Skip to content

Commit 9b4f440

Browse files
norajKINGSABRI
authored andcommitted
Revert "Revert "References fix""
This reverts commit babc7ea.
1 parent babc7ea commit 9b4f440

13 files changed

Lines changed: 2391 additions & 0 deletions

File tree

‎files/module06/packets.pcap‎

100644100755
File mode changed.

‎images/other/logo.png‎

100644100755
File mode changed.

‎package.json‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
{
2+
"name": "book",
3+
"version": "0.0.0",
4+
"dependencies": {}
5+
}

‎references.md‎

Lines changed: 76 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,76 @@
1+
# References
2+
3+
* **Contributors**
4+
* GitBook Desktop Editor
5+
* [Download and installation](https://www.gitbook.com/editor)
6+
* How to GitBook \[Videos\]
7+
* [Create GitBook online](https://www.youtube.com/watch?v=kdpfRLpu0FQ)
8+
* [Download and Install Gitbook package](https://www.gitbook.com/editor)
9+
* [Create GitBook with Editor](https://www.youtube.com/watch?v=IkV2HQLAKHY)
10+
* Markdown \[Documentations\]
11+
* [Markdown docs - GitBook \| Official docs](http://help.gitbook.com/format/markdown.html)
12+
* [Mastering Markdown - GitHub \| Mastering Markdown](https://guides.github.com/features/mastering-markdown/)
13+
* **Beginner**
14+
* [Ruby Tutorials - Tutorialspoint](http://www.tutorialspoint.com/ruby/)
15+
* [Ruby programming Tutorials - Simple Free videos](https://www.thenewboston.com/videos.php?cat=50)
16+
* [Lynda: Ruby Essential Training - Commercial Training](https://www.youtube.com/playlist?list=PLFI1RBqfVaOrMxWjIuFXbtGYtdmezgap3)
17+
* [Ruby from InfiniteSkills - Commercial Training](https://www.youtube.com/playlist?list=PLFI1RBqfVaOqvspvlnwS_ECczfRXnJee2)
18+
* [Quick Ruby syntax Cheat sheet](http://overapi.com/ruby/)
19+
* [4Programmer.com - Ruby](http://4programmer.com/ruby)
20+
* [Ruby Programming Tutorials - Free Video series](https://www.youtube.com/playlist?list=PLMK2xMz5H5Zv8eC8b4K6tMaE1-Z9FgSOp)
21+
* [Ruby3arabi - Arabic Ruby community](http://ruby3arabi.com/)
22+
* **Books**
23+
* [Ruby Learning](http://rubylearning.com/satishtalim/tutorial.html)
24+
* [Working with TCP Sockets](http://www.jstorimer.com/products/working-with-tcp-sockets)
25+
* [Working with Unix Processes](http://www.jstorimer.com/products/working-with-unix-processes)
26+
* [Working with Ruby Threads](http://www.jstorimer.com/products/working-with-ruby-threads)
27+
* [Ruby Cookbook](http://shop.oreilly.com/product/9780596523695.do)
28+
* [Learn Ruby The Hard Way](http://learnrubythehardway.org/book/)
29+
* [AllRubyBooks](http://www.allrubybooks.com/)
30+
* **Sites, Topics and Articles**
31+
* [Rubymonk.com](https://rubymonk.com/)
32+
* [Byte manipulation in ruby](http://www.happybearsoftware.com/byte-manipulation-in-ruby.html)
33+
* [Ruby Format](http://www.dotnetperls.com/format)
34+
* [Codewars](http://www.codewars.com/?language=ruby)
35+
* [rubeque](http://www.rubeque.com/)
36+
* [Hackerrank](https://www.hackerrank.com/)
37+
* [RubySec - Ruby Security Advisory](http://rubysec.com/)
38+
* [/r/ruby\_infosec](https://www.reddit.com/r/ruby_infosec)
39+
* A dozen \(or so\) ways to start sub-processes in Ruby: \[[Part 1](https://devver.wordpress.com/2009/06/30/a-dozen-or-so-ways-to-start-sub-processes-in-ruby-part-1/), [Part 2](https://devver.wordpress.com/2009/07/13/a-dozen-or-so-ways-to-start-sub-processes-in-ruby-part-2/), [Part 3](https://devver.wordpress.com/2009/10/12/ruby-subprocesses-part_3/)\]
40+
* **Hacking Tools built with ruby**
41+
* Metasploit framework - Exploitation framework \[ [link](https://github.com/rapid7/metasploit-framework) \]
42+
* Beef framework - XSS framework \[ [link](http://beefproject.com/) \]
43+
* Arachni - Web Application scanner framework \[ [link](http://www.arachni-scanner.com/) \]
44+
* Metasm - Assembly manipulation suite \[ [link](https://github.com/jjyg/metasm) \]
45+
* WPscan - WordPress vulnerability scanner \[ [link](http://wpscan.org) \]
46+
* WPXF - Wordpress Exploit Framework \[ [link](http://www.getwpxf.com/) \]
47+
* BufferOverflow kit - Exploitation tool Kit \[ [link](https://github.com/KINGSABRI/BufferOverflow-Kit) \]
48+
* HTTP Traceroute \[ [link](https://digi.ninja/projects/http_traceroute.php) \]
49+
* CeWL - Custom Word List generator \[ [link](https://digi.ninja/projects/cewl.php) \]
50+
* Roini - Vulnerability research and exploit development framework \[ [link](http://ronin-ruby.github.io/) \]
51+
* Idb - Simplifys some common tasks for iOS pentesting & research \[ [link](https://github.com/dmayer/idb) \]
52+
* Bettercap - Extensible MitM tool and framework \[ [link](https://www.bettercap.org/) \]
53+
* WATOBO - The Web Application Security Toolbox \[ [link](http://watobo.sourceforge.net/) \]
54+
* Intrigue.io - Open Source project, discovering attack surface through OSINT \[ [link](https://intrigue.io/) \]
55+
* OhNo - The Evil Image Builder & Meta Manipulator \[ [link](https://github.com/Hood3dRob1n/OhNo) \]
56+
* WhatWeb - Website Fingerprinter \[ [link](https://github.com/urbanadventurer/WhatWeb) \]
57+
* Relyze - reverse engineer similar to IDA-Pro supports Ruby plugins \[ [link](https://www.relyze.com/) \]
58+
* Capstone - multi-platform, multi-architecture disassembly framework supports Ruby \[ [link](http://www.capstone-engine.org/) \]
59+
* Rabid - A CLI tool and library allowing to simply decode all kind of BigIP cookies \[ [link](https://github.com/noraj/rabid) \]
60+
* Haiti - A CLI tool and library to identify the hash type of a given hash \[ [link](https://github.com/noraj/haiti) \]
61+
* ctf-party - A library to enhance and speed up script/exploit writing for CTF players \[ [link](https://github.com/noraj/ctf-party) \]
62+
* itdis - A small tool that allows you to check if a list of domains you have been provided is in the scope of your pentest or not. \[ [link](https://gitlab.com/noraj/itdis) \]
63+
* nvd\_feed\_api - A simple ruby API/library for managing NVD CVE feeds. The API will help you to download and manage NVD Data Feeds, search for CVEs, build your vulnerability assessment platform or vulnerability database. \[ [link](https://gitlab.com/noraj/nvd_api) \]
64+
* VBSmin - VBScript minifier CLI tool and library \[ [link](https://github.com/noraj/vbsmin) \]
65+
* Fingerprinter - CMS/LMS/Library etc Versions Fingerprinter \[ [link](https://github.com/erwanlr/Fingerprinter) \]
66+
* API-fuzzer - API Fuzzer which allows to fuzz request attributes using common pentesting techniques and lists vulnerabilities \[ [link](https://github.com/Fuzzapi/API-fuzzer) \]
67+
* oxml\_xxe - Tool for embedding XXE/XML exploits into different filetypes \(docx/xlsx, odt/ods, svg, xml, etc.\) \[ [link](https://github.com/BuffaloWill/oxml_xxe) \]
68+
* SSRF Proxy - Facilitates tunneling HTTP communications through servers vulnerable to SSRF \[ [link](https://github.com/bcoles/ssrf_proxy) \]
69+
* XXEinjector - Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods \[ [link](https://github.com/enjoiz/XXEinjector) \]
70+
* envizon - Network visualization & vulnerability management/reporting \[ [link](https://github.com/evait-security/envizon) \]
71+
* HellRaiser - Vulnerability Scanner \[ [link](https://github.com/m0nad/HellRaiser) \]
72+
* YASUO - A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network \[ [link](https://github.com/0xsauby/yasuo) \]
73+
* Evil-WinRM - WinRM shell for hacking/pentesting enhanced with a lot of features \[ [link](https://github.com/Hackplayers/evil-winrm) \]
74+
* apullo - A scanner for taking basic fingerprints \[ [link](https://github.com/ninoseki/apullo) \]
75+
* **\[**ADD YOUR RUBY HACKING TOOL HERE!**\]**
76+

‎required-gems.md‎

Lines changed: 112 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,112 @@
1+
# Required Gems
2+
3+
I'd like to list all external gems that might be used in this book. This list will be updated once a new gem is required.
4+
5+
Note that you don't need to install them all unless you specifically need them.
6+
7+
## Main Gems
8+
9+
* Pry - An IRB alternative and runtime developer console.
10+
* pry-doc - Pry Doc is a Pry REPL plugin. Extending documentation support for the REPL by improving the `show-doc & show-source commands.`
11+
* pry-byebug - Combine 'pry' with 'byebug'. Adds 'step', 'next', 'finish', 'continue' and 'break' commands to control execution.
12+
13+
```text
14+
gem install pry
15+
gem install pry-doc
16+
gem install pry-byebug
17+
```
18+
19+
To run pry with best appearance
20+
21+
```bash
22+
pry --simple-prompt
23+
```
24+
25+
> **Note:** Most of our examples will be executed on **pry** so please consider it as main part of our environment. Otherwise, when you see `#!/usr/bin/env ruby, it means a file script to execute.`
26+
27+
## Module Gems
28+
29+
Due the demand of wrapping all required gems into one gem, we've created [hacker-gems](https://rubygems.org/gems/hacker-gems) which installs all the below gems at one time.
30+
31+
```text
32+
gem install hacker-gems
33+
```
34+
35+
You might need to install some packages beforehand to avoid any errors of missing libraries.
36+
37+
```text
38+
sudo apt-get install build-essential libreadline-dev libssl-dev libpq5 libpq-dev libreadline5 libsqlite3-dev libpcap-dev git-core autoconf postgresql pgadmin3 curl zlib1g-dev libxml2-dev libxslt1-dev vncviewer libyaml-dev curl nmap
39+
```
40+
41+
### Module 0x1 \| Basic Ruby Kung Fu
42+
43+
* colorize - Extends String class or add a ColorizedString with methods to set text color, background.
44+
45+
### Module 0x2 \| System Kung Fu
46+
47+
* virustotal - A script for automating virustotal.com queries.
48+
* uirusu - A tool and REST library for interacting with Virustotal.org.
49+
* clipboard - Lets you access the clipboard on Linux, MacOS, Windows, and Cygwin.
50+
51+
**Extra gems**
52+
53+
Useful gems to build command line applications
54+
55+
* tty-prompt - A beautiful and powerful interactive command line prompt.
56+
* Thor - Create a command-suite app simply and easily, as well as Rails generators.
57+
* GLI - Create awesome, polished command suites without a lot of code.
58+
* Slop - Create simple command-line apps with a syntax similar to trollop.
59+
* Highline - handle user input and output via a “Q&A” style API, including type conversions and validation.
60+
* Escort - A library that makes building command-line apps in ruby so easy, you’ll feel like an expert is guiding you through it.
61+
* commander - The complete solution for Ruby command-line executables.
62+
63+
### Module 0x3 \| Network Kung Fu
64+
65+
* geoip - searches a GeoIP database host or IP address, returns the country, city, ISP and location.
66+
* net-ping - A ping interface. Includes TCP, HTTP, LDAP, ICMP, UDP, WMI \(for Windows\).
67+
* ruby-nmap - A Ruby interface to Nmap, the exploration tool and security / port scanner.
68+
* ronin-scanners - A library for Ronin that provides Ruby interfaces to various third-party security scanners.
69+
* net-dns - A pure Ruby DNS library, with a clean OO interface and an extensible API.
70+
* snmp - A Ruby implementation of SNMP \(the Simple Network Management Protocol\).
71+
* net-ssh - A pure-Ruby implementation of the SSH2 client protocol.
72+
* net-scp - A pure Ruby implementation of the SCP client protocol.
73+
* ftpd - A pure Ruby FTP server library. It supports implicit and explicit TLS, IPV6, passive and active mode.
74+
* packetfu - A mid-level packet manipulation library for Ruby.
75+
* packetgen - Ruby library to easily generate and capture network packets.
76+
77+
### Module 0x4 \| Web Kung Fu
78+
79+
* net-http-digest\_auth - An implementation of RFC 2617 - Digest Access Authentication.
80+
* ruby-ntlm - NTLM implementation for Ruby.
81+
* activerecord - Databases on Rails. Build a persistent domain model by mapping database tables to Ruby.
82+
* tiny\_tds - TinyTDS - A modern, simple and fast FreeTDS library for Ruby using DB-Library.
83+
* activerecord-sqlserver-adapter.
84+
* activerecord-oracle\_enhanced-adapter.
85+
* buby - a mashup of JRuby with the popular commercial web security testing tool Burp Suite from PortSwigger.
86+
* wasabi - A simple WSDL parser.
87+
* savon - Heavy metal SOAP client.
88+
* httpclient - gives something like the functionality of libwww-perl \(LWP\) in Ruby.
89+
* nokogiri - An HTML, XML, SAX, and Reader parser.
90+
* twitter - A Ruby interface to the Twitter API.
91+
* selenium-webdriver - A tool for writing automated tests of websites. It aims to mimic the behaviour of a real user.
92+
* watir-webdriver - WebDriver-backed Watir.
93+
* coffee-script - Ruby CoffeeScript is a bridge to the JS CoffeeScript compiler.
94+
* opal - Ruby runtime and core library for JavaScript.
95+
96+
**Extra gems**
97+
Useful gems to deal with web:
98+
99+
* Mechanize - a ruby library that makes automated web interaction easy.
100+
* HTTP.rb - Fast, Elegant HTTP client for ruby.
101+
* RestClient - A class and executable for interacting with RESTful web services.
102+
* httparty - Makes http fun! Also, makes consuming restful web services dead easy.
103+
* websocket - Universal Ruby library to handle WebSocket protocol.
104+
105+
### Module 0x5 \| Exploitation Kung Fu
106+
107+
* metasm - A cross-architecture assembler, disassembler, linker, and debugger.
108+
109+
### Module 0x6 \| Forensic Kung Fu
110+
111+
* metasm - A cross-architecture assembler, disassembler, linker, and debugger.
112+

‎rubyfu.png‎

26.6 KB
Loading

‎styles/ebook.css‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
/* CSS for ebook */

‎styles/epub.css‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
/* CSS for epub */

‎styles/header.js‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
window.onload = function(){
2+
$( "body" ).prepend('<div id="header" class="header absolute"><div class="wrap"><div class="clearfix" style="width:100%;"><div id="logo"><a href="https://rubyfu.net/"><img src="https://rubyfu.net/content/images/other/logo.png" class="logo_rubyfu"></a></div></div></div></div>');
3+
4+
$(".book-body .body-inner").niceScroll({cursorcolor:"#b21818"});
5+
$(".book-summary").niceScroll({cursorcolor:"#b21818"});
6+
7+
$('.fa-spin').nextAll().remove()
8+
};
9+
10+
11+
// Google Analytics
12+
(function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){
13+
(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),
14+
m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
15+
})(window,document,'script','https://www.google-analytics.com/analytics.js','ga');
16+
17+
ga('create', 'UA-88660585-1', 'auto');
18+
ga('send', 'pageview');

0 commit comments

Comments
 (0)