Linux Information Gathering
- 将环境变量
HISTFILE
设置为 /dev/null
export HISTFILE=/dev/null
/sbin/ifconfig -a
ip addr show
cat /etc/network/interfaces
cat /etc/sysconfig/network
route
# 显示核心路由表
ip route show
# 显示邻居表
ip neigh
# -a 表示显示所有活动的连接和监听端口,即显示所有状态的套接字
# -n 表示以数字形式显示IP地址和端口号,而不使用主机名和服务名
# -t 表示只显示TCP连接和监听端口
# -p 表示显示与每个套接字关联的进程ID(PID)和程序名称
netstat -antp
netstat -anltp | grep $PID
uname -a # 所有版本
uname -r # 内核版本信息
uname -n # 系统主机名字
uname -m # Linux内核架构
cat /etc/*-release
cat /etc/issue
awk -F: 'length($2)==0 {print $1}' /etc/shadow
awk '/\$1|\$6/{print $1}' /etc/shadow
cat /etc/sudoers | grep -v "^#\|^$" | grep "ALL=(ALL)"
# 查看开机启动服务命令
chkconfig
# 查看开机启动配置文件命令
ls /etc/init.d
# 查看 rc 启动文件
cat /etc/rc.local
/var/spool/cron/*
/var/spool/anacron/*
/etc/crontab
/etc/anacrontab
/etc/cron.*
/etc/anacrontab
ls -alh /var/spool/cron
ls -al /etc/ | grep cron
ls -al /etc/cron*
cat /etc/cron*
cat /etc/at.allow
cat /etc/at.deny
cat /etc/cron.allow
cat /etc/cron.deny
cat /etc/crontab
cat /var/spool/cron/crontabs/root
yum list | grep installed
ls -l /etc/yum.repos.d/
cat /etc/apt/sources.list
find / -ctime +1 -ctime -5
/var/log/boot.log
/var/log/cron
/var/log/faillog
/var/log/lastlog
/var/log/messages
/var/log/secure
/var/log/syslog
/var/log/syslog
/var/log/wtmp
/var/log/wtmp
/var/run/utmp
lsmod | grep -i "vboxsf\|vboxguest"
lsmod | grep -i "vmw_baloon\|vmxnet"
lsmod | grep -i "xen-vbd\|xen-vnif"
lsmod | grep -i "virtio_pci\|virtio_net"
lsmod | grep -i "hv_vmbus\|hv_blkvsc\|hv_netvsc\|hv_utils\|hv_storvsc"
capsh --print
cat /proc/1/cgroup
env | grep KUBE
ls -l .dockerenv
ls -l /run/secrets/Kubernetes.io/
mount
ps aux
grep -i user [filename]
grep -i pass [filename]
grep -C 5 "password" [filename]
find . -name "*.php" -print0 | xargs -0 grep -i -n "var $password" # Joomla
cat ~/.bash_history
cat ~/.nano_history
cat ~/.atftp_history
cat ~/.mysql_history
cat ~/.php_history
cat /etc/syslog.conf
cat /etc/chttp.conf
cat /etc/lighttpd.conf
cat /etc/cups/cupsd.conf
cat /etc/inetd.conf
cat /etc/apache2/apache2.conf
cat /etc/my.conf
cat /etc/httpd/conf/httpd.conf
cat /opt/lampp/etc/httpd.conf
ls -aRl /etc/ | awk '$1 ~ /^.\*r.\*/