Skip to content

Commit

Permalink
re
Browse files Browse the repository at this point in the history
  • Loading branch information
carlospolop committed Dec 14, 2024
1 parent cfff5cc commit 9f71c0c
Show file tree
Hide file tree
Showing 199 changed files with 199 additions and 6 deletions.
1 change: 1 addition & 0 deletions network-services-pentesting/11211-memcache/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -223,3 +223,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -165,3 +165,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -89,3 +89,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-finger.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,3 +109,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-ftp/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -306,3 +306,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -61,3 +61,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -72,3 +72,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}



1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-imap.md
Original file line number Diff line number Diff line change
Expand Up @@ -219,3 +219,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-irc.md
Original file line number Diff line number Diff line change
Expand Up @@ -110,3 +110,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -104,3 +104,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -92,3 +92,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -48,3 +48,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}



Original file line number Diff line number Diff line change
Expand Up @@ -66,3 +66,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-ldap.md
Original file line number Diff line number Diff line change
Expand Up @@ -439,3 +439,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-modbus.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,3 +68,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}



Original file line number Diff line number Diff line change
Expand Up @@ -721,3 +721,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d
</details>
{% endhint %}
Original file line number Diff line number Diff line change
Expand Up @@ -49,3 +49,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-mysql.md
Original file line number Diff line number Diff line change
Expand Up @@ -688,3 +688,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
</details>
{% endhint %}
1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-ntp.md
Original file line number Diff line number Diff line change
Expand Up @@ -138,3 +138,4 @@ Learn & practice GCP Hacking: <img src="../.gitbook/assets/grte.png" alt="" data

</details>
{% endhint %}

2 changes: 1 addition & 1 deletion network-services-pentesting/pentesting-pop.md
Original file line number Diff line number Diff line change
Expand Up @@ -154,4 +154,4 @@ Learn & practice GCP Hacking: <img src="../.gitbook/assets/grte.png" alt="" data
* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
</details>
{% endhint %}
{% endhint %}
1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-postgresql.md
Original file line number Diff line number Diff line change
Expand Up @@ -852,3 +852,4 @@ Use [**Trickest**](https://trickest.com/?utm_source=hacktricks&utm_medium=text&u
Get Access Today:

{% embed url="https://trickest.com/?utm_source=hacktricks&utm_medium=banner&utm_campaign=ppc&utm_content=pentesting-postgresql" %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-rdp.md
Original file line number Diff line number Diff line change
Expand Up @@ -195,3 +195,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-remote-gdbserver.md
Original file line number Diff line number Diff line change
Expand Up @@ -224,3 +224,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-rlogin.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,3 +71,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-rpcbind.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,3 +145,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-rsh.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,3 +57,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-sap.md
Original file line number Diff line number Diff line change
Expand Up @@ -423,3 +423,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}



1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-smb.md
Original file line number Diff line number Diff line change
Expand Up @@ -617,3 +617,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-smb/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -617,3 +617,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -125,3 +125,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-smtp/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -652,3 +652,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
</details>
{% endhint %}
Original file line number Diff line number Diff line change
Expand Up @@ -86,3 +86,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -59,3 +59,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-snmp/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -319,3 +319,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-snmp/cisco-snmp.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,3 +76,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-snmp/snmp-rce.md
Original file line number Diff line number Diff line change
Expand Up @@ -83,3 +83,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}



1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-ssh.md
Original file line number Diff line number Diff line change
Expand Up @@ -375,3 +375,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-telnet.md
Original file line number Diff line number Diff line change
Expand Up @@ -119,3 +119,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-vnc.md
Original file line number Diff line number Diff line change
Expand Up @@ -88,3 +88,4 @@ Learn & practice GCP Hacking: <img src="../.gitbook/assets/grte.png" alt="" data

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-voip/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -750,3 +750,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -124,3 +124,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}
</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -271,3 +271,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}
</details>
{% endhint %}
Original file line number Diff line number Diff line change
Expand Up @@ -160,3 +160,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -463,3 +463,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -36,3 +36,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}



1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/angular.md
Original file line number Diff line number Diff line change
Expand Up @@ -611,3 +611,4 @@ According to the W3C documentation, the `window.location` and `document.location
* [Angular Document](https://angular.io/api/common/DOCUMENT)
* [Angular Location](https://angular.io/api/common/Location)
* [Angular Router](https://angular.io/api/router/Router)

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/apache.md
Original file line number Diff line number Diff line change
Expand Up @@ -304,3 +304,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -33,3 +33,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}



1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/bolt-cms.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,3 +49,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -33,3 +33,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -37,3 +37,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/cgi.md
Original file line number Diff line number Diff line change
Expand Up @@ -122,3 +122,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}



Original file line number Diff line number Diff line change
Expand Up @@ -503,3 +503,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/django.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,4 @@ Django's default cache storage method is [Python pickles](https://docs.python.or
Django cache is stored in one of four places: [Redis](https://github.com/django/django/blob/48a1929ca050f1333927860ff561f6371706968a/django/core/cache/backends/redis.py#L12), [memory](https://github.com/django/django/blob/48a1929ca050f1333927860ff561f6371706968a/django/core/cache/backends/locmem.py#L16), [files](https://github.com/django/django/blob/48a1929ca050f1333927860ff561f6371706968a/django/core/cache/backends/filebased.py#L16), or a [database](https://github.com/django/django/blob/48a1929ca050f1333927860ff561f6371706968a/django/core/cache/backends/db.py#L95). Cache stored in a Redis server or database are the most likely attack vectors (Redis injection and SQL injection), but an attacker may also be able to use file-based cache to turn an arbitrary write into RCE. Maintainers have marked this as a non-issue. It's important to note that the cache file folder, SQL table name, and Redis server details will vary based on implementation.

This HackerOne report provides a great, reproducible example of exploiting Django cache stored in a SQLite database: https://hackerone.com/reports/1415436

Original file line number Diff line number Diff line change
Expand Up @@ -68,3 +68,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -134,4 +134,4 @@ Learn & practice GCP Hacking: <img src="../../../.gitbook/assets/grte.png" alt="
* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.

</details>
{% endhint %}
{% endhint %}
Original file line number Diff line number Diff line change
Expand Up @@ -274,3 +274,4 @@ Learn & practice GCP Hacking: <img src="../../../.gitbook/assets/grte.png" alt="

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -351,3 +351,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -87,3 +87,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -127,3 +127,4 @@ Learn & practice GCP Hacking: <img src="../../../.gitbook/assets/grte.png" alt="

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -112,3 +112,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/flask.md
Original file line number Diff line number Diff line change
Expand Up @@ -140,3 +140,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/git.md
Original file line number Diff line number Diff line change
Expand Up @@ -47,3 +47,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/golang.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,3 +52,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}



1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/grafana.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,3 +39,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/graphql.md
Original file line number Diff line number Diff line change
Expand Up @@ -690,3 +690,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

Original file line number Diff line number Diff line change
@@ -1,2 +1,3 @@
# GWT - Google Web Toolkit


Original file line number Diff line number Diff line change
Expand Up @@ -66,3 +66,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -301,3 +301,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -69,3 +69,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/jboss.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,3 +58,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/jira.md
Original file line number Diff line number Diff line change
Expand Up @@ -155,3 +155,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/joomla.md
Original file line number Diff line number Diff line change
Expand Up @@ -161,3 +161,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/jsp.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,3 +41,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/laravel.md
Original file line number Diff line number Diff line change
Expand Up @@ -140,3 +140,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/moodle.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,3 +145,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s
{% endhint %}
</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/nextjs.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,3 +35,4 @@ Learn & practice GCP Hacking: <img src="../../.gitbook/assets/grte.png" alt="" d

</details>
{% endhint %}

1 change: 1 addition & 0 deletions network-services-pentesting/pentesting-web/nginx.md
Original file line number Diff line number Diff line change
Expand Up @@ -340,3 +340,4 @@ Learn & practice GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-s

</details>
{% endhint %}

Original file line number Diff line number Diff line change
Expand Up @@ -35,3 +35,4 @@ iI you know the secret you can sign a the cookie.
```bash
cookie-monster -e -f new_cookie.json -k secret
```

Loading

0 comments on commit 9f71c0c

Please sign in to comment.