Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.
原文语言:英语
菜单
这个仓库中的 skills
SkillsMP 已收集 xalgord/xalgorix 中的 855 个 Skill。打开任一 Skill 可查看来源和详情。
xalgord/xalgorix已展示 40 / 855 个已收集 Skill。
Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.
原文语言:英语
Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture.
原文语言:英语
Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.
原文语言:英语
Performs advanced network reconnaissance using Nmap's scripting engine, timing controls, evasion techniques, and output parsing to discover hosts, enumerate services, detect vulnerabilities, and fingerprint operating systems across authorized target networks.
原文语言:英语
Testing Apache JServ Protocol (AJP13) connectors (default 8009/TCP) for the Ghostcat LFI/RCE vulnerability (CVE-2020-1938), trusted-request-attribute abuse, AJP secret brute forcing, and reaching the Tomcat Manager via an nginx/Apache AJP proxy during…
原文语言:英语
Testing Apache CouchDB document databases (default HTTP port 5984, HTTPS 6984) for unauthenticated/admin-party access, database dumping over the REST API, default/weak credentials, the CVE-2017-12635 privilege-escalation admin-creation bug and…
原文语言:英语
Testing DNS services (default 53/TCP+UDP, 5353/UDP mDNS) for zone transfers (AXFR), version/banner disclosure, subdomain and reverse-lookup enumeration, open recursion/amplification, DNSSEC and CAA misconfiguration, and Active Directory SRV record discovery…
原文语言:英语
Testing Docker Registry / Distribution services (default 5000/TCP, HTTP or HTTPS) for unauthenticated catalog access, image and blob/manifest extraction, weak basic-auth, and supply-chain image backdooring (push poisoned WordPress/SSH images) during…
原文语言:英语
Testing the Docker Engine remote API (default 2375/TCP plaintext, 2376/TCP TLS) for unauthenticated access leading to instant host takeover by mounting the host filesystem into a privileged container, plus secret/credential extraction and container-escape…
原文语言:英语
Testing Elasticsearch search/analytics clusters (default HTTP port 9200, transport 9300) for disabled authentication and full index dumping, default/weak credentials, write access to indices, and the historical Groovy/MVEL dynamic-scripting…
原文语言:英语
Testing FTP services (default port 21, plus FileZilla admin 14147) for anonymous access, default/weak credentials, FTP bounce port scanning and protocol relay, writable webroot uploads, and dangerous vsFTPd/ProFTPD configuration during authorized engagements.
原文语言:英语
Testing IMAP services (default ports 143 cleartext, 993 IMAPS) for weak/default credentials and brute force, NTLM info disclosure, cleartext credential exposure, capability enumeration, and authenticated mailbox access/data extraction via raw IMAP commands…
原文语言:英语
Testing IPMI / BMC out-of-band management interfaces (default 623/UDP, sometimes TCP) for the cipher-zero authentication bypass, RAKP password-hash retrieval, anonymous/default BMC credentials, cleartext password storage, and host takeover via KVM/SOL during…
原文语言:英语
Testing the Kerberos authentication service (88/tcp and 88/udp) in Active Directory during authorized engagements. Covers username enumeration (kerbrute, nmap krb5-enum-users), AS-REP roasting of accounts without pre-auth, Kerberoasting service accounts…
原文语言:英语
Testing LDAP / LDAPS directory services (389, 636, and Global Catalog 3268/3269) including Active Directory during authorized engagements. Covers anonymous/null bind enumeration, naming-context discovery, user/group/computer extraction with ldapsearch and…
原文语言:英语
Testing Memcached distributed memory caching servers (default port 11211 TCP/UDP) for unauthenticated stats/version access, slab-based key dumping and cached-data exfiltration, cache poisoning, and the UDP reflection/amplification DDoS primitive during…
原文语言:英语
Testing MongoDB document databases (default ports 27017 and 27018) for no-auth/unauthenticated access, weak credentials, database and collection dumping, predictable ObjectID enumeration, config-based auth bypass, and the MongoBleed unauthenticated…
原文语言:英语
Testing the Microsoft RPC (MSRPC / DCE-RPC) endpoint mapper and exposed RPC interfaces during authorized engagements. The endpoint mapper listens on TCP/UDP 135 (also reachable over SMB named pipes on 139/445 and HTTP on 593). Covers endpoint enumeration with…
原文语言:英语
Testing Microsoft SQL Server (default port 1433, UDP 1434 browser) for default/weak SA credentials, Windows-auth and NTLM relay/coercion, xp_cmdshell OS command execution, linked-server lateral movement, and OLE/BULK file read-write primitives during…
原文语言:英语
Testing MySQL / MariaDB database services (default port 3306) for empty/default root credentials, authentication-bypass and version CVEs, FILE-privilege data theft, and the INTO OUTFILE webshell / lib_mysqludf_sys UDF remote-code-execution primitives during…
原文语言:英语
Testing NetBIOS over TCP/IP services during authorized engagements. Covers the NetBIOS Name Service (137/udp, 137/tcp), Datagram Service (138/udp), and Session Service (139/tcp). Focuses on name and MAC enumeration with nmblookup, nbtscan and nmap nbstat,…
原文语言:英语
Testing NFS services (default port 2049, with rpcbind/mountd on 111 and dynamic ports) for exported share enumeration, missing authentication, UID/GID impersonation, no_root_squash/no_all_squash misconfiguration, subtree_check export escape, and group-based…
原文语言:英语
Testing NTP services (default 123/UDP for time data and legacy control, 4460/TCP for NTS-KE/TLS) for monlist/Mode-7 amplification exposure, remote query/control leakage, time-shift MITM, weak NTS-KE TLS, and known ntpd/chrony/ntpd-rs CVEs during authorized…
原文语言:英语
Testing Oracle Database via the TNS Listener (default ports 1521, plus secondary listeners 1522-1529) for SID disclosure/bruteforce, default and weak account credentials, TNS listener misconfiguration and poisoning, and ODAT-driven file read/write and OS…
原文语言:英语
Testing POP3 services (default ports 110 cleartext, 995 POP3S) for weak/default credentials and brute force, NTLM info disclosure, cleartext credential exposure, capability enumeration, and authenticated mailbox retrieval/data extraction via raw POP3 commands…
原文语言:英语
Testing PostgreSQL database services (default port 5432, fallback 5433) for trust-auth and default/weak credentials, role/privilege enumeration, the COPY ... FROM PROGRAM command-execution primitive, large-object and server-file read/write, CREATEROLE…
原文语言:英语
Testing RabbitMQ / AMQP message brokers (default 5672/TCP plaintext, 5671/TCP TLS; management 15672) for default guest credentials, anonymous/SASL login, message sniffing via topic/stream/event-exchange binds, queue-deletion DoS (CVE-2024-51988),…
原文语言:英语
Testing the Remote Desktop Protocol (RDP, 3389/tcp ms-wbt-server) during authorized engagements. Covers encryption/NLA fingerprinting and NTLM info with nmap NSE, credential validation and pre/post-auth screenshots with netexec, password brute force (mindful…
原文语言:英语
Testing Redis in-memory data stores (default port 6379) for unauthenticated access, weak AUTH credentials, keyspace dumping, and the high-impact RCE primitives - module load (system.exec), webshell/cron write via CONFIG SET dir + dbfilename + SAVE, SSH…
原文语言:英语
Testing rsync daemon services (default port 873) for unauthenticated module listing and access, weak/default credentials and brute force, arbitrary file read/download and write/upload (including authorized_keys planting), and rsyncd.conf/secrets…
原文语言:英语
Testing SMB/CIFS file-sharing services (TCP 445, and 139 over NetBIOS) on Windows and Samba hosts during authorized engagements. Covers share enumeration, null/guest session abuse, user and RID enumeration, credentialed access with netexec/crackmapexec,…
原文语言:英语
Testing SMTP services (default ports 25, 465/SSL, 587/submission) for open relays, user enumeration (VRFY/EXPN/RCPT), NTLM info disclosure, weak/no authentication, SPF/DKIM/DMARC spoofing gaps, Secure Email Gateway bypass, and SMTP smuggling during authorized…
原文语言:英语
Testing SNMP services (default 161/UDP for agents, 162/UDP for traps, 10161/10162 over TLS/DTLS) for default/guessable community strings, sensitive MIB/OID data harvesting, writable rwcommunity strings, and SNMP-to-RCE via NET-SNMP-EXTEND-MIB during…
原文语言:英语
Testing SSH services (default port 22) for weak algorithms/host keys, default and brute-forceable credentials, key-based auth gaps, SFTP shell escapes and tunneling, auth-method downgrade, and high-impact CVEs (regreSSHion CVE-2024-6387, XZ backdoor…
原文语言:英语
Testing Telnet services (default port 23) for cleartext credential capture, default/weak and hard-coded credentials, NTLM info disclosure, option negotiation issues, and code-execution/DoS CVEs (inetutils telnetd NEW_ENVIRON option injection CVE-2026-24061,…
原文语言:英语
Testing TFTP services (default port 69/UDP) for unauthenticated file read/write, default path enumeration (no directory listing), exposure of device configuration files and ROM/firmware images, and arbitrary upload during authorized engagements.
原文语言:英语
Testing VNC remote desktop services using the Remote Frame Buffer (RFB) protocol during authorized engagements. VNC commonly listens on 5900/5901 (and web clients on 5800/5801). Covers RFB fingerprinting, no-auth / RealVNC auth-bypass detection with nmap NSE…
原文语言:英语
Testing VoIP / SIP infrastructure (default 5060/UDP+TCP, 5061/TLS, RTP media on high UDP ports) for endpoint and extension enumeration, REGISTER/digest credential cracking, unauthenticated INVITE toll fraud, SIP Digest Leak, RTP eavesdropping, and Asterisk…
原文语言:英语
Testing Windows Remote Management (WinRM / WS-Management) during authorized engagements. WinRM exposes an HTTP(S) SOAP interface for WMI/PowerShell remoting on 5985/tcp (HTTP) and 5986/tcp (HTTPS). Covers service detection with Test-WSMan and netexec,…
原文语言:英语
Testing the X Window System (X11) display server during authorized engagements. X11 listens on TCP 6000+<display> and the local Unix socket /tmp/.X11-unix/X<display>. Covers detecting unauthenticated ("xhost +") access with nmap NSE and Metasploit, abusing…
原文语言:英语