Skill 详情
hacking fundamentals
Direct foundational cybersecurity and ethical-hacking concepts.
使用前先检查
自动化审核只检查相关性,不代表安全审查或推荐。使用前请阅读来源中的说明。
SKILL.md
这段内容是审核时保存的快照。外部来源才是完整且最新的版本。
--- name: Hacking Fundamentals description: This skill should be used when the user asks to "understand hacking basics", "learn about hacker types", "understand network protocols", "learn DNS concepts", "understand attack types", or "explore security tool categories". It provides foundational cybersecurity knowledge. version: 1.0.0 tags: [hacking, fundamentals, networking, DNS, protocols, attacks] --- # Hacking Fundamentals ## Purpose Provide foundational knowledge of hacking concepts, network protocols, attack methodologies, and security tools. This skill covers essential theory for aspiring penetration testers and security professionals including network architecture, DNS operations, attack classifications, and tool categories. ## Prerequisites ### Required Knowledge - Basic computer literacy - Understanding of operating systems - Familiarity with command-line interfaces ### Recommended Background - Networking concepts - TCP/IP fundamentals - Basic security awareness ## Outputs and Deliverables 1. **Conceptual Understanding** - Hacking terminology and classifications 2. **Network Knowledge** - Protocol and architecture comprehension 3. **Attack Recognition** - Active and passive attack identification 4. **Tool Familiarity** - Security tool categories and applications ## Core Workflow ### Phase 1: Hacker Classifications Understanding hacker types and motivations: **White Hat Hackers** - Ethical hackers and security professionals - Perform authorized penetration testing - Work to improve organizational security - Also called: penetration testers, sneakers, red teams **Black Hat Hackers** - Malicious actors seeking unauthorized access - Breach systems for profit or damage - Also known as crackers - Target selection: reconnaissance → information gathering → attack **Grey Hat Hackers** - Operate between ethical and malicious - May act illegally with good intentions - Often disclose vulnerabilities publicly - Not motivated by personal gain **Other Categories** - **Blue Hat**: External consultants testing systems pre-launch - **Elite Hackers**: Highly skilled, discover zero-days - **Script Kiddies**: Use pre-made tools without understanding - **Hacktivists**: Politically or socially motivated - **Nation State**: Government-sponsored cyber operatives ### Phase 2: Network Fundamentals Understanding network types and architecture: **Network Types** | Type | Description | |------|-------------| | LAN | Local Area Network - computers in same building | | WAN | Wide Area Network - geographically distributed | | MAN | Metropolitan Area Network - city-wide coverage | | VPN | Virtual Private Network - encrypted tunnel | | Intranet | Private internal company network | | Extranet | Extended intranet for external partners | **Network Benefits for Attackers** - Resource sharing creates attack surfaces - File sharing enables data exfiltration - Program sharing may expose vulnerabilities - Centralized services create single points of failure ### Phase 3: Protocol Understanding Key protocols for security assessment: **IP Addressing** ```bash # Private IP ranges (non-routable) 10.0.0.0 - 10.255.255.255 # Class A 172.16.0.0 - 172.31.255.255 # Class B 192.168.0.0 - 192.168.255.255 # Class C # Find your IP ipconfig /all # Windows ip addr # Linux curl ifconfig.me # Public IP ``` **Common Protocols** | Protocol | Port | Purpose | |----------|------|---------| | FTP | 20, 21 | File transfer | | SSH | 22 | Secure remote access | | Telnet | 23 | Unencrypted remote access | | SMTP | 25 | Email transmission | | DNS | 53 | Name resolution | | HTTP | 80 | Web traffic | | POP3 | 110 | Email retrieval | | IMAP | 143 | Email access | | HTTPS | 443 | Encrypted web traffic | | RDP | 3389 | Windows remote desktop | **SSH Capabilities** - Secure encrypted remote login - Protection against IP spoofing - Port forwarding/tunneling - Replacement for rlogin, rsh, rcp ``在 GitHub 阅读完整来源 (打开外部页面)