Operator guides

Tips & tricks

Full writeups grown from the Community tip cards — nmap, Burp, Wireshark, msfconsole, aircrack-ng, Hydra, sqlmap, john, hashcat, ffuf. Ethical / authorized targets only.

16 guides
nmap · easy

Scripts + versions without -A

Prefer nmap -sC -sV -p- over blind -A. Faster feedback, less noise, same intel on most labs.

Open guide →
nmap · easy

Host discovery first

On a flat lab net: nmap -sn 10.10.0.0/24 then target live hosts. Skip -Pn until you know ICMP is blocked.

Open guide →
burp · med

Match and replace

Proxy → Match and replace: auto-fix a header or cookie across Repeater/Intruder. Stop hand-editing the same byte 40 times.

Open guide →
burp · easy

Logger++ / Logger tab

Keep a full history of proxied traffic. When a bug reproduces once, your scrollback is the writeup backbone.

Open guide →
wireshark · easy

HTTP POSTs only

Display filter: http.request.method == "POST". Combine with ip.addr== your lab target.

Open guide →
wireshark · easy

Follow the stream

Right-click → Follow → TCP/HTTP Stream. Rebuild the conversation instead of squinting at frames.

Open guide →
msfconsole · med

search + info before exploit

search type:exploit apache then info / show options. Set RHOSTS, check required options, then run. Labs love patience.

Open guide →
msfconsole · med

Workspaces keep you honest

workspace -a lab-oslo isolates hosts/loot per engagement. Don't mix client A with Friday CTF notes.

Open guide →
aircrack-ng · hard

Own AP / own handshake

Capture and crack only networks you own or are contracted to test. Lab kit + isolated AP = education. Neighbour's SSID = crime.

Open guide →
aircrack-ng · med

airmon-ng check kill

Kill NetworkManager interference before monitor mode. Remember to restart networking after the lab session.

Open guide →
hydra · med

Throttle or get banned

Use -t 4 and respect lockouts. Against production without written scope: don't. Against your lab: still be nice to the logs.

Open guide →
sqlmap · med

Level/risk deliberately

Start low: default level/risk, then climb. Add --tamper only when a WAF actually blocks. Always --batch in labs you own.

Open guide →
sqlmap · hard

Dump with intent

--tables / --columns before --dump. Know what you're extracting and why it is in scope.

Open guide →
john · easy

Format detection

john --list=formats | rg -i sha then --format= explicitly. Wrong format = silent sadness.

Open guide →
hashcat · med

Mode numbers matter

Example: -m 1000 NTLM, -m 1800 sha512crypt. Check the example hashes wiki before burning GPU time.

Open guide →
ffuf · med

Filter smart

ffuf -u URL/FUZZ -w wordlist -mc 200,204,301,302,403 -fs <size> to drop boring catch-all responses.

Open guide →