← Sızma Testi & Kırmızı Takım

Penetration Testing

Kategori: Sızma Testi & Kırmızı Takım · Sayfa: 31

Penetration Testing başlıklı teknik kaynağın içeriği, sızma testi & kırmızı takım alanında pratik bilgiler sunmaktadır. Aşağıda belgeden hareketle hazırlanan teknik inceleme yer almaktadır.

Genel Bakış

1 Penetration Testing Methodology --------------------------------------------------------------------------------- Prepared By / Mohamed Nabil Diab https://www.linkedin.com/in/mohamed-nabil-diab/ --------------------------------------------------------------------------------- Content 1....

Temel Kavramlar

Information Gathering • OSINT & Public resources • Host Discovery • Port Scanning • Services & OS Detection 2....

Teknik Uygulama

Enumeration • Service Enumeration 3....

Örnek Senaryo

Vulnerability Assessment • Detect Vulnerable Services • Search for Relative Exploits 4....

Dikkat Edilmesi Gerekenler

Exploitation • Starting MSF • Windows Exploitation • Linux Exploitation • Network Exploitation 5....

Özet

Post Exploitation • Pre Post Exploitation • Windows Post Exploitation • Linux Post Exploitation 6....

Bölüm 7

Web Application Pen testing 2 Passive Information Gathering Description Syntax Type Tool بتعملname resolution $ host command host بيحتوي على web pages domain/robots.txt domain/sitemap.xml web-file web-file robots.txt sitemap.xml معلومات وتواريخ وعناوين وأرقام و Ip addresses $ whois www.who.is www.netcraft.com command website website Whois Who.is netcraft DNS records Name servers DNS info $ dnsrecon https://dnsdumpster.com $ dnsenum command website command dnsrecon dnsdumpster dnsenum بتتشك لو فيه firewall $ wafw00f command wafw00f بتبحث عن subdomains $ sublist3r command sublist3r directory navigation $ dirb command dirbuster بتبحث عن emails $ theHarvester Command theHarvester بتتشك لوemail مخترق او له تسريب www.haveibeenpwned.com website haveibeenpwned Scan the LAN $ netdiscover -i -r command Netdiscover بتعمل كل حاجة $nmap -options command nmap 3 Nmap Usage a) Host Discovery • -sn ➔ default scan, disable port scanning....

Bölüm 8

b) Scanning Types • -sS ➔ TCP SYN scan....

Bu makale "Penetration Testing" kaynağından üretilmiştir. Tam metin ve orijinal doküman /root/pdf klasöründe mevcuttur. İçerik eğitim amaçlıdır.

← Kategoriye dön