Credential Hunting
Files
Configuration Files
cry0l1t3@unixclient:~$ for l in $(echo ".conf .config .cnf");do echo -e "\nFile extension: " $l; find / -name *$l 2>/dev/null | grep -v "lib\|fonts\|share\|core" ;donecry0l1t3@unixclient:~$ for i in $(find / -name *.cnf 2>/dev/null | grep -v "doc\|lib");do echo -e "\nFile: " $i; grep "user\|password\|pass" $i 2>/dev/null | grep -v "\#";doneDatabases
cry0l1t3@unixclient:~$ for l in $(echo ".sql .db .*db .db*");do echo -e "\nDB File extension: " $l; find / -name *$l 2>/dev/null | grep -v "doc\|lib\|headers\|share\|man";doneNotes
Scripts
Cronjobs
SSH Keys
Private Keys
Public Keys
History
Bash History
Logs
Memory and Cache
Mimipenguin (requires root)
LaZagne
Browsers
Firefox Stored Credentials
Decrypting Firefox Stored Credentials
Using LaZagne
Last updated