Hacker News new | past | comments | ask | show | jobs | submit login

I agree most of these are obvious noise, maybe useful for CTF contests where these scenarios actually happen and you want a dictionary..?

This one surprised me, though: https://gtfobins.github.io/gtfobins/whois/

I found the whois example interesting from a "huh, didn't realize whois let you do that" perspective, but... again, found it kinda pointless. If `nc` is on the box, then you don't need whois to send files around... you can just use `nc` to do it.

nc is used on the attacker box, not on the box where whois is run.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
