have shell access to a Linux machine and need to extract Kerberos credentials (TGTs, TGS tickets) from file caches, kernel keyrings, KCM, or process memory.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to harvest Kerberos tickets from Windows systems using Mimikatz and Rubeus. Use this skill whenever you need to extract, dump, triage, renew, or convert Kerberos tickets from Windows environments during security assessments, penetration testing, or red…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest Kerberos services (port 88/tcp/udp) in Active Directory environments. Use this skill whenever the user mentions Kerberos, port 88, AD authentication, TGT tickets, krb5.conf, GSSAPI, or needs to authenticate to Windows/AD services. Also trigger for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform LDAP/Active Directory pentesting including enumeration, anonymous access testing, credential attacks, and domain information extraction. Use this skill whenever the user mentions LDAP, Active Directory, directory services, ports 389/636/3268/3269,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to enumerate and pentest Modbus protocol services (port 502). Use this skill whenever the user mentions Modbus, SCADA systems, industrial control systems (ICS), port 502, or needs to assess Modbus-enabled devices. Trigger for any Modbus enumeration,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to pentest Microsoft SQL Server (MSSQL) on port 1433. Use this skill whenever the user mentions MSSQL, SQL Server, port 1433, database enumeration, SQL injection against MSSQL, xp_cmdshell, linked servers, SQL Server privilege escalation, or any…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to understand and query MSSQL user types from sys.database_principals. Use this skill whenever you need to enumerate SQL Server users, understand principal types (SQL users, Windows users, roles, etc.), interpret authentication types, or analyze database…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

MySQL database penetration testing and exploitation. Use this skill whenever the user needs to enumerate, exploit, or escalate privileges on MySQL databases (port 3306). Trigger for: MySQL connection testing, credential extraction, privilege escalation, SQL…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest NTP (Network Time Protocol) services on port 123/UDP and 4460/TCP. Use this skill whenever you need to enumerate NTP servers, check for monlist vulnerabilities, assess NTS security, or harden NTP configurations. Trigger this for any NTP assessment,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to enumerate, test, and exploit POP3 mail servers during security assessments. Use this skill whenever the user mentions POP3, port 110, port 995, email server testing, mail server enumeration, or any task related to testing Post Office Protocol services.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

PostgreSQL database penetration testing and exploitation. Use this skill whenever the user needs to enumerate, exploit, or escalate privileges in PostgreSQL databases. Trigger on mentions of PostgreSQL, pgsql, port 5432, database pentesting, SQL injection…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to enumerate, attack, and exploit RDP (Remote Desktop Protocol) services during penetration testing. Use this skill whenever the user mentions RDP, port 3389, remote desktop, Windows remote access, RDP enumeration, RDP brute force, RDP shadowing, session…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit remote gdbserver instances for pentesting. Use this skill whenever you encounter an open gdbserver port during reconnaissance, need to debug a remote process, want to upload and execute binaries on a target, or need to run arbitrary commands through a…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest Rlogin (port 513) services on target systems. Use this skill when you need to test for Rlogin vulnerabilities, attempt unauthorized access via .rhosts files, or enumerate Rlogin services during security assessments. Trigger this skill for any…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to enumerate and exploit RPCBind/Portmapper services (port 111) during network penetration testing. Use this skill whenever you're scanning a target and find port 111 open, or when you need to enumerate RPC services, NFS shares, or NIS domains. Trigger…

原文の言語: 英語

更新
収集済み skill 908 件中 40 件を表示しています。