Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

Pentesting-for-Beginners

2. Requirements & LAB Setups

  • Introduction
  • Download Files
  • Installation
  • Kali Changes

3. Linux - Basics

  • Part 1: Basic Commands
  • Permissions: Relative
  • Permissions: Absolute
  • Sudo Users
  • APT Commands

4. Networking

  • Routers and Switches
  • IP Address
  • DHCP
  • MAC Address
  • Services and Ports
  • Apache Service
  • Bridged and NAT
  • DNS
  • TCP vs UDP
  • Port Forwarding

5. Information Gathering

  • Introduction to Recon
  • Active Recon & Passive Recon
  • OSINT
  • Google Hacking
  • Shodan

6. Sniffing Attacks

  • What are Sniffing Attacks?
  • ARP Broadcasting
  • MITM (Man-in-the-Middle)
  • ARP Poisoning
  • MAC Address Spoofing
  • Wireshark Sniffing

7. Nmap

  • What is Nmap
  • Target Specification
  • Host Discovery
  • Scan Techniques: TCP
  • Scan Techniques: UDP
  • Port Specification
  • Service & Version Detection
  • OS Detection
  • Default Scripts
  • Output Save
  • Timing and Performance

8. Enumeration

  • FTP
  • MySQL
  • SMB
  • SMTP
  • VNC
  • Web

9. Reverse Shell

  • What is a Reverse Shell?
  • Netcat Introduction
  • Netcat Bind Shell
  • Reverse Shell Alternatives
  • Real-Time Reverse Shell Access

10. Exploitation

  • Introduction
  • Remote Exploits
  • Local Exploits

11. File Transfers

  • File Transfer Introduction
  • HTTP File Transfer
  • PowerShell
  • FTP
  • SMB

12. Privilege Escalation (PrivEsc)

  • What is Privilege Escalation?
  • SUID - Linux
  • Jump User using su
  • Sudo Abuse

13. Password Attacks

  • Password Attack Introduction
  • Wordlist Location
  • What is Hashing?
  • Hash Identifier
  • Crack Hashes Using John and Hashcat
  • Nmap Brute Force
  • CUPP Password Generator

14. Metasploit

  • Metasploit Introduction
  • Auxiliary Basics
  • Password Brute Force
  • What is a Payload?
  • Single Payload Demo
  • Staged Payload Demo
  • Other MSF Payloads with Platforms

15. Social Engineering

  • Introduction to Social Engineering
  • Phishing with SEToolkit

16. Web Application Pentesting

  • Introduction
  • OWASP Juice Shop Installation
  • Burp Suite Introduction
  • Recon Introduction
  • Tech Detection
  • Directory Brute Forcing (Manual & Automated)
  • Subdomain Enumeration
  • Improper Input Validation
  • Sensitive Data Exposure
  • Security Misconfiguration (Error Handling)
  • Outdated Whitelists - Unvalidated Redirection
  • Brute Forcing on Login Pages
  • Admin Account SQL Injection
  • Unrestricted File Upload
  • Admin Registration
  • Broken Access Control
  • SQL Injection Introduction
  • SQLMap
  • XSS - HTML
  • CSRF Attack
  • LFI

About

No description, website, or topics provided.

Resources

Stars

7 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors