Brute Force - CheatSheet

Default Credentials
Create your own Dictionaries
Crunch
Cewl
Wordlists

Services
AFP
AJP
AMQP (ActiveMQ, RabbitMQ, Qpid, JORAM and Solace)
Cassandra
CouchDB
Docker Registry
Elasticsearch
FTP
HTTP Generic Brute
HTTP Basic Auth
HTTP - NTLM
HTTP - Post Form
HTTP - CMS -- (W)ordpress, (J)oomla or (D)rupal or (M)oodle
IMAP
IRC
ISCSI
JWT
LDAP
MQTT
Mongo
MSSQL
MySQL
OracleSQL
POP
PostgreSQL
PPTP
RDP
Redis
Rexec
Rlogin
Rsh
Rsync
RTSP
SFTP
SNMP
SMB
SMTP
SOCKS
SQL Server
SSH
Weak SSH keys / Debian predictable PRNG
STOMP (ActiveMQ, RabbitMQ, HornetQ and OpenMQ)
Telnet
VNC
Winrm

Local
Online cracking databases
ZIP
Known plaintext zip attack
7z
PDF
PDF Owner Password
JWT
NTLM cracking
Keepass
Keberoasting
Lucks image
Method 1
Method 2
Mysql
PGP/GPG Private key
Cisco

DPAPI Master Key
Open Office Pwd Protected Column
PFX Certificates

Tools
Hash-identifier
Wordlists
Wordlist Generation Tools
John mutation
Hashcat
Hashcat attacks
Hashcat modes

Last updated

