The examples demonstrate how to solve actual problems. I think many of us run into the problem where we get those funny windows characters in our files. These command are very useful if you do not have gui access to a host. Command line kung fu this blog will include fun, useful, interesting, security related, nonsecurity related, tips, and tricks associated with the command line.

Kung fu is a term that has become synonymous with martial arts in both the west and the east.

One of my students had a very interesting challenge.

Sure, linux command line tools have help features, but they can be pretty cumbersome. Subscribe to sans newsletters join the sans community to receive the latest curated cyber security news, vulnerabilities and mitigations, training opportunities, and our webcast schedule.

Each tip was submitted by the pen test instructors and curated by sans fellow, ed skoudis. Windows command line kungfu for extracting windows data through smb sessions sniffers, including tcpdump sniffer detection tools, including ifconfig, ifstatus, and promiscdetect. To help analyze malicious pdf documents, he was trying to parse the output of didier stevens pdf parser. A pdf containing an overview and alphabetical listing of windows commands. Learn penetration testing strategies, ethical hacking techniques to help security professionals evaluate the effectiveness of information security.

I even got a chance to give my return of command line kung fu talk, so I got a bunch of shell questions. Alternatively, you might consider using screen to start the wget download in a background command line instance that you can switch in and out of in order to check progress. Sans institute, including sans security 531, windows commandline kung fu for infosec pros.

Even though the title is command line kung fu, you dont have to be a Linux ninja to use the tactics presented in this book. Command line kung fu, for example, worth the price on its own, would be made into a serious reference with an expansion on other frequent command options, and examples. To help analyze malicious pdf documents, he was trying to parse the output of didier stevens pdf.

During my day job pen testing, I regularly look at nmap results to see what services are available. For example, lots of tcp445 means a bunch of windows boxes. Many are regularly selection from penetration testing. I simply, or not so simply, pulled out the commands and paraphrased from the discussions of the authors of command line kung fu. Sans sec 531 windows commandline kung fu indepth.

It is also useful to quickly see the one off ports. Many tools in a penetration testers arsenal are designed to get command shell on vulnerable target machines. Even in mainland China today the martial arts are referred to frequently as gung fu mandarin pronunciation. But, for winxp pro and win2003, wmic is a command line console to access windows machines via windows management instrumentation, a framework established by everyones favorite software.

I want to list some great windows command enable rdp reg add hklm\system\currentcontrolset\control\terminal server f v. And, often, windows machines are in the crosshairs, lacking critical patches or being run by clickhappy users that blindly open files sent during a carefully scoped penetration test. This is 948 pages of windows raw commandline power, for blue and red.

