Important Pentest Tools You must Check

PowerUpSQL• SysInternals• Donut• Chisel• Powermad• Burpsuite• Metasploit• Powershell-Suite• Rubeus• Fuzzdb• gobuster• Acunetix• Nessus• Cobalt Strike• PowerSploit• Impacket• PingCastle• Process Hacker• Hashcat• John the Ripper• Hydra• Aircrack-ng• Burpsuite• Metasploit•Lair – Reactive attack collaboration framework and web application built with meteor.•Pentest Collaboration Framework (PCF) – Open source, cross-platform, and portable toolkit for automating routine pentest processes with a team.•peda –… Continue reading Important Pentest Tools You must Check

Web Application Penetration Testing – Training

Web Application Penetration Testing Phase 1 – History History of Internet – https://www.youtube.com/watch?v=9hIQjrMHTv4 Phase 2 – Web and Server Technology   Basic concepts of web applications, how they work and the HTTP protocol – https://www.youtube.com/watch?v=RsQ1tFLwldY&t=7s HTML basics part 1 – https://www.youtube.com/watch?v=p6fRBGI_BY0 HTML basics part 2 – https://www.youtube.com/watch?v=Zs6lzuBVK2w Difference between static and dynamic website – https://www.youtube.com/watch?v=hlg6q6OFoxQ… Continue reading Web Application Penetration Testing – Training

OSINT and Ephemeral exposures

OSINT and Ephemeral Cloud Native exposures Tools Attack Surface Mapper – https://www.blackhat.com/us-19/arsenal/schedule/index.html#attack-surface-mapper-automate-and-simplify-the-osint-process-16713 Public Cloud Security – https://cloudsploit.com/github https://sysdig.com/ https://www.twistlock.com/ Upguard – https://www.itnews.com.au/news/data-from-nokias-interception-kit-for-russian-telcos-exposed-531186  

Published
Categorised as PenTesting

Penetration Testing

Penetration Testing Advice on how to get the most from penetration testing https://www.ncsc.gov.uk/guidance/penetration-testing Penetration testing is a core tool for analysing the security of IT systems, but it’s not a magic bullet. This guidance will help you understand the proper commissioning and use of penetration tests. It will also help you to plan your routine… Continue reading Penetration Testing

OSCP Intro Letter

  OSCP Intro Letter Dear Applicant,Thank you for your interest in Penetration Testing with Kali Linux. Please read this entire email carefully as it contains very important information. Course Prerequisites To be successful, you must have basic Linux skills – meaning you need to be able to navigate through the Linux filesystem, run simple commands,… Continue reading OSCP Intro Letter

Bug Bounties

Bug Bounties HackerOne Bugcrowd https://yeswehack.com/programs https://www.vulnmachines.com/ Vulnerability Lab Fire Bounty https://www.hackthebox.eu/ https://tryhackme.com/signup Bug Bounty Methodologies https://www.linkedin.com/posts/hackingarticles_bug-hunting-methodology-activity-6731105184459571201-1qJB Targets Web/API Mobile App/API Tools Selenium Testing http://webbreaker.io/ Automation https://www.jhaddix.com/post/the-secrets-of-automation-kings-in-bug-bounty Companies Microsoft – https://msrc-blog.microsoft.com/2019/08/05/azure-security-lab-a-new-space-for-azure-research-and-collaboration/ DOD – Apple Spotify

Published
Categorised as PenTesting

PenTesting / Scanning Cached/Load Balanced Targets

PenTesting / Scanning Cached/Load Balanced Targets   As part of the PCI Certification process, external facing application that are in scope of the PCI environment require a PCI ASV scan. If these external facing applications are using load balancing and/or caching, please be aware of the following; (Examples of Load Balancers include; F5 LTM, AWS… Continue reading PenTesting / Scanning Cached/Load Balanced Targets

Published
Categorised as PenTesting

Mailware analysis

Mailware analysis Debuggers – gdb, WinDBG, OllyDBG Operating System Primer – https://www.slideshare.net/saumilshah/operating-systems-a-primer How functions work – https://www.slideshare.net/saumilshah/how-functions-work-7776073 Introduction to Debuggers – https://www.slideshare.net/saumilshah/introduction-to-debuggers Return Oriented Programming – https://www.slideshare.net/saumilshah/dive-into-rop-a-quick-introduction-to-return-oriented-programming https://www.winitor.com/ RawDisk – https://www.eldos.com/rawdisk/ Cuckoo – https://cuckoosandbox.org/

Published
Categorised as PenTesting

PenTesting Methodology

PenTesting Methodology F3EAD Model Find: essentially ‘picking up the scent’ of the opponent, with the classic “Who, What, When, Where, Why” questions being used within this phase to identify a candidate target Fix: verification of the target(s) identified within the previous phase, which typically involves multiple triangulation points. This phase effectively transforms the intelligence gained within the… Continue reading PenTesting Methodology

Published
Categorised as PenTesting

Kali Cheatsheet

Kali Cheatsheet The following is a list of improvements to the Kali distro to turbo charge your Pen Test tool kit.. Kali VM Username and Password: kali/kali Fresh Install Setup Kali on AWS – https://www.alienvault.com/blogs/security-essentials/configuring-kali-linux-on-amazon-aws-cloud-for-free Use Generation 1 in Hyper-V Install VM Guest Tools https://www.kali.org/docs/virtualization/install-vmware-guest-tools/ sudo su sudo apt-get install asciinema asciinema rec / exit lsb_release… Continue reading Kali Cheatsheet