finds.dev← search

// the find

JohnHammond/ctf-katana

★ 2,928 · updated May 2023

This repository aims to hold suggestions (and hopefully/eventually code) for CTF challenges. The "project" is nicknamed Katana.

A single long README listing tools and one-liners for CTF categories — SMB/enum, steganography, classic crypto attacks, PHP magic hashes, web and forensics tricks. It's a personal cheat-sheet from John Hammond, useful for people doing HackTheBox-style challenges or just starting out in CTFs who don't yet have these commands memorized.

The breadth is genuinely useful as a quick-reference index — things like the PHP magic hash table, the RSA attack checklist (Wiener, Boneh-Durfee, small-e cube root), and the stego tool list (zsteg, stegseek, stepic) save you a search when you're mid-challenge. Commands are given as copy-pasteable one-liners with the actual flags, not just tool names. It links out to the author's follow-up project (`katana`) which actually automates some of this instead of leaving it manual forever.

There's no code in this repo at all — it's one giant markdown file, so 'repository' is a stretch; it's really a gist that outgrew itself. Content hasn't been meaningfully touched since 2018 despite the 2023 last push, and several entries are already stale (SMB1-by-default smbclient warnings, old enum4linux, dead links like domnit.org/stepic). No structure beyond a table of contents — no tagging, no search, no way to contribute a fix without a huge diff to one file. It also stopped being the active project; the author explicitly points people to `katana` for anything beyond copy-pasting commands, so this is a frozen artifact rather than a maintained resource.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →