pentest-tooling
Pentest: nmap, nuclei, sqlmap, ffuf, subfinder, Sploitus CVE lookup — tool usage playbooks.
소스 정보
- 저장소
- aurict/aurict
- 최근 소스 활동
- 2026년 6월 24일 19:34
- 감지된 SKILL.md 언어
- 영어
- 스타
- 33
- 포크
- 2
설치 방법
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
소스 파일 검토
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
SKILL.md 표시 중
SKILL.md
소스 지침 · 읽기 전용 미리보기- name
- pentest-tooling
- description
- Pentest: nmap, nuclei, sqlmap, ffuf, subfinder, Sploitus CVE lookup — tool usage playbooks.
- triggers
- {"keywords":["nmap","nuclei","sqlmap","ffuf","subfinder","sploitus","pentest","exploit","scan","vulnerability scan","cve lookup"]}
- auto_load_when
- Active security testing or vulnerability scanning with CLI tools
- agent
- pentest
- tools
- ["Read","Bash","WebFetch","WebSearch"]
# Penetration Testing Tooling Playbooks
> ⚠ These tools require Linux or macOS. On Windows use WSL2.
> Install: `apt install nmap nuclei sqlmap ffuf subfinder` or use `go install` for Go tools.
---
## 1. nmap — Service & Port Scanning
```bash
# Quick top-1000 ports with service detection
nmap -sV -sC -T4 TARGET
# Full port scan (slow but complete)
nmap -p- --min-rate 5000 TARGET
# Save output for later analysis
nmap -sV -sC -oN nmap_scan.txt -oX nmap_scan.xml TARGET
# Specific port range
nmap -p 80,443,8080,8443 -sV TARGET
# UDP scan (requires root)
sudo nmap -sU --top-ports 20 TARGET
```
**Read output for:**
- Open ports + service versions → match against CVE databases
- Default scripts (`-sC`) detect: HTTP headers, SSL certs, SMB info, FTP banners
---
## 2. nuclei — Template-Based Vulnerability Scanning
```bash
# Scan with all severity levels
nuclei -u https://TARGET -severity critical,high,medium,low
# Scan specific template category
nuclei -u https://TARGET -tags cve,sqli,xss,ssrf
# Scan from file with multiple targets
nuclei -l targets.txt -severity critical,high
# Update templates first (always do this)
nuclei -update-templates
# Save findings to file
nuclei -u https://TARGET -o nuclei_findings.txt -severity critical,high
```
**Good for:** mass CVE detection, misconfigurations, exposed panels, default credentials
---
## 3. sqlmap — SQL Injection Testing
```bash
# Basic injection test on GET parameter
sqlmap -u "https://TARGET/page?id=1" --batch
# POST parameter injection
sqlmap -u "https://TARGET/login" --data="username=admin&password=test" --batch
# Enumerate databases (after injection confirmed)
sqlmap -u "URL" --batch --dbs
# Dump specific database
sqlmap -u "URL" --batch -D database_name --tables
sqlmap -u "URL" --batch -D database_name -T users --dump
# With session cookie (authenticated)
sqlmap -u "URL" --cookie="session=VALUE" --batch
# Bypass WAF with tamper scripts
sqlmap -u "URL" --batch --tamper=space2comment,charencode
```
---
## 4. ffuf — Web Fuzzing
```bash
# Directory/path discovery
ffuf -w /usr/share/wordlists/dirb/common.txt -u https://TARGET/FUZZ
# Subdomain enumeration via DNS
ffuf -w subdomains.txt -u https://FUZZ.TARGET -H "Host: FUZZ.TARGET"
# Parameter fuzzing (GET)
ffuf -w params.txt -u "https://TARGET/page?FUZZ=test"
# POST body fuzzing
ffuf -w payloads.txt -u https://TARGET/login -X POST \
-d "username=admin&password=FUZZ" -fc 401
# Filter by response size or status code
ffuf -w wordlist.txt -u https://TARGET/FUZZ -fc 404 -fs 1234
```
**Wordlists:** `/usr/share/wordlists/dirb/common.txt`, SecLists (`/usr/share/seclists/`)
---
## 5. subfinder — Subdomain Enumeration
```bash
# Basic subdomain discovery
subfinder -d target.com -o subdomains.txt
# With all sources (slower but more complete)
subfinder -d target.com -all -o subdomains.txt
# Silent mode (output only)
subfinder -d target.com -silent
# Feed into nuclei
subfinder -d target.com -silent | nuclei -severity critical,high
```
---
## 6. Sploitus — CVE & Exploit Lookup
```
# Search by product/component name
webfetch https://sploitus.com/search?query=PRODUCT+VERSION&type=exploits
# Search by CVE ID
webfetch https://sploitus.com/search?query=CVE-2024-XXXXX
# Search by technology
webfetch https://sploitus.com/search?query=apache+log4j
```
**Also useful:**
```
websearch "CVE-XXXX-XXXXX exploit github"
websearch "PRODUCT VERSION remote code execution poc"
```
---
## 7. Dependency Audit
```bash
# Node.js
npm audit --json | jq '.vulnerabilities | to_entries[] | select(.value.severity == "critical" or .value.severity == "high")'
# Python
pip audit --format json
# Rust
cargo audit
# Go
govulncheck ./...
```
---
## Quick Decision Matrix
| Goal | Tool |
|---|---|
| What ports/services are open? | nmap |
| Known CVEs for this version? | nuclei + Sploitus |
| Is this endpoint SQLi vulnerable? | sqlmap |
| What endpoints/dirs exist? | ffuf |
| What subdomains exist? | subfinder |
| Is this dependency CVE'd? | npm audit / cargo audit |
GitHub에서 보기