diff --git a/.gitignore b/.gitignore new file mode 100755 index 00000000..e43b0f98 --- /dev/null +++ b/.gitignore @@ -0,0 +1 @@ +.DS_Store diff --git a/Discovery/Web_Content/WebServices/README b/Discovery/Web_Content/WebServices/README new file mode 100755 index 00000000..abef0032 --- /dev/null +++ b/Discovery/Web_Content/WebServices/README @@ -0,0 +1 @@ +This directory will contain list information that will be helpful in attacking both SOAP and REST-based web services. diff --git a/Discovery/Web_Content/WebServices/SOAP_functions.txt b/Discovery/Web_Content/WebServices/SOAP_functions.txt new file mode 100755 index 00000000..060283ae --- /dev/null +++ b/Discovery/Web_Content/WebServices/SOAP_functions.txt @@ -0,0 +1,3 @@ +GetAccount +GetUser +GetCCN diff --git a/Pattern_Matching/README b/Pattern_Matching/README new file mode 100755 index 00000000..5680b123 --- /dev/null +++ b/Pattern_Matching/README @@ -0,0 +1 @@ +The GrepStrings directory will hold various lists that can be passed to grep when looking for intersting content within filesystems or source code. diff --git a/Pattern_Matching/basic_grepstrings.txt b/Pattern_Matching/basic_grepstrings.txt new file mode 100755 index 00000000..b38d17a8 --- /dev/null +++ b/Pattern_Matching/basic_grepstrings.txt @@ -0,0 +1,14 @@ +password +user +username +select +update +delete +ssn +dob +ccn +passwd +pass +administrator +secret +key diff --git a/Pattern_Matching/malicious.txt b/Pattern_Matching/malicious.txt new file mode 100644 index 00000000..f5e258ff --- /dev/null +++ b/Pattern_Matching/malicious.txt @@ -0,0 +1,94 @@ +# strings for finding backdoor shells, rootkits, botnets, and exploitable functions +# grep -Rn "shell *(" /var/www + +passthru +shell_exec +system +phpinfo +base64_decode +chmod +mkdir +fopen +fclose +readfile +php_uname +eval +edoced_46esab +popen +include +create_function +mysql_execute +php_uname +proc_open +pcntl_exec +`` +include_once +require +require_once +posix_mkfifo +posix_getlogin +posix_ttyname +getenv +get_current_user +proc_get_status +get_cfg_var +disk_free_space +disk_total_space +diskfreespace +getcwd +getlastmo +getmygid +getmyinode +getmypid +getmyuid +assert +extract +parse_str +putenv +ini_set +pfsockopen +fsockopen +apache_child_terminate +posix_kill +posix_setpgid +posix_setsid +posix_setuid +tmpfile +bzopen +gzopen +chgrp +chown +copy +file_put_contents +lchgrp +lchown +link +mkdir +move_uploaded_file +symlink +tempnam +imagecreatefromgif +imagecreatefromjpeg +imagecreatefrompng +imagecreatefromwbmp +imagecreatefromxbm +imagecreatefromxpm +ftp_put +ftp_nb_put +exif_read_data +read_exif_data +exif_thumbnail +exif_imagetype +hash_file +hash_hmac_file +hash_update_file +md5_file +sha1_file +highlight_file +show_source +php_strip_whitespace +get_meta_tags +str_repeat +unserialize +register_tick_function +register_shutdown_function diff --git a/Pattern_Matching/pcap_strings.txt b/Pattern_Matching/pcap_strings.txt new file mode 100644 index 00000000..b2916466 --- /dev/null +++ b/Pattern_Matching/pcap_strings.txt @@ -0,0 +1,13 @@ +username +SSN +DOB +password +uname +encryption-key +encryptionkey +secretkey +secret_key +secret-key +aeskey +passphrase +wombat diff --git a/Pattern_Matching/thickclient_basic_.txt b/Pattern_Matching/thickclient_basic_.txt new file mode 100755 index 00000000..0ef7c715 --- /dev/null +++ b/Pattern_Matching/thickclient_basic_.txt @@ -0,0 +1,13 @@ +password +select +username +social +ssn +dob +DOB +Password +security +protected +SSN +update +delete diff --git a/Payloads/Backdoors/FUZZDB_Simple.php b/Payloads/FUZZDB_Simple.php similarity index 100% rename from Payloads/Backdoors/FUZZDB_Simple.php rename to Payloads/FUZZDB_Simple.php diff --git a/Payloads/Backdoors/FUZZDB_Up.php b/Payloads/FUZZDB_Up.php similarity index 100% rename from Payloads/Backdoors/FUZZDB_Up.php rename to Payloads/FUZZDB_Up.php diff --git a/Payloads/Backdoors/FUZZDB_cmd.jsp b/Payloads/FUZZDB_cmd.jsp similarity index 100% rename from Payloads/Backdoors/FUZZDB_cmd.jsp rename to Payloads/FUZZDB_cmd.jsp diff --git a/Payloads/Backdoors/FUZZDB_cmd.php b/Payloads/FUZZDB_cmd.php similarity index 100% rename from Payloads/Backdoors/FUZZDB_cmd.php rename to Payloads/FUZZDB_cmd.php diff --git a/Payloads/Backdoors/FUZZDB_cmd.sh b/Payloads/FUZZDB_cmd.sh similarity index 100% rename from Payloads/Backdoors/FUZZDB_cmd.sh rename to Payloads/FUZZDB_cmd.sh diff --git a/Payloads/Backdoors/FUZZDB_cmdasp.aspx b/Payloads/FUZZDB_cmdasp.aspx similarity index 100% rename from Payloads/Backdoors/FUZZDB_cmdasp.aspx rename to Payloads/FUZZDB_cmdasp.aspx diff --git a/Payloads/Backdoors/FUZZDB_jsp-reverse.jsp b/Payloads/FUZZDB_jsp-reverse.jsp similarity index 100% rename from Payloads/Backdoors/FUZZDB_jsp-reverse.jsp rename to Payloads/FUZZDB_jsp-reverse.jsp diff --git a/Payloads/Backdoors/FUZZDB_list.jsp b/Payloads/FUZZDB_list.jsp similarity index 100% rename from Payloads/Backdoors/FUZZDB_list.jsp rename to Payloads/FUZZDB_list.jsp diff --git a/Payloads/Backdoors/FUZZDB_list.php b/Payloads/FUZZDB_list.php similarity index 100% rename from Payloads/Backdoors/FUZZDB_list.php rename to Payloads/FUZZDB_list.php diff --git a/Payloads/Backdoors/FUZZDB_list.sh b/Payloads/FUZZDB_list.sh similarity index 100% rename from Payloads/Backdoors/FUZZDB_list.sh rename to Payloads/FUZZDB_list.sh diff --git a/Payloads/Backdoors/FUZZDB_nc.exe b/Payloads/FUZZDB_nc.exe similarity index 100% rename from Payloads/Backdoors/FUZZDB_nc.exe rename to Payloads/FUZZDB_nc.exe diff --git a/Payloads/Backdoors/FUZZDB_php-backdoor.php b/Payloads/FUZZDB_php-backdoor.php similarity index 100% rename from Payloads/Backdoors/FUZZDB_php-backdoor.php rename to Payloads/FUZZDB_php-backdoor.php diff --git a/Payloads/Backdoors/FUZZDB_up.sh b/Payloads/FUZZDB_up.sh similarity index 100% rename from Payloads/Backdoors/FUZZDB_up.sh rename to Payloads/FUZZDB_up.sh diff --git a/Payloads/Backdoors/laudanum-0.8/CREDITS b/Payloads/laudanum-0.8/CREDITS similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/CREDITS rename to Payloads/laudanum-0.8/CREDITS diff --git a/Payloads/Backdoors/laudanum-0.8/GPL b/Payloads/laudanum-0.8/GPL similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/GPL rename to Payloads/laudanum-0.8/GPL diff --git a/Payloads/Backdoors/laudanum-0.8/README b/Payloads/laudanum-0.8/README similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/README rename to Payloads/laudanum-0.8/README diff --git a/Payloads/Backdoors/laudanum-0.8/asp/dns.asp b/Payloads/laudanum-0.8/asp/dns.asp similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/asp/dns.asp rename to Payloads/laudanum-0.8/asp/dns.asp diff --git a/Payloads/Backdoors/laudanum-0.8/asp/file.asp b/Payloads/laudanum-0.8/asp/file.asp similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/asp/file.asp rename to Payloads/laudanum-0.8/asp/file.asp diff --git a/Payloads/Backdoors/laudanum-0.8/asp/proxy.asp b/Payloads/laudanum-0.8/asp/proxy.asp similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/asp/proxy.asp rename to Payloads/laudanum-0.8/asp/proxy.asp diff --git a/Payloads/Backdoors/laudanum-0.8/asp/shell.asp b/Payloads/laudanum-0.8/asp/shell.asp similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/asp/shell.asp rename to Payloads/laudanum-0.8/asp/shell.asp diff --git a/Payloads/Backdoors/laudanum-0.8/aspx/dns.aspx b/Payloads/laudanum-0.8/aspx/dns.aspx similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/aspx/dns.aspx rename to Payloads/laudanum-0.8/aspx/dns.aspx diff --git a/Payloads/Backdoors/laudanum-0.8/aspx/file.aspx b/Payloads/laudanum-0.8/aspx/file.aspx similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/aspx/file.aspx rename to Payloads/laudanum-0.8/aspx/file.aspx diff --git a/Payloads/Backdoors/laudanum-0.8/aspx/shell.aspx b/Payloads/laudanum-0.8/aspx/shell.aspx similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/aspx/shell.aspx rename to Payloads/laudanum-0.8/aspx/shell.aspx diff --git a/Payloads/Backdoors/laudanum-0.8/cfm/shell.cfm b/Payloads/laudanum-0.8/cfm/shell.cfm similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/cfm/shell.cfm rename to Payloads/laudanum-0.8/cfm/shell.cfm diff --git a/Payloads/Backdoors/laudanum-0.8/jsp/cmd.war b/Payloads/laudanum-0.8/jsp/cmd.war similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/jsp/cmd.war rename to Payloads/laudanum-0.8/jsp/cmd.war diff --git a/Payloads/Backdoors/laudanum-0.8/jsp/makewar.sh b/Payloads/laudanum-0.8/jsp/makewar.sh similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/jsp/makewar.sh rename to Payloads/laudanum-0.8/jsp/makewar.sh diff --git a/Payloads/Backdoors/laudanum-0.8/jsp/warfiles/META-INF/MANIFEST.MF b/Payloads/laudanum-0.8/jsp/warfiles/META-INF/MANIFEST.MF similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/jsp/warfiles/META-INF/MANIFEST.MF rename to Payloads/laudanum-0.8/jsp/warfiles/META-INF/MANIFEST.MF diff --git a/Payloads/Backdoors/laudanum-0.8/jsp/warfiles/WEB-INF/web.xml b/Payloads/laudanum-0.8/jsp/warfiles/WEB-INF/web.xml similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/jsp/warfiles/WEB-INF/web.xml rename to Payloads/laudanum-0.8/jsp/warfiles/WEB-INF/web.xml diff --git a/Payloads/Backdoors/laudanum-0.8/jsp/warfiles/cmd.jsp b/Payloads/laudanum-0.8/jsp/warfiles/cmd.jsp similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/jsp/warfiles/cmd.jsp rename to Payloads/laudanum-0.8/jsp/warfiles/cmd.jsp diff --git a/Payloads/Backdoors/laudanum-0.8/php/dns.php b/Payloads/laudanum-0.8/php/dns.php similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/php/dns.php rename to Payloads/laudanum-0.8/php/dns.php diff --git a/Payloads/Backdoors/laudanum-0.8/php/file.php b/Payloads/laudanum-0.8/php/file.php similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/php/file.php rename to Payloads/laudanum-0.8/php/file.php diff --git a/Payloads/Backdoors/laudanum-0.8/php/php-reverse-shell.php b/Payloads/laudanum-0.8/php/php-reverse-shell.php similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/php/php-reverse-shell.php rename to Payloads/laudanum-0.8/php/php-reverse-shell.php diff --git a/Payloads/Backdoors/laudanum-0.8/php/proxy.php b/Payloads/laudanum-0.8/php/proxy.php similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/php/proxy.php rename to Payloads/laudanum-0.8/php/proxy.php diff --git a/Payloads/Backdoors/laudanum-0.8/php/shell.php b/Payloads/laudanum-0.8/php/shell.php similarity index 100% rename from Payloads/Backdoors/laudanum-0.8/php/shell.php rename to Payloads/laudanum-0.8/php/shell.php