Skip to content

Latest commit

 

History

35 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

PenHub - Web-Based Pentesting Toolkit

PenHub - Pentesting Toolkit License: MIT Platform: Web

PenHub is a comprehensive, browser-based penetration testing toolkit designed for security professionals, CTF players, and ethical hackers. This all-in-one web interface provides instant access to essential commands, post-exploitation techniques, payload generators, and network pivoting tools. all without requiring local installation or dependencies.

Access PenHub at: https://penhub.netlify.app

PenHub Demo


🚀 Recent Updates (2026-03-03)

Newly Implemented

  • HashKit Suite:
    • Advanced Hash Identifier: Massive expansion to 100+ patterns spanning database (MySQL/PostgreSQL), networking (Cisco/FortiGate), and filesystem hashes (LUKS/RAR).
    • Multi-Algorithm Generator: Production-grade generator supporting 30+ algorithms (SHA-3, BLAKE2, RIPEMD, etc.) with organized categorized output.
    • Encoding Intelligence: Integrated detection for Base64, Hex, URL-encoded, Binary, and Unicode character sets.
    • Bidirectional Processor: Fully overhauled encoder/decoder with intuitive flow and unlocked output fields for seamless data manipulation.
  • Advanced Exploitation Repository:
    • Global Payload Expansion: All vulnerability categories (XSS, SQLi, LFI, RCE, etc.) expanded to 200+ high-quality, production-grade payloads.
    • Bulk Export Utility: New system to copy entire payload categories with a single click for efficient tool-chaining.
  • Refreshed CTF & Cryptography Toolkit:
    • Fixed Cryptography Engines: Completely overhauled Vigenère engine ensuring perfect accuracy for encryption and decryption tasks.
    • ROT Brute-Force Suite: Professionally rebranded and optimized Caesar cipher analysis tools for technical accuracy.
  • Automated Recon Dashboard:
    • Enhanced Command Orchestration: Refined command generation templates with advanced parameter handling for systematic reconnaissance.

🌟 Core Features

  1. Interactive Commands Generator

    Dynamic Command Templates: Real-time generation of penetration testing commands with customizable parameters

    Comprehensive Tool Coverage:

     Network scanning (Nmap)
    
     Directory/enumeration tools (Gobuster, Feroxbuster)
    
     Vulnerability scanners (Nuclei, Nikto)
    
     Password attacks (Hydra, John, Hashcat)
    
     SQL injection (SQLMap)
    
     Reverse shells (multiple languages)
    
     File transfer methods
    

    Smart Parameter System: Configure once, automatically updates all related commands

    One-Click Copy: Direct clipboard integration for immediate use

  2. Post-Exploitation Cheatsheet

    Dual-Platform Coverage: Extensive Linux and Windows post-exploitation techniques

    Systematic Methodology:

     Step-by-step system reconnaissance
    
     Privilege escalation (SUID/SGID, sudo exploits, kernel vulnerabilities)
    
     Credential discovery and extraction
    
     File transfer techniques
    
     Persistence mechanisms
    

    Intelligent Search: Quick filtering across all commands and techniques

    Platform Toggle: Seamlessly switch between Linux and Windows environments

  3. Image Payload Generator

    Stealthy Payload Delivery: Embed malicious code within legitimate image files

    Multiple Payload Types:

     Reverse shells (PHP, Python, Bash)
    
     Command execution
    
     Web shells
    
     Custom payloads
    

    File Format Support: JPG, PNG, GIF, BMP

    Technique Documentation: Includes file extension bypass, magic bytes manipulation, and polyglot file creation

  4. Port Forwarding & Pivoting Toolkit

    Multi-Tool Support: Ligolo-ng, Chisel, SSH tunneling, Socat

    Visual Configuration: Interactive parameter setup with network diagrams

    Step-by-Step Guides: Complete setup instructions for each tool

    Real-time Command Generation: Commands update dynamically as you configure parameters

    Network Flow Visualization: Clear representations of pivoting scenarios

🎯 Target Audience

Penetration Testers: Quick reference for common commands during engagements

CTF Players: Fast access to enumeration and exploitation techniques

Security Researchers: Template for building custom payloads and pivots

OSCP/PNPT Students: Comprehensive cheatsheet for exam preparation

Red Teamers: All-in-one toolkit for operational workflows

Security Educators: Teaching tool for penetration testing methodologies

🔒 Legal & Ethical Use

IMPORTANT: PenHub is designed strictly for:

✅ Authorized security assessments and penetration tests

✅ CTF competitions and legal hacking challenges

✅ Educational purposes in controlled environments

✅ Security research with proper authorization

STRICTLY PROHIBITED:

❌ Unauthorized penetration testing

❌ Illegal hacking activities

❌ Attacks against systems without explicit permission

❌ Violating laws, regulations, or terms of service

Disclaimer: The author assumes no responsibility for misuse of this tool. Always obtain proper written authorization before testing any system. Users are solely responsible for ensuring their activities comply with applicable laws and regulations. 🧩 Integration with Workflows With Your Security Environment

Bookmark PenHub in your browser for quick access during engagements

Use alongside professional tools like Burp Suite, Metasploit, and CrackMapExec

Reference during assessments without disrupting your workflow

🐛 Troubleshooting Common Issues

JavaScript Not Working: Ensure JavaScript is enabled in your browser settings

Commands Not Updating: Refresh the page and ensure all required fields are filled

Layout Issues: Use Chrome 80+, Firefox 75+, or Edge 80+ for optimal experience

Mobile Experience: Desktop browsers recommended for full functionality

🔄 Updates & Roadmap Current Version: v1.1

Initial release with core functionality

Four main modules: Commands, Cheatsheet, Payloads, Pivoting

Planned Features

Export functionality for reports

Additional tool integrations

Community command contributions

Reporting Issues

Use GitHub Issues to report:

Bugs or unexpected behavior

Missing tools or techniques

Feature requests and suggestions

🙏 Acknowledgments

Inspired by various pentesting cheatsheets and community resources

Contributions from security researchers worldwide

Special thanks to open-source tool developers (Nmap, Gobuster, Nuclei, etc.)

OSCP/PNPT community for methodology and techniques

Everyone who tests, uses, and provides feedback

📄 License

MIT License - See LICENSE file for complete details.

Built with ❤️ by 0x8e8fb for the security community

Remember: With great power comes great responsibility. Always hack ethically.

About

PenHub - Web-Based Pentesting Toolkit

Topics

Resources

Stars

2 stars

Watchers

1 watching

Forks

Contributors