Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Empty file modified files/module06/packets.pcap
100644 → 100755
Empty file.
Empty file modified images/other/logo.png
100644 → 100755
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
5 changes: 5 additions & 0 deletions package.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
{
"name": "book",
"version": "0.0.0",
"dependencies": {}
}
76 changes: 76 additions & 0 deletions references.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
# References

* **Contributors**
* GitBook Desktop Editor
* [Download and installation](https://www.gitbook.com/editor)
* How to GitBook \[Videos\]
* [Create GitBook online](https://www.youtube.com/watch?v=kdpfRLpu0FQ)
* [Download and Install Gitbook package](https://www.gitbook.com/editor)
* [Create GitBook with Editor](https://www.youtube.com/watch?v=IkV2HQLAKHY)
* Markdown \[Documentations\]
* [Markdown docs - GitBook \| Official docs](http://help.gitbook.com/format/markdown.html)
* [Mastering Markdown - GitHub \| Mastering Markdown](https://guides.github.com/features/mastering-markdown/)
* **Beginner**
* [Ruby Tutorials - Tutorialspoint](http://www.tutorialspoint.com/ruby/)
* [Ruby programming Tutorials - Simple Free videos](https://www.thenewboston.com/videos.php?cat=50)
* [Lynda: Ruby Essential Training - Commercial Training](https://www.youtube.com/playlist?list=PLFI1RBqfVaOrMxWjIuFXbtGYtdmezgap3)
* [Ruby from InfiniteSkills - Commercial Training](https://www.youtube.com/playlist?list=PLFI1RBqfVaOqvspvlnwS_ECczfRXnJee2)
* [Quick Ruby syntax Cheat sheet](http://overapi.com/ruby/)
* [4Programmer.com - Ruby](http://4programmer.com/ruby)
* [Ruby Programming Tutorials - Free Video series](https://www.youtube.com/playlist?list=PLMK2xMz5H5Zv8eC8b4K6tMaE1-Z9FgSOp)
* [Ruby3arabi - Arabic Ruby community](http://ruby3arabi.com/)
* **Books**
* [Ruby Learning](http://rubylearning.com/satishtalim/tutorial.html)
* [Working with TCP Sockets](http://www.jstorimer.com/products/working-with-tcp-sockets)
* [Working with Unix Processes](http://www.jstorimer.com/products/working-with-unix-processes)
* [Working with Ruby Threads](http://www.jstorimer.com/products/working-with-ruby-threads)
* [Ruby Cookbook](http://shop.oreilly.com/product/9780596523695.do)
* [Learn Ruby The Hard Way](http://learnrubythehardway.org/book/)
* [AllRubyBooks](http://www.allrubybooks.com/)
* **Sites, Topics and Articles**
* [Rubymonk.com](https://rubymonk.com/)
* [Byte manipulation in ruby](http://www.happybearsoftware.com/byte-manipulation-in-ruby.html)
* [Ruby Format](http://www.dotnetperls.com/format)
* [Codewars](http://www.codewars.com/?language=ruby)
* [rubeque](http://www.rubeque.com/)
* [Hackerrank](https://www.hackerrank.com/)
* [RubySec - Ruby Security Advisory](http://rubysec.com/)
* [/r/ruby\_infosec](https://www.reddit.com/r/ruby_infosec)
* A dozen \(or so\) ways to start sub-processes in Ruby: \[[Part 1](https://devver.wordpress.com/2009/06/30/a-dozen-or-so-ways-to-start-sub-processes-in-ruby-part-1/), [Part 2](https://devver.wordpress.com/2009/07/13/a-dozen-or-so-ways-to-start-sub-processes-in-ruby-part-2/), [Part 3](https://devver.wordpress.com/2009/10/12/ruby-subprocesses-part_3/)\]
* **Hacking Tools built with ruby**
* Metasploit framework - Exploitation framework \[ [link](https://github.com/rapid7/metasploit-framework) \]
* Beef framework - XSS framework \[ [link](http://beefproject.com/) \]
* Arachni - Web Application scanner framework \[ [link](http://www.arachni-scanner.com/) \]
* Metasm - Assembly manipulation suite \[ [link](https://github.com/jjyg/metasm) \]
* WPscan - WordPress vulnerability scanner \[ [link](http://wpscan.org) \]
* WPXF - Wordpress Exploit Framework \[ [link](http://www.getwpxf.com/) \]
* BufferOverflow kit - Exploitation tool Kit \[ [link](https://github.com/KINGSABRI/BufferOverflow-Kit) \]
* HTTP Traceroute \[ [link](https://digi.ninja/projects/http_traceroute.php) \]
* CeWL - Custom Word List generator \[ [link](https://digi.ninja/projects/cewl.php) \]
* Roini - Vulnerability research and exploit development framework \[ [link](http://ronin-ruby.github.io/) \]
* Idb - Simplifys some common tasks for iOS pentesting & research \[ [link](https://github.com/dmayer/idb) \]
* Bettercap - Extensible MitM tool and framework \[ [link](https://www.bettercap.org/) \]
* WATOBO - The Web Application Security Toolbox \[ [link](http://watobo.sourceforge.net/) \]
* Intrigue.io - Open Source project, discovering attack surface through OSINT \[ [link](https://intrigue.io/) \]
* OhNo - The Evil Image Builder & Meta Manipulator \[ [link](https://github.com/Hood3dRob1n/OhNo) \]
* WhatWeb - Website Fingerprinter \[ [link](https://github.com/urbanadventurer/WhatWeb) \]
* Relyze - reverse engineer similar to IDA-Pro supports Ruby plugins \[ [link](https://www.relyze.com/) \]
* Capstone - multi-platform, multi-architecture disassembly framework supports Ruby \[ [link](http://www.capstone-engine.org/) \]
* Rabid - A CLI tool and library allowing to simply decode all kind of BigIP cookies \[ [link](https://github.com/noraj/rabid) \]
* Haiti - A CLI tool and library to identify the hash type of a given hash \[ [link](https://github.com/noraj/haiti) \]
* ctf-party - A library to enhance and speed up script/exploit writing for CTF players \[ [link](https://github.com/noraj/ctf-party) \]
* itdis - A small tool that allows you to check if a list of domains you have been provided is in the scope of your pentest or not. \[ [link](https://gitlab.com/noraj/itdis) \]
* nvd\_feed\_api - A simple ruby API/library for managing NVD CVE feeds. The API will help you to download and manage NVD Data Feeds, search for CVEs, build your vulnerability assessment platform or vulnerability database. \[ [link](https://gitlab.com/noraj/nvd_api) \]
* VBSmin - VBScript minifier CLI tool and library \[ [link](https://github.com/noraj/vbsmin) \]
* Fingerprinter - CMS/LMS/Library etc Versions Fingerprinter \[ [link](https://github.com/erwanlr/Fingerprinter) \]
* API-fuzzer - API Fuzzer which allows to fuzz request attributes using common pentesting techniques and lists vulnerabilities \[ [link](https://github.com/Fuzzapi/API-fuzzer) \]
* oxml\_xxe - Tool for embedding XXE/XML exploits into different filetypes \(docx/xlsx, odt/ods, svg, xml, etc.\) \[ [link](https://github.com/BuffaloWill/oxml_xxe) \]
* SSRF Proxy - Facilitates tunneling HTTP communications through servers vulnerable to SSRF \[ [link](https://github.com/bcoles/ssrf_proxy) \]
* XXEinjector - Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods \[ [link](https://github.com/enjoiz/XXEinjector) \]
* envizon - Network visualization & vulnerability management/reporting \[ [link](https://github.com/evait-security/envizon) \]
* HellRaiser - Vulnerability Scanner \[ [link](https://github.com/m0nad/HellRaiser) \]
* YASUO - A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network \[ [link](https://github.com/0xsauby/yasuo) \]
* Evil-WinRM - WinRM shell for hacking/pentesting enhanced with a lot of features \[ [link](https://github.com/Hackplayers/evil-winrm) \]
* apullo - A scanner for taking basic fingerprints \[ [link](https://github.com/ninoseki/apullo) \]
* **\[**ADD YOUR RUBY HACKING TOOL HERE!**\]**

112 changes: 112 additions & 0 deletions required-gems.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,112 @@
# Required Gems

I'd like to list all external gems that might be used in this book. This list will be updated once a new gem is required.

Note that you don't need to install them all unless you specifically need them.

## Main Gems

* Pry - An IRB alternative and runtime developer console.
* pry-doc - Pry Doc is a Pry REPL plugin. Extending documentation support for the REPL by improving the `show-doc & show-source commands.`
* pry-byebug - Combine 'pry' with 'byebug'. Adds 'step', 'next', 'finish', 'continue' and 'break' commands to control execution.

```text
gem install pry
gem install pry-doc
gem install pry-byebug
```

To run pry with best appearance

```bash
pry --simple-prompt
```

> **Note:** Most of our examples will be executed on **pry** so please consider it as main part of our environment. Otherwise, when you see `#!/usr/bin/env ruby, it means a file script to execute.`

## Module Gems

Due the demand of wrapping all required gems into one gem, we've created [hacker-gems](https://rubygems.org/gems/hacker-gems) which installs all the below gems at one time.

```text
gem install hacker-gems
```

You might need to install some packages beforehand to avoid any errors of missing libraries.

```text
sudo apt-get install build-essential libreadline-dev libssl-dev libpq5 libpq-dev libreadline5 libsqlite3-dev libpcap-dev git-core autoconf postgresql pgadmin3 curl zlib1g-dev libxml2-dev libxslt1-dev vncviewer libyaml-dev curl nmap
```

### Module 0x1 \| Basic Ruby Kung Fu

* colorize - Extends String class or add a ColorizedString with methods to set text color, background.

### Module 0x2 \| System Kung Fu

* virustotal - A script for automating virustotal.com queries.
* uirusu - A tool and REST library for interacting with Virustotal.org.
* clipboard - Lets you access the clipboard on Linux, MacOS, Windows, and Cygwin.

**Extra gems**

Useful gems to build command line applications

* tty-prompt - A beautiful and powerful interactive command line prompt.
* Thor - Create a command-suite app simply and easily, as well as Rails generators.
* GLI - Create awesome, polished command suites without a lot of code.
* Slop - Create simple command-line apps with a syntax similar to trollop.
* Highline - handle user input and output via a “Q&A” style API, including type conversions and validation.
* Escort - A library that makes building command-line apps in ruby so easy, you’ll feel like an expert is guiding you through it.
* commander - The complete solution for Ruby command-line executables.

### Module 0x3 \| Network Kung Fu

* geoip - searches a GeoIP database host or IP address, returns the country, city, ISP and location.
* net-ping - A ping interface. Includes TCP, HTTP, LDAP, ICMP, UDP, WMI \(for Windows\).
* ruby-nmap - A Ruby interface to Nmap, the exploration tool and security / port scanner.
* ronin-scanners - A library for Ronin that provides Ruby interfaces to various third-party security scanners.
* net-dns - A pure Ruby DNS library, with a clean OO interface and an extensible API.
* snmp - A Ruby implementation of SNMP \(the Simple Network Management Protocol\).
* net-ssh - A pure-Ruby implementation of the SSH2 client protocol.
* net-scp - A pure Ruby implementation of the SCP client protocol.
* ftpd - A pure Ruby FTP server library. It supports implicit and explicit TLS, IPV6, passive and active mode.
* packetfu - A mid-level packet manipulation library for Ruby.
* packetgen - Ruby library to easily generate and capture network packets.

### Module 0x4 \| Web Kung Fu

* net-http-digest\_auth - An implementation of RFC 2617 - Digest Access Authentication.
* ruby-ntlm - NTLM implementation for Ruby.
* activerecord - Databases on Rails. Build a persistent domain model by mapping database tables to Ruby.
* tiny\_tds - TinyTDS - A modern, simple and fast FreeTDS library for Ruby using DB-Library.
* activerecord-sqlserver-adapter.
* activerecord-oracle\_enhanced-adapter.
* buby - a mashup of JRuby with the popular commercial web security testing tool Burp Suite from PortSwigger.
* wasabi - A simple WSDL parser.
* savon - Heavy metal SOAP client.
* httpclient - gives something like the functionality of libwww-perl \(LWP\) in Ruby.
* nokogiri - An HTML, XML, SAX, and Reader parser.
* twitter - A Ruby interface to the Twitter API.
* selenium-webdriver - A tool for writing automated tests of websites. It aims to mimic the behaviour of a real user.
* watir-webdriver - WebDriver-backed Watir.
* coffee-script - Ruby CoffeeScript is a bridge to the JS CoffeeScript compiler.
* opal - Ruby runtime and core library for JavaScript.

**Extra gems**
Useful gems to deal with web:

* Mechanize - a ruby library that makes automated web interaction easy.
* HTTP.rb - Fast, Elegant HTTP client for ruby.
* RestClient - A class and executable for interacting with RESTful web services.
* httparty - Makes http fun! Also, makes consuming restful web services dead easy.
* websocket - Universal Ruby library to handle WebSocket protocol.

### Module 0x5 \| Exploitation Kung Fu

* metasm - A cross-architecture assembler, disassembler, linker, and debugger.

### Module 0x6 \| Forensic Kung Fu

* metasm - A cross-architecture assembler, disassembler, linker, and debugger.

Binary file added rubyfu.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
1 change: 1 addition & 0 deletions styles/ebook.css
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
/* CSS for ebook */
1 change: 1 addition & 0 deletions styles/epub.css
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
/* CSS for epub */
18 changes: 18 additions & 0 deletions styles/header.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
window.onload = function(){
$( "body" ).prepend('<div id="header" class="header absolute"><div class="wrap"><div class="clearfix" style="width:100%;"><div id="logo"><a href="https://rubyfu.net/"><img src="https://rubyfu.net/content/images/other/logo.png" class="logo_rubyfu"></a></div></div></div></div>');

$(".book-body .body-inner").niceScroll({cursorcolor:"#b21818"});
$(".book-summary").niceScroll({cursorcolor:"#b21818"});

$('.fa-spin').nextAll().remove()
};


// Google Analytics
(function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){
(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),
m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
})(window,document,'script','https://www.google-analytics.com/analytics.js','ga');

ga('create', 'UA-88660585-1', 'auto');
ga('send', 'pageview');
Loading