Skip to content

Commit

Permalink
Merge branch 'master' into ad-enhance
Browse files Browse the repository at this point in the history
  • Loading branch information
carlospolop authored Mar 18, 2022
2 parents c02afd1 + 3c47e07 commit 051dabb
Show file tree
Hide file tree
Showing 195 changed files with 2,773 additions and 417 deletions.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .gitbook/assets/image (201) (2) (1) (1).png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .gitbook/assets/image (201) (2) (1).png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .gitbook/assets/image (201) (2).png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified .gitbook/assets/image (201).png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .gitbook/assets/image (307) (2).png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified .gitbook/assets/image (307).png
Binary file modified .gitbook/assets/image (389).png
Binary file added .gitbook/assets/image (465) (2).png
Binary file modified .gitbook/assets/image (465).png
Binary file added .gitbook/assets/image (621) (1) (1) (1).png
Binary file added .gitbook/assets/image (630) (1) (1).png
Binary file modified .gitbook/assets/image (630) (1).png
Binary file modified .gitbook/assets/image (630).png
Binary file added .gitbook/assets/image (631) (1).png
Binary file modified .gitbook/assets/image (631).png
Binary file added .gitbook/assets/image (634) (1).png
Binary file modified .gitbook/assets/image (634).png
Binary file added .gitbook/assets/image (635) (1) (1) (1).png
Binary file modified .gitbook/assets/image (635) (1) (1).png
Binary file modified .gitbook/assets/image (635) (1).png
Binary file modified .gitbook/assets/image (635).png
Binary file added .gitbook/assets/image (636) (1).png
Binary file modified .gitbook/assets/image (636).png
Binary file added .gitbook/assets/image (637) (1) (1).png
Binary file modified .gitbook/assets/image (637) (1).png
Binary file modified .gitbook/assets/image (637).png
Binary file added .gitbook/assets/image (638) (1).png
Binary file modified .gitbook/assets/image (638).png
Binary file added .gitbook/assets/image (640) (1).png
Binary file modified .gitbook/assets/image (640).png
Binary file added .gitbook/assets/image (641) (1) (1).png
Binary file modified .gitbook/assets/image (641) (1).png
Binary file modified .gitbook/assets/image (641).png
Binary file added .gitbook/assets/image (642) (1) (1) (1) (1).png
Binary file added .gitbook/assets/image (642) (1) (1) (1).png
Binary file added .gitbook/assets/image (642) (1) (1) (2).png
Binary file modified .gitbook/assets/image (642) (1) (1).png
Binary file modified .gitbook/assets/image (642) (1).png
Binary file modified .gitbook/assets/image (642).png
Binary file added .gitbook/assets/image (643) (1) (1).png
Binary file added .gitbook/assets/image (643) (1).png
Binary file modified .gitbook/assets/image (643).png
Binary file added .gitbook/assets/image (644) (1).png
Binary file modified .gitbook/assets/image (644).png
Binary file added .gitbook/assets/image (645) (1) (1).png
Binary file modified .gitbook/assets/image (645) (1).png
Binary file modified .gitbook/assets/image (645).png
Binary file added .gitbook/assets/image (646) (1) (1).png
Binary file modified .gitbook/assets/image (646) (1).png
Binary file modified .gitbook/assets/image (646).png
Binary file added .gitbook/assets/image (647) (1) (1).png
Binary file added .gitbook/assets/image (647) (1).png
Binary file modified .gitbook/assets/image (647).png
Binary file added .gitbook/assets/image (648) (1) (1) (1).png
Binary file added .gitbook/assets/image (648) (1) (1).png
Binary file modified .gitbook/assets/image (648) (1).png
Binary file modified .gitbook/assets/image (648).png
Binary file added .gitbook/assets/image (649) (1) (1).png
Binary file modified .gitbook/assets/image (649) (1).png
Binary file modified .gitbook/assets/image (649).png
Binary file added .gitbook/assets/image (650) (1).png
Binary file modified .gitbook/assets/image (650).png
Binary file added .gitbook/assets/image (651) (1) (1) (1) (1).png
Binary file added .gitbook/assets/image (651) (1) (1) (1).png
Binary file modified .gitbook/assets/image (651) (1) (1).png
Binary file modified .gitbook/assets/image (651) (1).png
Binary file modified .gitbook/assets/image (651).png
Binary file added .gitbook/assets/image (652) (1).png
Binary file modified .gitbook/assets/image (652).png
Binary file added .gitbook/assets/image (653) (1) (1).png
Binary file modified .gitbook/assets/image (653) (1).png
Binary file modified .gitbook/assets/image (653).png
Binary file added .gitbook/assets/image (654) (1) (1) (1).png
Binary file modified .gitbook/assets/image (654) (1) (1).png
Binary file modified .gitbook/assets/image (654) (1).png
Binary file modified .gitbook/assets/image (654).png
Binary file added .gitbook/assets/image (655) (1) (1).png
Binary file modified .gitbook/assets/image (655) (1).png
Binary file modified .gitbook/assets/image (655).png
Binary file added .gitbook/assets/image (656) (1) (1).png
Binary file modified .gitbook/assets/image (656) (1).png
Binary file modified .gitbook/assets/image (656).png
Binary file modified .gitbook/assets/image (657).png
Binary file added .gitbook/assets/image (658) (1).png
Binary file modified .gitbook/assets/image (658).png
Binary file added .gitbook/assets/image (659) (1).png
Binary file modified .gitbook/assets/image (659).png
Binary file added .gitbook/assets/image (660) (1) (1) (1).png
Binary file modified .gitbook/assets/image (660) (1) (1).png
Binary file modified .gitbook/assets/image (660) (1).png
Binary file modified .gitbook/assets/image (660).png
Binary file added .gitbook/assets/image (661) (1) (1).png
Binary file modified .gitbook/assets/image (661) (1).png
Binary file modified .gitbook/assets/image (661).png
Binary file added .gitbook/assets/image (662) (1) (1).png
Binary file modified .gitbook/assets/image (662) (1).png
Binary file modified .gitbook/assets/image (662).png
Binary file not shown.
Binary file not shown.
771 changes: 771 additions & 0 deletions .gitbook/assets/sqli-authbypass-long (1).txt

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions 1911-pentesting-fox.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,15 +2,15 @@

And more services:

ubiquiti-discover udp "Ubiquiti Networks Device"
ubiquiti-discover udp "Ubiquiti Networks Device" 

dht udp "DHT Nodes"

5060 udp sip "SIP/"

![](<.gitbook/assets/image (273).png>)

![](<.gitbook/assets/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1) (2).png>)
![](<.gitbook/assets/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1) (2) (1).png>)

InfluxDB

Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ If you want to **share some tricks with the community** you can also submit **pu

### [STM Cyber](https://www.stmcyber.com)

![](<.gitbook/assets/image (642) (1).png>)
![](<.gitbook/assets/image (642) (1) (1).png>)

[**STM Cyber**](https://www.stmcyber.com) is a great cybersecurity company whose slogan is **HACK THE UNHACKABLE**. They perform their own research and develop their own hacking tools to **offer several valuable cybersecurity services** like pentestings, Red teams and training.

Expand Down
20 changes: 17 additions & 3 deletions SUMMARY.md
Original file line number Diff line number Diff line change
Expand Up @@ -190,13 +190,13 @@
* [Pentesting Network](pentesting/pentesting-network/README.md)
* [Spoofing LLMNR, NBT-NS, mDNS/DNS and WPAD and Relay Attacks](pentesting/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md)
* [Spoofing SSDP and UPnP Devices with EvilSSDP](pentesting/pentesting-network/spoofing-ssdp-and-upnp-devices.md)
* [Wifi Attacks](pentesting/pentesting-network/wifi-attacks/README.md)
* [Evil Twin EAP-TLS](pentesting/pentesting-network/wifi-attacks/evil-twin-eap-tls.md)
* [Pentesting IPv6](pentesting/pentesting-network/pentesting-ipv6.md)
* [Nmap Summary (ESP)](pentesting/pentesting-network/nmap-summary-esp.md)
* [Network Protocols Explained (ESP)](pentesting/pentesting-network/network-protocols-explained-esp.md)
* [IDS and IPS Evasion](pentesting/pentesting-network/ids-evasion.md)
* [DHCPv6](pentesting/pentesting-network/dhcpv6.md)
* [Pentesting Wifi](pentesting/pentesting-wifi/README.md)
* [Evil Twin EAP-TLS](pentesting/pentesting-wifi/evil-twin-eap-tls.md)
* [Pentesting JDWP - Java Debug Wire Protocol](pentesting/pentesting-jdwp-java-debug-wire-protocol.md)
* [Pentesting Printers](pentesting/pentesting-printers/README.md)
* [Accounting bypass](pentesting/pentesting-printers/accounting-bypass.md)
Expand Down Expand Up @@ -458,6 +458,7 @@
* [XSS Tools](pentesting-web/xss-cross-site-scripting/xss-tools.md)
* [Iframes in XSS and CSP](pentesting-web/xss-cross-site-scripting/iframes-in-xss-and-csp.md)
* [Other JS Tricks](pentesting-web/xss-cross-site-scripting/other-js-tricks.md)
* [Steal Info JS](pentesting-web/xss-cross-site-scripting/steal-info-js.md)
* [XSSI (Cross-Site Script Inclusion)](pentesting-web/xssi-cross-site-script-inclusion.md)
* [XS-Search](pentesting-web/xs-search.md)

Expand Down Expand Up @@ -530,6 +531,10 @@
* [Monitoring with Falco](pentesting/pentesting-kubernetes/kubernetes-hardening/monitoring-with-falco.md)
* [Kubernetes SecurityContext(s)](pentesting/pentesting-kubernetes/kubernetes-hardening/kubernetes-securitycontext-s.md)
* [Kubernetes NetworkPolicies](pentesting/pentesting-kubernetes/kubernetes-hardening/kubernetes-networkpolicies.md)
* [Concourse](cloud-security/concourse/README.md)
* [Concourse Architecture](cloud-security/concourse/concourse-architecture.md)
* [Concourse Lab Creation](cloud-security/concourse/concourse-lab-creation.md)
* [Concourse Enumeration & Attacks](cloud-security/concourse/concourse-enumeration-and-attacks.md)
* [Cloud Security Review](cloud-security/cloud-security-review.md)
* [AWS Security](cloud-security/aws-security.md)

Expand Down Expand Up @@ -625,10 +630,19 @@
* [More Tools](todo/more-tools.md)
* [MISC](todo/misc.md)
* [Pentesting DNS](todo/pentesting-dns.md)
* [Hardware Hacking](todo/hardware-hacking.md)
* [Hardware Hacking](todo/hardware-hacking/README.md)
* [I2C](todo/hardware-hacking/i2c.md)
* [UART](todo/hardware-hacking/uart.md)
* [Radio](todo/hardware-hacking/radio.md)
* [JTAG](todo/hardware-hacking/jtag.md)
* [SPI](todo/hardware-hacking/spi.md)

***

* [Radio Hacking](radio-hacking/README.md)
* [Pentesting RFID](radio-hacking/pentesting-rfid.md)
* [Low-Power Wide Area Network](radio-hacking/low-power-wide-area-network.md)
* [Pentesting BLE - Bluetooth Low Energy](radio-hacking/pentesting-ble-bluetooth-low-energy.md)
* [Burp Suite](burp-suite.md)
* [Other Web Tricks](other-web-tricks.md)
* [Interesting HTTP](interesting-http.md)
Expand Down
10 changes: 4 additions & 6 deletions about-the-author.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,15 +10,13 @@ I also wants to say **thanks to all the people that share cyber-security related

### BIO

If for some weird reason you are interested in knowing about my bio here you have a summary:

* I've worked in different companies as sysadmin, developer and **pentester**.
* I've worked in different companies as sysadmin, developer and **pentester**
* I'm a **Telecommunications Engineer** with a **Masters** in **Cybersecurity**
* Relevant certifications: **OSCP, OSWE**, **CRTP, eMAPT, eWPTXv2** and Professional Drone pilot.
* I speak **Spanish** and **English** and little of French (some day I will improve that).
* Relevant certifications: **OSCP, OSWE**, **CRTP, eMAPT, eWPTXv2** and Professional Drone pilot
* I speak **Spanish** and **English** and little of French (some day I will improve that)
* I'm a **CTF player**
* I'm very proud of this **book** and my **PEASS** (I'm talking about these peass: [https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite))
* And I really enjoy researching, playing CTFs, pentesting and everything related to **hacking**.
* And I really enjoy researching, playing CTFs, pentesting and everything related to **hacking**

### Support HackTricks

Expand Down
31 changes: 31 additions & 0 deletions cloud-security/concourse/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# Concourse

**Concourse allows you to build pipelines to automatically run tests, actions and build images whenever you need it (time based, when something happens...)**

## Concourse Architecture

Learn how the concourse environment is structured in:

{% content-ref url="concourse-architecture.md" %}
[concourse-architecture.md](concourse-architecture.md)
{% endcontent-ref %}

## Run Concourse Locally

Learn how you can run a concourse environment locally to do your own tests in:

{% content-ref url="concourse-lab-creation.md" %}
[concourse-lab-creation.md](concourse-lab-creation.md)
{% endcontent-ref %}

## Enumerate & Attack Concourse

Learn how you can enumerate the concourse environment and abuse it in:

{% content-ref url="concourse-enumeration-and-attacks.md" %}
[concourse-enumeration-and-attacks.md](concourse-enumeration-and-attacks.md)
{% endcontent-ref %}

## References

* [https://concourse-ci.org/internals.html#architecture-worker](https://concourse-ci.org/internals.html#architecture-worker)
26 changes: 26 additions & 0 deletions cloud-security/concourse/concourse-architecture.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Concourse Architecture

## Architecture

![](<../../.gitbook/assets/image (651).png>)

### ATC: web UI & build scheduler

The ATC is the heart of Concourse. It runs the **web UI and API** and is responsible for all pipeline **scheduling**. It **connects to PostgreSQL**, which it uses to store pipeline data (including build logs).

The [checker](https://concourse-ci.org/checker.html)'s responsibility is to continously checks for new versions of resources. The [scheduler](https://concourse-ci.org/scheduler.html) is responsible for scheduling builds for a job and the [build tracker](https://concourse-ci.org/build-tracker.html) is responsible for running any scheduled builds. The [garbage collector](https://concourse-ci.org/garbage-collector.html) is the cleanup mechanism for removing any unused or outdated objects, such as containers and volumes.

### TSA: worker registration & forwarding

The TSA is a **custom-built SSH server** that is used solely for securely **registering** [**workers**](https://concourse-ci.org/internals.html#architecture-worker) with the [ATC](https://concourse-ci.org/internals.html#component-atc).

The TSA by **default listens on port `2222`**, and is usually colocated with the [ATC](https://concourse-ci.org/internals.html#component-atc) and sitting behind a load balancer.

The **TSA implements CLI over the SSH connection,** supporting [**these commands**](https://concourse-ci.org/internals.html#component-tsa).

### Workers

In order to execute tasks concourse must have some workers. These workers **register themselves** via the [TSA](https://concourse-ci.org/internals.html#component-tsa) and run the services [**Garden**](https://github.com/cloudfoundry-incubator/garden) and [**Baggageclaim**](https://github.com/concourse/baggageclaim).

* **Garden**: This is the **Container Manage AP**I, usually run in **port 7777** via **HTTP**.
* **Baggageclaim**: This is the **Volume Management API**, usually run in **port 7788** via **HTTP**.
Loading

0 comments on commit 051dabb

Please sign in to comment.