commit ac5150025625721c187639dab92e9c3b125642e9 parent 646cfa11da22a06be65050a2bd54e27de4014f14 Author: DAEMON <zer0sec.xp@icloud.com> Date: Thu, 17 Sep 2026 01:23:02 +0100 Fix broken links across the HackTricks mirror sync-hacktricks.py stripped {{#ref}}/{{#file}} wrappers entirely instead of converting them to real markdown links, leaving every upstream cross-reference as a bare, unclickable filename — the site's copy of these pages had no working internal navigation at all, unlike the InternalAllTheThings mirror this collection is modelled on. - Convert {{#ref}}/{{#file}} and {% content-ref %} blocks into proper [label](target) links so rewrite_links() resolves them to on-site routes, with a humanized label ("No New Privileges" instead of the raw filename). - Resolve bare directory references (e.g. "protections/") to that section's index page. - Accept upstream's {{/ref}} typo as a valid close tag, and bound how many lines a block may span — the typo was making the regex run past its real closing tag and swallow unrelated headings/paragraphs into one garbled link (found in the SSTI page's BlackHat-PDF section). - Percent-encode ref/file targets so a filename with literal parentheses (the same BlackHat PDF) doesn't break the link's own markdown syntax. Re-ran the sync against the pinned upstream commit to regenerate the affected pages. Diffstat:
151 files changed, 667 insertions(+), 403 deletions(-)
diff --git a/scripts/sync-hacktricks.py b/scripts/sync-hacktricks.py @@ -132,7 +132,12 @@ def resolve_target(current_source: str, target: str, image: bool) -> str | None: return None current_dir = posixpath.dirname(current_source) - resolved = posixpath.normpath(posixpath.join(current_dir, unquote(target))) + raw_target = unquote(target) + # A bare directory reference (upstream {{#ref}} blocks often point at a + # whole section, not a file) means "that section's index page". + if raw_target.endswith("/"): + raw_target += "README.md" + resolved = posixpath.normpath(posixpath.join(current_dir, raw_target)) if resolved.startswith("../"): return None if resolved.lower().endswith(".md"): @@ -142,7 +147,77 @@ def resolve_target(current_source: str, target: str, image: bool) -> str | None: return None +# Upstream has at least one typo'd close tag ({{/ref}} instead of +# {{#endref}} — see ssti-server-side-template-injection/README.md around its +# LESS section). Accepting that variant here matters: with only the correct +# spelling recognized, the non-greedy match instead runs on to the *next* +# real {{#endref}}, silently swallowing every heading and paragraph between +# the two into a single garbled link. MAX_BLOCK_LINES below is the backstop +# for whatever variant of this a future upstream edit introduces. +REF_BLOCK = re.compile(r"^[ \t]*\{\{#ref\}\}[ \t]*\n(.*?)\n[ \t]*\{\{(?:#end|/)ref\}\}[ \t]*$", re.M | re.S) +FILE_BLOCK = re.compile(r"^[ \t]*\{\{#file\}\}[ \t]*\n(.*?)\n[ \t]*\{\{(?:#end|/)file\}\}[ \t]*$", re.M | re.S | re.I) +MAX_BLOCK_LINES = 8 +CONTENT_REF_BLOCK = re.compile( + r'^[ \t]*\{%\s*content-ref\s+url=["\']([^"\']+)["\'][^%]*%\}[ \t]*\n(.*?)\n[ \t]*\{%\s*endcontent-ref\s*%\}[ \t]*$', + re.M | re.S | re.I, +) +WRAPPING_LINK = re.compile(r"^\[([^\]]*)\]\(([^)]+)\)$") + + +def humanize_ref_label(path: str) -> str: + """"protections/no-new-privileges.md" -> "No New Privileges" — same + dash-to-title-case fallback page_title() already uses for a page's own + title, so a ref link reads like a page name rather than a bare path.""" + stem = path.rstrip("/").rsplit("/", 1)[-1] + stem = re.sub(r"\.md$", "", stem, flags=re.I) + return stem.replace("-", " ").replace("_", " ").title() or path + + +def linkify_ref_blocks(body: str) -> str: + """ + {{#ref}}/{{#file}} wrap a bare relative path with no markdown link syntax + at all — upstream renders these as GitBook card links. Deleting the + wrapper (as this script used to) left the bare path behind as plain, + unclickable text throughout every synced page. Turning each path into a + real `[label](target)` link here lets rewrite_links() below resolve it + to the right on-site route exactly like an ordinary inline link. + """ + + def ref_repl(match: "re.Match[str]") -> str: + lines = [line.strip() for line in match.group(1).splitlines() if line.strip()] + # A legitimate {{#ref}} block is a short list of bare paths. Anything + # longer, or containing a heading, is a sign the regex ran past its + # real closing tag onto unrelated content — leave it untouched rather + # than turn a chunk of the page into garbage nested links. + if not lines or len(lines) > MAX_BLOCK_LINES or any(line.startswith("#") for line in lines): + return match.group(0) + # A raw filename can contain spaces or literal parentheses (seen in + # an upstream PDF name); MARKDOWN_LINK's `([^)]+)` target group can't + # tell those apart from the link's own closing paren, so quote the + # target the same way quoted_blob()/quoted_raw() already do. + return "\n\n".join( + f"[{humanize_ref_label(line)}]({quote(line, safe='/')})" for line in lines + ) + + body = REF_BLOCK.sub(ref_repl, body) + body = FILE_BLOCK.sub(ref_repl, body) + + def content_ref_repl(match: "re.Match[str]") -> str: + target = match.group(1).strip() + label = match.group(2).strip() + # The label is sometimes already `[text](target)` — unwrap it rather + # than nesting a link inside a link. + wrapped = WRAPPING_LINK.match(label) + if wrapped: + label = wrapped.group(1) + label = label or humanize_ref_label(target) + return f"[{label}]({target})" + + return CONTENT_REF_BLOCK.sub(content_ref_repl, body) + + def clean_gitbook(body: str) -> str: + body = linkify_ref_blocks(body) # The banner is repeated at the top and bottom of most upstream pages. body = re.sub(r"^\s*\{\{#include\s+[^}]*banners/hacktricks-training\.md\}\}\s*$", "", body, flags=re.M | re.I) # Other mdBook/GitBook includes cannot be expanded safely without copying @@ -161,11 +236,10 @@ def clean_gitbook(body: str) -> str: flags=re.M | re.I, ) body = re.sub(r"^\s*\{\{#(?:end)?tabs?[^}]*\}\}\s*$", "", body, flags=re.M | re.I) - body = re.sub(r"^\s*\{\{#(?:end)?(?:ref|file)[^}]*\}\}\s*$", "", body, flags=re.M | re.I) # Keep the useful content inside GitBook wrappers while dropping syntax # Astro would otherwise display as literal template tags. body = re.sub(r"^\s*\{%\s*tab\s+title=[\"']([^\"']+)[\"'][^%]*%\}\s*$", r"### \1", body, flags=re.M | re.I) - body = re.sub(r"^\s*\{%\s*(?:end)?(?:hint|tabs|tab|code|endcode|embed|content-ref)[^%]*%\}\s*$", "", body, flags=re.M | re.I) + body = re.sub(r"^\s*\{%\s*(?:end)?(?:hint|tabs|tab|code|endcode|embed)[^%]*%\}\s*$", "", body, flags=re.M | re.I) body = re.sub(r"\n{4,}", "\n\n\n", body) return body.strip() + "\n" diff --git a/src/content/hacktricks/linux-hardening/containers-namespaces/container-security/distroless.md b/src/content/hacktricks/linux-hardening/containers-namespaces/container-security/distroless.md @@ -118,7 +118,7 @@ That combination makes classic "download binary to disk and run it" workflows un The dedicated page for that is: -../../linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/ +[Bypass Fs Protections Read Only No Exec Distroless](/hacktricks/linux-hardening/linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/overview) The most relevant techniques there are: @@ -167,13 +167,13 @@ The key point is that distroless is an **image property**, not a runtime protect For filesystem and memory-execution bypasses commonly needed in distroless environments: -../../linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/ +[Bypass Fs Protections Read Only No Exec Distroless](/hacktricks/linux-hardening/linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/overview) For container runtime, socket, and mount abuse that still applies to distroless workloads: -runtime-api-and-daemon-exposure.md +[Runtime Api And Daemon Exposure](/hacktricks/linux-hardening/containers-namespaces/container-security/runtime-api-and-daemon-exposure) -sensitive-host-mounts.md +[Sensitive Host Mounts](/hacktricks/linux-hardening/containers-namespaces/container-security/sensitive-host-mounts) ## References diff --git a/src/content/hacktricks/linux-hardening/containers-namespaces/container-security/overview.md b/src/content/hacktricks/linux-hardening/containers-namespaces/container-security/overview.md @@ -46,49 +46,49 @@ The section is organized from the most general concepts to the most specific one Start with the runtime and ecosystem overview: -runtimes-and-engines.md +[Runtimes And Engines](/hacktricks/linux-hardening/containers-namespaces/container-security/runtimes-and-engines) Then review the control planes and supply-chain surfaces that frequently decide whether an attacker even needs a kernel escape: -runtime-api-and-daemon-exposure.md +[Runtime Api And Daemon Exposure](/hacktricks/linux-hardening/containers-namespaces/container-security/runtime-api-and-daemon-exposure) -authorization-plugins.md +[Authorization Plugins](/hacktricks/linux-hardening/containers-namespaces/container-security/authorization-plugins) -image-security-and-secrets.md +[Image Security And Secrets](/hacktricks/linux-hardening/containers-namespaces/container-security/image-security-and-secrets) -assessment-and-hardening.md +[Assessment And Hardening](/hacktricks/linux-hardening/containers-namespaces/container-security/assessment-and-hardening) Then move into the protection model: -protections/ +[Protections](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/overview) The namespace pages explain the kernel isolation primitives individually: -protections/namespaces/ +[Namespaces](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/namespaces/overview) The pages on cgroups, capabilities, seccomp, AppArmor, SELinux, `no_new_privs`, masked paths, and read-only system paths explain the mechanisms that are usually layered on top of namespaces: -protections/cgroups.md +[Cgroups](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/cgroups) -protections/capabilities.md +[Capabilities](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/capabilities) -protections/seccomp.md +[Seccomp](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/seccomp) -protections/apparmor.md +[Apparmor](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/apparmor) -protections/selinux.md +[Selinux](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/selinux) -protections/no-new-privileges.md +[No New Privileges](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/no-new-privileges) -protections/masked-paths.md +[Masked Paths](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/masked-paths) -protections/read-only-paths.md +[Read Only Paths](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/read-only-paths) -distroless.md +[Distroless](/hacktricks/linux-hardening/containers-namespaces/container-security/distroless) -privileged-containers.md +[Privileged Containers](/hacktricks/linux-hardening/containers-namespaces/container-security/privileged-containers) -sensitive-host-mounts.md +[Sensitive Host Mounts](/hacktricks/linux-hardening/containers-namespaces/container-security/sensitive-host-mounts) ## A Good First Enumeration Mindset diff --git a/src/content/hacktricks/linux-hardening/containers-namespaces/container-security/privileged-containers.md b/src/content/hacktricks/linux-hardening/containers-namespaces/container-security/privileged-containers.md @@ -61,9 +61,9 @@ The weakened protections being abused here are: Related pages: -protections/capabilities.md +[Capabilities](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/capabilities) -protections/namespaces/mount-namespace.md +[Mount Namespace](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/namespaces/mount-namespace) ### 2. Mount Or Reuse A Host Bind Mount And `chroot` @@ -105,9 +105,9 @@ If `/var` is host-mounted or the runtime directories are visible, this can be en Related pages: -protections/namespaces/mount-namespace.md +[Mount Namespace](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/namespaces/mount-namespace) -sensitive-host-mounts.md +[Sensitive Host Mounts](/hacktricks/linux-hardening/containers-namespaces/container-security/sensitive-host-mounts) ## Checks @@ -125,23 +125,23 @@ Any one of those may be enough for post-exploitation. Several together usually m ## Related Pages -protections/capabilities.md +[Capabilities](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/capabilities) -protections/seccomp.md +[Seccomp](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/seccomp) -protections/apparmor.md +[Apparmor](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/apparmor) -protections/selinux.md +[Selinux](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/selinux) -protections/masked-paths.md +[Masked Paths](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/masked-paths) -protections/read-only-paths.md +[Read Only Paths](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/read-only-paths) -protections/namespaces/mount-namespace.md +[Mount Namespace](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/namespaces/mount-namespace) -protections/namespaces/pid-namespace.md +[Pid Namespace](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/namespaces/pid-namespace) -protections/namespaces/network-namespace.md +[Network Namespace](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/namespaces/network-namespace) ## References diff --git a/src/content/hacktricks/linux-hardening/containers-namespaces/container-security/protections/capabilities.md b/src/content/hacktricks/linux-hardening/containers-namespaces/container-security/protections/capabilities.md @@ -20,7 +20,7 @@ Containers depend on this distinction heavily. Many workloads are still launched For the full Linux capability reference and many abuse examples, see: -../../../interesting-files-permissions/linux-capabilities.md +[Linux Capabilities](/hacktricks/linux-hardening/interesting-files-permissions/linux-capabilities) ## Operation diff --git a/src/content/hacktricks/linux-hardening/containers-namespaces/container-security/protections/overview.md b/src/content/hacktricks/linux-hardening/containers-namespaces/container-security/protections/overview.md @@ -30,27 +30,27 @@ The rest of this folder explains each of these mechanisms in more detail, includ ## Read Next -namespaces/ +[Namespaces](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/namespaces/overview) -cgroups.md +[Cgroups](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/cgroups) -capabilities.md +[Capabilities](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/capabilities) -seccomp.md +[Seccomp](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/seccomp) -apparmor.md +[Apparmor](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/apparmor) -selinux.md +[Selinux](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/selinux) -no-new-privileges.md +[No New Privileges](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/no-new-privileges) -masked-paths.md +[Masked Paths](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/masked-paths) -read-only-paths.md +[Read Only Paths](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/read-only-paths) Many real escapes also depend on what host content was mounted into the workload, so after reading the core protections it is useful to continue with: -../sensitive-host-mounts.md +[Sensitive Host Mounts](/hacktricks/linux-hardening/containers-namespaces/container-security/sensitive-host-mounts) ## References diff --git a/src/content/hacktricks/linux-hardening/containers-namespaces/containerd-ctr-privilege-escalation.md b/src/content/hacktricks/linux-hardening/containers-namespaces/containerd-ctr-privilege-escalation.md @@ -16,7 +16,7 @@ license: "CC-BY-NC-4.0" Go to the following link to learn **where `containerd` and `ctr` fit in the container stack**: -container-security/runtimes-and-engines.md +[Runtimes And Engines](/hacktricks/linux-hardening/containers-namespaces/container-security/runtimes-and-engines) ## PE 1 @@ -32,7 +32,7 @@ If you find that a host contains the `ctr` command, the native CLI bundled with ```text `--privileged` grants the process the caller's effective Linux capabilities and removes several isolation controls, but an escape remains environment-dependent; use the techniques mentioned in the following page to test for it:<sup>[[5]](#references)</sup> -container-security/ +[Container Security](/hacktricks/linux-hardening/containers-namespaces/container-security/overview) ## References diff --git a/src/content/hacktricks/linux-hardening/containers-namespaces/runc-privilege-escalation.md b/src/content/hacktricks/linux-hardening/containers-namespaces/runc-privilege-escalation.md @@ -16,7 +16,7 @@ license: "CC-BY-NC-4.0" If you want to learn more about **runc** check the following page: -../../network-services-pentesting/2375-pentesting-docker.md +[2375 Pentesting Docker](/hacktricks/network-services-pentesting/2375-pentesting-docker) ## PE diff --git a/src/content/hacktricks/linux-hardening/interesting-files-permissions/nfs-no-root-squash-misconfiguration-pe.md b/src/content/hacktricks/linux-hardening/interesting-files-permissions/nfs-no-root-squash-misconfiguration-pe.md @@ -24,7 +24,7 @@ If an allowed client can mount a writable export in **`/etc/exports`** configure For more information about **NFS** check: -../../network-services-pentesting/nfs-service-pentesting.md +[Nfs Service Pentesting](/hacktricks/network-services-pentesting/nfs-service-pentesting) ## Privilege Escalation diff --git a/src/content/hacktricks/linux-hardening/interesting-files-permissions/selinux.md b/src/content/hacktricks/linux-hardening/interesting-files-permissions/selinux.md @@ -151,7 +151,7 @@ Modern container operations worth noting:<sup>[[16]](#references)[[17]](#referen This page keeps the container content short to avoid duplication. For the container-specific abuse cases and runtime examples, check: -../containers-namespaces/container-security/protections/selinux.md +[Selinux](/hacktricks/linux-hardening/containers-namespaces/container-security/protections/selinux) ## References diff --git a/src/content/hacktricks/linux-hardening/linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/overview.md b/src/content/hacktricks/linux-hardening/linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/overview.md @@ -79,7 +79,7 @@ With a similar purpose to DDexec, [**memdlopen**](https://github.com/arget13/mem For a dedicated explanation of **what distroless actually is**, when it helps, when it does not, and how it changes post-exploitation tradecraft in containers, check: -../../../containers-namespaces/container-security/distroless.md +[Distroless](/hacktricks/linux-hardening/containers-namespaces/container-security/distroless) ### What is distroless diff --git a/src/content/hacktricks/linux-hardening/linux-basics/bypass-linux-restrictions/overview.md b/src/content/hacktricks/linux-hardening/linux-basics/bypass-linux-restrictions/overview.md @@ -153,11 +153,11 @@ ln /f* ```text If you are inside a filesystem with **read-only and noexec protections**, or in a **distroless image**, the environment imposes execution constraints documented by Linux `mount(8)` and the Distroless project; the linked page collects techniques for working within them.<sup>[[11]](#references)[[12]](#references)</sup> -bypass-fs-protections-read-only-no-exec-distroless/ +[Bypass Fs Protections Read Only No Exec Distroless](/hacktricks/linux-hardening/linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/overview) ## Chroot & other Jails Bypass -../../main-system-information/escaping-from-limited-bash.md +[Escaping From Limited Bash](/hacktricks/linux-hardening/main-system-information/escaping-from-limited-bash) ## Space-Based Bash NOP Sled ("Bashsledding") diff --git a/src/content/hacktricks/linux-hardening/linux-basics/linux-privilege-escalation/overview.md b/src/content/hacktricks/linux-hardening/linux-basics/linux-privilege-escalation/overview.md @@ -390,19 +390,22 @@ Note that if you have write permissions over the docker socket because you are * Check **more ways to break out from containers or abuse container runtimes to escalate privileges** in: -../../containers-namespaces/container-security/ + +[Container Security](/hacktricks/linux-hardening/containers-namespaces/container-security/overview) ## Containerd (ctr) privilege escalation If you find that you can use the **`ctr`** command read the following page as **you may be able to abuse it to escalate privileges**: -../../containers-namespaces/containerd-ctr-privilege-escalation.md + +[Containerd Ctr Privilege Escalation](/hacktricks/linux-hardening/containers-namespaces/containerd-ctr-privilege-escalation) ## **RunC** privilege escalation If you find that you can use the **`runc`** command read the following page as **you may be able to abuse it to escalate privileges**: -../../containers-namespaces/runc-privilege-escalation.md + +[Runc Privilege Escalation](/hacktricks/linux-hardening/containers-namespaces/runc-privilege-escalation) ## **D-Bus** @@ -462,7 +465,8 @@ Loopback (`lo`) is especially valuable in post-exploitation because many interna Check if you are a **member of some group** that could grant you root privileges: -../../user-information/interesting-groups-linux-pe/ + +[Interesting Groups Linux Pe](/hacktricks/linux-hardening/user-information/interesting-groups-linux-pe/overview) ### Clipboard @@ -658,9 +662,11 @@ The project collects legitimate functions of Unix binaries that can be abused to > strace -o /dev/null /bin/sh\ > sudo awk 'BEGIN {system("/bin/sh")}' -https://gtfobins.github.io/ -https://gtfoargs.github.io/ +[Gtfobins.Github.Io](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/linux-basics/linux-privilege-escalation/https%3A/gtfobins.github.io/README.md) + + +[Gtfoargs.Github.Io](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/linux-basics/linux-privilege-escalation/https%3A/gtfoargs.github.io/README.md) ### FallOfSudo @@ -727,7 +733,8 @@ That means that the configuration files from `/etc/ld.so.conf.d/*.conf` will be If for some reason **a user has write permissions** on any of the paths indicated: `/etc/ld.so.conf`, `/etc/ld.so.conf.d/`, any file inside `/etc/ld.so.conf.d/` or any folder within the config file inside `/etc/ld.so.conf.d/*.conf` he may be able to escalate privileges.\ Take a look at **how to exploit this misconfiguration** in the following page: -../../interesting-files-permissions/ld.so.conf-example.md + +[Ld.So.Conf Example](/hacktricks/linux-hardening/interesting-files-permissions/ld-so-conf-example) ### RPATH @@ -816,7 +823,8 @@ The file `/etc/sshd_config` can **allow** or **denied** ssh-agent forwarding wit If you find that Forward Agent is configured in an environment read the following page as **you may be able to abuse it to escalate privileges**: -../../user-information/ssh-forward-agent-exploitation.md + +[Ssh Forward Agent Exploitation](/hacktricks/linux-hardening/user-information/ssh-forward-agent-exploitation) ## Interesting Files @@ -930,21 +938,25 @@ On the other hand, `/etc/init` is associated with **Upstart**, a newer **service ### NFS Privilege escalation -../../interesting-files-permissions/nfs-no_root_squash-misconfiguration-pe.md + +[Nfs No Root Squash Misconfiguration Pe](/hacktricks/linux-hardening/interesting-files-permissions/nfs-no-root-squash-misconfiguration-pe) ### Escaping from restricted Shells -../../main-system-information/escaping-from-limited-bash.md + +[Escaping From Limited Bash](/hacktricks/linux-hardening/main-system-information/escaping-from-limited-bash) ### Cisco - vmanage -../../network-information/cisco-vmanage.md + +[Cisco Vmanage](/hacktricks/linux-hardening/network-information/cisco-vmanage) ## Android rooting frameworks: manager-channel abuse Android rooting frameworks commonly hook a syscall to expose privileged kernel functionality to a userspace manager. Weak manager authentication (e.g., signature checks based on FD-order or poor password schemes) can enable a local app to impersonate the manager and escalate to root on already-rooted devices. Learn more and exploitation details here: -../../software-information/android-rooting-frameworks-manager-auth-bypass-syscall-hook.md + +[Android Rooting Frameworks Manager Auth Bypass Syscall Hook](/hacktricks/linux-hardening/software-information/android-rooting-frameworks-manager-auth-bypass-syscall-hook) ## VMware Tools service discovery LPE (CWE-426) via regex-based exec (CVE-2025-41244) @@ -952,7 +964,7 @@ Regex-driven service discovery in VMware Tools/Aria Operations can extract a bin Learn more and see a generalized pattern applicable to other discovery/monitoring stacks here: -../../main-system-information/kernel-lpe-cves/vmware-tools-service-discovery-untrusted-search-path-cve-2025-41244.md +[Vmware Tools Service Discovery Untrusted Search Path Cve 2025 41244](/hacktricks/linux-hardening/main-system-information/kernel-lpe-cves/vmware-tools-service-discovery-untrusted-search-path-cve-2025-41244) ## Kernel Security Protections diff --git a/src/content/hacktricks/linux-hardening/main-system-information/escaping-from-limited-bash.md b/src/content/hacktricks/linux-hardening/main-system-information/escaping-from-limited-bash.md @@ -107,13 +107,14 @@ Also check: **It could also be interesting the page:** -../linux-basics/bypass-linux-restrictions/ +[Bypass Linux Restrictions](/hacktricks/linux-hardening/linux-basics/bypass-linux-restrictions/overview) ## Python Jails Tricks about escaping from python jails in the following page: -../../generic-methodologies-and-resources/python/bypass-python-sandboxes/ + +[Bypass Python Sandboxes](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/python/bypass-python-sandboxes/README.md) ## Lua Jails diff --git a/src/content/hacktricks/linux-hardening/network-information/cisco-vmanage.md b/src/content/hacktricks/linux-hardening/network-information/cisco-vmanage.md @@ -16,7 +16,7 @@ Once you have code execution on Cisco vManage / *Catalyst SD-WAN Manager* as `vm If you still need the **initial foothold** on a controller, check the dedicated control-plane page first: -../../network-services-pentesting/12346-udp-pentesting-cisco-sd-wan-control-plane.md +[12346 Udp Pentesting Cisco Sd Wan Control Plane](/hacktricks/network-services-pentesting/12346-udp-pentesting-cisco-sd-wan-control-plane) ## Quick local triage diff --git a/src/content/hacktricks/linux-hardening/post-exploitation/linux-post-exploitation/overview.md b/src/content/hacktricks/linux-hardening/post-exploitation/linux-post-exploitation/overview.md @@ -12,13 +12,14 @@ license: "CC-BY-NC-4.0" # Linux Post-Exploitation -trojanized-system-daemons-and-reverse-proxies.md +[Trojanized System Daemons And Reverse Proxies](/hacktricks/linux-hardening/post-exploitation/linux-post-exploitation/trojanized-system-daemons-and-reverse-proxies) ## Sniffing Logon Passwords with PAM Let's configure a PAM module to log each password each user uses to login. If you don't know what is PAM check: -../../software-information/pam-pluggable-authentication-modules.md + +[Pam Pluggable Authentication Modules](/hacktricks/linux-hardening/software-information/pam-pluggable-authentication-modules) **For further details check the [original post](https://embracethered.com/blog/posts/2022/post-exploit-pam-ssh-password-grabbing/)**. This is just a summary:<sup>[[8]](#references)</sup> diff --git a/src/content/hacktricks/linux-hardening/software-information/freeipa-pentesting.md b/src/content/hacktricks/linux-hardening/software-information/freeipa-pentesting.md @@ -55,7 +55,8 @@ Keytab files, containing Kerberos principals and encrypted keys, are critical fo You can find more information about how to use tickets in linux in the following link: -../user-information/linux-active-directory.md + +[Linux Active Directory](/hacktricks/linux-hardening/user-information/linux-active-directory) ## Enumeration diff --git a/src/content/hacktricks/linux-hardening/software-information/splunk-lpe-and-persistence.md b/src/content/hacktricks/linux-hardening/software-information/splunk-lpe-and-persistence.md @@ -16,7 +16,7 @@ If **enumerating** a machine **internally** or **externally** you find **Splunk If you only need the generic remote attack surface, enumeration, or app-upload RCE path, check: -../../network-services-pentesting/8089-splunkd.md +[8089 Splunkd](/hacktricks/network-services-pentesting/8089-splunkd) If you are **already root** and the Splunk service is not listening only on localhost, you can also steal **Splunk password hashes**, recover **encrypted secrets**, or push a **malicious app** to keep persistence locally or across multiple forwarders.<sup>[[7]](#references)[[8]](#references)[[11]](#references)</sup> diff --git a/src/content/hacktricks/linux-hardening/user-information/linux-active-directory.md b/src/content/hacktricks/linux-hardening/user-information/linux-active-directory.md @@ -24,13 +24,15 @@ If you have access over an AD in linux (or bash in Windows) you can try [https:/ You can also check the following page to learn **other ways to enumerate AD from linux**: -../../network-services-pentesting/pentesting-ldap.md + +[Pentesting Ldap](/hacktricks/network-services-pentesting/pentesting-ldap) ### FreeIPA FreeIPA is an open-source **alternative** to Microsoft Windows **Active Directory**, mainly for **Unix** environments. It combines a complete **LDAP directory** with an MIT **Kerberos** Key Distribution Center for management akin to Active Directory. Utilizing the Dogtag **Certificate System** for CA & RA certificate management, it supports **multi-factor** authentication, including smartcards. SSSD is integrated for Unix authentication processes.<sup>[[14]](#references)[[15]](#references)</sup> Learn more about it in: -../software-information/freeipa-pentesting.md + +[Freeipa Pentesting](/hacktricks/linux-hardening/software-information/freeipa-pentesting) ### Domain-joined host artefacts @@ -40,7 +42,7 @@ Before touching tickets, identify **how the host was joined to AD** and **where ```text If you want the **Linux-specific ticket harvesting workflows** (`FILE`, `DIR`, `KEYRING`, `KCM`, `/proc`, etc.), check the dedicated page: -../../network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-linux.md +[Harvesting Tickets From Linux](/hacktricks/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-linux) ### CCACHE ticket reuse from /tmp diff --git a/src/content/hacktricks/mobile-pentesting/android-app-pentesting/frida-tutorial/frida-tutorial-2.md b/src/content/hacktricks/mobile-pentesting/android-app-pentesting/frida-tutorial/frida-tutorial-2.md @@ -86,7 +86,7 @@ Here you will see how to make **Python and JS interact** using JSON objects. JS - Frida 17.1.4 bumped `frida-java-bridge` to `7.0.3` in internal Android agents, adding **Android 16** support. If heap scans or Java hooks behave strangely on very recent Android versions, first verify that **frida-tools**, **frida-python**, and **frida-server/gadget** are on matching recent versions. - For **anti-Frida**, **root detection**, and **SSL pinning** bypasses, keep that content in the dedicated page: -../android-anti-instrumentation-and-ssl-pinning-bypass.md +[Android Anti Instrumentation And Ssl Pinning Bypass](/hacktricks/mobile-pentesting/android-app-pentesting/android-anti-instrumentation-and-ssl-pinning-bypass) There is a part 5 that is not explained here because it doesn't add anything substantially new. If you want to read it, it is here: [https://11x256.github.io/Frida-hooking-android-part-5/](https://11x256.github.io/Frida-hooking-android-part-5/) diff --git a/src/content/hacktricks/mobile-pentesting/android-app-pentesting/frida-tutorial/objection-tutorial.md b/src/content/hacktricks/mobile-pentesting/android-app-pentesting/frida-tutorial/objection-tutorial.md @@ -28,7 +28,7 @@ The goal of **objection** is to expose common Frida-powered mobile-testing actio For this tutorial I am going to use the APK that you can download here: -app-release.zip +[App Release.Zip](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/frida-tutorial/app-release.zip) Or from its [original repository](https://github.com/asvid/FridaApp) (download app-release.apk) @@ -46,7 +46,7 @@ If you are using a **non-rooted device**, a common workflow is to patch the APK ```text For a complete Gadget embedding workflow (including `--gadget-config` and `-l`/script-mode patching), check: -README.md +[Readme](/hacktricks/mobile-pentesting/android-app-pentesting/frida-tutorial/overview) If the application still crashes or exits as soon as Objection/Frida attaches, continue with [this anti-instrumentation workflow](/hacktricks/mobile-pentesting/android-app-pentesting/android-anti-instrumentation-and-ssl-pinning-bypass). diff --git a/src/content/hacktricks/mobile-pentesting/android-app-pentesting/intent-injection.md b/src/content/hacktricks/mobile-pentesting/android-app-pentesting/intent-injection.md @@ -33,7 +33,7 @@ PoC via adb: See also: -webview-attacks.md +[Webview Attacks](/hacktricks/mobile-pentesting/android-app-pentesting/webview-attacks) ## Order-of-checks bug enabling JavaScript diff --git a/src/content/hacktricks/mobile-pentesting/android-app-pentesting/overview.md b/src/content/hacktricks/mobile-pentesting/android-app-pentesting/overview.md @@ -12,13 +12,14 @@ license: "CC-BY-NC-4.0" # Android Applications Pentesting -../../generic-methodologies-and-resources/pentesting-network/dds-rtps-security.md +[Dds Rtps Security](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/dds-rtps-security.md) ## Android Applications Basics It's highly recommended to start reading this page to know about the **most important parts related to Android security and the most dangerous components in an Android application**: -android-applications-basics.md + +[Android Applications Basics](/hacktricks/mobile-pentesting/android-app-pentesting/android-applications-basics) For broader study, combine the OWASP Mobile Application Security project with Android reverse-engineering courses and practical security guides. The Android App Reverse Engineering 101 course, Manifest Security series, Android-Security-Teryaagh notes, Mobile Hacking Workshop, and Application Security Wiki provide complementary labs, methodology, and tool references.<sup>[[2]](#references)[[3]](#references)[[4]](#references)[[5]](#references)[[6]](#references)[[17]](#references)</sup> @@ -41,7 +42,7 @@ Sometimes it is useful to **modify application code** to access **hidden informa - [Android app-level virtualization / app cloning abuse & detection](/hacktricks/mobile-pentesting/android-app-pentesting/android-application-level-virtualization) - [Shizuku Privileged API (ADB-based non-root privileged access)](/hacktricks/mobile-pentesting/android-app-pentesting/shizuku-privileged-api) -../../binary-exploitation/linux-kernel-exploitation/futex-pi-uaf-pipe-buffer-workqueue-usermodehelper.md +[Futex Pi Uaf Pipe Buffer Workqueue Usermodehelper](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/binary-exploitation/linux-kernel-exploitation/futex-pi-uaf-pipe-buffer-workqueue-usermodehelper.md) - [Exploiting Insecure In-App Update Mechanisms](/hacktricks/mobile-pentesting/android-app-pentesting/insecure-in-app-update-rce) - [Abusing Accessibility Services (Android RAT)](/hacktricks/mobile-pentesting/android-app-pentesting/accessibility-services-abuse) @@ -85,19 +86,21 @@ Use the decompiled tree and a test device to quickly validate this class of bug: ## Android Enterprise & Work Profile Attacks -android-enterprise-work-profile-bypass.md +[Android Enterprise Work Profile Bypass](/hacktricks/mobile-pentesting/android-app-pentesting/android-enterprise-work-profile-bypass) ## Case Studies & Vulnerabilities -../ios-pentesting/air-keyboard-remote-input-injection.md -../../linux-hardening/software-information/android-rooting-frameworks-manager-auth-bypass-syscall-hook.md +[Air Keyboard Remote Input Injection](/hacktricks/mobile-pentesting/ios-pentesting/air-keyboard-remote-input-injection) + -abusing-android-media-pipelines-image-parsers.md +[Android Rooting Frameworks Manager Auth Bypass Syscall Hook](/hacktricks/linux-hardening/software-information/android-rooting-frameworks-manager-auth-bypass-syscall-hook) -baseband-and-soc-isolation-exploitation.md +[Abusing Android Media Pipelines Image Parsers](/hacktricks/mobile-pentesting/android-app-pentesting/abusing-android-media-pipelines-image-parsers) -firmware-level-zygote-backdoor-libandroid_runtime.md +[Baseband And Soc Isolation Exploitation](/hacktricks/mobile-pentesting/android-app-pentesting/baseband-and-soc-isolation-exploitation) + +[Firmware Level Zygote Backdoor Libandroid Runtime](/hacktricks/mobile-pentesting/android-app-pentesting/firmware-level-zygote-backdoor-libandroid-runtime) ### Pre-installed privileged Android TV-box implants (OEM / reseller firmware abuse) @@ -176,7 +179,8 @@ In effect, it is **blinding the user from knowing they are actually performing a Find more information in: -tapjacking.md + +[Tapjacking](/hacktricks/mobile-pentesting/android-app-pentesting/tapjacking) ### Task Hijacking @@ -184,7 +188,8 @@ An **activity** with the **`launchMode`** set to **`singleTask` without any `tas More info in: -android-task-hijacking.md + +[Android Task Hijacking](/hacktricks/mobile-pentesting/android-app-pentesting/android-task-hijacking) ### Insecure data storage @@ -235,11 +240,12 @@ For some reason sometimes developers accept all the certificates even if for exa - [Read this to learn **how to reverse native functions**](/hacktricks/mobile-pentesting/android-app-pentesting/reversing-native-libraries) - In-memory native code execution via JNI (downloaded shellcode → mmap/mprotect → call):<sup>[[12]](#references)</sup> -in-memory-jni-shellcode-execution.md +[In Memory Jni Shellcode Execution](/hacktricks/mobile-pentesting/android-app-pentesting/in-memory-jni-shellcode-execution) ### **Other tricks** -content-protocol.md + +[Content Protocol](/hacktricks/mobile-pentesting/android-app-pentesting/content-protocol) --- @@ -266,7 +272,8 @@ Thanks to the ADB connection you can use **Drozer** and **Frida** inside the emu - [**Android Studio**](https://developer.android.com/studio) (You can create **x86** and **ARM** devices, and recent x86 system images can run ARM binaries without requiring a slow ARM-only emulator).<sup>[[19]](#references)</sup> - Learn to set it up in this page: -avd-android-virtual-device.md + +[Avd Android Virtual Device](/hacktricks/mobile-pentesting/android-app-pentesting/avd-android-virtual-device) - [**Genymotion**](https://www.genymotion.com/fun-zone/) **(Free version:** Personal Edition, you need to create an account. _It's recommend to **download** the version **WITH**_ _**VirtualBox** to avoid potential errors._) - [**Nox**](https://es.bignox.com) (Free, but it doesn't support Frida or Drozer). @@ -480,7 +487,7 @@ If you want to pentest Android applications you need to know how to use Frida. #### Anti-instrumentation & SSL pinning bypass workflow -android-anti-instrumentation-and-ssl-pinning-bypass.md +[Android Anti Instrumentation And Ssl Pinning Bypass](/hacktricks/mobile-pentesting/android-app-pentesting/android-anti-instrumentation-and-ssl-pinning-bypass) ### **Dump Memory - Fridump** diff --git a/src/content/hacktricks/mobile-pentesting/android-app-pentesting/react-native-application.md b/src/content/hacktricks/mobile-pentesting/android-app-pentesting/react-native-application.md @@ -107,9 +107,9 @@ React Native Android typically relies on OkHttp under the hood (via the `Network For generic Android interception and pinning bypass techniques refer to: -make-apk-accept-ca-certificate.md +[Make Apk Accept Ca Certificate](/hacktricks/mobile-pentesting/android-app-pentesting/make-apk-accept-ca-certificate) -frida-tutorial/objection-tutorial.md +[Objection Tutorial](/hacktricks/mobile-pentesting/android-app-pentesting/frida-tutorial/objection-tutorial) ### Runtime GATT protocol discovery with Frida (Hermes-friendly) diff --git a/src/content/hacktricks/mobile-pentesting/android-app-pentesting/tapjacking.md b/src/content/hacktricks/mobile-pentesting/android-app-pentesting/tapjacking.md @@ -94,7 +94,8 @@ Besides classic Tapjacking, modern Android banking malware families (e.g. **Toxi For additional details on leveraging Accessibility Services for full remote device control (e.g. PlayPraetor, SpyNote, etc.) see: -accessibility-services-abuse.md + +[Accessibility Services Abuse](/hacktricks/mobile-pentesting/android-app-pentesting/accessibility-services-abuse) ## References - [1] [Android Developers – Tapjacking risk & mitigations (updated 2024)](https://developer.android.com/privacy-and-security/risks/tapjacking) diff --git a/src/content/hacktricks/mobile-pentesting/ios-pentesting/ios-testing-environment.md b/src/content/hacktricks/mobile-pentesting/ios-pentesting/ios-testing-environment.md @@ -71,7 +71,8 @@ Corellium is a commercial virtual iOS environment commonly used for mobile secur Check this blog post about how to pentest an iOS application in a **non jailbroken device**: -ios-pentesting-without-jailbreak.md + +[Ios Pentesting Without Jailbreak](/hacktricks/mobile-pentesting/ios-pentesting/ios-pentesting-without-jailbreak) ## Jailbreaking @@ -130,7 +131,8 @@ Jailbreaking expands the tester's access and permits unsigned tooling or tweaks, ### **After Jailbreaking** -basic-ios-testing-operations.md + +[Basic Ios Testing Operations](/hacktricks/mobile-pentesting/ios-pentesting/basic-ios-testing-operations) ### **Jailbreak Detection** diff --git a/src/content/hacktricks/mobile-pentesting/ios-pentesting/overview.md b/src/content/hacktricks/mobile-pentesting/ios-pentesting/overview.md @@ -14,13 +14,15 @@ license: "CC-BY-NC-4.0" ## iOS Basics -ios-basics.md + +[Ios Basics](/hacktricks/mobile-pentesting/ios-pentesting/ios-basics) ## Testing Environment In this page you can find information about the **iOS simulator**, **emulators** and **jailbreaking:** -ios-testing-environment.md + +[Ios Testing Environment](/hacktricks/mobile-pentesting/ios-pentesting/ios-testing-environment) For structured practice, useful training material includes the INE iOS course, RE:iOS Apps, the *iPwn Apps* paper, and an introductory iOS application-security course.<sup>[[3]](#references)[[17]](#references)[[19]](#references)[[20]](#references)</sup> Deliberately vulnerable targets include DVIA/DVIA-v2, the OWASP MSTG Hacking Playground, iGoat, and WheresMyBrowser.iOS; they provide concrete binaries and source code for reproducing the techniques described below.<sup>[[21]](#references)[[22]](#references)[[23]](#references)[[24]](#references)[[26]](#references)</sup> @@ -30,7 +32,8 @@ For structured practice, useful training material includes the INE iOS course, R During the testing **several operations are going to be suggested** (connect to the device, read/write/upload/download files, use some tools...). Therefore, if you don't know how to perform any of these actions please, **start reading the page**: -basic-ios-testing-operations.md + +[Basic Ios Testing Operations](/hacktricks/mobile-pentesting/ios-pentesting/basic-ios-testing-operations) > [!TIP] > For the following steps **the app should be installed** in the device and should have already obtained the **IPA file** of the application.\ diff --git a/src/content/hacktricks/network-services-pentesting/11211-memcache/overview.md b/src/content/hacktricks/network-services-pentesting/11211-memcache/overview.md @@ -77,7 +77,8 @@ Memcached itself does not provide replication; the following historical or third ### Commands Cheat-Sheet -memcache-commands.md + +[Memcache Commands](/hacktricks/network-services-pentesting/11211-memcache/memcache-commands) ### **Shodan** diff --git a/src/content/hacktricks/network-services-pentesting/3702-udp-pentesting-ws-discovery.md b/src/content/hacktricks/network-services-pentesting/3702-udp-pentesting-ws-discovery.md @@ -107,9 +107,9 @@ In CCTV environments, WS-Discovery is often the quickest way to separate: This makes UDP/3702 a good **first-pass recon target** before moving into more specific pages such as: -554-8554-pentesting-rtsp.md +[554 8554 Pentesting Rtsp](/hacktricks/network-services-pentesting/554-8554-pentesting-rtsp) -pentesting-631-internet-printing-protocol-ipp.md +[Pentesting 631 Internet Printing Protocol Ipp](/hacktricks/network-services-pentesting/pentesting-631-internet-printing-protocol-ipp) ## References diff --git a/src/content/hacktricks/network-services-pentesting/5439-pentesting-redshift.md b/src/content/hacktricks/network-services-pentesting/5439-pentesting-redshift.md @@ -18,7 +18,7 @@ This port is used by **Amazon Redshift** (AWS managed data warehouse). Redshift For more information check: -https://cloud.hacktricks.wiki/en/pentesting-cloud/aws-security/aws-services/aws-redshift-enum.html +[Aws Redshift Enum.Html](https%3A//cloud.hacktricks.wiki/en/pentesting-cloud/aws-security/aws-services/aws-redshift-enum.html) ## Enumeration & Connectivity diff --git a/src/content/hacktricks/network-services-pentesting/554-8554-pentesting-rtsp.md b/src/content/hacktricks/network-services-pentesting/554-8554-pentesting-rtsp.md @@ -68,7 +68,7 @@ For bounded credential testing, `rtsp_authgrinder` is one available tool.<sup>[[ ### See also -32100-udp-pentesting-pppp-cs2-p2p-cameras.md +[32100 Udp Pentesting Pppp Cs2 P2P Cameras](/hacktricks/network-services-pentesting/32100-udp-pentesting-pppp-cs2-p2p-cameras) ## References diff --git a/src/content/hacktricks/network-services-pentesting/6379-pentesting-redis.md b/src/content/hacktricks/network-services-pentesting/6379-pentesting-redis.md @@ -176,7 +176,7 @@ Recent Redis releases fixed multiple issues in the embedded Lua engine that allo Tip: If you are new to Lua sandboxing tricks, check this page for general techniques: -../generic-methodologies-and-resources/lua/bypass-lua-sandboxes/README.md +[Readme](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/lua/bypass-lua-sandboxes/README.md) **Patch-level context:** - Fixed in: 8.2.2, 8.0.4, 7.4.6, 7.2.11, 6.2.20 diff --git a/src/content/hacktricks/network-services-pentesting/9000-pentesting-fastcgi.md b/src/content/hacktricks/network-services-pentesting/9000-pentesting-fastcgi.md @@ -16,7 +16,8 @@ license: "CC-BY-NC-4.0" If you want to **learn what is FastCGI** check the following page: -pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-fpm-fastcgi.md + +[Disable Functions Bypass Php Fpm Fastcgi](/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable-functions-open-basedir-bypass/disable-functions-bypass-php-fpm-fastcgi) TCP/9000 is a common PHP-FPM/FastCGI configuration, not a protocol-mandated default. PHP-FPM can instead listen on another TCP address or a Unix socket; secure deployments normally restrict which clients can reach it.<sup>[[4]](#references)</sup> diff --git a/src/content/hacktricks/network-services-pentesting/nfs-service-pentesting.md b/src/content/hacktricks/network-services-pentesting/nfs-service-pentesting.md @@ -79,7 +79,8 @@ Ofc, the only problem here is that by default it's not possible to impersonate r Check the page: -../linux-hardening/interesting-files-permissions/nfs-no_root_squash-misconfiguration-pe.md + +[Nfs No Root Squash Misconfiguration Pe](/hacktricks/linux-hardening/interesting-files-permissions/nfs-no-root-squash-misconfiguration-pe) ### Escaping from the exports diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-ftp/overview.md b/src/content/hacktricks/network-services-pentesting/pentesting-ftp/overview.md @@ -141,7 +141,7 @@ This will probably return an error such as _**Socket not writable**_ because the - If you are sending an HTTP request, **put the same request one after another** until **\~0.5MB** at least. Like this: -posts.txt +[Posts.Txt](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-ftp/posts.txt) - Try to **fill the request with "junk" data relative to the protocol** (talking to FTP maybe just junk commands or repeating the `RETR`instruction to get the file) - Just **fill the request with a lot of null characters or others** (divided on lines or not) diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-mssql-microsoft-sql-server/types-of-mssql-users.md b/src/content/hacktricks/network-services-pentesting/pentesting-mssql-microsoft-sql-server/types-of-mssql-users.md @@ -65,7 +65,7 @@ From an attacker perspective, this view is more useful than just a user list:<su If you find interesting `IMPERSONATE`, `db_owner`, or linked-server paths, continue from the main MSSQL page: -README.md +[Readme](/hacktricks/network-services-pentesting/pentesting-mssql-microsoft-sql-server/overview) ## Tooling diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-postgresql.md b/src/content/hacktricks/network-services-pentesting/pentesting-postgresql.md @@ -26,7 +26,7 @@ license: "CC-BY-NC-4.0" ```text > Finding an **`rdsadmin`** database with `\list` is a strong indicator of an **Amazon RDS for PostgreSQL** instance. -For SQL-injection-specific techniques, see [PostgreSQL injection](../pentesting-web/sql-injection/postgresql-injection/). +For SQL-injection-specific techniques, see [PostgreSQL injection](/hacktricks/pentesting-web/sql-injection/postgresql-injection/overview). ## Automatic Enumeration diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-sap.md b/src/content/hacktricks/network-services-pentesting/pentesting-sap.md @@ -38,8 +38,7 @@ Password guessing may help, but account-lockout controls may be enabled.<sup>[[8 - Map instance numbers from open ports before logging in. Useful patterns during enumeration: `32<NR>` \(dispatcher\), `33<NR>` \(gateway\), `5<NR>13` / `5<NR>14` \(sapstartsrv / sapcontrol\), and SAP Host Agent on `1128`/`1129` \(HTTP/HTTPS SOAP\). This quickly tells you which instance number \(`NR`\) to reuse in SAP GUI, RFC, or Metasploit modules. - If you find a reachable SAProuter, keep the deep-dive in the dedicated page and use it for pivoting instead of duplicating tests here: -3299-pentesting-saprouter.md - +[3299 Pentesting Saprouter](/hacktricks/network-services-pentesting/3299-pentesting-saprouter) - Crawl the URLs if there is a web server running. - Fuzz the directories \(you can use Burp Intruder\) if it has web servers on certain ports. Here are some good wordlists provided by the SecLists Project for finding default SAP ICM Paths and other interesting directories or files: diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-smb/overview.md b/src/content/hacktricks/network-services-pentesting/pentesting-smb/overview.md @@ -40,7 +40,7 @@ The above command is an example of how `enum4linux` might be used to perform a f ## What is NTLM -For protocol details, attack prerequisites, and defenses, see [NTLM](../../windows-hardening/ntlm/). +For protocol details, attack prerequisites, and defenses, see [NTLM](/hacktricks/windows-hardening/ntlm/overview). ## **Server Enumeration** diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-ssh.md b/src/content/hacktricks/network-services-pentesting/pentesting-ssh.md @@ -68,7 +68,8 @@ Or use `ssh-keybrute.py` (native python3, lightweight and has legacy algorithms #### Known badkeys can be found here: -https://github.com/rapid7/ssh-badkeys/tree/master/authorized + +[Authorized](https%3A//github.com/rapid7/ssh-badkeys/tree/master/authorized) #### Weak SSH keys / Debian predictable PRNG diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-voip/basic-voip-protocols/overview.md b/src/content/hacktricks/network-services-pentesting/pentesting-voip/basic-voip-protocols/overview.md @@ -18,7 +18,7 @@ license: "CC-BY-NC-4.0" This is the industry standard, for more information check: -sip-session-initiation-protocol.md +[Sip Session Initiation Protocol](/hacktricks/network-services-pentesting/pentesting-voip/basic-voip-protocols/sip-session-initiation-protocol) ### MGCP (Media Gateway Control Protocol) diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-voip/overview.md b/src/content/hacktricks/network-services-pentesting/pentesting-voip/overview.md @@ -16,7 +16,8 @@ license: "CC-BY-NC-4.0" To start learning about how VoIP works check: -basic-voip-protocols/ + +[Basic Voip Protocols](/hacktricks/network-services-pentesting/pentesting-voip/basic-voip-protocols/overview) ## Basic messages<sup>[[7]](#references)</sup> diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/django.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/django.md @@ -75,7 +75,7 @@ The same gadget works for **Debug Toolbar** or **Django-CMS** template rendering ### Also see: ReportLab/xhtml2pdf PDF export RCE Applications built on Django commonly integrate xhtml2pdf/ReportLab to export views as PDF. When user-controlled HTML flows into PDF generation, rl_safe_eval may evaluate expressions inside triple brackets `[[[ ... ]]]` enabling code execution (CVE-2023-33733).<sup>[[3]](#references)</sup> Details, payloads, and mitigations: -../../generic-methodologies-and-resources/python/bypass-python-sandboxes/reportlab-xhtml2pdf-triple-brackets-expression-evaluation-rce-cve-2023-33733.md +[Reportlab Xhtml2Pdf Triple Brackets Expression Evaluation Rce Cve 2023 33733](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/python/bypass-python-sandboxes/reportlab-xhtml2pdf-triple-brackets-expression-evaluation-rce-cve-2023-33733.md) --- diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/drupal/overview.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/drupal/overview.md @@ -60,7 +60,8 @@ Exposed configuration-synchronization files may reveal enabled modules and servi If you have access to the Drupal web console check these options to get RCE: -drupal-rce.md + +[Drupal Rce](/hacktricks/network-services-pentesting/pentesting-web/drupal/drupal-rce) ## From XSS to RCE diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/electron-desktop-apps/overview.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/electron-desktop-apps/overview.md @@ -73,11 +73,14 @@ If the contexts aren't isolated an attacker can: There are 2 places where built-int methods can be overwritten: In preload code or in Electron internal code: -electron-contextisolation-rce-via-preload-code.md -electron-contextisolation-rce-via-electron-internal-code.md +[Electron Contextisolation Rce Via Preload Code](/hacktricks/network-services-pentesting/pentesting-web/electron-desktop-apps/electron-contextisolation-rce-via-preload-code) -electron-contextisolation-rce-via-ipc.md + +[Electron Contextisolation Rce Via Electron Internal Code](/hacktricks/network-services-pentesting/pentesting-web/electron-desktop-apps/electron-contextisolation-rce-via-electron-internal-code) + + +[Electron Contextisolation Rce Via Ipc](/hacktricks/network-services-pentesting/pentesting-web/electron-desktop-apps/electron-contextisolation-rce-via-ipc) ### Bypass click event @@ -183,7 +186,9 @@ It's usually **configured** in the **`main.js`** file or in the **`index.html`** For more information check: -pentesting-web/content-security-policy-csp-bypass/ + +[Content Security Policy Csp Bypass](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/electron-desktop-apps/pentesting-web/content-security-policy-csp-bypass/README.md) + ## RCE: Webview CSP + postMessage trust + local file loading (VS Code 1.63) diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/grafana.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/grafana.md @@ -95,9 +95,9 @@ If output shows `uid=0(root)`, the Grafana process is running as root. Do not as The 2025 Grafana client-side traversal and open-redirect chain is already documented in more generic client-side pages. Use those techniques against Grafana-specific paths such as plugin assets, dashboard script loaders, and token-rotation redirects: -../../pentesting-web/client-side-path-traversal.md +[Client Side Path Traversal](/hacktricks/pentesting-web/client-side-path-traversal) -../../pentesting-web/open-redirect.md +[Open Redirect](/hacktricks/pentesting-web/open-redirect) ## References diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/graphql.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/graphql.md @@ -203,7 +203,7 @@ Similar to CRSF vulnerabilities abusing graphQL it's also possible to perform a For more information check: -../../pentesting-web/websocket-attacks.md +[Websocket Attacks](/hacktricks/pentesting-web/websocket-attacks) ## Authorization in GraphQL @@ -330,7 +330,7 @@ Quick start: ### Automatic Tests -https://graphql-dashboard.herokuapp.com/ +[Graphql Dashboard.Herokuapp.Com](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/https%3A/graphql-dashboard.herokuapp.com/README.md) - Video explaining AutoGraphQL: [https://www.youtube.com/watch?v=JJmufWfVvyU](https://www.youtube.com/watch?v=JJmufWfVvyU) diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/iis-internet-information-services.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/iis-internet-information-services.md @@ -57,7 +57,7 @@ Before brute-forcing, try to identify IIS/ASP.NET hosts passively:<sup>[[3]](#re Download the list that I have created: -iisfinal.txt +[Iisfinal.Txt](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/iisfinal.txt) It was created merging the contents of the following lists: diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/microsoft-sharepoint.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/microsoft-sharepoint.md @@ -173,7 +173,7 @@ Correlate the following server, proxy, and endpoint signals rather than matching * IIS post-exploitation & web.config abuse: -../../network-services-pentesting/pentesting-web/iis-internet-information-services.md +[Iis Internet Information Services](/hacktricks/network-services-pentesting/pentesting-web/iis-internet-information-services) ## References diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/moodle.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/moodle.md @@ -52,7 +52,7 @@ On older branches, this was sometimes reachable from a teacher account by chaini If you can reach the plugin installer, upload a malicious plugin. For example, you can use the following ZIP that contains the classic pentestmonkey PHP reverse shell (decompress it first, change the IP/port, and compress it again): -moodle-rce-plugin.zip +[Moodle Rce Plugin.Zip](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/moodle-rce-plugin.zip) You can also use [https://github.com/HoangKien1020/Moodle_RCE](https://github.com/HoangKien1020/Moodle_RCE) to get a regular PHP shell controlled with the `cmd` parameter. diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/nextjs.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/nextjs.md @@ -397,7 +397,7 @@ CORS headers can also be applied centrally to matching API routes in **`middlewa Attackers can craft websites that make cross-origin requests to the API. Whether they can read data or act with a victim's credentials depends on the complete CORS policy, cookie attributes, and endpoint authorization. -../../pentesting-web/cors-bypass.md +[Cors Bypass](/hacktricks/pentesting-web/cors-bypass) ### Server code exposure in Client Side @@ -630,7 +630,7 @@ Take a valid POST observed in-proxy as a template and swap the `Next-Action` val Next.js App Router deployments that expose Server Actions on `react-server-dom-webpack` **19.0.0–19.2.0 (Next.js 15.x/16.x)** contain a critical server-side prototype pollution during **Flight** chunk deserialization. By crafting `$` references inside a Flight payload an attacker can pivot from polluted prototypes to arbitrary JavaScript execution and then to OS command execution inside the Node.js process.<sup>[[3]](#references)</sup> -../../pentesting-web/deserialization/nodejs-proto-prototype-pollution/README.md +[Readme](/hacktricks/pentesting-web/deserialization/nodejs-proto-prototype-pollution/overview) #### Attack chain in Flight chunks diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/overview.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/overview.md @@ -130,7 +130,7 @@ _Note that anytime a new directory is discovered during brute-forcing or spideri **403 Forbidden/Basic Authentication/401 Unauthorized (bypass)** -403-and-401-bypasses.md +[403 And 401 Bypasses](/hacktricks/network-services-pentesting/pentesting-web/403-and-401-bypasses) **502 Proxy Error** @@ -150,7 +150,7 @@ It is possible to **put content** inside a **Redirection**. This content **won't Now that a comprehensive enumeration of the web application has been performed it's time to check for a lot of possible vulnerabilities. You can find the checklist here: -../../pentesting-web/web-vulnerabilities-methodology.md +[Web Vulnerabilities Methodology](/hacktricks/pentesting-web/web-vulnerabilities-methodology) Find more info about web vulns in: diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/overview.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/overview.md @@ -28,7 +28,7 @@ PHP comparison tables: [https://www.php.net/manual/en/types.comparisons.php](htt  -EN-PHP-loose-comparison-Type-Juggling-OWASP (1).pdf +[En Php Loose Comparison Type Juggling Owasp (1).Pdf](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/php-tricks-esp/EN-PHP-loose-comparison-Type-Juggling-OWASP%20%281%29.pdf) Classic cases to test include: diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable-functions-open-basedir-bypass/disable-functions-bypass-php-5-2-3-win32std-ext-protections-bypass.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable-functions-open-basedir-bypass/disable-functions-bypass-php-5-2-3-win32std-ext-protections-bypass.md @@ -69,7 +69,7 @@ A more realistic variant drops a one-shot batch file or PowerShell command into - The relative path to `cmd.exe` is a convenience trick for old deployments. If you already know an absolute path, prefer passing it directly. - This is primarily a **process execution** primitive. If you need a broader survey of newer `disable_functions` / `open_basedir` bypasses, go back to the parent page: -README.md +[Readme](/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable-functions-open-basedir-bypass/overview) - On **modern** Windows PHP targets, the interesting pivot is usually **not** `win32std` but another bug or exposed feature set. For example, vulnerable PHP-CGI deployments on Windows were hit in 2024 by **CVE-2024-4577** argument injection, which is a completely different path from this extension-based trick.<sup>[[3]](#references)</sup> diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable-functions-open-basedir-bypass/disable-functions-bypass-php-5-2-4-and-5-2-5-php-curl.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable-functions-open-basedir-bypass/disable-functions-bypass-php-5-2-4-and-5-2-5-php-curl.md @@ -41,7 +41,7 @@ If safe_mode or open_basedir are active and cURL is enabled, the following will Other disable_functions/open_basedir bypasses and modern techniques are collected here: -README.md +[Readme](/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable-functions-open-basedir-bypass/overview) ## References diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable-functions-open-basedir-bypass/disable-functions-bypass-php-fpm-fastcgi.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable-functions-open-basedir-bypass/disable-functions-bypass-php-fpm-fastcgi.md @@ -48,7 +48,7 @@ Before trying any of the payloads below, keep these points in mind: If you first need to enumerate a reachable FastCGI listener or build raw FastCGI requests, check: -../../../9000-pentesting-fastcgi.md +[9000 Pentesting Fastcgi](/hacktricks/network-services-pentesting/9000-pentesting-fastcgi) ### Via Gopherus diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/sitecore/overview.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/sitecore/overview.md @@ -19,9 +19,9 @@ This page summarizes a practical attack chain tested against Sitecore XP 10.4.1. See also: -../../../pentesting-web/cache-deception/README.md +[Readme](/hacktricks/pentesting-web/cache-deception/overview) -../../../pentesting-web/deserialization/README.md +[Readme](/hacktricks/pentesting-web/deserialization/overview) ## Pre‑auth primitive: XAML Ajax reflection → HtmlCache write diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/special-http-headers.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/special-http-headers.md @@ -49,14 +49,16 @@ A hop-by-hop header is a header which is designed to be processed and consumed b - `Connection: close, X-Forwarded-For` -../../pentesting-web/abusing-hop-by-hop-headers.md + +[Abusing Hop By Hop Headers](/hacktricks/pentesting-web/abusing-hop-by-hop-headers) ## HTTP Request Smuggling - `Content-Length: 30` - `Transfer-Encoding: chunked` -../../pentesting-web/http-request-smuggling/ + +[Http Request Smuggling](/hacktricks/pentesting-web/http-request-smuggling/overview) ## The Expect header @@ -72,7 +74,8 @@ Interesting observed results of `Expect: 100-continue` testing include:<sup>[[10 For more info about HTTP Request Smuggling check: -../../pentesting-web/http-request-smuggling/ +[Http Request Smuggling](/hacktricks/pentesting-web/http-request-smuggling/overview) + ## Cache Headers @@ -85,7 +88,8 @@ For more info about HTTP Request Smuggling check: - **`Age`** defines the times in seconds the object has been in the proxy cache. - **`Server-Timing: cdn-cache; desc=HIT`** also indicates that a resource was cached -../../pentesting-web/cache-deception/ + +[Cache Deception](/hacktricks/pentesting-web/cache-deception/overview) **Browser and legacy cache headers**:<sup>[[9]](#references)</sup> diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/symphony.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/symphony.md @@ -103,7 +103,8 @@ Symfony is one of the most widely-used PHP frameworks and regularly appears in a ### 10. Symfony 1 gadget chains (still found in legacy apps) * `phpggc symfony/1 system id` produces a Phar payload that triggers RCE when an unserialize() happens on classes such as `sfNamespacedParameterHolder`. Check file-upload endpoints and `phar://` wrappers. -../../pentesting-web/deserialization/php-deserialization-+-autoload-classes.md + +[Php Deserialization + Autoload Classes](/hacktricks/pentesting-web/deserialization/php-deserialization-autoload-classes) --- diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/uncovering-cloudflare.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/uncovering-cloudflare.md @@ -32,7 +32,7 @@ license: "CC-BY-NC-4.0" For more recon pivots around favicon hashes, CT logs, passive DNS and related-domain discovery: -../../generic-methodologies-and-resources/external-recon-methodology/README.md +[Readme](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/external-recon-methodology/README.md) ## Tools to uncover Cloudflare diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/vmware-esx-vcenter.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/vmware-esx-vcenter.md @@ -62,7 +62,7 @@ Recent Mario builds replace the original linear, single-key routine with a spars Linux LPE via VMware Tools service discovery (CWE-426 / CVE-2025-41244): -../../linux-hardening/main-system-information/kernel-lpe-cves/vmware-tools-service-discovery-untrusted-search-path-cve-2025-41244.md +[Vmware Tools Service Discovery Untrusted Search Path Cve 2025 41244](/hacktricks/linux-hardening/main-system-information/kernel-lpe-cves/vmware-tools-service-discovery-untrusted-search-path-cve-2025-41244) ## References diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/werkzeug.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/werkzeug.md @@ -75,7 +75,7 @@ This is because, In Werkzeug it's possible to send some **Unicode** characters a ## Automated Exploitation -https://github.com/Ruulian/wconsole_extractor +[Wconsole Extractor](https%3A//github.com/Ruulian/wconsole_extractor) ## References diff --git a/src/content/hacktricks/network-services-pentesting/pentesting-web/wsgi.md b/src/content/hacktricks/network-services-pentesting/pentesting-web/wsgi.md @@ -18,9 +18,9 @@ Web Server Gateway Interface (WSGI) is a specification that describes how a web Related pages you may also want to check: -werkzeug.md +[Werkzeug](/hacktricks/network-services-pentesting/pentesting-web/werkzeug) -../../pentesting-web/ssrf-server-side-request-forgery/README.md +[Readme](/hacktricks/pentesting-web/ssrf-server-side-request-forgery/overview) ## uWSGI Magic Variables Exploitation diff --git a/src/content/hacktricks/pentesting-web/account-takeover.md b/src/content/hacktricks/pentesting-web/account-takeover.md @@ -45,7 +45,8 @@ Practical checks: For further details, refer to the document on Unicode Normalization: -unicode-injection/unicode-normalization.md + +[Unicode Normalization](/hacktricks/pentesting-web/unicode-injection/unicode-normalization) ## **Reusing Reset Token** @@ -61,19 +62,22 @@ Should the target system allow the **reset link** (or an equivalent **magic link If the page contains **CORS misconfigurations** you might be able to **steal sensitive information** from the user to **takeover his account** or make him change auth information for the same purpose:<sup>[[2]](#references)</sup> -cors-bypass.md + +[Cors Bypass](/hacktricks/pentesting-web/cors-bypass) ## **CSRF to Account Takeover** If the page is vulnerable to CSRF, you may be able to make the **user modify their password, email, or authentication settings** and then access the account:<sup>[[2]](#references)</sup> -csrf-cross-site-request-forgery.md + +[Csrf Cross Site Request Forgery](/hacktricks/pentesting-web/csrf-cross-site-request-forgery) ## **XSS to Account Takeover** If you find XSS in an application, you may be able to steal cookies, local-storage data, or page content that enables account takeover:<sup>[[2]](#references)</sup> -xss-cross-site-scripting/ + +[Xss Cross Site Scripting](/hacktricks/pentesting-web/xss-cross-site-scripting/overview) - Attribute-only reflected payloads on login pages can hook `document.onkeypress`, exfiltrate keystrokes through `new Image().src`, and steal credentials without submitting the form. See [Attribute-only login XSS behind WAFs](/hacktricks/pentesting-web/xss-cross-site-scripting/overview#attribute-only-login-xss-behind-wafs) for a practical workflow.<sup>[[1]](#references)</sup> @@ -81,7 +85,8 @@ xss-cross-site-scripting/ If you find a limited XSS or a subdomain take over, you could play with the cookies (fixating them for example) to try to compromise the victim account:<sup>[[2]](#references)</sup> -hacking-with-cookies/ + +[Hacking With Cookies](/hacktricks/pentesting-web/hacking-with-cookies/overview) ## **Predictable SSO / bearer cookies and staged login replay** @@ -110,7 +115,8 @@ Safe detection tip: send an **impossible historical token** plus the **mismatche ## **Attacking Password Reset Mechanism** -reset-password.md + +[Reset Password](/hacktricks/pentesting-web/reset-password) ## **Magic Links / Passwordless Login** @@ -138,7 +144,8 @@ Enumerated usernames can then be targeted via the overwrite technique above or r ## OAuth to Account takeover -oauth-to-account-takeover.md + +[Oauth To Account Takeover](/hacktricks/pentesting-web/oauth-to-account-takeover) ## **QR / Cross-Device Login Flows** diff --git a/src/content/hacktricks/pentesting-web/browser-extension-pentesting-methodology/browext-clickjacking.md b/src/content/hacktricks/pentesting-web/browser-extension-pentesting-methodology/browext-clickjacking.md @@ -17,7 +17,8 @@ license: "CC-BY-NC-4.0" This page is going to abuse a ClickJacking vulnerability in a Browser extension.\ If you don't know what ClickJacking is check: -../clickjacking.md + +[Clickjacking](/hacktricks/pentesting-web/clickjacking) Extensions contain a **`manifest.json`** file whose `web_accessible_resources` field declares packaged files that matching web origins or extensions may request.<sup>[[4]](#references)</sup> @@ -57,7 +58,8 @@ A [**blog post about a ClickJacking in metamask can be found here**](https://slo Check the following page to check how a **XSS** in a browser extension was chained with a **ClickJacking** vulnerability: -browext-xss-example.md + +[Browext Xss Example](/hacktricks/pentesting-web/browser-extension-pentesting-methodology/browext-xss-example) --- diff --git a/src/content/hacktricks/pentesting-web/browser-extension-pentesting-methodology/overview.md b/src/content/hacktricks/pentesting-web/browser-extension-pentesting-methodology/overview.md @@ -154,7 +154,8 @@ As browser extensions can be so **privileged**, a malicious one or one being com Check how these settings work and how they could get abused in: -browext-permissions-and-host_permissions.md + +[Browext Permissions And Host Permissions](/hacktricks/pentesting-web/browser-extension-pentesting-methodology/browext-permissions-and-host-permissions) ### `content_security_policy` @@ -180,7 +181,8 @@ Although, if the `manifest.json` parameter **`use_dynamic_url`** is used, this * Being allowed to access these pages make these pages **potentially vulnerable ClickJacking**: -browext-clickjacking.md + +[Browext Clickjacking](/hacktricks/pentesting-web/browser-extension-pentesting-methodology/browext-clickjacking) > [!TIP] > Allowing these pages to be loaded only by the extension and not by random URLs could prevent ClickJacking attacks. @@ -293,13 +295,15 @@ It's also possible to send messages from a background script to a content script The previous checks, even if performed, could be vulnerable, so check in the following page **potential Post Message bypasses**: -../postmessage-vulnerabilities/ + +[Postmessage Vulnerabilities](/hacktricks/pentesting-web/postmessage-vulnerabilities/overview) ### Iframe Another possible way of communication might be through **Iframe URLs**, you can find an example in: -browext-xss-example.md + +[Browext Xss Example](/hacktricks/pentesting-web/browser-extension-pentesting-methodology/browext-xss-example) ### DOM @@ -307,7 +311,8 @@ This isn't "exactly" a communication way, but the **web and the content script w You can also find an example of a **DOM based XSS to compromise a browser extension** in: -browext-xss-example.md + +[Browext Xss Example](/hacktricks/pentesting-web/browser-extension-pentesting-methodology/browext-xss-example) ## Content Script **↔︎** Background Script Communication diff --git a/src/content/hacktricks/pentesting-web/cache-deception/overview.md b/src/content/hacktricks/pentesting-web/cache-deception/overview.md @@ -39,7 +39,8 @@ If you are thinking that the response is being stored in a cache, you could try You can find more options in: -cache-poisoning-to-dos.md + +[Cache Poisoning To Dos](/hacktricks/pentesting-web/cache-deception/cache-poisoning-to-dos) However, note that **sometimes these kinds of status codes aren't cached** so this test could not be reliable. @@ -124,7 +125,8 @@ _Note that this will poison a request to `/en?region=uk` not to `/en`_<sup>[[1]] ### Cache poisoning to DoS -cache-poisoning-to-dos.md + +[Cache Poisoning To Dos](/hacktricks/pentesting-web/cache-deception/cache-poisoning-to-dos) ### Cache poisoning through CDNs @@ -144,7 +146,8 @@ Cookies could also be reflected on the response of a page. If you can abuse it t This is also explained better in: -cache-poisoning-via-url-discrepancies.md + +[Cache Poisoning Via Url Discrepancies](/hacktricks/pentesting-web/cache-deception/cache-poisoning-via-url-discrepancies) ### Using multiple headers to exploit web cache poisoning vulnerabilities <a href="#using-multiple-headers-to-exploit-web-cache-poisoning-vulnerabilities" id="using-multiple-headers-to-exploit-web-cache-poisoning-vulnerabilities"></a> diff --git a/src/content/hacktricks/pentesting-web/captcha-bypass.md b/src/content/hacktricks/pentesting-web/captcha-bypass.md @@ -42,7 +42,7 @@ During an authorized assessment, test whether the **server** actually binds a CA **CapSolver** is one example of a commercial API and browser-extension service that claims support for reCAPTCHA, DataDome, AWS CAPTCHA, GeeTest, and Cloudflare Turnstile. Its client options include extensions for [Chrome](https://chromewebstore.google.com/detail/captcha-solver-auto-captc/pgojnojmmhpofjgdmaebadhbocahppod) and [Firefox](https://addons.mozilla.org/firefox/addon/capsolver-captcha-solver/). Treat any external solver as a data processor: test only accounts and challenges covered by the engagement, and do not send sensitive screenshots, tokens, or production user data without approval.<sup>[[3]](#references)</sup> -https://www.capsolver.com/?utm_campaign=scraping&utm_content=captchabypass&utm_medium=ads&utm_source=google&utm_term=hacktricks +[?Utm Campaign=Scraping&Utm Content=Captchabypass&Utm Medium=Ads&Utm Source=Google&Utm Term=Hacktricks](https%3A//www.capsolver.com/%3Futm_campaign%3Dscraping%26utm_content%3Dcaptchabypass%26utm_medium%3Dads%26utm_source%3Dgoogle%26utm_term%3Dhacktricks) ## References diff --git a/src/content/hacktricks/pentesting-web/client-side-template-injection-csti.md b/src/content/hacktricks/pentesting-web/client-side-template-injection-csti.md @@ -100,7 +100,9 @@ For manual testing, Burp's current Web Security Academy CSTI labs and XSS cheat ## **Brute-Force Detection List** -https://github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/ssti.txt + +[Ssti.Txt](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/https%3A/github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/ssti.txt) + ## References diff --git a/src/content/hacktricks/pentesting-web/command-injection.md b/src/content/hacktricks/pentesting-web/command-injection.md @@ -144,7 +144,9 @@ Example payloads: ## Brute-Force Detection List -https://github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/command_injection.txt + +[Command Injection.Txt](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/https%3A/github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/command_injection.txt) + ## References diff --git a/src/content/hacktricks/pentesting-web/content-security-policy-csp-bypass/overview.md b/src/content/hacktricks/pentesting-web/content-security-policy-csp-bypass/overview.md @@ -88,7 +88,8 @@ Working payload: `"/><script>alert(1);</script>`<sup>[[4]](#references)</sup> #### self + 'unsafe-inline' via Iframes -csp-bypass-self-+-unsafe-inline-with-iframes.md + +[Csp Bypass Self + Unsafe Inline With Iframes](/hacktricks/pentesting-web/content-security-policy-csp-bypass/csp-bypass-self-unsafe-inline-with-iframes) ### 'unsafe-eval' @@ -201,7 +202,8 @@ Online Example:[ ](https://jsbin.com/werevijewa/edit?html,output)[https://jsbin. ### Iframes JS execution -../xss-cross-site-scripting/iframes-in-xss-and-csp.md + +[Iframes In Xss And Csp](/hacktricks/pentesting-web/xss-cross-site-scripting/iframes-in-xss-and-csp) ### missing **base-uri** @@ -254,7 +256,8 @@ You can bypass this CSP by exfiltrating the data via images (in this occasion th ```text Service workers **`importScripts`** function isn't limited by CSP: -../xss-cross-site-scripting/abusing-service-workers.md + +[Abusing Service Workers](/hacktricks/pentesting-web/xss-cross-site-scripting/abusing-service-workers) ### Policy Injection @@ -376,7 +379,8 @@ Because headers must be sent before any output, warnings emitted by PHP can inva ```text SOME is a technique that abuses an XSS (or highly limited XSS) **in an endpoint of a page** to **abuse** **other endpoints of the same origin.** This is done by loading the vulnerable endpoint from an attacker page and then refreshing the attacker page to the real endpoint in the same origin you want to abuse. This way the **vulnerable endpoint** can use the **`opener`** object in the **payload** to **access the DOM** of the **real endpoint to abuse**. For more information check: -../xss-cross-site-scripting/some-same-origin-method-execution.md + +[Some Same Origin Method Execution](/hacktricks/pentesting-web/xss-cross-site-scripting/some-same-origin-method-execution) Moreover, **wordpress** has a **JSONP** endpoint in `/wp-json/wp/v2/users/1?_jsonp=data` that will **reflect** the **data** sent in the output (with the limitation of only letter, numbers and dots). diff --git a/src/content/hacktricks/pentesting-web/cors-bypass.md b/src/content/hacktricks/pentesting-web/cors-bypass.md @@ -140,7 +140,8 @@ https://example.com.`.attacker.com/ ### **Other funny URL tricks** -ssrf-server-side-request-forgery/url-format-bypass.md + +[Url Format Bypass](/hacktricks/pentesting-web/ssrf-server-side-request-forgery/url-format-bypass) ### **Server-side cache poisoning** @@ -177,7 +178,8 @@ One way to bypass the `Access-Control-Allow-Origin` restriction is by requesting You can **bypass CORS checks** such as `e.origin === window.origin` by **creating an iframe** and **from it opening a new window**. More information in the following page: -xss-cross-site-scripting/iframes-in-xss-and-csp.md + +[Iframes In Xss And Csp](/hacktricks/pentesting-web/xss-cross-site-scripting/iframes-in-xss-and-csp) ### DNS Rebinding via TTL diff --git a/src/content/hacktricks/pentesting-web/crlf-0d-0a.md b/src/content/hacktricks/pentesting-web/crlf-0d-0a.md @@ -80,7 +80,8 @@ CRLF injection can be utilized to craft and inject an entirely new HTTP request. Memcache is a **key-value store that uses a clear text protocol**. More info in: -../network-services-pentesting/11211-memcache/ + +[11211 Memcache](/hacktricks/network-services-pentesting/11211-memcache/overview) **For the full information read the**[ **original writeup**](https://www.sonarsource.com/blog/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/)<sup>[[12]](#references)</sup> diff --git a/src/content/hacktricks/pentesting-web/csrf-cross-site-request-forgery.md b/src/content/hacktricks/pentesting-web/csrf-cross-site-request-forgery.md @@ -119,7 +119,7 @@ Quick hunting checklist: - Check whether a controlled GET sink can feed data into a second state-changing request. - Review SPAs that parse imported dashboards, themes, or config files and later concatenate those fields into API paths. -client-side-path-traversal.md +[Client Side Path Traversal](/hacktricks/pentesting-web/client-side-path-traversal) ### Upload gadget to CSPT2CSRF @@ -171,7 +171,8 @@ This ensures the `Referer` header is omitted, potentially bypassing validation c **Regexp bypasses** -ssrf-server-side-request-forgery/url-format-bypass.md + +[Url Format Bypass](/hacktricks/pentesting-web/ssrf-server-side-request-forgery/url-format-bypass) To place the trusted domain string inside a query parameter that will appear in the `Referer`, use a URL such as the following:<sup>[[3]](#references)</sup><sup>[[4]](#references)</sup> diff --git a/src/content/hacktricks/pentesting-web/dapps-decentralizedapplications.md b/src/content/hacktricks/pentesting-web/dapps-decentralizedapplications.md @@ -80,7 +80,7 @@ Modern DApps often assume that the wallet/provider layer is just plumbing, but t When reviewing a DApp, treat the wallet connection layer exactly like an authentication boundary: inspect provider discovery, event handling (`accountsChanged`, `chainChanged`), transaction building after chain switches, and whether external wallet metadata is reflected in the DOM without sanitization. -../blockchain/blockchain-and-crypto-currencies/web3-signing-workflow-compromise-safe-delegatecall-proxy-takeover.md +[Web3 Signing Workflow Compromise Safe Delegatecall Proxy Takeover](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/blockchain/blockchain-and-crypto-currencies/web3-signing-workflow-compromise-safe-delegatecall-proxy-takeover.md) ### Signature-based approvals and gasless abuse @@ -138,7 +138,8 @@ More recent DApps may expose relayer, bundler, or paymaster APIs to sponsor user Keep this page generic, but note that account-abstraction-specific bugs are covered in more detail here: -../blockchain/blockchain-and-crypto-currencies/erc-4337-smart-account-security-pitfalls.md +[Erc 4337 Smart Account Security Pitfalls](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/blockchain/blockchain-and-crypto-currencies/erc-4337-smart-account-security-pitfalls.md) + ## References diff --git a/src/content/hacktricks/pentesting-web/deserialization/basic-java-deserialization-objectinputstream-readobject.md b/src/content/hacktricks/pentesting-web/deserialization/basic-java-deserialization-objectinputstream-readobject.md @@ -45,7 +45,7 @@ The offensive lesson is that the dangerous trust boundary is often **not** “us If you need low-noise reachability checks before spending time on full gadget research, use the dedicated Java pages for: -java-dns-deserialization-and-gadgetprobe.md +[Java Dns Deserialization And Gadgetprobe](/hacktricks/pentesting-web/deserialization/java-dns-deserialization-and-gadgetprobe) ## `readObject()` anti-patterns that still create gadget entrypoints diff --git a/src/content/hacktricks/pentesting-web/deserialization/nodejs-proto-prototype-pollution/client-side-prototype-pollution.md b/src/content/hacktricks/pentesting-web/deserialization/nodejs-proto-prototype-pollution/client-side-prototype-pollution.md @@ -20,7 +20,7 @@ Moreover, you could also use the **browser extension** [**PPScan**](https://gith For Burp users, **DOM Invader** is currently the most practical option for browser-side work because it can test query/hash/JSON web-message sources and then **scan automatically for gadgets**. -../../xss-cross-site-scripting/dom-invader.md +[Dom Invader](/hacktricks/pentesting-web/xss-cross-site-scripting/dom-invader) ### Debugging where a property is used <a href="#id-5530" id="id-5530"></a> diff --git a/src/content/hacktricks/pentesting-web/deserialization/overview.md b/src/content/hacktricks/pentesting-web/deserialization/overview.md @@ -54,13 +54,14 @@ You can read an explained **PHP example here**: [https://www.notsosecure.com/rem You could abuse the PHP autoload functionality to load arbitrary php files and more: -php-deserialization-+-autoload-classes.md + +[Php Deserialization + Autoload Classes](/hacktricks/pentesting-web/deserialization/php-deserialization-autoload-classes) ### Laravel Livewire Hydration Chains Livewire 3 synthesizers can be coerced into instantiating arbitrary gadget graphs (with or without `APP_KEY`) to reach Laravel Queueable/SerializableClosure sinks: -livewire-hydration-synthesizer-abuse.md +[Livewire Hydration Synthesizer Abuse](/hacktricks/pentesting-web/deserialization/livewire-hydration-synthesizer-abuse) ### Serializing Referenced Values @@ -107,7 +108,8 @@ So, if you can, check the `phpinfo()` of the server and **search on the internet If you have found a LFI that is just reading the file and not executing the php code inside of it, for example using functions like _**file_get_contents(), fopen(), file() or file_exists(), md5_file(), filemtime() or filesize()**_**.** You can try to abuse a **deserialization** occurring when **reading** a **file** using the **phar** protocol.\ For more information read the following post: -../file-inclusion/phar-deserialization.md + +[Phar Deserialization](/hacktricks/pentesting-web/file-inclusion/phar-deserialization) ## Python @@ -122,17 +124,20 @@ Before checking the bypass technique, try using `print(base64.b64encode(pickle.d For more information about escaping from **pickle jails** check: -../../generic-methodologies-and-resources/python/bypass-python-sandboxes/ + +[Bypass Python Sandboxes](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/python/bypass-python-sandboxes/README.md) ### Yaml **&** jsonpickle The following page present the technique to **abuse an unsafe deserialization in yamls** python libraries and finishes with a tool that can be used to generate RCE deserialization payload for **Pickle, PyYAML, jsonpickle and ruamel.yaml**: -python-yaml-deserialization.md + +[Python Yaml Deserialization](/hacktricks/pentesting-web/deserialization/python-yaml-deserialization) ### Class Pollution (Python Prototype Pollution) -../../generic-methodologies-and-resources/python/class-pollution-pythons-prototype-pollution.md + +[Class Pollution Pythons Prototype Pollution](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/python/class-pollution-pythons-prototype-pollution.md) ## NodeJS @@ -149,7 +154,8 @@ Another **"magic" way to call a function** without calling it directly is by **c If you want to learn about this technique **take a look to the following tutorial**: -nodejs-proto-prototype-pollution/ + +[Nodejs Proto Prototype Pollution](/hacktricks/pentesting-web/deserialization/nodejs-proto-prototype-pollution/overview) ### [node-serialize](https://www.npmjs.com/package/node-serialize) @@ -274,7 +280,7 @@ Modern codebases sometimes wrap deserialization with `java.security.SignedObject For a concrete case study with requests, IoCs, and hardening guidance, see: -java-signedobject-gated-deserialization.md +[Java Signedobject Gated Deserialization](/hacktricks/pentesting-web/deserialization/java-signedobject-gated-deserialization) #### White Box Test diff --git a/src/content/hacktricks/pentesting-web/file-inclusion/lfi2rce-via-phpinfo.md b/src/content/hacktricks/pentesting-web/file-inclusion/lfi2rce-via-phpinfo.md @@ -99,13 +99,14 @@ If you want a ready-made wrapper instead of adapting the minimal PoC, a modern o ## Related HackTricks techniques -lfi2rce-via-temp-file-uploads.md +[Lfi2Rce Via Temp File Uploads](/hacktricks/pentesting-web/file-inclusion/lfi2rce-via-temp-file-uploads) -via-php_session_upload_progress.md +[Via Php Session Upload Progress](/hacktricks/pentesting-web/file-inclusion/via-php-session-upload-progress) -lfi2rce-via-nginx-temp-files.md +[Lfi2Rce Via Nginx Temp Files](/hacktricks/pentesting-web/file-inclusion/lfi2rce-via-nginx-temp-files) + +[Lfi2Rce Via Eternal Waiting](/hacktricks/pentesting-web/file-inclusion/lfi2rce-via-eternal-waiting) -lfi2rce-via-eternal-waiting.md ## References diff --git a/src/content/hacktricks/pentesting-web/file-inclusion/overview.md b/src/content/hacktricks/pentesting-web/file-inclusion/overview.md @@ -12,7 +12,7 @@ license: "CC-BY-NC-4.0" # File Inclusion and Path Traversal -../../generic-methodologies-and-resources/pentesting-network/dds-rtps-security.md +[Dds Rtps Security](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/dds-rtps-security.md) ## File Inclusion @@ -38,7 +38,8 @@ A list that uses several techniques to find the file /etc/password (to check if Merge of different wordlists: -https://github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/file_inclusion_windows.txt + +[File Inclusion Windows.Txt](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/file-inclusion/https%3A/github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/file_inclusion_windows.txt) Try also to change `/` for `\`\ Try also to remove `C:/` and add `../../../../../` @@ -232,7 +233,8 @@ For a detailed understanding of exploiting deserialization vulnerabilities in th [Phar Deserialization Exploitation Guide](/hacktricks/pentesting-web/file-inclusion/phar-deserialization) -phar-deserialization.md + +[Phar Deserialization](/hacktricks/pentesting-web/file-inclusion/phar-deserialization) ### CVE-2024-2961 @@ -358,25 +360,29 @@ Set the cookie to `<?php system('cat /etc/passwd');?>` ```text **Upload** a file that will be stored as **temporary** in `/tmp`, then in the **same request,** trigger a **segmentation fault**, and then the **temporary file won't be deleted** and you can search for it. -lfi2rce-via-segmentation-fault.md + +[Lfi2Rce Via Segmentation Fault](/hacktricks/pentesting-web/file-inclusion/lfi2rce-via-segmentation-fault) ### Via Nginx temp file storage If you found a **Local File Inclusion** and **Nginx** is running in front of PHP you might be able to obtain RCE with the following technique: -lfi2rce-via-nginx-temp-files.md + +[Lfi2Rce Via Nginx Temp Files](/hacktricks/pentesting-web/file-inclusion/lfi2rce-via-nginx-temp-files) ### Via PHP_SESSION_UPLOAD_PROGRESS If you found a **Local File Inclusion** even if you **don't have a session** and `session.auto_start` is `Off`. If you provide the **`PHP_SESSION_UPLOAD_PROGRESS`** in **multipart POST** data, PHP will **enable the session for you**. You could abuse this to get RCE: -via-php_session_upload_progress.md + +[Via Php Session Upload Progress](/hacktricks/pentesting-web/file-inclusion/via-php-session-upload-progress) ### Via temp file uploads in Windows If you found a **Local File Inclusion** and and the server is running in **Windows** you might get RCE: -lfi2rce-via-temp-file-uploads.md + +[Lfi2Rce Via Temp File Uploads](/hacktricks/pentesting-web/file-inclusion/lfi2rce-via-temp-file-uploads) ### Via `pearcmd.php` + URL args @@ -392,13 +398,15 @@ The following request create a file in `/tmp/hello.php` with the content `<?=php If you found a **Local File Inclusion** and you **can exfiltrate the path** of the temp file BUT the **server** is **checking** if the **file to be included has PHP marks**, you can try to **bypass that check** with this **Race Condition**: -lfi2rce-via-compress.zlib-+-php_stream_prefer_studio-+-path-disclosure.md + +[Lfi2Rce Via Compress.Zlib + Php Stream Prefer Studio + Path Disclosure](/hacktricks/pentesting-web/file-inclusion/lfi2rce-via-compress-zlib-php-stream-prefer-studio-path-disclosure) ### Via eternal waiting and brute force If you can abuse the LFI to **upload temporary files** and make the server **hang** the PHP execution, you could then **brute force filenames during hours** to find the temporary file: -lfi2rce-via-eternal-waiting.md + +[Lfi2Rce Via Eternal Waiting](/hacktricks/pentesting-web/file-inclusion/lfi2rce-via-eternal-waiting) ### To Fatal Error @@ -441,4 +449,4 @@ Tune the number of `../` segments until you escape the intended directory, then - [19] [Docker PHP LFI Summary / pearcmd.php getshell](https://www.leavesongs.com/PENETRATION/docker-php-include-getshell.html#0x06-pearcmdphp) - [20] [docs.python.org - Library - Os.path: Os.path.join](https://docs.python.org/3.10/library/os.path.html#os.path.join) -EN-Local-File-Inclusion-1.pdf +[En Local File Inclusion 1.Pdf](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/file-inclusion/EN-Local-File-Inclusion-1.pdf) diff --git a/src/content/hacktricks/pentesting-web/file-upload/overview.md b/src/content/hacktricks/pentesting-web/file-upload/overview.md @@ -227,7 +227,7 @@ Some legacy upload handlers that use `snprintf()` or similar to build multi-file ### GeoNetwork formatter upload to XSLT execution -../../network-services-pentesting/pentesting-web/geonetwork.md +[Geonetwork](/hacktricks/network-services-pentesting/pentesting-web/geonetwork) ## From File upload to other vulnerabilities @@ -262,7 +262,8 @@ Here’s a top 10 list of things that you can achieve by uploading (from [here]( #### Burp Extension -https://github.com/portswigger/upload-scanner + +[Upload Scanner](https%3A//github.com/portswigger/upload-scanner) ## Magic Header Bytes diff --git a/src/content/hacktricks/pentesting-web/hacking-jwt-json-web-tokens.md b/src/content/hacktricks/pentesting-web/hacking-jwt-json-web-tokens.md @@ -242,7 +242,8 @@ However, if the maximum ID space is four decimal digits (`0001`–`9999`), reque ### JWT Registered claims -https://www.iana.org/assignments/jwt/jwt.xhtml#claims + +[Jwt.Xhtml#Claims](https%3A//www.iana.org/assignments/jwt/jwt.xhtml%23claims) ### Other attacks @@ -264,7 +265,8 @@ The token's expiry is checked using the "exp" Payload claim. Given that JWTs are - [Burp JWT Editor](https://github.com/PortSwigger/jwt-editor) – decode/re-sign in Repeater, generate custom keys, and run built-in attacks (**none**, **HMAC key confusion**, **embedded JWK**, **jku/x5u collaborator payloads**).<sup>[[2]](#references)</sup> - [hashcat](https://hashcat.net/hashcat/) `-m 16500` – GPU-accelerated HS256 secret cracking after exporting JWTs to a wordlist.<sup>[[4]](#references)</sup> -https://github.com/ticarpi/jwt_tool + +[Jwt Tool](https%3A//github.com/ticarpi/jwt_tool) ## References diff --git a/src/content/hacktricks/pentesting-web/hacking-with-cookies/cookie-tossing.md b/src/content/hacktricks/pentesting-web/hacking-with-cookies/cookie-tossing.md @@ -51,7 +51,8 @@ A possible protection is for the server to reject requests containing two cookie To bypass the scenario where the attacker is setting a cookie after the victim was already given the cookie, the attacker could cause a **cookie overflow** and then, once the **legit cookie is deleted, set the malicious one**. -cookie-jar-overflow.md + +[Cookie Jar Overflow](/hacktricks/pentesting-web/hacking-with-cookies/cookie-jar-overflow) Another useful **bypass** is to **URL-encode the cookie name** when a front-end protection compares raw names but the back end decodes them.<sup>[[2]](#references)</sup> @@ -59,7 +60,8 @@ Another useful **bypass** is to **URL-encode the cookie name** when a front-end A Cookie Tossing attack may also be used to perform a **Cookie Bomb** attack: -cookie-bomb.md + +[Cookie Bomb](/hacktricks/pentesting-web/hacking-with-cookies/cookie-bomb) ## Defenses diff --git a/src/content/hacktricks/pentesting-web/hacking-with-cookies/overview.md b/src/content/hacktricks/pentesting-web/hacking-with-cookies/overview.md @@ -74,7 +74,8 @@ The `HttpOnly` flag prevents **client-side JavaScript** from reading the cookie - Another way is the exploitation of zero/day vulnerabilities of the browsers. - It's possible to **overwrite HttpOnly cookies** by performing a Cookie Jar overflow attack: -cookie-jar-overflow.md + +[Cookie Jar Overflow](/hacktricks/pentesting-web/hacking-with-cookies/cookie-jar-overflow) - It's possible to use [**Cookie Smuggling**](#cookie-smuggling) attack to exfiltrate these cookies - If any server-side endpoint echoes the raw session ID in the HTTP response (e.g., inside HTML comments or a debug block), you can bypass HttpOnly by using an XSS gadget to fetch that endpoint, regex the secret, and exfiltrate it.<sup>[[7]](#references)</sup> Example XSS payload pattern: @@ -173,7 +174,8 @@ In this scenario, an attacker tricks a victim into using a specific cookie to lo If you found XSS on a subdomain or control a subdomain, review the related cookie-tossing technique: -cookie-tossing.md + +[Cookie Tossing](/hacktricks/pentesting-web/hacking-with-cookies/cookie-tossing) ### Session Donation @@ -181,7 +183,8 @@ Here, the attacker convinces the victim to use the attacker's session cookie. Th For session-donation variants involving a controlled or XSS-affected subdomain, see the cookie-tossing technique below: -cookie-tossing.md + +[Cookie Tossing](/hacktricks/pentesting-web/hacking-with-cookies/cookie-tossing) ### [JWT Cookies](/hacktricks/pentesting-web/hacking-jwt-json-web-tokens) diff --git a/src/content/hacktricks/pentesting-web/http-request-smuggling/overview.md b/src/content/hacktricks/pentesting-web/http-request-smuggling/overview.md @@ -294,7 +294,7 @@ Abusing hop-by-hop headers you could indicate the proxy to **delete the header C Check how this header can help exploiting a http desync in: -../../network-services-pentesting/pentesting-web/special-http-headers.md +[Special Http Headers](/hacktricks/network-services-pentesting/pentesting-web/special-http-headers) ## CRLF-powered request splitting and desynchronization @@ -401,7 +401,7 @@ If you’re targeting browser-powered/client-side desync, the malicious request For background and end-to-end workflows: -browser-http-request-smuggling.md +[Browser Http Request Smuggling](/hacktricks/pentesting-web/http-request-smuggling/browser-http-request-smuggling) ### Tooling to help decide diff --git a/src/content/hacktricks/pentesting-web/iframe-traps.md b/src/content/hacktricks/pentesting-web/iframe-traps.md @@ -67,9 +67,9 @@ The main limitation is still escape: if the victim **closes the tab**, **switche ## Related -clickjacking.md +[Clickjacking](/hacktricks/pentesting-web/clickjacking) -xss-cross-site-scripting/iframes-in-xss-and-csp.md +[Iframes In Xss And Csp](/hacktricks/pentesting-web/xss-cross-site-scripting/iframes-in-xss-and-csp) ## References diff --git a/src/content/hacktricks/pentesting-web/json-xml-yaml-hacking.md b/src/content/hacktricks/pentesting-web/json-xml-yaml-hacking.md @@ -137,7 +137,7 @@ err := json.Unmarshal([]byte(`{"role":"user","role":"admin"}`), &dst) ## See also -mass-assignment-cwe-915.md +[Mass Assignment Cwe 915](/hacktricks/pentesting-web/mass-assignment-cwe-915) See [HTTP parameter pollution and JSON key-collision payloads](/hacktricks/pentesting-web/parameter-pollution#json-injection) and [XXE/XEE](/hacktricks/pentesting-web/xxe-xee-xml-external-entity) for their format-specific attack payloads. diff --git a/src/content/hacktricks/pentesting-web/ldap-injection.md b/src/content/hacktricks/pentesting-web/ldap-injection.md @@ -18,11 +18,11 @@ license: "CC-BY-NC-4.0" **If you want to know what is LDAP access the following page:** -../network-services-pentesting/pentesting-ldap.md +[Pentesting Ldap](/hacktricks/network-services-pentesting/pentesting-ldap) **LDAP Injection** is an attack targeting web applications that construct LDAP statements from user input. It occurs when the application **fails to properly sanitize** input, allowing attackers to **manipulate LDAP statements** through a local proxy, potentially leading to unauthorized access or data manipulation. -EN-Blackhat-Europe-2008-LDAP-Injection-Blind-LDAP-Injection.pdf +[En Blackhat Europe 2008 Ldap Injection Blind Ldap Injection.Pdf](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/EN-Blackhat-Europe-2008-LDAP-Injection-Blind-LDAP-Injection.pdf) **Filter** = ( filtercomp )\ **Filtercomp** = and / or / not / item\ diff --git a/src/content/hacktricks/pentesting-web/login-bypass/overview.md b/src/content/hacktricks/pentesting-web/login-bypass/overview.md @@ -41,7 +41,8 @@ If you find a login page, test the following authentication and authorization fa In the following page you can find a **custom list to try to bypass login** via SQL Injections: -sql-login-bypass.md + +[Sql Login Bypass](/hacktricks/pentesting-web/login-bypass/sql-login-bypass) ### No SQL Injection authentication bypass diff --git a/src/content/hacktricks/pentesting-web/open-redirect.md b/src/content/hacktricks/pentesting-web/open-redirect.md @@ -30,7 +30,7 @@ license: "CC-BY-NC-4.0" - Userinfo/parser differential payloads are still producing real bugs in 2024+: - `https://trusted.example[@attacker.example` or `https://trusted.example%5B@attacker.example` can confuse server-side URL parsers/host validators while browsers still navigate to `attacker.example`. This is especially interesting in frameworks that validate `host` from a parsed object and later redirect with the original string.<sup>[[1]](#references)</sup> -ssrf-server-side-request-forgery/url-format-bypass.md +[Url Format Bypass](/hacktricks/pentesting-web/ssrf-server-side-request-forgery/url-format-bypass) ### OAuth / SSO allowlist footguns @@ -67,11 +67,11 @@ ssrf-server-side-request-forgery/url-format-bypass.md - Frameworks often introduce footguns when redirect destinations are derived from untrusted input (query params, Referer, cookies). See Next.js notes about redirects and avoid dynamic destinations derived from user input. -../network-services-pentesting/pentesting-web/nextjs.md +[Nextjs](/hacktricks/network-services-pentesting/pentesting-web/nextjs) - OAuth/OIDC flows: abusing open redirectors frequently escalates to account takeover by leaking authorization codes/tokens. See dedicated guide: -./oauth-to-account-takeover.md +[Oauth To Account Takeover](/hacktricks/pentesting-web/oauth-to-account-takeover) - Server responses that implement redirects without Location (meta refresh/JavaScript) are still exploitable for phishing and can sometimes be chained. Grep for: diff --git a/src/content/hacktricks/pentesting-web/pocs-and-polygloths-cheatsheet/overview.md b/src/content/hacktricks/pentesting-web/pocs-and-polygloths-cheatsheet/overview.md @@ -55,7 +55,7 @@ javascript:alert(1) javascript:alert() javascript:"/*'/*`/*--></noscript></title></textarea></style></template></noembed></script><html \" onmouseover=/*<svg/*/onload=alert()//> -->'"/></sCript><deTailS open x=">" ontoggle=(co\u006efirm)``> -">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/index.html) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm( 1)"/alt="/"src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src//"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg"> +">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/index.html) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm( 1)"/alt="/"src="https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src//README.md"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg"> " onclick=alert(1)//<button ‘ onclick=alert(1)//> */ alert(1)// ';alert(String.fromCharCode(88,83,83))//';alert(String. fromCharCode(88,83,83))//";alert(String.fromCharCode (88,83,83))//";alert(String.fromCharCode(88,83,83))//-- ></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83)) </SCRIPT> ```text @@ -98,7 +98,7 @@ $(ls) javascript:"/*'/*`/*--></noscript></title></textarea></style></template></noembed></script><html \" onmouseover=/*<svg/*/onload=alert()//> -->'"/></sCript><deTailS open x=">" ontoggle=(co\u006efirm)``> jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0D%0A//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e -">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/index.html) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm( 1)"/alt="/"src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src//"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg"> +">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/index.html) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm( 1)"/alt="/"src="https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src//README.md"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg"> " onclick=alert(1)//<button ‘ onclick=alert(1)//> */ alert(1)// ';alert(String.fromCharCode(88,83,83))//';alert(String. fromCharCode(88,83,83))//";alert(String.fromCharCode (88,83,83))//";alert(String.fromCharCode(88,83,83))//-- ></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83)) </SCRIPT> javascript://'/</title></style></textarea></script>--><p" onclick=alert()//>*/alert()/* diff --git a/src/content/hacktricks/pentesting-web/pocs-and-polygloths-cheatsheet/web-vulns-list.md b/src/content/hacktricks/pentesting-web/pocs-and-polygloths-cheatsheet/web-vulns-list.md @@ -49,7 +49,7 @@ javascript:alert(1) javascript:alert() javascript:"/*'/*`/*--></noscript></title></textarea></style></template></noembed></script><html \" onmouseover=/*<svg/*/onload=alert()//> -->'"/></sCript><deTailS open x=">" ontoggle=(co\u006efirm)``> -">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/index.html) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm( 1)"/alt="/"src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src//"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg"> +">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/index.html) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm( 1)"/alt="/"src="https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src//README.md"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg"> " onclick=alert(1)//<button ‘ onclick=alert(1)//> */ alert(1)// ';alert(String.fromCharCode(88,83,83))//';alert(String. fromCharCode(88,83,83))//";alert(String.fromCharCode (88,83,83))//";alert(String.fromCharCode(88,83,83))//-- ></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83)) </SCRIPT> ```text diff --git a/src/content/hacktricks/pentesting-web/postmessage-vulnerabilities/overview.md b/src/content/hacktricks/pentesting-web/postmessage-vulnerabilities/overview.md @@ -114,7 +114,8 @@ Consequently, when a popup is opened under these conditions and a message is sen For more information **read**: -bypassing-sop-with-iframes-1.md + +[Bypassing Sop With Iframes 1](/hacktricks/pentesting-web/postmessage-vulnerabilities/bypassing-sop-with-iframes-1) ### Bypassing e.source @@ -126,7 +127,8 @@ You can force **`e.source`** of a message to be null by creating an **iframe** t For more information **read:** -bypassing-sop-with-iframes-2.md + +[Bypassing Sop With Iframes 2](/hacktricks/pentesting-web/postmessage-vulnerabilities/bypassing-sop-with-iframes-2) ### Framing-protection bypass @@ -137,7 +139,8 @@ In those scenarios you can still use a less stealthy attack. You can open a new ```text If a frameable page contains another iframe, an attacker may be able to **change the child iframe's location**. If that child receives a `postMessage` sent with wildcard `targetOrigin`, navigating it to an attacker-controlled origin can expose the message: -steal-postmessage-modifying-iframe-location.md + +[Steal Postmessage Modifying Iframe Location](/hacktricks/pentesting-web/postmessage-vulnerabilities/steal-postmessage-modifying-iframe-location) ### postMessage to Prototype Pollution and/or XSS diff --git a/src/content/hacktricks/pentesting-web/proxy-waf-protections-bypass.md b/src/content/hacktricks/pentesting-web/proxy-waf-protections-bypass.md @@ -126,9 +126,9 @@ This is especially relevant in exploit chains such as **React2Shell**, where the These ambiguities often overlap with: -http-request-smuggling/README.md +[Readme](/hacktricks/pentesting-web/http-request-smuggling/overview) -file-upload/README.md +[Readme](/hacktricks/pentesting-web/file-upload/overview) ## TLS, JA3/JA4 and HTTP/2 fingerprint evasion @@ -197,7 +197,7 @@ Practical use cases: This pairs well with header-reflection cache poisoning. See: -cache-deception/README.md +[Readme](/hacktricks/pentesting-web/cache-deception/overview) - [How I found a 0-Click Account takeover in a public BBP and leveraged it to access Admin-Level functionalities](https://hesar101.github.io/posts/How-I-found-a-0-Click-Account-takeover-in-a-public-BBP-and-leveraged-It-to-access-Admin-Level-functionalities/)<sup>[[5]](#references)</sup> @@ -230,7 +230,8 @@ Some inline-inspection rulesets only parse the first JavaScript statement presen ### H2C Smuggling <a href="#ip-rotation" id="ip-rotation"></a> -h2c-smuggling.md + +[H2C Smuggling](/hacktricks/pentesting-web/h2c-smuggling) ### IP Rotation <a href="#ip-rotation" id="ip-rotation"></a> diff --git a/src/content/hacktricks/pentesting-web/registration-vulnerabilities.md b/src/content/hacktricks/pentesting-web/registration-vulnerabilities.md @@ -50,11 +50,13 @@ When creating a user, check whether the password policy permits weak passwords. ### OAuth Takeovers -oauth-to-account-takeover.md + +[Oauth To Account Takeover](/hacktricks/pentesting-web/oauth-to-account-takeover) ### SAML Vulnerabilities -saml-attacks/ + +[Saml Attacks](/hacktricks/pentesting-web/saml-attacks/overview) ### Change Email @@ -68,9 +70,9 @@ After registration, try changing the email address and verify that ownership of - Use username@**burp_collab**.net and analyze the **callback** - If phone number verification is used, check phone parsing/injection edge cases -phone-number-injections.md +[Phone Number Injections](/hacktricks/pentesting-web/phone-number-injections) -captcha-bypass.md +[Captcha Bypass](/hacktricks/pentesting-web/captcha-bypass) ### Contact-discovery / identifier-enumeration oracles @@ -118,9 +120,9 @@ Practical tips Note: Extensive methodology and case studies of these techniques are documented by Microsoft’s pre‑hijacking research (see References at the end).<sup>[[2]](#references)</sup> -reset-password.md +[Reset Password](/hacktricks/pentesting-web/reset-password) -race-condition.md +[Race Condition](/hacktricks/pentesting-web/race-condition) ## **Password Reset Takeover** diff --git a/src/content/hacktricks/pentesting-web/saml-attacks/overview.md b/src/content/hacktricks/pentesting-web/saml-attacks/overview.md @@ -16,7 +16,8 @@ license: "CC-BY-NC-4.0" The first part of the referenced SAML testing methodology covers request collection, decoding, and baseline validation checks that should precede the attacks on this page.<sup>[[14]](#references)</sup> -saml-basics.md + +[Saml Basics](/hacktricks/pentesting-web/saml-attacks/saml-basics) ## Tool diff --git a/src/content/hacktricks/pentesting-web/sql-injection/mssql-injection.md b/src/content/hacktricks/pentesting-web/sql-injection/mssql-injection.md @@ -87,7 +87,7 @@ On **legacy** targets, `BACKUP ... TO DISK='\\attacker\file'` and `RESTORE ... F For a broader post-auth view of file reads and OS interaction, also check: -../../network-services-pentesting/pentesting-mssql-microsoft-sql-server/ +[Pentesting Mssql Microsoft Sql Server](/hacktricks/network-services-pentesting/pentesting-mssql-microsoft-sql-server/overview) ### `sys.dm_os_enumerate_filesystem`, `sys.dm_os_file_exists` @@ -101,7 +101,8 @@ If `xp_dirtree` / `xp_fileexist` have been revoked, recent research showed that Obviously you could also use **`xp_cmdshell`** to **execute** something that triggers a **SSRF**. For more info **read the relevant section** in the page: -../../network-services-pentesting/pentesting-mssql-microsoft-sql-server/ + +[Pentesting Mssql Microsoft Sql Server](/hacktricks/network-services-pentesting/pentesting-mssql-microsoft-sql-server/overview) ### MSSQL User Defined Function - SQLHttp <a href="#mssql-user-defined-function-sqlhttp" id="mssql-user-defined-function-sqlhttp"></a> diff --git a/src/content/hacktricks/pentesting-web/sql-injection/overview.md b/src/content/hacktricks/pentesting-web/sql-injection/overview.md @@ -235,7 +235,8 @@ $stmt->execute([$user_id]); ### WAF bypass suggester tools -https://github.com/m4ll0k/Atlas + +[Atlas](https%3A//github.com/m4ll0k/Atlas) ## Other Guides @@ -244,7 +245,8 @@ https://github.com/m4ll0k/Atlas ## Brute-Force Detection List -https://github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/sqli.txt + +[Sqli.Txt](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/sql-injection/https%3A/github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/sqli.txt) ## References diff --git a/src/content/hacktricks/pentesting-web/sql-injection/postgresql-injection/overview.md b/src/content/hacktricks/pentesting-web/sql-injection/postgresql-injection/overview.md @@ -28,7 +28,8 @@ You can [**read this example**](/hacktricks/pentesting-web/sql-injection/postgre Check how to compromise the host and escalate privileges from PostgreSQL in: -../../../network-services-pentesting/pentesting-postgresql.md + +[Pentesting Postgresql](/hacktricks/network-services-pentesting/pentesting-postgresql) ## WAF bypass diff --git a/src/content/hacktricks/pentesting-web/sql-injection/postgresql-injection/rce-with-postgresql-extensions.md b/src/content/hacktricks/pentesting-web/sql-injection/postgresql-injection/rce-with-postgresql-extensions.md @@ -70,7 +70,8 @@ A significant vulnerability arises from the `CREATE FUNCTION` command, which **p First of all you need to **use large objects to upload the dll**. You can see how to do that here: -big-binary-files-upload-postgresql.md + +[Big Binary Files Upload Postgresql](/hacktricks/pentesting-web/sql-injection/postgresql-injection/big-binary-files-upload-postgresql) Once you have uploaded the extension (with the name of poc.dll for this example) to the data directory you can load it with: diff --git a/src/content/hacktricks/pentesting-web/ssrf-server-side-request-forgery/overview.md b/src/content/hacktricks/pentesting-web/ssrf-server-side-request-forgery/overview.md @@ -18,7 +18,7 @@ A **Server-side Request Forgery (SSRF)** vulnerability occurs when an attacker m ### GeoNetwork SLD tool SSRF -../../network-services-pentesting/pentesting-web/geonetwork.md +[Geonetwork](/hacktricks/network-services-pentesting/pentesting-web/geonetwork) ## Capture SSRF @@ -38,7 +38,8 @@ The first thing you need to do is to capture a SSRF interaction generated by you Usually you will find that the SSRF is only working in **certain whitelisted domains** or URL. In the following page you have a **compilation of techniques to try to bypass that whitelist**: -url-format-bypass.md + +[Url Format Bypass](/hacktricks/pentesting-web/ssrf-server-side-request-forgery/url-format-bypass) ### Bypass via open redirect @@ -101,7 +102,8 @@ LESS is a CSS preprocessor that adds variables, mixins, functions, and the `@imp Check how to exploit it in: -../xs-search/css-injection/less-code-injection.md +[Less Code Injection](/hacktricks/pentesting-web/xs-search/css-injection/less-code-injection) + ## [Wget file upload](../file-upload/index.html#wget-file-upload-ssrf-trick) @@ -121,7 +123,8 @@ Create several sessions and try to download heavy files exploiting the SSRF from Check the following page for vulnerable PHP and even Wordpress functions: -../../network-services-pentesting/pentesting-web/php-tricks-esp/php-ssrf.md + +[Php Ssrf](/hacktricks/network-services-pentesting/pentesting-web/php-tricks-esp/php-ssrf) ## SSRF Redirect to Gopher @@ -236,13 +239,15 @@ A good example is **CFITSIO Extended Filename Syntax (EFS)**. Passing attacker-c If you find a SSRF vulnerability in a machine running inside a cloud environment you might be able to obtain interesting information about the cloud environment and even credentials: -cloud-ssrf.md + +[Cloud Ssrf](/hacktricks/pentesting-web/ssrf-server-side-request-forgery/cloud-ssrf) ## SSRF Vulnerable Platforms Several known platforms contains or has contained SSRF vulnerabilities, check them in: -ssrf-vulnerable-platforms.md + +[Ssrf Vulnerable Platforms](/hacktricks/pentesting-web/ssrf-server-side-request-forgery/ssrf-vulnerable-platforms) ## Tools @@ -275,7 +280,8 @@ SSRF Proxy is a multi-threaded HTTP proxy server designed to tunnel client HTTP ### To practice -https://github.com/incredibleindishell/SSRF_Vulnerable_Lab + +[Ssrf Vulnerable Lab](https%3A//github.com/incredibleindishell/SSRF_Vulnerable_Lab) ## References diff --git a/src/content/hacktricks/pentesting-web/ssti-server-side-template-injection/jinja2-ssti.md b/src/content/hacktricks/pentesting-web/ssti-server-side-template-injection/jinja2-ssti.md @@ -77,7 +77,8 @@ If the target filters some chars but still allows statement tags, combine this i To learn about **more classes** that you can use to **escape** you can **check**: -../../generic-methodologies-and-resources/python/bypass-python-sandboxes/ + +[Bypass Python Sandboxes](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/python/bypass-python-sandboxes/README.md) ### Filter bypasses diff --git a/src/content/hacktricks/pentesting-web/ssti-server-side-template-injection/overview.md b/src/content/hacktricks/pentesting-web/ssti-server-side-template-injection/overview.md @@ -177,7 +177,8 @@ Expression Language (EL) is a fundamental feature that facilitates interaction b Check the following page to learn more about the **exploitation of EL interpreters**: -el-expression-language.md + +[El Expression Language](/hacktricks/pentesting-web/ssti-server-side-template-injection/el-expression-language) ### Groovy (Java) @@ -368,8 +369,7 @@ For RCE via SSTI in Go, object methods can be invoked. For example, if the provi ```text When user-controlled template data reaches a LESS compilation step, LESS variables, mixins, functions, and `@import` rules become an additional injection surface. In particular, `@import (inline)` can retrieve attacker-selected content during compilation and embed the fetched response in the resulting CSS. -../xs-search/css-injection/less-code-injection.md -{{/ref}} +[Less Code Injection](/hacktricks/pentesting-web/xs-search/css-injection/less-code-injection) ### More Exploits @@ -378,7 +378,7 @@ Once the template engine is identified, use an engine-specific exploitation work ## BlackHat PDF -EN-Server-Side-Template-Injection-RCE-For-The-Modern-Web-App-BlackHat-15 (1).pdf +[En Server Side Template Injection Rce For The Modern Web App Blackhat 15 (1).Pdf](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/ssti-server-side-template-injection/EN-Server-Side-Template-Injection-RCE-For-The-Modern-Web-App-BlackHat-15%20%281%29.pdf) ## Related Help @@ -396,7 +396,8 @@ If you think it could be useful, read: ## Brute-Force Detection List -https://github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/ssti.txt + +[Ssti.Txt](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/ssti-server-side-template-injection/https%3A/github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/ssti.txt) ## References diff --git a/src/content/hacktricks/pentesting-web/timing-attacks.md b/src/content/hacktricks/pentesting-web/timing-attacks.md @@ -67,7 +67,7 @@ Timing is also useful for vulnerabilities where the application **parses attacke Once you confirm that timing is exposing internal parsing, move to the more specific exploitation pages instead of overloading this one: -parameter-pollution.md +[Parameter Pollution](/hacktricks/pentesting-web/parameter-pollution) ### Reverse Proxy Misconfigurations diff --git a/src/content/hacktricks/pentesting-web/unicode-injection/overview.md b/src/content/hacktricks/pentesting-web/unicode-injection/overview.md @@ -28,7 +28,7 @@ Unicode normalization occurs when **Unicode characters are normalized to ASCII c For more info check: -unicode-normalization.md +[Unicode Normalization](/hacktricks/pentesting-web/unicode-injection/unicode-normalization) ## SQL Server Best Fit / implicit conversion diff --git a/src/content/hacktricks/pentesting-web/web-vulnerabilities-methodology.md b/src/content/hacktricks/pentesting-web/web-vulnerabilities-methodology.md @@ -23,7 +23,7 @@ Every web pentest has both obvious and hidden attack surfaces. This page is a ch - [ ] [**Cache Poisoning/Cache Deception**](cache-deception/index.html) - [ ] [**HTTP Connection Contamination**](/hacktricks/pentesting-web/http-connection-contamination) - [ ] [**HTTP Connection Request Smuggling**](/hacktricks/pentesting-web/http-connection-request-smuggling) -- [ ] [**HTTP Request Smuggling**](http-request-smuggling/) +- [ ] [**HTTP Request Smuggling**](/hacktricks/pentesting-web/http-request-smuggling/overview) - [ ] [**HTTP Response Smuggling / Desync**](/hacktricks/pentesting-web/http-response-smuggling-desync) - [ ] [**H2C Smuggling**](/hacktricks/pentesting-web/h2c-smuggling) - [ ] [**Server Side Inclusion/Edge Side Inclusion**](/hacktricks/pentesting-web/server-side-inclusion-edge-side-inclusion-injection) @@ -62,7 +62,8 @@ If the introduced data may somehow be reflected in the response, the page might Some of these vulnerabilities require special conditions, while others only require reflection in a dangerous context. The following page contains polyglots for quickly testing several classes: -pocs-and-polygloths-cheatsheet/ + +[Pocs And Polygloths Cheatsheet](/hacktricks/pentesting-web/pocs-and-polygloths-cheatsheet/overview) ### Modern client-side code execution pivots @@ -223,7 +224,7 @@ Misconfigurations in the edge stack often unlock more impactful bugs in the appl - [ ] [**Apache**](/hacktricks/network-services-pentesting/pentesting-web/apache) - [ ] [**Nginx**](/hacktricks/network-services-pentesting/pentesting-web/nginx) - [ ] [**IIS**](/hacktricks/network-services-pentesting/pentesting-web/iis-internet-information-services) -- [ ] [**Tomcat**](../network-services-pentesting/pentesting-web/tomcat/) +- [ ] [**Tomcat**](/hacktricks/network-services-pentesting/pentesting-web/tomcat/overview) - [ ] [**Spring Actuators**](/hacktricks/network-services-pentesting/pentesting-web/spring-actuators) - [ ] [**PUT Method / WebDAV**](/hacktricks/network-services-pentesting/pentesting-web/put-method-webdav) - [ ] [**Special HTTP Headers**](/hacktricks/network-services-pentesting/pentesting-web/special-http-headers) diff --git a/src/content/hacktricks/pentesting-web/websocket-attacks.md b/src/content/hacktricks/pentesting-web/websocket-attacks.md @@ -62,11 +62,11 @@ You can use `websocat` to establish a raw connection with a websocket. If the endpoint turns out to be an MQTT broker, jump to the MQTT page (see the "MQTT over WebSocket in web applications" section there) to enumerate topics, abuse wildcard subscriptions and reach the broker with a `mqtt`/`websocket` PoC client: -../network-services-pentesting/1883-pentesting-mqtt-mosquitto.md +[1883 Pentesting Mqtt Mosquitto](/hacktricks/network-services-pentesting/1883-pentesting-mqtt-mosquitto) For AMQP brokers (RabbitMQ, etc.): -../network-services-pentesting/5671-5672-pentesting-amqp.md +[5671 5672 Pentesting Amqp](/hacktricks/network-services-pentesting/5671-5672-pentesting-amqp) ## Decrypting Websocket @@ -233,7 +233,7 @@ A common next step is tunneling into **localhost-only Erlang distribution** serv For the Erlang-side tradecraft, see: -../network-services-pentesting/4369-pentesting-erlang-port-mapper-daemon-epmd.md +[4369 Pentesting Erlang Port Mapper Daemon Epmd](/hacktricks/network-services-pentesting/4369-pentesting-erlang-port-mapper-daemon-epmd) #### Chaining tunneled footholds into root via maintenance path traversal @@ -265,7 +265,8 @@ As Web Sockets are a mechanism to **send data to server side and client side**, This vulnerability could allow you to **bypass reverse proxies restrictions** by making them believe that a **websocket communication was stablished** (even if it isn't true). This could allow an attacker to **access hidden endpoints**. For more information check the following page: -h2c-smuggling.md + +[H2C Smuggling](/hacktricks/pentesting-web/h2c-smuggling) ## References diff --git a/src/content/hacktricks/pentesting-web/xs-search/connection-pool-by-destination-example.md b/src/content/hacktricks/pentesting-web/xs-search/connection-pool-by-destination-example.md @@ -14,7 +14,7 @@ license: "CC-BY-NC-4.0" In [**this exploit**](https://gist.github.com/terjanq/0bc49a8ef52b0e896fca1ceb6ca6b00e#file-safelist-html), [**@terjanq**](https://twitter.com/terjanq) proposes yet another solution for the challenge mentioned in the following page:<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup> -connection-pool-example.md +[Connection Pool Example](/hacktricks/pentesting-web/xs-search/connection-pool-example) Let's see how this exploit works: diff --git a/src/content/hacktricks/pentesting-web/xs-search/cookie-bomb-onerror-xs-leak.md b/src/content/hacktricks/pentesting-web/xs-search/cookie-bomb-onerror-xs-leak.md @@ -67,7 +67,7 @@ Browser hardening watchlist (2025+) Related XS-Search tricks - URL length based oracles (no cookies needed) can be combined or used instead when you can force a very long request target: -url-max-length-client-side.md +[Url Max Length Client Side](/hacktricks/pentesting-web/xs-search/url-max-length-client-side) Notes - This class of attacks is discussed broadly as “Error Events” XS-Leaks.<sup>[[7]](#references)</sup> The cookie-bomb step is just a convenient way to push only one branch over server limits, producing a reliable boolean oracle. diff --git a/src/content/hacktricks/pentesting-web/xs-search/css-injection/overview.md b/src/content/hacktricks/pentesting-web/xs-search/css-injection/overview.md @@ -18,8 +18,7 @@ license: "CC-BY-NC-4.0" LESS expands ordinary CSS with variables, mixins, functions, and the `@import` directive. If attacker input is compiled as LESS, those features can generate selectors or force resource requests that provide CSS-injection and XS-Leak primitives. In particular, `@import (inline)` makes the compiler fetch a referenced resource and embed its contents in the resulting CSS. -less-code-injection.md -{{/ref}} +[Less Code Injection](/hacktricks/pentesting-web/xs-search/css-injection/less-code-injection) ### Attribute Selector diff --git a/src/content/hacktricks/pentesting-web/xs-search/event-loop-blocking-lazy-images.md b/src/content/hacktricks/pentesting-web/xs-search/event-loop-blocking-lazy-images.md @@ -16,7 +16,8 @@ In [**this exploit**](https://gist.github.com/aszx87410/155f8110e667bae3d10a3686 This is a **different exploit for the CTF chall** that was already commented in the following page. take a look for more info about the challenge: -connection-pool-example.md + +[Connection Pool Example](/hacktricks/pentesting-web/xs-search/connection-pool-example) This technique is useful when the attacker can create a **Boolean oracle** based on whether a **lazy-loaded image** is fetched or not, but **cannot** directly observe that request because of CSP, `img-src` restrictions, or `Cache-Control: no-store`. Instead of waiting for an external callback, the exploit converts image loading into a **timing side channel** by making those image requests compete with other requests. @@ -117,7 +118,7 @@ To make the oracle more stable: For more timing-based leak primitives, also check: -performance.now-+-force-heavy-task.md +[Performance.Now + Force Heavy Task](/hacktricks/pentesting-web/xs-search/performance-now-force-heavy-task) > [!WARNING] > Some privacy-focused defenses can break the "load only after a browser-driven scroll/viewport change" assumption. For example, XS-Leaks wiki documents `Document-Policy: force-load-at-top` as a way to disable load-on-scroll behaviors such as Scroll-to-Text navigation, which can also reduce similar viewport-based oracles. diff --git a/src/content/hacktricks/pentesting-web/xs-search/javascript-execution-xs-leak.md b/src/content/hacktricks/pentesting-web/xs-search/javascript-execution-xs-leak.md @@ -24,7 +24,7 @@ This is basically an **execution oracle**, not a timing oracle. The only thing t For the generic XS-Leaks background, see: -README.md +[Readme](/hacktricks/pentesting-web/xs-search/overview) ## When This Works diff --git a/src/content/hacktricks/pentesting-web/xs-search/overview.md b/src/content/hacktricks/pentesting-web/xs-search/overview.md @@ -80,7 +80,8 @@ For more info: [https://xsleaks.dev/docs/attacks/timing-attacks/clocks](https:// - **Summary**: if trying to load a resource onerror/onload events are triggered with the resource is loaded successfully/unsuccessfully it's possible to figure out the status code.<sup>[[2]](#references)[[7]](#references)</sup> - **Code example**: [https://xsinator.com/testing.html#Event%20Handler%20Leak%20(Script)](<https://xsinator.com/testing.html#Event%20Handler%20Leak%20(Script)>) -cookie-bomb-+-onerror-xs-leak.md + +[Cookie Bomb + Onerror Xs Leak](/hacktricks/pentesting-web/xs-search/cookie-bomb-onerror-xs-leak) The code example try lo **load scripts objects from JS**, but **other tags** such as objects, stylesheets, images, audios could be also used. Moreover, it's also possible to inject the **tag directly** and declare the `onload` and `onerror` events inside the tag (instead of injecting it from JS). @@ -129,7 +130,8 @@ It has been observed that in the absence of [Framing Protections](https://xsleak - **Summary:** If the **page** is **returning** the **sensitive** content, **or** a **content** that can be **controlled** by the user. The user could set **valid JS code in the negative case**, an **load** each try inside **`<script>`** tags, so in **negative** cases attackers **code** is **executed,** and in **affirmative** cases **nothing** will be executed. - **Code Example:** -javascript-execution-xs-leak.md + +[Javascript Execution Xs Leak](/hacktricks/pentesting-web/xs-search/javascript-execution-xs-leak) ### CORB - Onerror @@ -196,7 +198,8 @@ Because **only one request payment can be active** at the same time, if the targ - **Summary:** Measure execution time of a web abusing the single-threaded JS event loop.<sup>[[2]](#references)</sup> - **Code Example**: -event-loop-blocking-+-lazy-images.md + +[Event Loop Blocking + Lazy Images](/hacktricks/pentesting-web/xs-search/event-loop-blocking-lazy-images) JavaScript operates on a [single-threaded event loop](https://developer.mozilla.org/en-US/docs/Web/JavaScript/EventLoop) concurrency model, signifying that **it can only execute one task at a time**. This characteristic can be exploited to gauge **how long code from a different origin takes to execute**. An attacker can measure the execution time of their own code in the event loop by continuously dispatching events with fixed properties. These events will be processed when the event pool is empty. If other origins are also dispatching events to the same pool, an **attacker can infer the time it takes for these external events to execute by observing delays in the execution of their own tasks**. This method of monitoring the event loop for delays can reveal the execution time of code from different origins, potentially exposing sensitive information. @@ -224,7 +227,8 @@ A significant advantage of the technique of measuring execution time by locking - **Summary:** An attacker could lock all the sockets except 1, load the target web and at the same time load another page, the time until the last page is starting to load is the time the target page took to load.<sup>[[2]](#references)</sup> - **Code Example**: -connection-pool-example.md + +[Connection Pool Example](/hacktricks/pentesting-web/xs-search/connection-pool-example) Browsers utilize sockets for server communication, but due to the limited resources of the operating system and hardware, **browsers are compelled to impose a limit** on the number of concurrent sockets. Attackers can exploit this limitation through the following steps: @@ -535,7 +539,8 @@ The **noticeable difference**, is that if the **redirect** was **completed**, `w All the extra info needed to reach the **2MB** can be added via a **hash** in the initial URL so it will be **used in the redirect**. -url-max-length-client-side.md + +[Url Max Length Client Side](/hacktricks/pentesting-web/xs-search/url-max-length-client-side) ### Max Redirects @@ -727,7 +732,8 @@ Here you can find techniques to exfiltrate information from a cross-origin HTML ### Dangling Markup -../dangling-markup-html-scriptless-injection/ + +[Dangling Markup Html Scriptless Injection](/hacktricks/pentesting-web/dangling-markup-html-scriptless-injection/overview) ### Image Lazy Loading @@ -761,11 +767,13 @@ Some code example to exploit this: [https://gist.github.com/jorgectf/993d02bdadb If an external image cannot report a match directly, repeatedly **guess the character and measure the aggregate time**. Requests take longer when the matching image loads. This is the technique used in the [writeup's solution](https://blog.huli.tw/2022/10/08/en/sekaictf2022-safelist-and-connection/),<sup>[[22]](#references)</sup> summarized here: -event-loop-blocking-+-lazy-images.md + +[Event Loop Blocking + Lazy Images](/hacktricks/pentesting-web/xs-search/event-loop-blocking-lazy-images) ### ReDoS -../regular-expression-denial-of-service-redos.md + +[Regular Expression Denial Of Service Redos](/hacktricks/pentesting-web/regular-expression-denial-of-service-redos) ### CSS ReDoS diff --git a/src/content/hacktricks/pentesting-web/xss-cross-site-scripting/integer-overflow.md b/src/content/hacktricks/pentesting-web/xss-cross-site-scripting/integer-overflow.md @@ -15,7 +15,7 @@ license: "CC-BY-NC-4.0" > This page focuses on how **integer overflows/truncations can be abused in web applications and browsers**. For exploitation primitives inside native binaries you can continue reading the dedicated page: > > - +{{#ref}} > ../../binary-exploitation/integer-overflow-and-underflow.md > {{#endref}} @@ -152,7 +152,9 @@ If the callee later treats the same value as signed, truncates it again, or mult If the target uses Emscripten/WASM, a single integer bug in linear-memory management can often be upgraded into DOM XSS by corrupting writable HTML templates instead of the sanitized source string: +{{#ref}} wasm-linear-memory-template-overwrite-xss.md +{{#endref}} ### 4.7 Wrapper-aware parser reachability diff --git a/src/content/hacktricks/pentesting-web/xss-cross-site-scripting/overview.md b/src/content/hacktricks/pentesting-web/xss-cross-site-scripting/overview.md @@ -41,7 +41,8 @@ license: "CC-BY-NC-4.0" When working on a complex XSS you might find interesting to know about: -debugging-client-side-js.md + +[Debugging Client Side Js](/hacktricks/pentesting-web/xss-cross-site-scripting/debugging-client-side-js) ## Reflected values @@ -128,22 +129,26 @@ However, usually the endpoints executing the indicated function are endpoints wi Therefore, in order to **abuse this vulnerability in a different DOM** the **Same Origin Method Execution (SOME)** exploitation was developed: -some-same-origin-method-execution.md + +[Some Same Origin Method Execution](/hacktricks/pentesting-web/xss-cross-site-scripting/some-same-origin-method-execution) ### DOM There is **JS code** that is using **unsafely** some **data controlled by an attacker** like `location.href` . An attacker, could abuse this to execute arbitrary JS code. -dom-xss.md + +[Dom Xss](/hacktricks/pentesting-web/xss-cross-site-scripting/dom-xss) ### **Universal XSS** These kind of XSS can be found **anywhere**. They not depend just on the client exploitation of a web application but on **any** **context**. These kind of **arbitrary JavaScript execution** can even be abuse to obtain **RCE**, **read** **arbitrary** **files** in clients and servers, and more.\ Some **examples**: -server-side-xss-dynamic-pdf.md -../../network-services-pentesting/pentesting-web/electron-desktop-apps/ +[Server Side Xss Dynamic Pdf](/hacktricks/pentesting-web/xss-cross-site-scripting/server-side-xss-dynamic-pdf) + + +[Electron Desktop Apps](/hacktricks/network-services-pentesting/pentesting-web/electron-desktop-apps/overview) ## WAF bypass encoding image @@ -218,7 +223,8 @@ You can use **Hex** and **Octal encode** inside the `src` attribute of `iframe` ```text If you can inject any URL in an arbitrary **`<a href=`** tag that contains the **`target="_blank" and rel="opener"`** attributes, check the **following page to exploit this behavior**: -../reverse-tab-nabbing.md + +[Reverse Tab Nabbing](/hacktricks/pentesting-web/reverse-tab-nabbing) ### on Event Handlers Bypass @@ -481,7 +487,8 @@ top[8680439..toString(30)](1) There is **JS code** that is using **unsafely data controlled by an attacker** like `location.href` . An attacker, could abuse this to execute arbitrary JS code.\ **Due to the extension of the explanation of** [**DOM vulnerabilities it was moved to this page**](/hacktricks/pentesting-web/xss-cross-site-scripting/dom-xss)**:** -dom-xss.md + +[Dom Xss](/hacktricks/pentesting-web/xss-cross-site-scripting/dom-xss) There you will find a detailed **explanation of what DOM vulnerabilities are, how are they provoked, and how to exploit them**.\ Also, don't forget that **at the end of the mentioned post** you can find an explanation about [**DOM Clobbering attacks**](/hacktricks/pentesting-web/xss-cross-site-scripting/dom-xss#dom-clobbering). @@ -492,7 +499,8 @@ Also, don't forget that **at the end of the mentioned post** you can find an exp If you can trigger a XSS by sending the payload inside a cookie, this is usually a self-XSS. However, if you find a **vulnerable subdomain to XSS**, you could abuse this XSS to inject a cookie in the whole domain managing to trigger the cookie XSS in the main domain or other subdomains (the ones vulnerable to cookie XSS). For this you can use the cookie tossing attack: -../hacking-with-cookies/cookie-tossing.md + +[Cookie Tossing](/hacktricks/pentesting-web/hacking-with-cookies/cookie-tossing) You can find a great abuse of this technique in [**this blog post**](https://nokline.github.io/bugbounty/2024/06/07/Zoom-ATO.html).<sup>[[9]](#references)</sup> @@ -514,7 +522,8 @@ When a web app uses Emscripten/WASM, constant strings (like HTML format stubs) l Check the dedicated page with exploitation workflow, DevTools memory helpers, and defenses: -wasm-linear-memory-template-overwrite-xss.md +[Wasm Linear Memory Template Overwrite Xss](/hacktricks/pentesting-web/xss-cross-site-scripting/wasm-linear-memory-template-overwrite-xss) + ### Normalised Unicode @@ -593,7 +602,8 @@ For example in [**this writeup**](https://gitea.nitowa.xyz/nitowa/PlaidCTF-YACA) ### Chrome Cache to XSS -chrome-cache-to-xss.md + +[Chrome Cache To Xss](/hacktricks/pentesting-web/xss-cross-site-scripting/chrome-cache-to-xss) ### XS Jails Escape @@ -703,15 +713,18 @@ Rendered with `|safe`, the report outputs `<img ...>` and fires JS on view. ### Abusing Service Workers -abusing-service-workers.md + +[Abusing Service Workers](/hacktricks/pentesting-web/xss-cross-site-scripting/abusing-service-workers) ### Accessing Shadow DOM -shadow-dom.md + +[Shadow Dom](/hacktricks/pentesting-web/xss-cross-site-scripting/shadow-dom) ### Polyglots -https://github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/xss_polyglots.txt + +[Xss Polyglots.Txt](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/https%3A/github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/xss_polyglots.txt) ### Blind XSS payloads diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/abusing-ad-mssql.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/abusing-ad-mssql.md @@ -80,7 +80,7 @@ A strategy that many authors have come up with is to force a SYSTEM service to a ### SCCM Management Point NTLM Relay (OSD Secret Extraction) See how the default SQL roles of SCCM **Management Points** can be abused to dump Network Access Account and Task-Sequence secrets directly from the site database: -sccm-management-point-relay-sql-policy-secrets.md +[Sccm Management Point Relay Sql Policy Secrets](/hacktricks/windows-hardening/active-directory-methodology/sccm-management-point-relay-sql-policy-secrets) ## References diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/overview.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/overview.md @@ -16,7 +16,8 @@ license: "CC-BY-NC-4.0" ## BadSuccessor -BadSuccessor.md + +[Badsuccessor](/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/badsuccessor) ## **GenericAll Rights on User** @@ -37,7 +38,7 @@ This privilege grants an attacker full control over a target user account. Once ```text - **Shadow Credentials / Key Credential Link**: With `GenericAll` on a user you can add a certificate-based credential and authenticate as them without changing their password. See: -shadow-credentials.md +[Shadow Credentials](/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/shadow-credentials) ## **GenericAll Rights on Group** diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/account-persistence.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/account-persistence.md @@ -74,7 +74,8 @@ Requirements and caveats For more on weak explicit mappings and attack paths, see: -domain-escalation.md + +[Domain Escalation](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation) ## Enrollment Agent as Persistence – PERSIST5 diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/certificate-theft.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/certificate-theft.md @@ -30,7 +30,8 @@ However, if a private key is set as non-exportable, both CAPI and CNG will norma More info about DPAPI in: -../../windows-local-privilege-escalation/dpapi-extracting-passwords.md + +[Dpapi Extracting Passwords](/hacktricks/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords) In Windows, **certificate private keys are safeguarded by DPAPI**. It's crucial to recognize that the **storage locations for user and machine private keys** are distinct, and the file structures vary depending on the cryptographic API utilized by the operating system. **SharpDPAPI** is a tool that can navigate these differences automatically when decrypting the DPAPI blobs.<sup>[[1]](#references)</sup> diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation.md @@ -237,11 +237,13 @@ A common **issue** with NTLM relay attacks is the **short duration of NTLM sessi Nevertheless, this limitation is overcome by exploiting an NTLM relay attack to acquire a certificate for the user, as the certificate's validity period dictates the session's duration, and the certificate can be employed with services that **mandate NTLM signing**. For instructions on utilizing a stolen certificate, refer to: -account-persistence.md + +[Account Persistence](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/account-persistence) Another limitation of NTLM relay attacks is that **an attacker-controlled machine must be authenticated to by a victim account**. The attacker could either wait or attempt to **force** this authentication: -../printers-spooler-service-abuse.md + +[Printers Spooler Service Abuse](/hacktricks/windows-hardening/active-directory-methodology/printers-spooler-service-abuse) ### **Abuse** diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/badsuccessor-dmsa-migration-abuse.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/badsuccessor-dmsa-migration-abuse.md @@ -78,7 +78,8 @@ Correlating `4662` (attribute modification), `4741` (creation of a computer/serv ## See also -golden-dmsa-gmsa.md + +[Golden Dmsa Gmsa](/hacktricks/windows-hardening/active-directory-methodology/golden-dmsa-gmsa) ## References diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/bloodhound.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/bloodhound.md @@ -12,7 +12,7 @@ license: "CC-BY-NC-4.0" # BloodHound & Other Active Directory Enumeration Tools -adws-enumeration.md +[Adws Enumeration](/hacktricks/windows-hardening/active-directory-methodology/adws-enumeration) > NOTE: This page groups some of the most useful utilities to **enumerate** and **visualise** Active Directory relationships. For collection over the stealthy **Active Directory Web Services (ADWS)** channel check the reference above. diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/golden-ticket.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/golden-ticket.md @@ -56,7 +56,7 @@ In **newer Windows builds**, Event IDs **4768** and **4769** also expose much be Another OPSEC issue is **PAC fidelity**. Tickets with impossible group memberships, missing newer PAC buffers, or account metadata that doesn't match LDAP are easier to detect when defenders validate PAC contents against AD data. If you need a TGT that looks like it was really issued by a DC, review: -diamond-ticket.md +[Diamond Ticket](/hacktricks/windows-hardening/active-directory-methodology/diamond-ticket) There are also **environmental limits** to persistence. The `krbtgt` account keeps a **password history of 2**, so a forged TGT can remain valid across the **first** `krbtgt` reset if it was signed with the previous key. This is why defenders invalidate Golden Tickets by **resetting `krbtgt` twice** and waiting at least the domain's maximum ticket lifetime between resets.<sup>[[3]](#references)</sup> diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/kerberos-authentication.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/kerberos-authentication.md @@ -21,9 +21,7 @@ For a protocol-level walkthrough of the exchanges summarized below, see Tarlogic - **TGS-REQ / TGS-REP** → use a TGT to obtain **service tickets**. This is where **Kerberoasting**, **S4U abuse**, **delegation abuse**, and most **ticket-forging tradecraft** become relevant. - **AP-REQ / AP-REP** → present the ticket to the service. This is where **pass-the-ticket** and service-specific lateral movement happen. - For hands-on cheatsheets (AS-REP/Kerberoasting, ticket forgery, delegation abuse, etc.) see: - -../../network-services-pentesting/pentesting-kerberos-88/README.md - +[Readme](/hacktricks/network-services-pentesting/pentesting-kerberos-88/overview) - Use this page as the **overview / “what changed recently”** index, then jump to the dedicated pages for [Kerberoast](/hacktricks/windows-hardening/active-directory-methodology/kerberoast), [Resource-Based Constrained Delegation](/hacktricks/windows-hardening/active-directory-methodology/resource-based-constrained-delegation), [AD Certificates / PKINIT abuse](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates), or [BadSuccessor / dMSA abuse](/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/badsuccessor). ## Fresh attack notes (2024-2026) diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key.md @@ -68,7 +68,7 @@ Microsoft has been progressively reducing RC4-by-default behavior since the Nove For more details on Kerberos encryption types and related ticketing behaviour, check: -kerberos-authentication.md +[Kerberos Authentication](/hacktricks/windows-hardening/active-directory-methodology/kerberos-authentication) ## Stealthier version diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/overview.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/overview.md @@ -64,13 +64,15 @@ If you just have access to an AD environment but you don't have any credentials/ - `smbclient -U '%' -L //<DC IP> && smbclient -U 'guest%' -L //` - A more detailed guide on how to enumerate a SMB server can be found here: -../../network-services-pentesting/pentesting-smb/ + +[Pentesting Smb](/hacktricks/network-services-pentesting/pentesting-smb/overview) - **Enumerate Ldap** - `nmap -n -sV --script "ldap* and not brute" -p 389 <DC IP>` - A more detailed guide on how to enumerate LDAP can be found here (pay **special attention to the anonymous access**): -../../network-services-pentesting/pentesting-ldap.md + +[Pentesting Ldap](/hacktricks/network-services-pentesting/pentesting-ldap) - **Poison the network** - Gather credentials [**impersonating services with Responder**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md) @@ -125,13 +127,15 @@ Ok, so you know you have already a valid username but no passwords... Then try: - [**Password Spraying**](/hacktricks/windows-hardening/active-directory-methodology/password-spraying): Let's try the most **common passwords** with each of the discovered users, maybe some user is using a bad password (keep in mind the password policy!). - Note that you can also **spray OWA servers** to try to get access to the users mail servers. -password-spraying.md + +[Password Spraying](/hacktricks/windows-hardening/active-directory-methodology/password-spraying) ### LLMNR/NBT-NS Poisoning You might be able to **obtain** some challenge **hashes** to crack **poisoning** some protocols of the **network**: -../../generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md + +[Spoofing Llmnr Nbt Ns Mdns Dns And Wpad And Relay Attacks](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md) ### NTLM Relay @@ -170,7 +174,7 @@ The technique **does not work** against encryption types whose keys are not the History entries dramatically widen the candidate pool because Microsoft can store up to 24 previous hashes per account. For more ways to harvest NTDS secrets see: -dcsync.md +[Dcsync](/hacktricks/windows-hardening/active-directory-methodology/dcsync) - **Endpoint cache dumps** – `nxc smb <ip> -u <local_admin> -p <password> --local-auth --lsa` (or Mimikatz `lsadump::sam /patch`) extracts local SAM/SECURITY data and cached domain logons (DCC/DCC2). Deduplicate and append those hashes to the same `nt_candidates.txt` list. - **Track metadata** – Keep the username/domain that produced each hash (even if the wordlist contains only hex). Matching hashes tell you immediately which principal is reusing a password once Hashcat prints the winning candidate. @@ -199,7 +203,7 @@ Notes: 1. Capture an RC4 TGS for a target SPN with a low-privileged user (see the Kerberoast page for details): -kerberoast.md +[Kerberoast](/hacktricks/windows-hardening/active-directory-methodology/kerberoast) ```bash GetUserSPNs.py -dc-ip <dc_ip> -request <domain>/<user> -outputfile roastable_TGS @@ -246,7 +250,8 @@ For this phase you need to have **compromised the credentials or a session of a Before starting authenticated enumeration, understand the **Kerberos double-hop problem**. -kerberos-double-hop-problem.md + +[Kerberos Double Hop Problem](/hacktricks/windows-hardening/active-directory-methodology/kerberos-double-hop-problem) ### Enumeration @@ -310,7 +315,8 @@ After compromising the computer principal, graph its nested group memberships an The **Silver Ticket attack** creates a **legitimate Ticket Granting Service (TGS) ticket** for a specific service by using the **NTLM hash** (for instance, the **hash of the PC account**). This method is employed to **access the service privileges**. -silver-ticket.md + +[Silver Ticket](/hacktricks/windows-hardening/active-directory-methodology/silver-ticket) ### Golden Ticket @@ -318,25 +324,29 @@ A **Golden Ticket attack** involves an attacker gaining access to the **NTLM has Once the attacker obtains this hash, they can create **TGTs** for any account they choose (Silver ticket attack). -golden-ticket.md + +[Golden Ticket](/hacktricks/windows-hardening/active-directory-methodology/golden-ticket) ### Diamond Ticket These are like golden tickets forged in a way that **bypasses common golden tickets detection mechanisms.** -diamond-ticket.md + +[Diamond Ticket](/hacktricks/windows-hardening/active-directory-methodology/diamond-ticket) ### **Certificates Account Persistence** **Having certificates of an account or being able to request them** is a very good way to be able to persist in the users account (even if he changes the password): -ad-certificates/account-persistence.md + +[Account Persistence](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/account-persistence) ### **Certificates Domain Persistence** **Using certificates is also possible to persist with high privileges inside the domain:** -ad-certificates/domain-persistence.md + +[Domain Persistence](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/domain-persistence) ### AdminSDHolder Group @@ -348,52 +358,59 @@ The **AdminSDHolder** object in Active Directory ensures the security of **privi Inside every **Domain Controller (DC)**, a **local administrator** account exists. By obtaining admin rights on such a machine, the local Administrator hash can be extracted using **mimikatz**. Following this, a registry modification is necessary to **enable the use of this password**, allowing for remote access to the local Administrator account. -dsrm-credentials.md + +[Dsrm Credentials](/hacktricks/windows-hardening/active-directory-methodology/dsrm-credentials) ### ACL Persistence You could **give** some **special permissions** to a **user** over some specific domain objects that will let the user **escalate privileges in the future**. -acl-persistence-abuse/ + +[Acl Persistence Abuse](/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/overview) ### Security Descriptors The **security descriptors** are used to **store** the **permissions** an **object** have **over** an **object**. If you can just **make** a **little change** in the **security descriptor** of an object, you can obtain very interesting privileges over that object without needing to be member of a privileged group. -security-descriptors.md + +[Security Descriptors](/hacktricks/windows-hardening/active-directory-methodology/security-descriptors) ### Dynamic Objects Anti-Forensics / Evasion Abuse the `dynamicObject` auxiliary class to create short-lived principals/GPOs/DNS records with `entryTTL`/`msDS-Entry-Time-To-Die`; they self-delete without tombstones, erasing LDAP evidence while leaving orphan SIDs, broken `gPLink` references, or cached DNS responses (e.g., AdminSDHolder ACE pollution or malicious `gPCFileSysPath`/AD-integrated DNS redirects). -ad-dynamic-objects-anti-forensics.md +[Ad Dynamic Objects Anti Forensics](/hacktricks/windows-hardening/active-directory-methodology/ad-dynamic-objects-anti-forensics) ### Skeleton Key Alter **LSASS** in memory to establish a **universal password**, granting access to all domain accounts. -skeleton-key.md + +[Skeleton Key](/hacktricks/windows-hardening/active-directory-methodology/skeleton-key) ### Custom SSP [Learn what is a SSP (Security Support Provider) here.](../authentication-credentials-uac-and-efs/index.html#security-support-provider-interface-sspi)\ You can create you **own SSP** to **capture** in **clear text** the **credentials** used to access the machine. -custom-ssp.md + +[Custom Ssp](/hacktricks/windows-hardening/active-directory-methodology/custom-ssp) ### DCShadow It registers a **new Domain Controller** in the AD and uses it to **push attributes** (SIDHistory, SPNs...) on specified objects **without** leaving any **logs** regarding the **modifications**. You **need DA** privileges and be inside the **root domain**.\ Note that if you use wrong data, pretty ugly logs will appear. -dcshadow.md + +[Dcshadow](/hacktricks/windows-hardening/active-directory-methodology/dcshadow) ### LAPS Persistence Previously we have discussed about how to escalate privileges if you have **enough permission to read LAPS passwords**. However, these passwords can also be used to **maintain persistence**.\ Check: -laps.md + +[Laps](/hacktricks/windows-hardening/active-directory-methodology/laps) ## Forest Privilege Escalation - Domain Trusts @@ -469,7 +486,8 @@ You could check this in **Bloodhound** or using powerview: Escalate as Enterprise admin to the child/parent domain abusing the trust with SID-History injection: -sid-history-injection.md + +[Sid History Injection](/hacktricks/windows-hardening/active-directory-methodology/sid-history-injection) #### Exploit writeable Configuration NC @@ -487,11 +505,13 @@ An attack vector involves targeting privileged gMSAs within the domain. The KDS Detailed analysis and step-by-step guidance can be found in: -golden-dmsa-gmsa.md + +[Golden Dmsa Gmsa](/hacktricks/windows-hardening/active-directory-methodology/golden-dmsa-gmsa) Complementary delegated MSA attack (BadSuccessor – abusing migration attributes): -badsuccessor-dmsa-migration-abuse.md + +[Badsuccessor Dmsa Migration Abuse](/hacktricks/windows-hardening/active-directory-methodology/badsuccessor-dmsa-migration-abuse) Additional external research: [Golden gMSA Trust Attacks](https://itm8.com/articles/sid-filter-as-security-boundary-between-domains-part-5).<sup>[[13]](#references)</sup> @@ -540,7 +560,8 @@ The [LDAP BOF Collection](https://github.com/P0142/LDAP-Bof-Collection) re-imple ## AD -> Azure & Azure -> AD -https://cloud.hacktricks.wiki/en/pentesting-cloud/azure-security/az-lateral-movement-cloud-on-prem/azure-ad-connect-hybrid-identity/index.html + +[Index.Html](https%3A//cloud.hacktricks.wiki/en/pentesting-cloud/azure-security/az-lateral-movement-cloud-on-prem/azure-ad-connect-hybrid-identity/index.html) ## Some General Defenses @@ -553,7 +574,7 @@ https://cloud.hacktricks.wiki/en/pentesting-cloud/azure-security/az-lateral-move - **Temporal Privilege Limitation**: For tasks requiring DA privileges, their duration should be limited. This can be achieved by: `Add-ADGroupMember -Identity ‘Domain Admins’ -Members newDA -MemberTimeToLive (New-TimeSpan -Minutes 20)` - **LDAP relay mitigation**: Audit Event IDs 2889/3074/3075 and then enforce LDAP signing plus LDAPS channel binding on DCs/clients to block LDAP MITM/relay attempts. -ldap-signing-and-channel-binding.md +[Ldap Signing And Channel Binding](/hacktricks/windows-hardening/active-directory-methodology/ldap-signing-and-channel-binding) ### Protocol-level fingerprinting of Impacket activity diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/privileged-groups-and-token-privileges.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/privileged-groups-and-token-privileges.md @@ -141,7 +141,7 @@ The practical abuse is usually **offline access to DC disks/checkpoints** rather ```text From there, reuse the `Backup Operators` workflow to copy `Windows\NTDS\ntds.dit` and the registry hives offline. Related backup-file workflow: -../../network-services-pentesting/pentesting-veeam-backup-and-replication.md +[Pentesting Veeam Backup And Replication](/hacktricks/network-services-pentesting/pentesting-veeam-backup-and-replication) ## Group Policy Creators Owners diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/rdp-sessions-abuse.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/rdp-sessions-abuse.md @@ -59,7 +59,7 @@ High-level flow: See the AD CS pages for follow-up abuse: -ad-certificates/account-persistence.md +[Account Persistence](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/account-persistence) ## References diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/resource-based-constrained-delegation.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/resource-based-constrained-delegation.md @@ -200,11 +200,13 @@ In this example it was requested a TGS for the **CIFS** service from Administrat - You can also write the RBCD SD over AD Web Services (ADWS) if LDAP is filtered. See: -adws-enumeration.md + +[Adws Enumeration](/hacktricks/windows-hardening/active-directory-methodology/adws-enumeration) - Kerberos relay chains frequently end in RBCD to achieve local SYSTEM in one step. See practical end-to-end examples: -../../generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md + +[Spoofing Llmnr Nbt Ns Mdns Dns And Wpad And Relay Attacks](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md) - If LDAP signing/channel binding are **disabled** and you can create a machine account, tools like **KrbRelayUp** can relay a coerced Kerberos auth to LDAP, set `msDS-AllowedToActOnBehalfOfOtherIdentity` for your machine account on the target computer object, and immediately impersonate **Administrator** via S4U from off-host.<sup>[[8]](#references)</sup> diff --git a/src/content/hacktricks/windows-hardening/active-directory-methodology/sccm-management-point-relay-sql-policy-secrets.md b/src/content/hacktricks/windows-hardening/active-directory-methodology/sccm-management-point-relay-sql-policy-secrets.md @@ -106,12 +106,12 @@ You can inspect the full list with: ## See also * NTLM relay fundamentals: - - ../ntlm/README.md + +[Readme](/hacktricks/windows-hardening/ntlm/overview) * MSSQL abuse & post-exploitation: - - abusing-ad-mssql.md + +[Abusing Ad Mssql](/hacktricks/windows-hardening/active-directory-methodology/abusing-ad-mssql) ## References - [1] [I’d Like to Speak to Your Manager: Stealing Secrets with Management Point Relays](https://specterops.io/blog/2025/07/15/id-like-to-speak-to-your-manager-stealing-secrets-with-management-point-relays/) diff --git a/src/content/hacktricks/windows-hardening/authentication-credentials-uac-and-efs.md b/src/content/hacktricks/windows-hardening/authentication-credentials-uac-and-efs.md @@ -113,7 +113,7 @@ This approach requires the **victim user** to be **running** a **process** on th Mimikatz can import the user's certificate and private key, then use them to decrypt EFS-protected files.<sup>[[2]](#references)</sup> -https://github.com/gentilkiwi/mimikatz/wiki/howto-~-decrypt-EFS-files +[Howto ~ Decrypt Efs Files](https%3A//github.com/gentilkiwi/mimikatz/wiki/howto-~-decrypt-EFS-files) ## Group Managed Service Accounts (gMSA) diff --git a/src/content/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/overview.md b/src/content/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/overview.md @@ -160,7 +160,8 @@ Typical workflow: The **Local Administrator Password Solution (LAPS)**, available for download from [Microsoft](https://www.microsoft.com/en-us/download/details.aspx?id=46899), enables the management of local Administrator passwords. These passwords, which are **randomized**, unique, and **regularly changed**, are stored centrally in Active Directory. Access to these passwords is restricted through ACLs to authorized users. With sufficient permissions granted, the ability to read local admin passwords is provided. -../active-directory-methodology/laps.md + +[Laps](/hacktricks/windows-hardening/active-directory-methodology/laps) ## PS Constrained Language Mode diff --git a/src/content/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/uac-user-account-control.md b/src/content/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/uac-user-account-control.md @@ -18,7 +18,8 @@ license: "CC-BY-NC-4.0" For more info about integrity levels: -../windows-local-privilege-escalation/integrity-levels.md + +[Integrity Levels](/hacktricks/windows-hardening/windows-local-privilege-escalation/integrity-levels) When UAC is in place, an administrator user is given 2 tokens: a standard user token, to perform regular actions at medium integrity, and one with the admin privileges. @@ -235,7 +236,7 @@ Minimal flow: Some post-2024 chains no longer look like the classic `HKCU\Software\Classes` registry hijacks. For example, activation-context cache poisoning can chain a **drive remap** and **DLL redirection** to move from medium to high integrity through trusted UI / auto-elevated binaries such as `ctfmon.exe` and later targets like `fodhelper.exe`. Instead of duplicating the large PoC here, check the compact payload examples in: -../windows-local-privilege-escalation/windows-c-payloads.md +[Windows C Payloads](/hacktricks/windows-hardening/windows-local-privilege-escalation/windows-c-payloads) ### Administrator Protection (preview) drive-letter hijack via per-logon-session DOS device map @@ -244,7 +245,7 @@ Some post-2024 chains no longer look like the classic `HKCU\Software\Classes` re For the full `RAiLaunchAdminProcess` / UIAccess attack surface on Windows 11 25H2 preview builds, check the dedicated page: -../windows-local-privilege-escalation/uiaccess-admin-protection-bypass.md +[Uiaccess Admin Protection Bypass](/hacktricks/windows-hardening/windows-local-privilege-escalation/uiaccess-admin-protection-bypass) Windows 11 25H2 “Administrator Protection” uses shadow-admin tokens with per-session `\Sessions\0\DosDevices/<LUID>` maps. The directory is created lazily by `SeGetTokenDeviceMap` on first `\??` resolution. If the attacker impersonates the shadow-admin token only at **SecurityIdentification**, the directory is created with the attacker as **owner** (inherits `CREATOR OWNER`), allowing drive-letter links that take precedence over `\GLOBAL??`.<sup>[[7]](#references)</sup> diff --git a/src/content/hacktricks/windows-hardening/av-bypass.md b/src/content/hacktricks/windows-hardening/av-bypass.md @@ -386,11 +386,13 @@ Every environment you go against will have their own strengths and weaknesses. I highly encourage you go watch this talk from [@ATTL4S](https://twitter.com/DaniLJ94), to get a foothold into more Advanced Evasion techniques. -https://vimeo.com/502507556?embedded=true&owner=32913914&source=vimeo_logo + +[502507556?Embedded=True&Owner=32913914&Source=Vimeo Logo](https%3A//vimeo.com/502507556%3Fembedded%3Dtrue%26owner%3D32913914%26source%3Dvimeo_logo) his is also another great talk from [@mariuszbit](https://twitter.com/mariuszbit) about Evasion in Depth. -https://www.youtube.com/watch?v=IbA7Ung39o4 + +[Watch?V=Iba7Ung39O4](https%3A//www.youtube.com/watch%3Fv%3DIbA7Ung39o4) ## **Old Techniques** @@ -557,7 +559,7 @@ What makes a process run as PPL See also a broader intro to PP/PPL and LSASS protection here: -stealing-credentials/credentials-protections.md +[Credentials Protections](/hacktricks/windows-hardening/stealing-credentials/credentials-protections) Launcher tooling - Open-source helper: CreateProcessAsPPL (selects protection level and forwards arguments to the target EXE): diff --git a/src/content/hacktricks/windows-hardening/cobalt-strike.md b/src/content/hacktricks/windows-hardening/cobalt-strike.md @@ -180,7 +180,9 @@ However, you need to be **careful with the generated traffic**, as you might be Check the page: -av-bypass.md + +[Av Bypass](/hacktricks/windows-hardening/av-bypass) + #### Artifact Kit diff --git a/src/content/hacktricks/windows-hardening/lateral-movement/rdpexec.md b/src/content/hacktricks/windows-hardening/lateral-movement/rdpexec.md @@ -18,7 +18,7 @@ license: "CC-BY-NC-4.0" For background on RDP enumeration, configuration, and attack techniques, see: -../../network-services-pentesting/pentesting-rdp.md +[Pentesting Rdp](/hacktricks/network-services-pentesting/pentesting-rdp) ## References diff --git a/src/content/hacktricks/windows-hardening/lateral-movement/winrm.md b/src/content/hacktricks/windows-hardening/lateral-movement/winrm.md @@ -16,7 +16,7 @@ WinRM is one of the most convenient **lateral movement** transports in Windows e For the **protocol/service enumeration**, listeners, enabling WinRM, `Invoke-Command`, and generic client usage, check: -../../network-services-pentesting/5985-5986-pentesting-winrm.md +[5985 5986 Pentesting Winrm](/hacktricks/network-services-pentesting/5985-5986-pentesting-winrm) ## Why operators like WinRM @@ -41,7 +41,7 @@ Common ways to gain that access: If you already control a box with admin rights, remember you can also **delegate WinRM access without full admin group membership** using the techniques described here: -../active-directory-methodology/security-descriptors.md +[Security Descriptors](/hacktricks/windows-hardening/active-directory-methodology/security-descriptors) ### Authentication gotchas that matter during lateral movement @@ -52,7 +52,7 @@ If you already control a box with admin rights, remember you can also **delegate If you land valid credentials during password spraying, validating them over WinRM is often the fastest way to check whether they translate into a shell: -../active-directory-methodology/password-spraying.md +[Password Spraying](/hacktricks/windows-hardening/active-directory-methodology/password-spraying) ## Linux-to-Windows lateral movement @@ -141,7 +141,7 @@ When SMB relay is blocked by signing and LDAP relay is constrained, **WS-Man/Win For multi-hop constraints after landing a first WinRM session, check: -../active-directory-methodology/kerberos-double-hop-problem.md +[Kerberos Double Hop Problem](/hacktricks/windows-hardening/active-directory-methodology/kerberos-double-hop-problem) ## OPSEC and detection notes diff --git a/src/content/hacktricks/windows-hardening/ntlm/overview.md b/src/content/hacktricks/windows-hardening/ntlm/overview.md @@ -132,7 +132,8 @@ The PoC can be found in **[https://github.com/eladshamir/Internal-Monologue](htt **Read more detailed guide on how to perform those attacks here:** -../../generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md + +[Spoofing Llmnr Nbt Ns Mdns Dns And Wpad And Relay Attacks](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md) ## Parse NTLM challenges from a network capture @@ -167,7 +168,7 @@ Microsoft broke most public chains with MS08-068 (SMB→SMB), MS09-013 (HTTP→S For the **March 2026** local reflection variant that abuses **SMB arbitrary ports** and **TCP connection reuse** to reach `NT AUTHORITY\SYSTEM`, see: -../windows-local-privilege-escalation/local-ntlm-reflection-via-smb-arbitrary-port.md +[Local Ntlm Reflection Via Smb Arbitrary Port](/hacktricks/windows-hardening/windows-local-privilege-escalation/local-ntlm-reflection-via-smb-arbitrary-port) ## References - [1] [evilmog/ntlmv1-multi – NTLMv1 Multitool](https://github.com/evilmog/ntlmv1-multi) diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/access-tokens.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/access-tokens.md @@ -76,7 +76,8 @@ For examples of **session/user token hijacking** from a privileged context, chec Learn which **token privileges can be abused to escalate privileges:** -privilege-escalation-abusing-tokens.md + +[Privilege Escalation Abusing Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens) Take a look to [**all the possible token privileges and some definitions on this external page**](https://github.com/gtworek/Priv2Admin). diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/dll-hijacking/overview.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/dll-hijacking/overview.md @@ -27,7 +27,8 @@ Several methods are employed for DLL hijacking, each with its effectiveness depe 5. **WinSxS DLL Replacement**: Substituting the legitimate DLL with a malicious counterpart in the WinSxS directory, a method often associated with DLL side-loading. 6. **Relative Path DLL Hijacking**: Placing the malicious DLL in a user-controlled directory with the copied application, resembling Binary Proxy Execution techniques. -windows-cpython-build-landmark-sys-path-hijacking.md +[Windows Cpython Build Landmark Sys Path Hijacking](/hacktricks/windows-hardening/windows-local-privilege-escalation/dll-hijacking/windows-cpython-build-landmark-sys-path-hijacking) + ### AppDomainManager hijacking (`<exe>.config` + attacker assembly) @@ -97,7 +98,7 @@ Fast hunting pivots: > [!TIP] > For a step-by-step chain that layers HTML staging, AES-CTR configs, and .NET implants on top of DLL sideloading, review the workflow below. -advanced-html-staged-dll-sideloading.md +[Advanced Html Staged Dll Sideloading](/hacktricks/windows-hardening/windows-local-privilege-escalation/dll-hijacking/advanced-html-staged-dll-sideloading) ## Finding missing DLLs diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/dll-hijacking/writable-sys-path-dll-hijacking-privesc.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/dll-hijacking/writable-sys-path-dll-hijacking-privesc.md @@ -20,7 +20,8 @@ This can be abused through **DLL hijacking** when a more-privileged service or p For more information about **DLL hijacking**, see: -./ + +[.](/hacktricks/windows-hardening/windows-local-privilege-escalation/dll-hijacking/overview) ## Privesc with Dll Hijacking diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/juicypotato.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/juicypotato.md @@ -14,7 +14,7 @@ license: "CC-BY-NC-4.0" > [!WARNING] > JuicyPotato is legacy. It generally works on Windows versions up to Windows 10 1803 / Windows Server 2016. Microsoft changes shipped starting in Windows 10 1809 / Server 2019 broke the original technique. For those builds and newer, consider modern alternatives such as PrintSpoofer, RoguePotato, SharpEfsPotato/EfsPotato, GodPotato and others. See the page below for up-to-date options and usage. -roguepotato-and-printspoofer.md +[Roguepotato And Printspoofer](/hacktricks/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer) ## Juicy Potato (abusing the golden privileges) <a href="#juicy-potato-abusing-the-golden-privileges" id="juicy-potato-abusing-the-golden-privileges"></a> diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/local-ntlm-reflection-via-smb-arbitrary-port.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/local-ntlm-reflection-via-smb-arbitrary-port.md @@ -25,7 +25,7 @@ This is the primitive behind **CVE-2026-24294**, patched in **March 2026**.<sup> The older CMTI / serialized-SPN reflection trick is covered here: -../ntlm/README.md +[Readme](/hacktricks/windows-hardening/ntlm/overview) This newer variant does **not** need a marshalled hostname. Instead it abuses two SMB client behaviours:<sup>[[1]](#references)</sup> diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/overview.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/overview.md @@ -22,39 +22,43 @@ This page consolidates general Windows privilege-escalation methodology from sev **If you don't know what Windows access tokens are, read the following page before continuing:** -access-tokens.md + +[Access Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/access-tokens) ### ACLs - DACLs/SACLs/ACEs **Check the following page for more info about ACLs - DACLs/SACLs/ACEs:** -acls-dacls-sacls-aces.md + +[Acls Dacls Sacls Aces](/hacktricks/windows-hardening/windows-local-privilege-escalation/acls-dacls-sacls-aces) ### Integrity Levels **If you don't know what integrity levels are in Windows, read the following page before continuing:** -integrity-levels.md + +[Integrity Levels](/hacktricks/windows-hardening/windows-local-privilege-escalation/integrity-levels) ## Windows Security Controls There are different things in Windows that could **prevent you from enumerating the system**, run executables or even **detect your activities**. You should **read** the following **page** and **enumerate** all these **defenses** **mechanisms** before starting the privilege escalation enumeration: -../authentication-credentials-uac-and-efs/ + +[Authentication Credentials Uac And Efs](/hacktricks/windows-hardening/authentication-credentials-uac-and-efs/overview) ### Admin Protection / UIAccess silent elevation UIAccess processes launched through `RAiLaunchAdminProcess` can be abused to reach High IL without prompts when AppInfo secure-path checks are bypassed. Check the dedicated UIAccess/Admin Protection bypass workflow here: -uiaccess-admin-protection-bypass.md +[Uiaccess Admin Protection Bypass](/hacktricks/windows-hardening/windows-local-privilege-escalation/uiaccess-admin-protection-bypass) Secure Desktop accessibility registry propagation can be abused for an arbitrary SYSTEM registry write (RegPwn):<sup>[[18]](#references)</sup> -secure-desktop-accessibility-registry-propagation-regpwn.md +[Secure Desktop Accessibility Registry Propagation Regpwn](/hacktricks/windows-hardening/windows-local-privilege-escalation/secure-desktop-accessibility-registry-propagation-regpwn) Recent Windows builds also introduced an **SMB arbitrary-port** LPE path where a privileged local NTLM authentication is reflected over a reused SMB TCP connection: -local-ntlm-reflection-via-smb-arbitrary-port.md +[Local Ntlm Reflection Via Smb Arbitrary Port](/hacktricks/windows-hardening/windows-local-privilege-escalation/local-ntlm-reflection-via-smb-arbitrary-port) ## System Info @@ -100,7 +104,7 @@ In orther to exploit this vulnerabilities you can use tools like: [Wsuxploit](ht Read the research here: -CTX_WSUSpect_White_Paper (1).pdf +[Ctx Wsuspect White Paper (1).Pdf](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/CTX_WSUSpect_White_Paper%20%281%29.pdf) **WSUS CVE-2020-1013** @@ -117,7 +121,8 @@ You can exploit this vulnerability using the tool [**WSUSpicious**](https://gith Many enterprise agents expose a localhost IPC surface and a privileged update channel. If enrollment can be coerced to an attacker server and the updater trusts a rogue root CA or weak signer checks, a local user can deliver a malicious MSI that the SYSTEM service installs. See a generalized technique (based on the Netskope stAgentSvc chain – CVE-2025-0309) here: -abusing-auto-updaters-and-ipc.md + +[Abusing Auto Updaters And Ipc](/hacktricks/windows-hardening/windows-local-privilege-escalation/abusing-auto-updaters-and-ipc) ## Veeam Backup & Replication CVE-2023-27532 (SYSTEM via TCP 9401) @@ -281,14 +286,15 @@ Example tooling (RegPwn BOF / standalone):<sup>[[19]](#references)</sup> ```text Notepad++ autoloads any plugin DLL under its `plugins` subfolders. If a writable portable/copy install is present, dropping a malicious plugin gives automatic code execution inside `notepad++.exe` on every launch (including from `DllMain` and plugin callbacks). -notepad-plus-plus-plugin-autoload-persistence.md +[Notepad Plus Plus Plugin Autoload Persistence](/hacktricks/windows-hardening/windows-local-privilege-escalation/notepad-plus-plus-plugin-autoload-persistence) ### Run at startup **Check if you can overwrite some registry or binary that is going to be executed by a different user.**\ **Read** the **following page** to learn more about interesting **autoruns locations to escalate privileges**: -privilege-escalation-with-autorun-binaries.md + +[Privilege Escalation With Autorun Binaries](/hacktricks/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries) ### Drivers @@ -462,7 +468,8 @@ The **credentials files protected by the master password** are usually located i You can use **mimikatz module** `dpapi::cred` with the appropriate `/masterkey` to decrypt.\ You can **extract many DPAPI** **masterkeys** from **memory** with the `sekurlsa::dpapi` module (if you are root). -dpapi-extracting-passwords.md + +[Dpapi Extracting Passwords](/hacktricks/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords) ### PowerShell Credentials @@ -637,7 +644,8 @@ Basically, if you can **overwrite any of the DLLs** that are going to be execute To learn how attackers use COM Hijacking as a persistence mechanism check: -com-hijacking.md + +[Com Hijacking](/hacktricks/windows-hardening/windows-local-privilege-escalation/com-hijacking) ### **Generic Password search in files and registry** @@ -676,7 +684,7 @@ The Telephony service (TapiSrv) in server mode exposes `\\pipe\\tapsrv` (MS-TRP) More details: -telephony-tapsrv-arbitrary-dword-write-to-rce.md +[Telephony Tapsrv Arbitrary Dword Write To Rce](/hacktricks/windows-hardening/windows-local-privilege-escalation/telephony-tapsrv-arbitrary-dword-write-to-rce) ## Misc @@ -688,7 +696,7 @@ Check out the page **[https://filesec.io/](https://filesec.io/)** Clickable Markdown links forwarded to `ShellExecuteExW` can trigger dangerous URI handlers (`file:`, `ms-appinstaller:` or any registered scheme) and execute attacker-controlled files as the current user. See: -../protocol-handler-shell-execute-abuse.md +[Protocol Handler Shell Execute Abuse](/hacktricks/windows-hardening/protocol-handler-shell-execute-abuse) ### **Monitoring Command Lines for passwords** diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens.md @@ -16,7 +16,8 @@ license: "CC-BY-NC-4.0" If you **don't know what are Windows Access Tokens** read this page before continuing: -access-tokens.md + +[Access Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/access-tokens) **You may be able to escalate privileges by abusing tokens you already hold.** diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer.md @@ -20,11 +20,11 @@ license: "CC-BY-NC-4.0" Related pages for background and manual techniques: -seimpersonate-from-high-to-system.md +[Seimpersonate From High To System](/hacktricks/windows-hardening/windows-local-privilege-escalation/seimpersonate-from-high-to-system) -from-high-integrity-to-system-with-name-pipes.md +[From High Integrity To System With Name Pipes](/hacktricks/windows-hardening/windows-local-privilege-escalation/from-high-integrity-to-system-with-name-pipes) -privilege-escalation-abusing-tokens.md +[Privilege Escalation Abusing Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens) ## Requirements and common gotchas diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/secure-desktop-accessibility-registry-propagation-regpwn.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/secure-desktop-accessibility-registry-propagation-regpwn.md @@ -74,7 +74,7 @@ One straightforward chain is to overwrite a **service configuration** value (e.g For other Secure Desktop / UIAccess behaviors, see: -uiaccess-admin-protection-bypass.md +[Uiaccess Admin Protection Bypass](/hacktricks/windows-hardening/windows-local-privilege-escalation/uiaccess-admin-protection-bypass) ## References diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/sedebug-seimpersonate-copy-token.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/sedebug-seimpersonate-copy-token.md @@ -16,13 +16,13 @@ This page covers the **manual token-theft** variant where a **High Integrity** c If you only need a quick `SYSTEM` shell from a privileged admin process, also check: -seimpersonate-from-high-to-system.md +[Seimpersonate From High To System](/hacktricks/windows-hardening/windows-local-privilege-escalation/seimpersonate-from-high-to-system) If you do **not** have a process-handle path but you do have **`SeImpersonatePrivilege`**, the **named-pipe / Potato** route is usually easier: -named-pipe-client-impersonation.md +[Named Pipe Client Impersonation](/hacktricks/windows-hardening/windows-local-privilege-escalation/named-pipe-client-impersonation) -roguepotato-and-printspoofer.md +[Roguepotato And Printspoofer](/hacktricks/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer) ## Quick triage diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/seimpersonate-from-high-to-system.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/seimpersonate-from-high-to-system.md @@ -16,13 +16,13 @@ This page is about the **manual** version of going from a **High Integrity admin If you only have **`SeImpersonatePrivilege`** / **`SeAssignPrimaryTokenPrivilege`** but **cannot open a suitable SYSTEM process**, the **Potato / named-pipe** path is usually more reliable: -named-pipe-client-impersonation.md +[Named Pipe Client Impersonation](/hacktricks/windows-hardening/windows-local-privilege-escalation/named-pipe-client-impersonation) -roguepotato-and-printspoofer.md +[Roguepotato And Printspoofer](/hacktricks/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer) If what you want is not only `SYSTEM` but a **SYSTEM token with as many privileges as possible**, also check: -sedebug-+-seimpersonate-copy-token.md +[Sedebug + Seimpersonate Copy Token](/hacktricks/windows-hardening/windows-local-privilege-escalation/sedebug-seimpersonate-copy-token) ## Quick triage diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/service-triggers.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/service-triggers.md @@ -149,7 +149,7 @@ A trigger scoped to a specific port/protocol has been observed to start on any f - After starting a privileged service via a Named Pipe trigger, you may be able to impersonate it: -named-pipe-client-impersonation.md +[Named Pipe Client Impersonation](/hacktricks/windows-hardening/windows-local-privilege-escalation/named-pipe-client-impersonation) ## Quick command recap diff --git a/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/uiaccess-admin-protection-bypass.md b/src/content/hacktricks/windows-hardening/windows-local-privilege-escalation/uiaccess-admin-protection-bypass.md @@ -64,7 +64,7 @@ Get-AccessibleFile -Win32Path $paths -Access Execute,WriteData ` Secure Desktop accessibility registry propagation LPE (RegPwn): -secure-desktop-accessibility-registry-propagation-regpwn.md +[Secure Desktop Accessibility Registry Propagation Regpwn](/hacktricks/windows-hardening/windows-local-privilege-escalation/secure-desktop-accessibility-registry-propagation-regpwn) ## References