Core Path
48% OFF
Core Path
HAK 2
OSCP + CPTS
Advanced practical path for learners preparing for OSCP/CPTS-style methodology, reporting, labs, and job readiness.
- Structured practical learning path
- Bangla explanations with hands-on guidance
- Designed for ethical and legal skill building
Module Outline
Course Syllabus
01 CPTS Syllabus Hack The Box CPTS Syllabus 28 chapters
01 Penetration Testing Process Penetration Testing Process module 140 topics Module 1
-
1.1
Introduction to the Penetration Tester Path 3 topics-
1.1.1HTB Academy Learning Philosophy
-
1.1.2Ethical and Legal Considerations
-
1.1.3Penetration Tester Path Syllabus
-
-
1.2
Academy Modules Layout 8 topics-
1.2.1
Pre-Engagement 9 topics-
1.2.1.1Learning Process
-
1.2.1.2Linux Fundamentals
-
1.2.1.3Windows Fundamentals
-
1.2.1.4Introduction to Networking
-
1.2.1.5Introduction to Web Applications
-
1.2.1.6Web Requests
-
1.2.1.7JavaScript Deobfuscation
-
1.2.1.8Introduction to Active Directory
-
1.2.1.9Getting Started
-
-
1.2.2
Information Gathering 4 topics-
1.2.2.1Network Enumeration with Nmap
-
1.2.2.2Footprinting
-
1.2.2.3Information Gathering - Web Edition
-
1.2.2.4OSINT: Corporate Recon
-
-
1.2.3
Vulnerability Assessment 4 topics-
1.2.3.1Vulnerability Assessment
-
1.2.3.2File Transfers
-
1.2.3.3Shells & Payloads
-
1.2.3.4Using the Metasploit-Framework
-
-
1.2.4
Exploitation 15 topics-
1.2.4.1Password Attacks
-
1.2.4.2Attacking Common Services
-
1.2.4.3Pivoting, Tunneling & Port Forwarding
-
1.2.4.4Active Directory Enumeration & Attacks
-
1.2.4.5Web Exploitation
-
1.2.4.6Using Web Proxies
-
1.2.4.7Attacking Web Applications with Ffuf
-
1.2.4.8Login Brute Forcing
-
1.2.4.9SQL Injection Fundamentals
-
1.2.4.10SQLMap Essentials
-
1.2.4.11Cross-Site Scripting (XSS)
-
1.2.4.12File Inclusion
-
1.2.4.13Command Injections
-
1.2.4.14Web Attacks
-
1.2.4.15Attacking Common Applications
-
-
1.2.5
Post-Exploitation 2 topics-
1.2.5.1Linux Privilege Escalation
-
1.2.5.2Windows Privilege Escalation
-
-
1.2.6Lateral Movement
-
1.2.7
Proof-of-Concept 1 topic-
1.2.7.1Introduction to Python 3
-
-
1.2.8
Post-Engagement 2 topics-
1.2.8.1Documentation & Reporting
-
1.2.8.2Attacking Enterprise Networks
-
-
-
1.3
Academy Exercises & Questions 3 topics-
1.3.1The Goal
-
1.3.2Asking for Help
-
1.3.3Words of Wisdom
-
-
1.4
Penetration Testing Overview 4 topics-
1.4.1
Risk Management 1 topic-
1.4.1.1Vulnerability Assessments
-
-
1.4.2
Testing Methods 2 topics-
1.4.2.1External Penetration Test
-
1.4.2.2Internal Penetration Test
-
-
1.4.3Types of Penetration Testing
-
1.4.4Types of Testing Environments
-
-
1.5
Laws and Regulations 6 topics-
1.5.1USA
-
1.5.2Europe
-
1.5.3UK
-
1.5.4India
-
1.5.5China
-
1.5.6Precautionary Measures during Penetration Tests
-
-
1.6
Penetration Testing Process 2 topics-
1.6.1
Penetration Testing Stages 8 topics-
1.6.1.1Pre-Engagement
-
1.6.1.2Information Gathering
-
1.6.1.3Vulnerability Assessment
-
1.6.1.4Exploitation
-
1.6.1.5Post-Exploitation
-
1.6.1.6Lateral Movement
-
1.6.1.7Proof-of-Concept
-
1.6.1.8Post-Engagement
-
-
1.6.2Importance
-
-
1.7
Pre-Engagement 5 topics-
1.7.1Scoping Questionnaire
-
1.7.2
Pre-Engagement Meeting 2 topics-
1.7.2.1Contract - Checklist
-
1.7.2.2Rules of Engagement - Checklist
-
-
1.7.3Kick-Off Meeting
-
1.7.4
Contractors Agreement 1 topic-
1.7.4.1Contractors Agreement - Checklist for Physical Assessments
-
-
1.7.5
Setting Up 1 topic-
1.7.5.1Questions
-
-
-
1.8
Information Gathering 5 topics-
1.8.1
Open-Source Intelligence 1 topic-
1.8.1.1Private and Public SSH Keys
-
-
1.8.2Infrastructure Enumeration
-
1.8.3Service Enumeration
-
1.8.4Host Enumeration
-
1.8.5Pillaging
-
-
1.9
Vulnerability Assessment 3 topics-
1.9.1Vulnerability Research and Analysis
-
1.9.2Assessment of Possible Attack Vectors
-
1.9.3
The Return 1 topic-
1.9.3.1Questions
-
-
-
1.10
Exploitation 2 topics-
1.10.1
Prioritization of Possible Attacks 1 topic-
1.10.1.1Prioritization Example
-
-
1.10.2Preparation for the Attack
-
-
1.11
Post-Exploitation 7 topics-
1.11.1Evasive Testing
-
1.11.2Information Gathering
-
1.11.3Pillaging
-
1.11.4Persistence
-
1.11.5Vulnerability Assessment
-
1.11.6Privilege Escalation
-
1.11.7
Data Exfiltration 1 topic-
1.11.7.1Questions
-
-
-
1.12
Lateral Movement 6 topics-
1.12.1Pivoting
-
1.12.2Evasive Testing
-
1.12.3Information Gathering
-
1.12.4Vulnerability Assessment
-
1.12.5(Privilege) Exploitation
-
1.12.6Post-Exploitation
-
-
1.13Proof-of-Concept
-
1.14
Post-Engagement 8 topics-
1.14.1Cleanup
-
1.14.2Documentation and Reporting
-
1.14.3Report Review Meeting
-
1.14.4Deliverable Acceptance
-
1.14.5Post-Remediation Testing
-
1.14.6Role of the Pentester in Remediation
-
1.14.7Data Retention
-
1.14.8
Close Out 1 topic-
1.14.8.1Questions
-
-
-
1.15
Practice 1 topic-
1.15.1
Practicing Steps 4 topics-
1.15.1.1Modules
-
1.15.1.2Retired Machines
-
1.15.1.3Active Machines
-
1.15.1.4Pro Lab/Endgame
-
-
-
1.16Wrapping Up
02 Getting Started Getting Started module 139 topics Module 2
-
2.1
Infosec Overview 3 topics-
2.1.1Risk Management Process
-
2.1.2Red Team vs. Blue Team
-
2.1.3Role of Penetration Testers
-
-
2.2
Getting Started with a Pentest Distro 3 topics-
2.2.1Choosing a Distro
-
2.2.2
Setting Up a Pentest Distro 2 topics-
2.2.2.1ISO
-
2.2.2.2OVA
-
-
2.2.3Practicing with Parrot
-
-
2.3
Staying Organized 4 topics-
2.3.1Folder Structure
-
2.3.2Note Taking Tools
-
2.3.3Other Tools and Tips
-
2.3.4Moving On
-
-
2.4
Connecting Using VPN 3 topics-
2.4.1Why Use A VPN?
-
2.4.2Connecting to HTB VPN
-
2.4.3Help with VPN
-
-
2.5
Common Terms 3 topics-
2.5.1What is a Shell?
-
2.5.2What is a Port?
-
2.5.3What is a Web Server
-
-
2.6
Basic Tools 4 topics-
2.6.1Using SSH
-
2.6.2Using Netcat
-
2.6.3Using Tmux
-
2.6.4Using Vim
-
-
2.7
Service Scanning 3 topics-
2.7.1
Nmap 1 topic-
2.7.1.1Nmap Scripts
-
-
2.7.2
Attacking Network Services 5 topics-
2.7.2.1Banner Grabbing
-
2.7.2.2FTP
-
2.7.2.3SMB
-
2.7.2.4Shares
-
2.7.2.5SNMP
-
-
2.7.3Conclusion
-
-
2.8
Web Enumeration 2 topics-
2.8.1
Gobuster 3 topics-
2.8.1.1Directory/File Enumeration
-
2.8.1.2DNS Subdomain Enumeration
-
2.8.1.3Install SecLists
-
-
2.8.2
Web Enumeration Tips 5 topics-
2.8.2.1Banner Grabbing / Web Server Headers
-
2.8.2.2Whatweb
-
2.8.2.3Certificates
-
2.8.2.4Robots.txt
-
2.8.2.5Source Code
-
-
-
2.9
Public Exploits 2 topics-
2.9.1Finding Public Exploits
-
2.9.2Metasploit Primer
-
-
2.10
Types of Shells 3 topics-
2.10.1
Reverse Shell 3 topics-
2.10.1.1Netcat Listener
-
2.10.1.2Connect Back IP
-
2.10.1.3Reverse Shell Command
-
-
2.10.2
Bind Shell 3 topics-
2.10.2.1Bind Shell Command
-
2.10.2.2Netcat Connection
-
2.10.2.3Upgrading TTY
-
-
2.10.3
Web Shell 3 topics-
2.10.3.1Writing a Web Shell
-
2.10.3.2Uploading a Web Shell
-
2.10.3.3Accessing Web Shell
-
-
-
2.11
Privilege Escalation 8 topics-
2.11.1PrivEsc Checklists
-
2.11.2Enumeration Scripts
-
2.11.3Kernel Exploits
-
2.11.4Vulnerable Software
-
2.11.5User Privileges
-
2.11.6Scheduled Tasks
-
2.11.7Exposed Credentials
-
2.11.8SSH Keys
-
-
2.12
Transferring Files 4 topics-
2.12.1Using wget
-
2.12.2Using SCP
-
2.12.3Using Base64
-
2.12.4Validating File Transfers
-
-
2.13
Starting Out 2 topics-
2.13.1
Resources 9 topics-
2.13.1.1Vulnerable Machines/Applications
-
2.13.1.2YouTube Channels
-
2.13.1.3Blogs
-
2.13.1.4Tutorial Websites
-
2.13.1.5HTB Starting Point
-
2.13.1.6HTB Tracks
-
2.13.1.7Beginner Friendly HTB Machines
-
2.13.1.8Beginner Friendly HTB Challenges
-
2.13.1.9Dante Prolab
-
-
2.13.2Moving On
-
-
2.14
Navigating HTB 9 topics-
2.14.1Profile
-
2.14.2Rankings
-
2.14.3Tracks
-
2.14.4Machines
-
2.14.5Challenges
-
2.14.6Fortress
-
2.14.7Endgame
-
2.14.8Pro Labs
-
2.14.9Battlegrounds
-
-
2.15
Nibbles - Enumeration 1 topic-
2.15.1Nmap
-
-
2.16
Nibbles - Web Footprinting 1 topic-
2.16.1Directory Enumeration
-
-
2.17Nibbles - Initial Foothold
-
2.18Nibbles - Privilege Escalation
-
2.19
Nibbles - Alternate User Method - Metasploit 1 topic-
2.19.1Next Steps
-
-
2.20
Common Pitfalls 3 topics-
2.20.1
VPN Issues 7 topics-
2.20.1.1Still Connected to VPN
-
2.20.1.2Getting VPN Address
-
2.20.1.3Checking Routing Table
-
2.20.1.4Pinging Gateway
-
2.20.1.5Working on Two Devices
-
2.20.1.6Checking Region
-
2.20.1.7VPN Troubleshooting
-
-
2.20.2
Burp Suite Proxy Issues 1 topic-
2.20.2.1Not Disabling Proxy
-
-
2.20.3Changing SSH Key and Password
-
-
2.21
Getting Help 5 topics-
2.21.1Forum
-
2.21.2Discord
-
2.21.3Asking Questions Effectively
-
2.21.4Answering Questions Effectively
-
2.21.5Getting Technical Help
-
-
2.22
Next Steps 4 topics-
2.22.1
Boxes & Challenges 3 topics-
2.22.1.1Root a Retired Easy Box
-
2.22.1.2Complete a Retired Medium Box
-
2.22.1.3Root Our First Live Box
-
-
2.22.2Keep Learning
-
2.22.3
Giving Back 2 topics-
2.22.3.1Answer Questions
-
2.22.3.2Share a Retired Box Walkthrough
-
-
2.22.4Way Forward
-
-
2.23
Knowledge Check 1 topic-
2.23.1Tips
-
03 Network Enumeration with Nmap Network Enumeration with Nmap module 81 topics Module 3
-
3.1Enumeration
-
3.2
Introduction to Nmap 4 topics-
3.2.1Use Cases
-
3.2.2Nmap Architecture
-
3.2.3Syntax
-
3.2.4Scan Techniques
-
-
3.3
Host Discovery 4 topics-
3.3.1Scan Network Range
-
3.3.2Scan IP List
-
3.3.3Scan Multiple IPs
-
3.3.4
Scan Single IP 1 topic-
3.3.4.1Questions
-
-
-
3.4
Host and Port Scanning 3 topics-
3.4.1
Discovering Open TCP Ports 6 topics-
3.4.1.1Scanning Top 10 TCP Ports
-
3.4.1.2Nmap - Trace the Packets
-
3.4.1.3Request
-
3.4.1.4Response
-
3.4.1.5Connect Scan
-
3.4.1.6Connect Scan on TCP Port 443
-
-
3.4.2Filtered Ports
-
3.4.3
Discovering Open UDP Ports 2 topics-
3.4.3.1UDP Port Scan
-
3.4.3.2Version Scan
-
-
-
3.5
Saving the Results 2 topics-
3.5.1
Different Formats 3 topics-
3.5.1.1Normal Output
-
3.5.1.2Grepable Output
-
3.5.1.3XML Output
-
-
3.5.2
Style sheets 1 topic-
3.5.2.1Nmap Report
-
-
-
3.6
Service Enumeration 2 topics-
3.6.1Service Version Detection
-
3.6.2
Banner Grabbing 3 topics-
3.6.2.1Tcpdump
-
3.6.2.2Nc
-
3.6.2.3Tcpdump - Intercepted Traffic
-
-
-
3.7
Nmap Scripting Engine 2 topics-
3.7.1
Default Scripts 4 topics-
3.7.1.1Specific Scripts Category
-
3.7.1.2Defined Scripts
-
3.7.1.3Nmap - Specifying Scripts
-
3.7.1.4Nmap - Aggressive Scan
-
-
3.7.2
Vulnerability Assessment 1 topic-
3.7.2.1Nmap - Vuln Category
-
-
-
3.8
Performance 4 topics-
3.8.1
Timeouts 2 topics-
3.8.1.1Default Scan
-
3.8.1.2Optimized RTT
-
-
3.8.2
Max Retries 2 topics-
3.8.2.1Default Scan
-
3.8.2.2Reduced Retries
-
-
3.8.3
Rates 4 topics-
3.8.3.1Default Scan
-
3.8.3.2Optimized Scan
-
3.8.3.3Default Scan - Found Open Ports
-
3.8.3.4Optimized Scan - Found Open Ports
-
-
3.8.4
Timing 4 topics-
3.8.4.1Default Scan
-
3.8.4.2Insane Scan
-
3.8.4.3Default Scan - Found Open Ports
-
3.8.4.4Insane Scan - Found Open Ports
-
-
-
3.9
Firewall and IDS/IPS Evasion 6 topics-
3.9.1Firewalls
-
3.9.2
IDS/IPS 3 topics-
3.9.2.1Determine Firewalls and Their Rules
-
3.9.2.2SYN-Scan
-
3.9.2.3ACK-Scan
-
-
3.9.3Detect IDS/IPS
-
3.9.4
Decoys 3 topics-
3.9.4.1Scan by Using Decoys
-
3.9.4.2Testing Firewall Rule
-
3.9.4.3Scan by Using Different Source IP
-
-
3.9.5
DNS Proxying 3 topics-
3.9.5.1SYN-Scan of a Filtered Port
-
3.9.5.2SYN-Scan From DNS Port
-
3.9.5.3Connect To The Filtered Port
-
-
3.9.6Firewall and IDS/IPS Evasion Labs
-
-
3.10Firewall and IDS/IPS Evasion - Easy Lab
-
3.11Firewall and IDS/IPS Evasion - Medium Lab
-
3.12Firewall and IDS/IPS Evasion - Hard Lab
04 Footprinting Footprinting module 208 topics Module 4
-
4.1Enumeration Principles
-
4.2
Enumeration Methodology 7 topics-
4.2.1Layer No.1: Internet Presence
-
4.2.2Layer No.2: Gateway
-
4.2.3Layer No.3: Accessible Services
-
4.2.4Layer No.4: Processes
-
4.2.5Layer No.5: Privileges
-
4.2.6Layer No.6: OS Setup
-
4.2.7Enumeration Methodology in Practice
-
-
4.3
Domain Information 1 topic-
4.3.1
Online Presence 4 topics-
4.3.1.1Certificate Transparency
-
4.3.1.2Company Hosted Servers
-
4.3.1.3Shodan - IP List
-
4.3.1.4DNS Records
-
-
-
4.4
Cloud Resources 1 topic-
4.4.1
Company Hosted Servers 7 topics-
4.4.1.1Google Search for AWS
-
4.4.1.2Google Search for Azure
-
4.4.1.3Target Website - Source Code
-
4.4.1.4Domain.Glass Results
-
4.4.1.5GrayHatWarfare Results
-
4.4.1.6Private and Public SSH Keys Leaked
-
4.4.1.7SSH Private Key
-
-
-
4.5
Staff 1 topic-
4.5.1
LinkedIn - Job Post 3 topics-
4.5.1.1LinkedIn - Employee #1 About
-
4.5.1.2Github
-
4.5.1.3LinkedIn - Employee #2 Career
-
-
-
4.6
FTP 4 topics-
4.6.1TFTP
-
4.6.2
Default Configuration 3 topics-
4.6.2.1Install vsFTPd
-
4.6.2.2vsFTPd Config File
-
4.6.2.3FTPUSERS
-
-
4.6.3
Dangerous Settings 8 topics-
4.6.3.1Anonymous Login
-
4.6.3.2vsFTPd Status
-
4.6.3.3vsFTPd Detailed Output
-
4.6.3.4Hiding IDs - YES
-
4.6.3.5Recursive Listing
-
4.6.3.6Download a File
-
4.6.3.7Download All Available Files
-
4.6.3.8Upload a File
-
-
4.6.4
Footprinting the Service 4 topics-
4.6.4.1Nmap FTP Scripts
-
4.6.4.2Nmap
-
4.6.4.3Nmap Script Trace
-
4.6.4.4Service Interaction
-
-
-
4.7
SMB 4 topics-
4.7.1Samba
-
4.7.2
Default Configuration 1 topic-
4.7.2.1Default Configuration
-
-
4.7.3
Dangerous Settings 5 topics-
4.7.3.1Example Share
-
4.7.3.2Restart Samba
-
4.7.3.3SMBclient - Connecting to the Share
-
4.7.3.4Download Files from SMB
-
4.7.3.5Samba Status
-
-
4.7.4
Footprinting the Service 11 topics-
4.7.4.1Nmap
-
4.7.4.2RPCclient
-
4.7.4.3RPCclient - Enumeration
-
4.7.4.4Rpcclient - User Enumeration
-
4.7.4.5Rpcclient - Group Information
-
4.7.4.6Brute Forcing User RIDs
-
4.7.4.7Impacket - Samrdump.py
-
4.7.4.8SMBmap
-
4.7.4.9CrackMapExec
-
4.7.4.10Enum4Linux-ng - Installation
-
4.7.4.11Enum4Linux-ng - Enumeration
-
-
-
4.8
NFS 3 topics-
4.8.1
Default Configuration 2 topics-
4.8.1.1Exports File
-
4.8.1.2ExportFS
-
-
4.8.2Dangerous Settings
-
4.8.3
Footprinting the Service 6 topics-
4.8.3.1Nmap
-
4.8.3.2Show Available NFS Shares
-
4.8.3.3Mounting NFS Share
-
4.8.3.4List Contents with Usernames & Group Names
-
4.8.3.5List Contents with UIDs & GUIDs
-
4.8.3.6Unmounting
-
-
-
4.9
DNS 3 topics-
4.9.1
Default Configuration 3 topics-
4.9.1.1Local DNS Configuration
-
4.9.1.2Zone Files
-
4.9.1.3Reverse Name Resolution Zone Files
-
-
4.9.2Dangerous Settings
-
4.9.3
Footprinting the Service 6 topics-
4.9.3.1DIG - NS Query
-
4.9.3.2DIG - Version Query
-
4.9.3.3DIG - ANY Query
-
4.9.3.4DIG - AXFR Zone Transfer
-
4.9.3.5DIG - AXFR Zone Transfer - Internal
-
4.9.3.6Subdomain Brute Forcing
-
-
-
4.10
SMTP 3 topics-
4.10.1
Default Configuration 4 topics-
4.10.1.1Default Configuration
-
4.10.1.2Telnet - HELO/EHLO
-
4.10.1.3Telnet - VRFY
-
4.10.1.4Send an Email
-
-
4.10.2
Dangerous Settings 1 topic-
4.10.2.1Open Relay Configuration
-
-
4.10.3
Footprinting the Service 2 topics-
4.10.3.1Nmap
-
4.10.3.2Nmap - Open Relay
-
-
-
4.11
IMAP / POP3 3 topics-
4.11.1
Default Configuration 2 topics-
4.11.1.1IMAP Commands
-
4.11.1.2POP3 Commands
-
-
4.11.2Dangerous Settings
-
4.11.3
Footprinting the Service 4 topics-
4.11.3.1Nmap
-
4.11.3.2cURL
-
4.11.3.3OpenSSL - TLS Encrypted Interaction POP3
-
4.11.3.4OpenSSL - TLS Encrypted Interaction IMAP
-
-
-
4.12
SNMP 4 topics-
4.12.1
MIB 5 topics-
4.12.1.1OID
-
4.12.1.2SNMPv1
-
4.12.1.3SNMPv2
-
4.12.1.4SNMPv3
-
4.12.1.5Community Strings
-
-
4.12.2
Default Configuration 1 topic-
4.12.2.1SNMP Daemon Config
-
-
4.12.3Dangerous Settings
-
4.12.4
Footprinting the Service 3 topics-
4.12.4.1SNMPwalk
-
4.12.4.2OneSixtyOne
-
4.12.4.3Braa
-
-
-
4.13
MySQL 4 topics-
4.13.1
MySQL Clients 2 topics-
4.13.1.1MySQL Databases
-
4.13.1.2MySQL Commands
-
-
4.13.2
Default Configuration 1 topic-
4.13.2.1Default Configuration
-
-
4.13.3Dangerous Settings
-
4.13.4
Footprinting the Service 2 topics-
4.13.4.1Scanning MySQL Server
-
4.13.4.2Interaction with the MySQL Server
-
-
-
4.14
MSSQL 4 topics-
4.14.1
MSSQL Clients 1 topic-
4.14.1.1MSSQL Databases
-
-
4.14.2Default Configuration
-
4.14.3Dangerous Settings
-
4.14.4
Footprinting the Service 3 topics-
4.14.4.1NMAP MSSQL Script Scan
-
4.14.4.2MSSQL Ping in Metasploit
-
4.14.4.3Connecting with Mssqlclient.py
-
-
-
4.15
Oracle TNS 1 topic-
4.15.1
Default Configuration 12 topics-
4.15.1.1Tnsnames.ora
-
4.15.1.2Listener.ora
-
4.15.1.3Oracle-Tools-setup.sh
-
4.15.1.4Testing ODAT
-
4.15.1.5Nmap
-
4.15.1.6Nmap - SID Bruteforcing
-
4.15.1.7ODAT
-
4.15.1.8SQLplus - Log In
-
4.15.1.9Oracle RDBMS - Interaction
-
4.15.1.10Oracle RDBMS - Database Enumeration
-
4.15.1.11Oracle RDBMS - Extract Password Hashes
-
4.15.1.12Oracle RDBMS - File Upload
-
-
-
4.16
IPMI 2 topics-
4.16.1
Footprinting the Service 2 topics-
4.16.1.1Nmap
-
4.16.1.2Metasploit Version Scan
-
-
4.16.2
Dangerous Settings 1 topic-
4.16.2.1Metasploit Dumping Hashes
-
-
-
4.17
Linux Remote Management Protocols 7 topics-
4.17.1
SSH 1 topic-
4.17.1.1Public Key Authentication
-
-
4.17.2
Default Configuration 1 topic-
4.17.2.1Default Configuration
-
-
4.17.3Dangerous Settings
-
4.17.4
Footprinting the Service 2 topics-
4.17.4.1SSH-Audit
-
4.17.4.2Change Authentication Method
-
-
4.17.5
Rsync 3 topics-
4.17.5.1Scanning for Rsync
-
4.17.5.2Probing for Accessible Shares
-
4.17.5.3Enumerating an Open Share
-
-
4.17.6
R-Services 7 topics-
4.17.6.1/etc/hosts.equiv
-
4.17.6.2Scanning for R-Services
-
4.17.6.3Access Control & Trusted Relationships
-
4.17.6.4Sample .rhosts File
-
4.17.6.5Logging in Using Rlogin
-
4.17.6.6Listing Authenticated Users Using Rwho
-
4.17.6.7Listing Authenticated Users Using Rusers
-
-
4.17.7Final Thoughts
-
-
4.18
Windows Remote Management Protocols 6 topics-
4.18.1RDP
-
4.18.2
Footprinting the Service 4 topics-
4.18.2.1Nmap
-
4.18.2.2RDP Security Check - Installation
-
4.18.2.3RDP Security Check
-
4.18.2.4Initiate an RDP Session
-
-
4.18.3WinRM
-
4.18.4
Footprinting the Service 1 topic-
4.18.4.1Nmap WinRM
-
-
4.18.5WMI
-
4.18.6
Footprinting the Service 1 topic-
4.18.6.1WMIexec.py
-
-
-
4.19Footprinting Lab - Easy
-
4.20Footprinting Lab - Medium
-
4.21Footprinting Lab - Hard
05 Information Gathering - Web Edition Information Gathering - Web Edition module 93 topics Module 5
-
5.1
Introduction 1 topic-
5.1.1
Types of Reconnaissance 2 topics-
5.1.1.1Active Reconnaissance
-
5.1.1.2Passive Reconnaissance
-
-
-
5.2
WHOIS 2 topics-
5.2.1
History of WHOIS 4 topics-
5.2.1.1Formalisation and Standardization
-
5.2.1.2The Rise of Distributed WHOIS and RIRs
-
5.2.1.3ICANN and the Modernization of WHOIS
-
5.2.1.4Privacy Concerns and the GDPR Era
-
-
5.2.2Why WHOIS Matters for Web Recon
-
-
5.3
Utilising WHOIS 4 topics-
5.3.1Scenario 1: Phishing Investigation
-
5.3.2Scenario 2: Malware Analysis
-
5.3.3Scenario 3: Threat Intelligence Report
-
5.3.4Using WHOIS
-
-
5.4
DNS 2 topics-
5.4.1
How DNS Works 3 topics-
5.4.1.1The Hosts File
-
5.4.1.2It's Like a Relay Race
-
5.4.1.3Key DNS Concepts
-
-
5.4.2Why DNS Matters for Web Recon
-
-
5.5
Digging DNS 3 topics-
5.5.1DNS Tools
-
5.5.2
The Domain Information Groper 1 topic-
5.5.2.1Common dig Commands
-
-
5.5.3Groping DNS
-
-
5.6
Subdomains 2 topics-
5.6.1Why is this important for web reconnaissance?
-
5.6.2
Subdomain Enumeration 2 topics-
5.6.2.1Active Subdomain Enumeration
-
5.6.2.2Passive Subdomain Enumeration
-
-
-
5.7
Subdomain Bruteforcing 1 topic-
5.7.1DNSEnum
-
-
5.8
DNS Zone Transfers 2 topics-
5.8.1What is a Zone Transfer
-
5.8.2
The Zone Transfer Vulnerability 2 topics-
5.8.2.1Remediation
-
5.8.2.2Exploiting Zone Transfers
-
-
-
5.9
Virtual Hosts 2 topics-
5.9.1
How Virtual Hosts Work: Understanding VHosts and Subdomains 2 topics-
5.9.1.1Server VHost Lookup
-
5.9.1.2Types of Virtual Hosting
-
-
5.9.2
Virtual Host Discovery Tools 1 topic-
5.9.2.1gobuster
-
-
-
5.10
Certificate Transparency Logs 4 topics-
5.10.1What are Certificate Transparency Logs?
-
5.10.2
How Certificate Transparency Logs Work 1 topic-
5.10.2.1The Merkle Tree Structure
-
-
5.10.3CT Logs and Web Recon
-
5.10.4
Searching CT Logs 1 topic-
5.10.4.1crt.sh lookup
-
-
-
5.11
Fingerprinting 2 topics-
5.11.1Fingerprinting Techniques
-
5.11.2
Fingerprinting inlanefreight.com 3 topics-
5.11.2.1Banner Grabbing
-
5.11.2.2Wafw00f
-
5.11.2.3Nikto
-
-
-
5.12
Crawling 2 topics-
5.12.1
How Web Crawlers Work 2 topics-
5.12.1.1Breadth-First Crawling
-
5.12.1.2Depth-First Crawling
-
-
5.12.2
Extracting Valuable Information 1 topic-
5.12.2.1The Importance of Context
-
-
-
5.13
robots.txt 2 topics-
5.13.1
What is robots.txt? 3 topics-
5.13.1.1How robots.txt Works
-
5.13.1.2Understanding robots.txt Structure
-
5.13.1.3Why Respect robots.txt?
-
-
5.13.2
robots.txt in Web Reconnaissance 1 topic-
5.13.2.1Analyzing robots.txt
-
-
-
5.14
Well-Known URIs 1 topic-
5.14.1Web Recon and .well-known
-
-
5.15
Creepy Crawlies 2 topics-
5.15.1Popular Web Crawlers
-
5.15.2
Scrapy 3 topics-
5.15.2.1Installing Scrapy
-
5.15.2.2ReconSpider
-
5.15.2.3results.json
-
-
-
5.16
Search Engine Discovery 2 topics-
5.16.1Why Search Engine Discovery Matters
-
5.16.2
Search Operators 1 topic-
5.16.2.1Google Dorking
-
-
-
5.17
Web Archives 3 topics-
5.17.1
What is the Wayback Machine? 1 topic-
5.17.1.1How Does the Wayback Machine Work?
-
-
5.17.2Why the Wayback Machine Matters for Web Reconnaissance
-
5.17.3Going Wayback on HTB
-
-
5.18
Automating Recon 2 topics-
5.18.1Why Automate Reconnaissance?
-
5.18.2
Reconnaissance Frameworks 1 topic-
5.18.2.1FinalRecon
-
-
-
5.19Skills Assessment
06 Vulnerability Assessment Vulnerability Assessment module 109 topics Module 6
-
6.1
Security Assessments 5 topics-
6.1.1Vulnerability Assessment
-
6.1.2Penetration Test
-
6.1.3Vulnerability Assessments vs. Penetration Tests
-
6.1.4
Other Types of Security Assessments 4 topics-
6.1.4.1Security Audits
-
6.1.4.2Bug Bounties
-
6.1.4.3Red Team Assessment
-
6.1.4.4Purple Team Assessment
-
-
6.1.5Moving on
-
-
6.2
Vulnerability Assessment 4 topics-
6.2.1Methodology
-
6.2.2
Understanding Key Terms 4 topics-
6.2.2.1Vulnerability
-
6.2.2.2Threat
-
6.2.2.3Exploit
-
6.2.2.4Risk
-
-
6.2.3
Asset Management 2 topics-
6.2.3.1Asset Inventory
-
6.2.3.2Application and System Inventory
-
-
6.2.4Onwards
-
-
6.3
Assessment Standards 2 topics-
6.3.1
Compliance Standards 4 topics-
6.3.1.1Payment Card Industry Data Security Standard (PCI DSS)
-
6.3.1.2Health Insurance Portability and Accountability Act (HIPAA)
-
6.3.1.3Federal Information Security Management Act (FISMA)
-
6.3.1.4ISO 27001
-
-
6.3.2
Penetration Testing Standards 4 topics-
6.3.2.1PTES
-
6.3.2.2OSSTMM
-
6.3.2.3NIST
-
6.3.2.4OWASP
-
-
-
6.4
Common Vulnerability Scoring System (CVSS) 6 topics-
6.4.1Severity Scoring
-
6.4.2
Base Metric Group 2 topics-
6.4.2.1Exploitability Metrics
-
6.4.2.2Impact Metrics
-
-
6.4.3
Temporal Metric Group 3 topics-
6.4.3.1Exploit Code Maturity
-
6.4.3.2Remediation Level
-
6.4.3.3Report Confidence
-
-
6.4.4
Environmental Metric Group 1 topic-
6.4.4.1Modified Base Metrics
-
-
6.4.5
Calculating CVSS Severity 1 topic-
6.4.5.1CVSS Calculation Example
-
-
6.4.6Next Steps
-
-
6.5
Common Vulnerabilities and Exposures (CVE) 6 topics-
6.5.1
Open Vulnerability Assessment Language (OVAL) 2 topics-
6.5.1.1OVAL Process
-
6.5.1.2OVAL Definitions
-
-
6.5.2Common Vulnerabilities and Exposures (CVE)
-
6.5.3
Stages of Obtaining a CVE 9 topics-
6.5.3.1Stage 1: Identify if CVE is Required and Relevant
-
6.5.3.2Stage 2: Reach Out to Affected Product Vendor
-
6.5.3.3Stage 3: Identify if Request Should Be For Vendor CNA or Third Party CNA
-
6.5.3.4Stage 4: Requesting CVE ID Through CVE Web Form
-
6.5.3.5Stage 5: Confirmation of CVE Form
-
6.5.3.6Stage 6: Receival of CVE ID
-
6.5.3.7Stage 7: Public Disclosure of CVE ID
-
6.5.3.8Stage 8: Announcing the CVE
-
6.5.3.9Stage 9: Providing Information to The CVE Team
-
-
6.5.4Responsible Disclosure
-
6.5.5
Examples 2 topics-
6.5.5.1CVE-2020-5902
-
6.5.5.2CVE-2021-34527
-
-
6.5.6Getting Hands-on
-
-
6.6
Vulnerability Scanning Overview 2 topics-
6.6.1Nessus Overview
-
6.6.2OpenVAS Overview
-
-
6.7
Getting Started with Nessus 5 topics-
6.7.1Downloading Nessus
-
6.7.2Requesting Free License
-
6.7.3Installing Package
-
6.7.4Starting Nessus
-
6.7.5Accessing Nessus
-
-
6.8
Nessus Scan 4 topics-
6.8.1New Scan
-
6.8.2Discovery
-
6.8.3Assessment
-
6.8.4Advanced
-
-
6.9
Advanced Settings 4 topics-
6.9.1Scan Policies
-
6.9.2Creating a Scan Policy
-
6.9.3Nessus Plugins
-
6.9.4Scanning with Credentials
-
-
6.10
Working with Nessus Scan Output 2 topics-
6.10.1Nessus Reports
-
6.10.2Exporting Nessus Scans
-
-
6.11
Scanning Issues 2 topics-
6.11.1Mitigating Issues
-
6.11.2Network Impact
-
-
6.12
Nessus Skills Assessment 1 topic-
6.12.1Requirements
-
-
6.13
Getting Started with OpenVAS 2 topics-
6.13.1Installing Package
-
6.13.2Starting OpenVas
-
-
6.14
OpenVAS Scan 2 topics-
6.14.1Configuration
-
6.14.2Setting Up a Scan
-
-
6.15
Exporting The Results 1 topic-
6.15.1Exporting Formats
-
-
6.16
OpenVAS Skills Assessment 1 topic-
6.16.1Requirements
-
-
6.17
Reporting 5 topics-
6.17.1Executive Summary
-
6.17.2Overview of Assessment
-
6.17.3Scope and Duration
-
6.17.4Vulnerabilities and Recommendations
-
6.17.5Closing
-
07 File Transfers File Transfers module 175 topics Module 7
-
7.1File Transfers
-
7.2
Windows File Transfer Methods 24 topics-
7.2.1Introduction
-
7.2.2Download Operations
-
7.2.3
PowerShell Base64 Encode & Decode 3 topics-
7.2.3.1Pwnbox Check SSH Key MD5 Hash
-
7.2.3.2Pwnbox Encode SSH Key to Base64
-
7.2.3.3Confirming the MD5 Hashes Match
-
-
7.2.4
PowerShell Web Downloads 5 topics-
7.2.4.1PowerShell DownloadFile Method
-
7.2.4.2File Download
-
7.2.4.3PowerShell DownloadString - Fileless Method
-
7.2.4.4PowerShell Invoke-WebRequest
-
7.2.4.5Common Errors with PowerShell
-
-
7.2.5
SMB Downloads 4 topics-
7.2.5.1Create the SMB Server
-
7.2.5.2Copy a File from the SMB Server
-
7.2.5.3Create the SMB Server with a Username and Password
-
7.2.5.4Mount the SMB Server with Username and Password
-
-
7.2.6
FTP Downloads 4 topics-
7.2.6.1Installing the FTP Server Python3 Module - pyftpdlib
-
7.2.6.2Setting up a Python3 FTP Server
-
7.2.6.3Transfering Files from an FTP Server Using PowerShell
-
7.2.6.4Create a Command File for the FTP Client and Download the Target File
-
-
7.2.7Upload Operations
-
7.2.8
PowerShell Base64 Encode & Decode 2 topics-
7.2.8.1Encode File Using PowerShell
-
7.2.8.2Decode Base64 String in Linux
-
-
7.2.9
PowerShell Web Uploads 3 topics-
7.2.9.1Installing a Configured WebServer with Upload
-
7.2.9.2PowerShell Script to Upload a File to Python Upload Server
-
7.2.9.3PowerShell Base64 Web Upload
-
-
7.2.10
SMB Uploads 5 topics-
7.2.10.1Configuring WebDav Server
-
7.2.10.2Installing WebDav Python modules
-
7.2.10.3Using the WebDav Python module
-
7.2.10.4Connecting to the Webdav Share
-
7.2.10.5Uploading Files using SMB
-
-
7.2.11
FTP Uploads 2 topics-
7.2.11.1PowerShell Upload File
-
7.2.11.2Create a Command File for the FTP Client to Upload a File
-
-
7.2.12Recap
-
7.2.13Linux File Transfer Methods
-
7.2.14Download Operations
-
7.2.15
Base64 Encoding / Decoding 4 topics-
7.2.15.1Pwnbox - Check File MD5 hash
-
7.2.15.2Pwnbox - Encode SSH Key to Base64
-
7.2.15.3Linux - Decode the File
-
7.2.15.4Linux - Confirm the MD5 Hashes Match
-
-
7.2.16
Web Downloads with Wget and cURL 2 topics-
7.2.16.1Download a File Using wget
-
7.2.16.2Download a File Using cURL
-
-
7.2.17
Fileless Attacks Using Linux 2 topics-
7.2.17.1Fileless Download with cURL
-
7.2.17.2Fileless Download with wget
-
-
7.2.18
Download with Bash (/dev/tcp) 3 topics-
7.2.18.1Connect to the Target Webserver
-
7.2.18.2HTTP GET Request
-
7.2.18.3Print the Response
-
-
7.2.19
SSH Downloads 4 topics-
7.2.19.1Enabling the SSH Server
-
7.2.19.2Starting the SSH Server
-
7.2.19.3Checking for SSH Listening Port
-
7.2.19.4Linux - Downloading Files Using SCP
-
-
7.2.20Upload Operations
-
7.2.21
Web Upload 4 topics-
7.2.21.1Pwnbox - Start Web Server
-
7.2.21.2Pwnbox - Create a Self-Signed Certificate
-
7.2.21.3Pwnbox - Start Web Server
-
7.2.21.4Linux - Upload Multiple Files
-
-
7.2.22
Alternative Web File Transfer Method 5 topics-
7.2.22.1Linux - Creating a Web Server with Python3
-
7.2.22.2Linux - Creating a Web Server with Python2.7
-
7.2.22.3Linux - Creating a Web Server with PHP
-
7.2.22.4Linux - Creating a Web Server with Ruby
-
7.2.22.5Download the File from the Target Machine onto the Pwnbox
-
-
7.2.23
SCP Upload 1 topic-
7.2.23.1File Upload using SCP
-
-
7.2.24Onwards
-
-
7.3
Transferring Files with Code 7 topics-
7.3.1
Python 2 topics-
7.3.1.1Python 2 - Download
-
7.3.1.2Python 3 - Download
-
-
7.3.2
PHP 3 topics-
7.3.2.1PHP Download with File_get_contents()
-
7.3.2.2PHP Download with Fopen()
-
7.3.2.3PHP Download a File and Pipe it to Bash
-
-
7.3.3
Other Languages 2 topics-
7.3.3.1Ruby - Download a File
-
7.3.3.2Perl - Download a File
-
-
7.3.4
JavaScript 1 topic-
7.3.4.1Download a File Using JavaScript and cscript.exe
-
-
7.3.5
VBScript 1 topic-
7.3.5.1Download a File Using VBScript and cscript.exe
-
-
7.3.6
Upload Operations using Python3 2 topics-
7.3.6.1Starting the Python uploadserver Module
-
7.3.6.2Uploading a File Using a Python One-liner
-
-
7.3.7Section Recap
-
-
7.4
Miscellaneous File Transfer Methods 5 topics-
7.4.1Netcat
-
7.4.2
File Transfer with Netcat and Ncat 11 topics-
7.4.2.1NetCat - Compromised Machine - Listening on Port 8000
-
7.4.2.2Ncat - Compromised Machine - Listening on Port 8000
-
7.4.2.3Netcat - Attack Host - Sending File to Compromised machine
-
7.4.2.4Ncat - Attack Host - Sending File to Compromised machine
-
7.4.2.5Attack Host - Sending File as Input to Netcat
-
7.4.2.6Compromised Machine Connect to Netcat to Receive the File
-
7.4.2.7Attack Host - Sending File as Input to Ncat
-
7.4.2.8Compromised Machine Connect to Ncat to Receive the File
-
7.4.2.9NetCat - Sending File as Input to Netcat
-
7.4.2.10Ncat - Sending File as Input to Ncat
-
7.4.2.11Compromised Machine Connecting to Netcat Using /dev/tcp to Receive the File
-
-
7.4.3
PowerShell Session File Transfer 4 topics-
7.4.3.1From DC01 - Confirm WinRM port TCP 5985 is Open on DATABASE01.
-
7.4.3.2Create a PowerShell Remoting Session to DATABASE01
-
7.4.3.3Copy samplefile.txt from our Localhost to the DATABASE01 Session
-
7.4.3.4Copy DATABASE.txt from DATABASE01 Session to our Localhost
-
-
7.4.4
RDP 2 topics-
7.4.4.1Mounting a Linux Folder Using rdesktop
-
7.4.4.2Mounting a Linux Folder Using xfreerdp
-
-
7.4.5Practice Makes Perfect
-
-
7.5
Protected File Transfers 2 topics-
7.5.1
File Encryption on Windows 3 topics-
7.5.1.1Invoke-AESEncryption.ps1
-
7.5.1.2Import Module Invoke-AESEncryption.ps1
-
7.5.1.3File Encryption Example
-
-
7.5.2
File Encryption on Linux 2 topics-
7.5.2.1Encrypting /etc/passwd with openssl
-
7.5.2.2Decrypt passwd.enc with openssl
-
-
-
7.6
Catching Files over HTTP/S 3 topics-
7.6.1HTTP/S
-
7.6.2
Nginx - Enabling PUT 8 topics-
7.6.2.1Create a Directory to Handle Uploaded Files
-
7.6.2.2Change the Owner to www-data
-
7.6.2.3Create Nginx Configuration File
-
7.6.2.4Symlink our Site to the sites-enabled Directory
-
7.6.2.5Start Nginx
-
7.6.2.6Verifying Errors
-
7.6.2.7Remove NginxDefault Configuration
-
7.6.2.8Upload File Using cURL
-
-
7.6.3Using Built-in Tools
-
-
7.7
Living off The Land 3 topics-
7.7.1
Using the LOLBAS and GTFOBins Project 7 topics-
7.7.1.1LOLBAS
-
7.7.1.2Upload win.ini to our Pwnbox
-
7.7.1.3File Received in our Netcat Session
-
7.7.1.4GTFOBins
-
7.7.1.5Create Certificate in our Pwnbox
-
7.7.1.6Stand up the Server in our Pwnbox
-
7.7.1.7Download File from the Compromised Machine
-
-
7.7.2
Other Common Living off the Land tools 5 topics-
7.7.2.1Bitsadmin Download function
-
7.7.2.2File Download with Bitsadmin
-
7.7.2.3Download
-
7.7.2.4Certutil
-
7.7.2.5Download a File with Certutil
-
-
7.7.3Extra Practice
-
-
7.8
Detection 1 topic-
7.8.1
Invoke-WebRequest - Client 9 topics-
7.8.1.1Invoke-WebRequest - Server
-
7.8.1.2WinHttpRequest - Client
-
7.8.1.3WinHttpRequest - Server
-
7.8.1.4Msxml2 - Client
-
7.8.1.5Msxml2 - Server
-
7.8.1.6Certutil - Client
-
7.8.1.7Certutil - Server
-
7.8.1.8BITS - Client
-
7.8.1.9BITS - Server
-
-
-
7.9
Evading Detection 3 topics-
7.9.1
Changing User Agent 2 topics-
7.9.1.1Listing out User Agents
-
7.9.1.2Request with Chrome User Agent
-
-
7.9.2
LOLBAS / GTFOBins 1 topic-
7.9.2.1Transferring File with GfxDownloadWrapper.exe
-
-
7.9.3Closing Thoughts
-
08 Shells & Payloads Shells & Payloads module 192 topics Module 8
-
8.1
Shells Jack Us In, Payloads Deliver Us Shells 2 topics-
8.1.1Why Get a Shell?
-
8.1.2Payloads Deliver us Shells
-
-
8.2
CAT5 Security's Engagement Preparation 1 topic-
8.2.1
Shell basics 6 topics-
8.2.1.1Payload Basics
-
8.2.1.2Getting a Shell on Windows
-
8.2.1.3Getting a Shell on Linux
-
8.2.1.4Landing a Web Shell
-
8.2.1.5Spotting a Shell or Payload
-
8.2.1.6Final Challenge
-
-
-
8.3
Anatomy of a Shell 2 topics-
8.3.1Command Language Interpreters
-
8.3.2
Hands-on with Terminal Emulators and Shells 4 topics-
8.3.2.1Terminal Example
-
8.3.2.2Shell Validation From 'ps'
-
8.3.2.3Shell Validation Using 'env'
-
8.3.2.4PowerShell vs. Bash
-
-
-
8.4
Bind Shells 3 topics-
8.4.1
What Is It? 1 topic-
8.4.1.1Bind Example
-
-
8.4.2
Practicing with GNU Netcat 5 topics-
8.4.2.1No. 1: Server - Target starting Netcat listener
-
8.4.2.2No. 2: Client - Attack box connecting to target
-
8.4.2.3No. 3: Server - Target receiving connection from client
-
8.4.2.4No. 4: Client - Attack box sending message Hello Academy
-
8.4.2.5No. 5: Server - Target receiving Hello Academy message
-
-
8.4.3
Establishing a Basic Bind Shell with Netcat 2 topics-
8.4.3.1No. 1: Server - Binding a Bash shell to the TCP session
-
8.4.3.2No. 2: Client - Connecting to bind shell on target
-
-
-
8.5
Reverse Shells 2 topics-
8.5.1Reverse Shell Example
-
8.5.2
Hands-on With A Simple Reverse Shell in Windows 4 topics-
8.5.2.1Server ( attack box )
-
8.5.2.2Client (target)
-
8.5.2.3Disable AV
-
8.5.2.4Server (attack box)
-
-
-
8.6
Introduction to Payloads 3 topics-
8.6.1
One-Liners Examined 6 topics-
8.6.1.1Netcat/Bash Reverse Shell One-liner
-
8.6.1.2Remove /tmp/f
-
8.6.1.3Make A Named Pipe
-
8.6.1.4Output Redirection
-
8.6.1.5Set Shell Options
-
8.6.1.6Open a Connection with Netcat
-
-
8.6.2
PowerShell One-liner Explained 11 topics-
8.6.2.1Powershell One-liner
-
8.6.2.2Calling PowerShell
-
8.6.2.3Binding A Socket
-
8.6.2.4Setting The Command Stream
-
8.6.2.5Empty Byte Stream
-
8.6.2.6Stream Parameters
-
8.6.2.7Set The Byte Encoding
-
8.6.2.8Invoke-Expression
-
8.6.2.9Show Working Directory
-
8.6.2.10Sets Sendbyte
-
8.6.2.11Terminate TCP Connection
-
-
8.6.3Payloads Take Different Shapes and Forms
-
-
8.7
Automating Payloads & Delivery with Metasploit 1 topic-
8.7.1
Practicing with Metasploit 8 topics-
8.7.1.1Starting MSF
-
8.7.1.2NMAP Scan
-
8.7.1.3Searching Within Metasploit
-
8.7.1.4Option Selection
-
8.7.1.5Examining an Exploit's Options
-
8.7.1.6Setting Options
-
8.7.1.7Exploits Away
-
8.7.1.8Interactive Shell
-
-
-
8.8
Crafting Payloads with MSFvenom 6 topics-
8.8.1
Practicing with MSFvenom 1 topic-
8.8.1.1List Payloads
-
-
8.8.2Staged vs. Stageless Payloads
-
8.8.3
Building A Stageless Payload 7 topics-
8.8.3.1Build It
-
8.8.3.2Call MSFvenom
-
8.8.3.3Creating a Payload
-
8.8.3.4Choosing the Payload based on Architecture
-
8.8.3.5Address To Connect Back To
-
8.8.3.6Format To Generate Payload In
-
8.8.3.7Output
-
-
8.8.4
Executing a Stageless Payload 3 topics-
8.8.4.1Ubuntu Payload
-
8.8.4.2NC Connection
-
8.8.4.3Connection Established
-
-
8.8.5
Building a simple Stageless Payload for a Windows system 1 topic-
8.8.5.1Windows Payload
-
-
8.8.6Executing a Simple Stageless Payload On a Windows System
-
-
8.9
Infiltrating Windows 8 topics-
8.9.1Windows Vulnerability Table
-
8.9.2Prominent Windows Exploits
-
8.9.3
Enumerating Windows & Fingerprinting Methods 3 topics-
8.9.3.1Pinged Host
-
8.9.3.2OS Detection Scan
-
8.9.3.3Banner Grab to Enumerate Ports
-
-
8.9.4
Bats, DLLs, & MSI Files, Oh My! 1 topic-
8.9.4.1Payload Types to Consider
-
-
8.9.5
Tools, Tactics, and Procedures for Payload Generation, Transfer, and Execution 2 topics-
8.9.5.1Payload Generation
-
8.9.5.2Payload Transfer and Execution:
-
-
8.9.6
Example Compromise Walkthrough 7 topics-
8.9.6.1Enumerate the Host
-
8.9.6.2Determine an Exploit Path
-
8.9.6.3Choose & Configure Our Exploit & Payload
-
8.9.6.4Configure The Exploit & Payload
-
8.9.6.5Validate Our Options
-
8.9.6.6Execute Our Attack
-
8.9.6.7Identify Our Shell
-
-
8.9.7CMD-Prompt and Power[Shell]s for Fun and Profit.
-
8.9.8WSL and PowerShell For Linux
-
-
8.10
Infiltrating Unix/Linux 5 topics-
8.10.1Common Considerations
-
8.10.2
Gaining a Shell Through Attacking a Vulnerable Application 2 topics-
8.10.2.1Enumerate the Host
-
8.10.2.2rConfig Management Tool
-
-
8.10.3
Discovering a Vulnerability in rConfig 2 topics-
8.10.3.1Search For an Exploit Module
-
8.10.3.2Locate
-
-
8.10.4
Using the rConfig Exploit and Gaining a Shell 3 topics-
8.10.4.1Select an Exploit
-
8.10.4.2Execute the Exploit
-
8.10.4.3Interact With the Shell
-
-
8.10.5
Spawning a TTY Shell with Python 1 topic-
8.10.5.1Interactive Python
-
-
-
8.11
Spawning Interactive Shells 9 topics-
8.11.1
/bin/sh -i 1 topic-
8.11.1.1Interactive
-
-
8.11.2
Perl 1 topic-
8.11.2.1Perl To Shell
-
-
8.11.3
Ruby 1 topic-
8.11.3.1Ruby To Shell
-
-
8.11.4
Lua 1 topic-
8.11.4.1Lua To Shell
-
-
8.11.5
AWK 1 topic-
8.11.5.1AWK To Shell
-
-
8.11.6
Find 1 topic-
8.11.6.1Using Find For A Shell
-
-
8.11.7Using Exec To Launch A Shell
-
8.11.8
VIM 2 topics-
8.11.8.1Vim To Shell
-
8.11.8.2Vim Escape
-
-
8.11.9
Execution Permissions Considerations 2 topics-
8.11.9.1Permissions
-
8.11.9.2Sudo -l
-
-
-
8.12
Introduction to Web Shells 1 topic-
8.12.1What is a Web Shell?
-
-
8.13
Laudanum, One Webshell to Rule Them All 2 topics-
8.13.1Working with Laudanum
-
8.13.2
Laudanum Demonstration 5 topics-
8.13.2.1Move a Copy for Modification
-
8.13.2.2Modify the Shell for Use
-
8.13.2.3Take Advantage of the Upload Function
-
8.13.2.4Navigate to Our Shell
-
8.13.2.5Shell Success
-
-
-
8.14
Antak Webshell 5 topics-
8.14.1ASPX and a Quick Learning Tip
-
8.14.2ASPX Explained
-
8.14.3Antak Webshell
-
8.14.4Working with Antak
-
8.14.5
Antak Demonstration 4 topics-
8.14.5.1Move a Copy for Modification
-
8.14.5.2Modify the Shell for Use
-
8.14.5.3Shell Success
-
8.14.5.4Issuing Commands
-
-
-
8.15
PHP Web Shells 4 topics-
8.15.1PHP Login Page
-
8.15.2
Hands-on With a PHP-Based Web Shell. 2 topics-
8.15.2.1Vendors Tab
-
8.15.2.2Proxy Settings
-
-
8.15.3
Bypassing the File Type Restriction 3 topics-
8.15.3.1Post Request
-
8.15.3.2Vendor Added
-
8.15.3.3Webshell Success
-
-
8.15.4Considerations when Dealing with Web Shells
-
-
8.16
The Live Engagement 5 topics-
8.16.1Scenario:
-
8.16.2Objectives:
-
8.16.3Credentials and Other Needed Info:
-
8.16.4
Connectivity To The Foothold 2 topics-
8.16.4.1XFreeRDP Login
-
8.16.4.2Target Hosts
-
-
8.16.5Hints
-
-
8.17
Detection & Prevention 6 topics-
8.17.1
Monitoring 2 topics-
8.17.1.1ATT&CK Framework
-
8.17.1.2Notable MITRE ATT&CK Tactics and Techniques:
-
-
8.17.2Events To Watch For:
-
8.17.3
Establish Network Visibility 2 topics-
8.17.3.1Suspicious Traffic.. In Clear Text
-
8.17.3.2Following the Traffic
-
-
8.17.4Protecting End Devices
-
8.17.5Potential Mitigations:
-
8.17.6Sum It All Up
-
09 Using the Metasploit Framework Using the Metasploit Framework module 173 topics Module 9
-
9.1
Preface 2 topics-
9.1.1Discipline
-
9.1.2Conclusion
-
-
9.2
Introduction to Metasploit 3 topics-
9.2.1Metasploit Pro
-
9.2.2Metasploit Framework Console
-
9.2.3
Understanding the Architecture 6 topics-
9.2.3.1Data, Documentation, Lib
-
9.2.3.2Modules
-
9.2.3.3Plugins
-
9.2.3.4Scripts
-
9.2.3.5Tools
-
9.2.3.6Questions
-
-
-
9.3
Introduction to MSFconsole 2 topics-
9.3.1
Preparation 2 topics-
9.3.1.1Launching MSFconsole
-
9.3.1.2Installing MSF
-
-
9.3.2MSF Engagement Structure
-
-
9.4
Modules 4 topics-
9.4.1
Syntax 6 topics-
9.4.1.1Example
-
9.4.1.2Index No.
-
9.4.1.3Type
-
9.4.1.4OS
-
9.4.1.5Service
-
9.4.1.6Name
-
-
9.4.2
Searching for Modules 3 topics-
9.4.2.1MSF - Search Function
-
9.4.2.2MSF - Searching for EternalRomance
-
9.4.2.3MSF - Specific Search
-
-
9.4.3
Module Selection 1 topic-
9.4.3.1MSF - Search for MS17_010
-
-
9.4.4
Using Modules 6 topics-
9.4.4.1MSF - Select Module
-
9.4.4.2MSF - Module Information
-
9.4.4.3MSF - Target Specification
-
9.4.4.4MSF - Permanent Target Specification
-
9.4.4.5MSF - Exploit Execution
-
9.4.4.6MSF - Target Interaction
-
-
-
9.5
Targets 3 topics-
9.5.1MSF - Show Targets
-
9.5.2
Selecting a Target 1 topic-
9.5.2.1MSF - Target Selection
-
-
9.5.3Target Types
-
-
9.6
Payloads 6 topics-
9.6.1
Singles 2 topics-
9.6.1.1Stagers
-
9.6.1.2Stages
-
-
9.6.2
Staged Payloads 2 topics-
9.6.2.1MSF - Staged Payloads
-
9.6.2.2Meterpreter Payload
-
-
9.6.3
Searching for Payloads 2 topics-
9.6.3.1MSF - List Payloads
-
9.6.3.2MSF - Searching for Specific Payload
-
-
9.6.4
Selecting Payloads 1 topic-
9.6.4.1MSF - Select Payload
-
-
9.6.5
Using Payloads 4 topics-
9.6.5.1MSF - Exploit and Payload Configuration
-
9.6.5.2MSF - Meterpreter Commands
-
9.6.5.3MSF - Meterpreter Navigation
-
9.6.5.4MSF - Windows CMD
-
-
9.6.6Payload Types
-
-
9.7
Encoders 1 topic-
9.7.1
Selecting an Encoder 4 topics-
9.7.1.1Generating Payload - Without Encoding
-
9.7.1.2Generating Payload - With Encoding
-
9.7.1.3Shikata Ga Nai Encoding
-
9.7.1.4MSF - VirusTotal
-
-
-
9.8
Databases 9 topics-
9.8.1
Setting up the Database 6 topics-
9.8.1.1PostgreSQL Status
-
9.8.1.2Start PostgreSQL
-
9.8.1.3MSF - Initiate a Database
-
9.8.1.4MSF - Connect to the Initiated Database
-
9.8.1.5MSF - Reinitiate the Database
-
9.8.1.6MSF - Database Options
-
-
9.8.2
Using the Database 1 topic-
9.8.2.1Workspaces
-
-
9.8.3
Importing Scan Results 2 topics-
9.8.3.1Stored Nmap Scan
-
9.8.3.2Importing Scan Results
-
-
9.8.4
Using Nmap Inside MSFconsole 1 topic-
9.8.4.1MSF - Nmap
-
-
9.8.5
Data Backup 1 topic-
9.8.5.1MSF - DB Export
-
-
9.8.6
Hosts 1 topic-
9.8.6.1MSF - Stored Hosts
-
-
9.8.7
Services 1 topic-
9.8.7.1MSF - Stored Services of Hosts
-
-
9.8.8
Credentials 1 topic-
9.8.8.1MSF - Stored Credentials
-
-
9.8.9
Loot 1 topic-
9.8.9.1MSF - Stored Loot
-
-
-
9.9
Plugins 3 topics-
9.9.1
Using Plugins 1 topic-
9.9.1.1MSF - Load Nessus
-
-
9.9.2
Installing new Plugins 3 topics-
9.9.2.1Downloading MSF Plugins
-
9.9.2.2MSF - Copying Plugin to MSF
-
9.9.2.3MSF - Load Plugin
-
-
9.9.3Mixins
-
-
9.10
Sessions 2 topics-
9.10.1
Using Sessions 2 topics-
9.10.1.1Listing Active Sessions
-
9.10.1.2Interacting with a Session
-
-
9.10.2
Jobs 4 topics-
9.10.2.1Viewing the Jobs Command Help Menu
-
9.10.2.2Viewing the Exploit Command Help Menu
-
9.10.2.3Running an Exploit as a Background Job
-
9.10.2.4Listing Running Jobs
-
-
-
9.11
Meterpreter 5 topics-
9.11.1
Running Meterpreter 1 topic-
9.11.1.1MSF - Meterpreter Commands
-
-
9.11.2Stealthy
-
9.11.3Powerful
-
9.11.4Extensible
-
9.11.5
Using Meterpreter 9 topics-
9.11.5.1MSF - Scanning Target
-
9.11.5.2MSF - Searching for Exploit
-
9.11.5.3MSF - Configuring Exploit & Payload
-
9.11.5.4MSF - Meterpreter Migration
-
9.11.5.5MSF - Interacting with the Target
-
9.11.5.6MSF - Session Handling
-
9.11.5.7MSF - Privilege Escalation
-
9.11.5.8MSF - Dumping Hashes
-
9.11.5.9MSF - Meterpreter LSA Secrets Dump
-
-
-
9.12
Writing and Importing Modules 3 topics-
9.12.1
MSF - Search for Exploits 3 topics-
9.12.1.1MSF - Directory Structure
-
9.12.1.2MSF - Loading Additional Modules at Runtime
-
9.12.1.3MSF - Loading Additional Modules
-
-
9.12.2
Porting Over Scripts into Metasploit Modules 1 topic-
9.12.2.1Porting MSF Modules
-
-
9.12.3
Writing Our Module 4 topics-
9.12.3.1Proof-of-Concept - Requirements
-
9.12.3.2Proof-of-Concept - Module Information
-
9.12.3.3Proof-of-Concept - Functions
-
9.12.3.4Proof-of-Concept
-
-
-
9.13
Introduction to MSFVenom 3 topics-
9.13.1
Creating Our Payloads 4 topics-
9.13.1.1Scanning the Target
-
9.13.1.2FTP Anonymous Access
-
9.13.1.3Generating Payload
-
9.13.1.4MSF - Setting Up Multi/Handler
-
-
9.13.2
Executing the Payload 1 topic-
9.13.2.1MSF - Meterpreter Shell
-
-
9.13.3
Local Exploit Suggester 2 topics-
9.13.3.1MSF - Searching for Local Exploit Suggester
-
9.13.3.2MSF - Local Privilege Escalation
-
-
-
9.14
Firewall and IDS/IPS Evasion 8 topics-
9.14.1
Endpoint Protection 1 topic-
9.14.1.1Perimeter Protection
-
-
9.14.2Security Policies
-
9.14.3Evasion Techniques
-
9.14.4
Archives 7 topics-
9.14.4.1Generating Payload
-
9.14.4.2VirusTotal
-
9.14.4.3Archiving the Payload
-
9.14.4.4Removing the .RAR Extension
-
9.14.4.5Archiving the Payload Again
-
9.14.4.6Removing the .RAR Extension
-
9.14.4.7VirusTotal
-
-
9.14.5Packers
-
9.14.6Exploit Coding
-
9.14.7Recompiling Meterpreter from Source Code
-
9.14.8A Note on Evasion
-
-
9.15
Metasploit-Framework Updates - August 2020 6 topics-
9.15.1Generation Features
-
9.15.2Expanded Encryption
-
9.15.3Cleaner Payload Artifacts
-
9.15.4Plugins
-
9.15.5Payloads
-
9.15.6Closing Thoughts
-
10 Password Attacks Password Attacks module 292 topics Module 10
-
10.1
Theory of Protection 3 topics-
10.1.1Authentication
-
10.1.2The Use of Passwords
-
10.1.3Digging In
-
-
10.2
Credential Storage 2 topics-
10.2.1
Linux 2 topics-
10.2.1.1Shadow File
-
10.2.1.2Passwd File
-
-
10.2.2
Windows Authentication Process 5 topics-
10.2.2.1Windows Authentication Process Diagram
-
10.2.2.2LSASS
-
10.2.2.3SAM Database
-
10.2.2.4Credential Manager
-
10.2.2.5NTDS
-
-
-
10.3
John The Ripper 4 topics-
10.3.1Encryption Technologies
-
10.3.2
Attack Methods 3 topics-
10.3.2.1Dictionary Attacks
-
10.3.2.2Brute Force Attacks
-
10.3.2.3Rainbow Table Attacks
-
-
10.3.3
Cracking Modes 5 topics-
10.3.3.1Single Crack Mode
-
10.3.3.2Cracking with John
-
10.3.3.3Wordlist Mode
-
10.3.3.4Incremental Mode
-
10.3.3.5Incremental Mode in John
-
-
10.3.4
Cracking Files 1 topic-
10.3.4.1Cracking Files with John
-
-
-
10.4
Network Services 4 topics-
10.4.1
WinRM 8 topics-
10.4.1.1CrackMapExec
-
10.4.1.2Installing CrackMapExec
-
10.4.1.3CrackMapExec Menu Options
-
10.4.1.4CrackMapExec Protocol-Specific Help
-
10.4.1.5CrackMapExec Usage
-
10.4.1.6Evil-WinRM
-
10.4.1.7Installing Evil-WinRM
-
10.4.1.8Evil-WinRM Usage
-
-
10.4.2
SSH 4 topics-
10.4.2.1Symmetric Encryption
-
10.4.2.2Asymmetrical Encryption
-
10.4.2.3Hashing
-
10.4.2.4Hydra - SSH
-
-
10.4.3
Remote Desktop Protocol (RDP) 2 topics-
10.4.3.1Hydra - RDP
-
10.4.3.2xFreeRDP
-
-
10.4.4
SMB 5 topics-
10.4.4.1Hydra - SMB
-
10.4.4.2Hydra - Error
-
10.4.4.3Metasploit Framework
-
10.4.4.4CrackMapExec
-
10.4.4.5Smbclient
-
-
-
10.5
Password Mutations 1 topic-
10.5.1
Password List 4 topics-
10.5.1.1Hashcat Rule File
-
10.5.1.2Generating Rule-based Wordlist
-
10.5.1.3Hashcat Existing Rules
-
10.5.1.4Generating Wordlists Using CeWL
-
-
-
10.6
Password Reuse / Default Passwords 1 topic-
10.6.1
Credential Stuffing 3 topics-
10.6.1.1Credential Stuffing - Hydra Syntax
-
10.6.1.2Credential Stuffing - Hydra
-
10.6.1.3Google Search - Default Credentials
-
-
-
10.7
Attacking SAM 4 topics-
10.7.1
Copying SAM Registry Hives 4 topics-
10.7.1.1Using reg.exe save to Copy Registry Hives
-
10.7.1.2Creating a Share with smbserver.py
-
10.7.1.3Moving Hive Copies to Share
-
10.7.1.4Confirming Hive Copies Transferred to Attack Host
-
-
10.7.2
Dumping Hashes with Impacket's secretsdump.py 2 topics-
10.7.2.1Locating secretsdump.py
-
10.7.2.2Running secretsdump.py
-
-
10.7.3
Cracking Hashes with Hashcat 2 topics-
10.7.3.1Adding nthashes to a .txt File
-
10.7.3.2Running Hashcat against NT Hashes
-
-
10.7.4
Remote Dumping & LSA Secrets Considerations 2 topics-
10.7.4.1Dumping LSA Secrets Remotely
-
10.7.4.2Dumping SAM Remotely
-
-
-
10.8
Attacking LSASS 2 topics-
10.8.1
Dumping LSASS Process Memory 5 topics-
10.8.1.1Task Manager Method
-
10.8.1.2Rundll32.exe & Comsvcs.dll Method
-
10.8.1.3Finding LSASS PID in cmd
-
10.8.1.4Finding LSASS PID in PowerShell
-
10.8.1.5Creating lsass.dmp using PowerShell
-
-
10.8.2
Using Pypykatz to Extract Credentials 6 topics-
10.8.2.1Running Pypykatz
-
10.8.2.2MSV
-
10.8.2.3WDIGEST
-
10.8.2.4Kerberos
-
10.8.2.5DPAPI
-
10.8.2.6Cracking the NT Hash with Hashcat
-
-
-
10.9
Attacking Active Directory & NTDS.dit 4 topics-
10.9.1
Dictionary Attacks against AD accounts using CrackMapExec 3 topics-
10.9.1.1Creating a Custom list of Usernames
-
10.9.1.2Launching the Attack with CrackMapExec
-
10.9.1.3Event Logs from the Attack
-
-
10.9.2
Capturing NTDS.dit 7 topics-
10.9.2.1Connecting to a DC with Evil-WinRM
-
10.9.2.2Checking Local Group Membership
-
10.9.2.3Checking User Account Privileges including Domain
-
10.9.2.4Creating Shadow Copy of C:
-
10.9.2.5Copying NTDS.dit from the VSS
-
10.9.2.6Transferring NTDS.dit to Attack Host
-
10.9.2.7A Faster Method: Using cme to Capture NTDS.dit
-
-
10.9.3
Cracking Hashes & Gaining Credentials 1 topic-
10.9.3.1Cracking a Single Hash with Hashcat
-
-
10.9.4
Pass-the-Hash Considerations 1 topic-
10.9.4.1Pass-the-Hash with Evil-WinRM Example
-
-
-
10.10
Credential Hunting in Windows 3 topics-
10.10.1
Search Centric 1 topic-
10.10.1.1Key Terms to Search
-
-
10.10.2
Search Tools 3 topics-
10.10.2.1Running Lazagne All
-
10.10.2.2Lazagne Output
-
10.10.2.3Using findstr
-
-
10.10.3Additional Considerations
-
-
10.11
Credential Hunting in Linux 3 topics-
10.11.1
Files 9 topics-
10.11.1.1Configuration Files
-
10.11.1.2Credentials in Configuration Files
-
10.11.1.3Databases
-
10.11.1.4Notes
-
10.11.1.5Scripts
-
10.11.1.6Cronjobs
-
10.11.1.7SSH Keys
-
10.11.1.8SSH Private Keys
-
10.11.1.9SSH Public Keys
-
-
10.11.2
History 2 topics-
10.11.2.1Bash History
-
10.11.2.2Logs
-
-
10.11.3
Memory and Cache 6 topics-
10.11.3.1Memory - Mimipenguin
-
10.11.3.2Memory - LaZagne
-
10.11.3.3Browsers
-
10.11.3.4Firefox Stored Credentials
-
10.11.3.5Decrypting Firefox Credentials
-
10.11.3.6Browsers - LaZagne
-
-
-
10.12
Passwd, Shadow & Opasswd 4 topics-
10.12.1
Passwd File 4 topics-
10.12.1.1Passwd Format
-
10.12.1.2Editing /etc/passwd - Before
-
10.12.1.3Editing /etc/passwd - After
-
10.12.1.4Root without Password
-
-
10.12.2
Shadow File 3 topics-
10.12.2.1Shadow Format
-
10.12.2.2Shadow File
-
10.12.2.3Algorithm Types
-
-
10.12.3
Opasswd 1 topic-
10.12.3.1Reading /etc/security/opasswd
-
-
10.12.4
Cracking Linux Credentials 3 topics-
10.12.4.1Unshadow
-
10.12.4.2Hashcat - Cracking Unshadowed Hashes
-
10.12.4.3Hashcat - Cracking MD5 Hashes
-
-
-
10.13
Pass the Hash (PtH) 9 topics-
10.13.1Windows NTLM Introduction
-
10.13.2
Pass the Hash with Mimikatz (Windows) 1 topic-
10.13.2.1Pass the Hash from Windows Using Mimikatz:
-
-
10.13.3
Pass the Hash with PowerShell Invoke-TheHash (Windows) 3 topics-
10.13.3.1Invoke-TheHash with SMB
-
10.13.3.2Netcat Listener
-
10.13.3.3Invoke-TheHash with WMI
-
-
10.13.4
Pass the Hash with Impacket (Linux) 1 topic-
10.13.4.1Pass the Hash with Impacket PsExec
-
-
10.13.5
Pass the Hash with CrackMapExec (Linux) 2 topics-
10.13.5.1Pass the Hash with CrackMapExec
-
10.13.5.2CrackMapExec - Command Execution
-
-
10.13.6
Pass the Hash with evil-winrm (Linux) 1 topic-
10.13.6.1Pass the Hash with evil-winrm
-
-
10.13.7
Pass the Hash with RDP (Linux) 2 topics-
10.13.7.1Enable Restricted Admin Mode to Allow PtH
-
10.13.7.2Pass the Hash Using RDP
-
-
10.13.8UAC Limits Pass the Hash for Local Accounts
-
10.13.9Next Steps
-
-
10.14
Pass the Ticket (PtT) from Windows 10 topics-
10.14.1Kerberos Protocol Refresher
-
10.14.2Pass the Ticket (PtT) Attack
-
10.14.3Scenario
-
10.14.4
Harvesting Kerberos Tickets from Windows 2 topics-
10.14.4.1Mimikatz - Export Tickets
-
10.14.4.2Rubeus - Export Tickets
-
-
10.14.5
Pass the Key or OverPass the Hash 3 topics-
10.14.5.1Mimikatz - Extract Kerberos Keys
-
10.14.5.2Mimikatz - Pass the Key or OverPass the Hash
-
10.14.5.3Rubeus - Pass the Key or OverPass the Hash
-
-
10.14.6
Pass the Ticket (PtT) 5 topics-
10.14.6.1Rubeus Pass the Ticket
-
10.14.6.2Rubeus - Pass the Ticket
-
10.14.6.3Convert .kirbi to Base64 Format
-
10.14.6.4Pass the Ticket - Base64 Format
-
10.14.6.5Mimikatz - Pass the Ticket
-
-
10.14.7Pass The Ticket with PowerShell Remoting (Windows)
-
10.14.8
Mimikatz - PowerShell Remoting with Pass the Ticket 1 topic-
10.14.8.1Mimikatz - Pass the Ticket for Lateral Movement.
-
-
10.14.9
Rubeus - PowerShell Remoting with Pass the Ticket 2 topics-
10.14.9.1Create a Sacrificial Process with Rubeus
-
10.14.9.2Rubeus - Pass the Ticket for Lateral Movement
-
-
10.14.10Moving On
-
-
10.15
Pass the Ticket (PtT) from Linux 12 topics-
10.15.1Kerberos on Linux
-
10.15.2
Scenario 2 topics-
10.15.2.1Linux Auth from MS01 Image
-
10.15.2.2Linux Auth via Port Forward
-
-
10.15.3
Identifying Linux and Active Directory Integration 2 topics-
10.15.3.1realm - Check If Linux Machine is Domain Joined
-
10.15.3.2PS - Check if Linux Machine is Domain Joined
-
-
10.15.4Finding Kerberos Tickets in Linux
-
10.15.5
Finding Keytab Files 2 topics-
10.15.5.1Using Find to Search for Files with Keytab in the Name
-
10.15.5.2Identifying Keytab Files in Cronjobs
-
-
10.15.6
Finding ccache Files 2 topics-
10.15.6.1Reviewing Environment Variables for ccache Files.
-
10.15.6.2Searching for ccache Files in /tmp
-
-
10.15.7
Abusing KeyTab Files 7 topics-
10.15.7.1Listing keytab File Information
-
10.15.7.2Impersonating a User with a keytab
-
10.15.7.3Connecting to SMB Share as Carlos
-
10.15.7.4Keytab Extract
-
10.15.7.5Extracting Keytab Hashes with KeyTabExtract
-
10.15.7.6Log in as Carlos
-
10.15.7.7Obtaining More Hashes
-
-
10.15.8
Abusing Keytab ccache 4 topics-
10.15.8.1Privilege Escalation to Root
-
10.15.8.2Looking for ccache Files
-
10.15.8.3Identifying Group Membership with the id Command
-
10.15.8.4Importing the ccache File into our Current Session
-
-
10.15.9
Using Linux Attack Tools with Kerberos 14 topics-
10.15.9.1Host File Modified
-
10.15.9.2Proxychains Configuration File
-
10.15.9.3Download Chisel to our Attack Host
-
10.15.9.4Connect to MS01 with xfreerdp
-
10.15.9.5Execute chisel from MS01
-
10.15.9.6Setting the KRB5CCNAME Environment Variable
-
10.15.9.7Impacket
-
10.15.9.8Using Impacket with proxychains and Kerberos Authentication
-
10.15.9.9Evil-Winrm
-
10.15.9.10Installing Kerberos Authentication Package
-
10.15.9.11Default Kerberos Version 5 realm
-
10.15.9.12Administrative Server for your Kerberos Realm
-
10.15.9.13Kerberos Configuration File for INLANEFREIGHT.HTB
-
10.15.9.14Using Evil-WinRM with Kerberos
-
-
10.15.10
Miscellaneous 2 topics-
10.15.10.1Impacket Ticket Converter
-
10.15.10.2Importing Converted Ticket into Windows Session with Rubeus
-
-
10.15.11
Linikatz 1 topic-
10.15.11.1Linikatz Download and Execution
-
-
10.15.12Onwards
-
-
10.16
Protected Files 3 topics-
10.16.1
Hunting for Encoded Files 3 topics-
10.16.1.1Hunting for Files
-
10.16.1.2Hunting for SSH Keys
-
10.16.1.3Encrypted SSH Keys
-
-
10.16.2
Cracking with John 2 topics-
10.16.2.1John Hashing Scripts
-
10.16.2.2Cracking SSH Keys
-
-
10.16.3
Cracking Documents 2 topics-
10.16.3.1Cracking Microsoft Office Documents
-
10.16.3.2Cracking PDFs
-
-
-
10.17
Protected Archives 5 topics-
10.17.1Download All File Extensions
-
10.17.2Cracking Archives
-
10.17.3
Cracking ZIP 4 topics-
10.17.3.1Using zip2john
-
10.17.3.2Viewing the Contents of zip.hash
-
10.17.3.3Cracking the Hash with John
-
10.17.3.4Viewing the Cracked Hash
-
-
10.17.4
Cracking OpenSSL Encrypted Archives 4 topics-
10.17.4.1Listing the Files
-
10.17.4.2Using file
-
10.17.4.3Using a for-loop to Display Extracted Contents
-
10.17.4.4Listing the Contents of the Cracked Archive
-
-
10.17.5
Cracking BitLocker Encrypted Drives 4 topics-
10.17.5.1Using bitlocker2john
-
10.17.5.2Using hashcat to Crack backup.hash
-
10.17.5.3Viewing the Cracked Hash
-
10.17.5.4Windows - Mounting BitLocker VHD
-
-
-
10.18
Password Policies 5 topics-
10.18.1Password Policy
-
10.18.2Password Policy Standards
-
10.18.3Password Policy Recommendations
-
10.18.4Enforcing Password Policy
-
10.18.5Creating a Good password
-
-
10.19
Password Managers 6 topics-
10.19.1How Does a Password Manager Work?
-
10.19.2Online Password Managers
-
10.19.3Local Password Managers
-
10.19.4Features
-
10.19.5Alternatives
-
10.19.6Passwordless
-
-
10.20Password Attacks Lab - Easy
-
10.21Password Attacks Lab - Medium
-
10.22Password Attacks Lab - Hard
11 Attacking Common Services Attacking Common Services module 195 topics Module 11
-
11.1
Interacting with Common Services 5 topics-
11.1.1File Share Services
-
11.1.2
Server Message Block (SMB) 13 topics-
11.1.2.1Windows
-
11.1.2.2Windows CMD - DIR
-
11.1.2.3Windows CMD - Net Use
-
11.1.2.4Windows CMD - DIR
-
11.1.2.5Windows CMD - Findstr
-
11.1.2.6Windows PowerShell
-
11.1.2.7Windows PowerShell - PSCredential Object
-
11.1.2.8Windows PowerShell - GCI
-
11.1.2.9Windows PowerShell - Select-String
-
11.1.2.10Linux
-
11.1.2.11Linux - Mount
-
11.1.2.12CredentialFile
-
11.1.2.13Linux - Find
-
-
11.1.3
Other Services 5 topics-
11.1.3.1Email
-
11.1.3.2Linux - Install Evolution
-
11.1.3.3Video - Connecting to IMAP and SMTP using Evolution
-
11.1.3.4Databases
-
11.1.3.5MySQL example
-
-
11.1.4
Command Line Utilities 13 topics-
11.1.4.1MSSQL
-
11.1.4.2Linux - SQSH
-
11.1.4.3Windows - SQLCMD
-
11.1.4.4MySQL
-
11.1.4.5Linux - MySQL
-
11.1.4.6Windows - MySQL
-
11.1.4.7GUI Application
-
11.1.4.8Install dbeaver
-
11.1.4.9Run dbeaver
-
11.1.4.10Video - Connecting to MSSQL DB using dbeaver
-
11.1.4.11Video - Connecting to MySQL DB using dbeaver
-
11.1.4.12Tools
-
11.1.4.13Tools to Interact with Common Services
-
-
11.1.5General Troubleshooting
-
-
11.2
The Concept of Attacks 5 topics-
11.2.1The Concept of Attacks
-
11.2.2
Source 1 topic-
11.2.2.1Log4j
-
-
11.2.3
Processes 1 topic-
11.2.3.1Log4j
-
-
11.2.4
Privileges 1 topic-
11.2.4.1Log4j
-
-
11.2.5
Destination 3 topics-
11.2.5.1Log4j
-
11.2.5.2Initiation of the Attack
-
11.2.5.3Trigger Remote Code Execution
-
-
-
11.3
Service Misconfigurations 3 topics-
11.3.1
Authentication 2 topics-
11.3.1.1Anonymous Authentication
-
11.3.1.2Misconfigured Access Rights
-
-
11.3.2Unnecessary Defaults
-
11.3.3Preventing Misconfiguration
-
-
11.4
Finding Sensitive Information 1 topic-
11.4.1Understanding of What We Have to Look for
-
-
11.5
Attacking FTP 3 topics-
11.5.1
Enumeration 1 topic-
11.5.1.1Nmap
-
-
11.5.2
Misconfigurations 1 topic-
11.5.2.1Anonymous Authentication
-
-
11.5.3
Protocol Specifics Attacks 3 topics-
11.5.3.1Brute Forcing
-
11.5.3.2Brute Forcing with Medusa
-
11.5.3.3FTP Bounce Attack
-
-
-
11.6
Latest FTP Vulnerabilities 1 topic-
11.6.1
The Concept of the Attack 5 topics-
11.6.1.1CoreFTP Exploitation
-
11.6.1.2The Concept of Attacks
-
11.6.1.3Directory Traversal
-
11.6.1.4Arbitrary File Write
-
11.6.1.5Target System
-
-
-
11.7
Attacking SMB 3 topics-
11.7.1Enumeration
-
11.7.2
Misconfigurations 3 topics-
11.7.2.1Anonymous Authentication
-
11.7.2.2File Share
-
11.7.2.3Remote Procedure Call (RPC)
-
-
11.7.3
Protocol Specifics Attacks 10 topics-
11.7.3.1Brute Forcing and Password Spray
-
11.7.3.2SMB
-
11.7.3.3Remote Code Execution (RCE)
-
11.7.3.4Impacket PsExec
-
11.7.3.5CrackMapExec
-
11.7.3.6Enumerating Logged-on Users
-
11.7.3.7Extract Hashes from SAM Database
-
11.7.3.8Pass-the-Hash (PtH)
-
11.7.3.9Forced Authentication Attacks
-
11.7.3.10RPC
-
-
-
11.8
Latest SMB Vulnerabilities 1 topic-
11.8.1
The Concept of the Attack 3 topics-
11.8.1.1The Concept of Attacks
-
11.8.1.2Initiation of the Attack
-
11.8.1.3Trigger Remote Code Execution
-
-
-
11.9
Attacking SQL Databases 9 topics-
11.9.1
Enumeration 1 topic-
11.9.1.1Banner Grabbing
-
-
11.9.2
Authentication Mechanisms 2 topics-
11.9.2.1Misconfigurations
-
11.9.2.2Privileges
-
-
11.9.3
Protocol Specific Attacks 9 topics-
11.9.3.1Read/Change the Database
-
11.9.3.2MySQL - Connecting to the SQL Server
-
11.9.3.3Sqlcmd - Connecting to the SQL Server
-
11.9.3.4SQL Default Databases
-
11.9.3.5SQL Syntax
-
11.9.3.6Show Databases
-
11.9.3.7Select a Database
-
11.9.3.8Show Tables
-
11.9.3.9Select all Data from Table "users"
-
-
11.9.4
Execute Commands 1 topic-
11.9.4.1XP_CMDSHELL
-
-
11.9.5
Write Local Files 4 topics-
11.9.5.1MySQL - Write Local File
-
11.9.5.2MySQL - Secure File Privileges
-
11.9.5.3MSSQL - Enable Ole Automation Procedures
-
11.9.5.4MSSQL - Create a File
-
-
11.9.6
Read Local Files 2 topics-
11.9.6.1Read Local Files in MSSQL
-
11.9.6.2MySQL - Read Local Files in MySQL
-
-
11.9.7
Capture MSSQL Service Hash 4 topics-
11.9.7.1XP_DIRTREE Hash Stealing
-
11.9.7.2XP_SUBDIRS Hash Stealing
-
11.9.7.3XP_SUBDIRS Hash Stealing with Responder
-
11.9.7.4XP_SUBDIRS Hash Stealing with impacket
-
-
11.9.8
Impersonate Existing Users with MSSQL 3 topics-
11.9.8.1Identify Users that We Can Impersonate
-
11.9.8.2Verifying our Current User and Role
-
11.9.8.3Impersonating the SA User
-
-
11.9.9
Communicate with Other Databases with MSSQL 1 topic-
11.9.9.1Identify linked Servers in MSSQL
-
-
-
11.10
Latest SQL Vulnerabilities 1 topic-
11.10.1
The Concept of the Attack 3 topics-
11.10.1.1The Concept of Attacks
-
11.10.1.2Initiation of the Attack
-
11.10.1.3Steal The Hash
-
-
-
11.11
Attacking RDP 3 topics-
11.11.1
Misconfigurations 3 topics-
11.11.1.1Crowbar - RDP Password Spraying
-
11.11.1.2Hydra - RDP Password Spraying
-
11.11.1.3RDP Login
-
-
11.11.2
Protocol Specific Attacks 1 topic-
11.11.2.1RDP Session Hijacking
-
-
11.11.3
RDP Pass-the-Hash (PtH) 1 topic-
11.11.3.1Adding the DisableRestrictedAdmin Registry Key
-
-
-
11.12
Latest RDP Vulnerabilities 1 topic-
11.12.1
The Concept of the Attack 3 topics-
11.12.1.1The Concept of Attacks
-
11.12.1.2Initiation of the Attack
-
11.12.1.3Trigger Remote Code Execution
-
-
-
11.13
Attacking DNS 4 topics-
11.13.1Enumeration
-
11.13.2
DNS Zone Transfer 1 topic-
11.13.2.1DIG - AXFR Zone Transfer
-
-
11.13.3
Domain Takeovers & Subdomain Enumeration 2 topics-
11.13.3.1Subdomain Enumeration
-
11.13.3.2Subbrute
-
-
11.13.4
DNS Spoofing 1 topic-
11.13.4.1Local DNS Cache Poisoning
-
-
-
11.14
Latest DNS Vulnerabilities 2 topics-
11.14.1RedHuntLabs Study
-
11.14.2
The Concept of the Attack 3 topics-
11.14.2.1The Concept of Attacks
-
11.14.2.2Initiation of Subdomain Takeover
-
11.14.2.3Trigger the Forwarding
-
-
-
11.15
Attacking Email Services 5 topics-
11.15.1
Enumeration 3 topics-
11.15.1.1Host - MX Records
-
11.15.1.2DIG - MX Records
-
11.15.1.3Host - A Records
-
-
11.15.2
Misconfigurations 5 topics-
11.15.2.1Authentication
-
11.15.2.2VRFY Command
-
11.15.2.3EXPN Command
-
11.15.2.4RCPT TO Command
-
11.15.2.5USER Command
-
-
11.15.3
Cloud Enumeration 1 topic-
11.15.3.1O365 Spray
-
-
11.15.4
Password Attacks 2 topics-
11.15.4.1Hydra - Password Attack
-
11.15.4.2O365 Spray - Password Spraying
-
-
11.15.5
Protocol Specifics Attacks 1 topic-
11.15.5.1Open Relay
-
-
-
11.16
Latest Email Service Vulnerabilities 3 topics-
11.16.1
Shodan Search 1 topic-
11.16.1.1Shodan Trend
-
-
11.16.2
The Concept of the Attack 3 topics-
11.16.2.1The Concept of Attacks
-
11.16.2.2Initiation of the Attack
-
11.16.2.3Trigger Remote Code Execution
-
-
11.16.3Next Steps
-
-
11.17Attacking Common Services - Easy
-
11.18Attacking Common Services - Medium
-
11.19Attacking Common Services - Hard
12 Pivoting, Tunneling, and Port Forwarding Pivoting, Tunneling, and Port Forwarding module 162 topics Module 12
-
12.1
Introduction to Pivoting, Tunneling, and Port Forwarding 1 topic-
12.1.1
Lateral Movement, Pivoting, and Tunneling Compared 3 topics-
12.1.1.1Lateral Movement
-
12.1.1.2Pivoting
-
12.1.1.3Tunneling
-
-
-
12.2
The Networking Behind Pivoting 3 topics-
12.2.1
IP Addressing & NICs 2 topics-
12.2.1.1Using ifconfig
-
12.2.1.2Using ipconfig
-
-
12.2.2
Routing 1 topic-
12.2.2.1Routing Table on Pwnbox
-
-
12.2.3
Protocols, Services & Ports 1 topic-
12.2.3.1Questions
-
-
-
12.3
Dynamic Port Forwarding with SSH and SOCKS Tunneling 4 topics-
12.3.1Port Forwarding in Context
-
12.3.2
SSH Local Port Forwarding 5 topics-
12.3.2.1Scanning the Pivot Target
-
12.3.2.2Executing the Local Port Forward
-
12.3.2.3Confirming Port Forward with Netstat
-
12.3.2.4Confirming Port Forward with Nmap
-
12.3.2.5Forwarding Multiple Ports
-
-
12.3.3
Setting up to Pivot 5 topics-
12.3.3.1Looking for Opportunities to Pivot using ifconfig
-
12.3.3.2Enabling Dynamic Port Forwarding with SSH
-
12.3.3.3Checking /etc/proxychains.conf
-
12.3.3.4Using Nmap with Proxychains
-
12.3.3.5Enumerating the Windows Target through Proxychains
-
-
12.3.4
Using Metasploit with Proxychains 3 topics-
12.3.4.1Using rdp_scanner Module
-
12.3.4.2Using xfreerdp with Proxychains
-
12.3.4.3Successful RDP Pivot
-
-
-
12.4
Remote/Reverse Port Forwarding with SSH 1 topic-
12.4.1
Creating a Windows Payload with msfvenom 7 topics-
12.4.1.1Configuring & Starting the multi/handler
-
12.4.1.2Transferring Payload to Pivot Host
-
12.4.1.3Starting Python3 Webserver on Pivot Host
-
12.4.1.4Downloading Payload on the Windows Target
-
12.4.1.5Using SSH -R
-
12.4.1.6Viewing the Logs from the Pivot
-
12.4.1.7Meterpreter Session Established
-
-
-
12.5
Meterpreter Tunneling & Port Forwarding 3 topics-
12.5.1
Creating Payload for Ubuntu Pivot Host 13 topics-
12.5.1.1Configuring & Starting the multi/handler
-
12.5.1.2Executing the Payload on the Pivot Host
-
12.5.1.3Meterpreter Session Establishment
-
12.5.1.4Ping Sweep
-
12.5.1.5Ping Sweep For Loop on Linux Pivot Hosts
-
12.5.1.6Ping Sweep For Loop Using CMD
-
12.5.1.7Ping Sweep Using PowerShell
-
12.5.1.8Configuring MSF's SOCKS Proxy
-
12.5.1.9Confirming Proxy Server is Running
-
12.5.1.10Adding a Line to proxychains.conf if Needed
-
12.5.1.11Creating Routes with AutoRoute
-
12.5.1.12Listing Active Routes with AutoRoute
-
12.5.1.13Testing Proxy & Routing Functionality
-
-
12.5.2
Port Forwarding 4 topics-
12.5.2.1Portfwd options
-
12.5.2.2Creating Local TCP Relay
-
12.5.2.3Connecting to Windows Target through localhost
-
12.5.2.4Netstat Output
-
-
12.5.3
Meterpreter Reverse Port Forwarding 4 topics-
12.5.3.1Reverse Port Forwarding Rules
-
12.5.3.2Configuring & Starting multi/handler
-
12.5.3.3Generating the Windows Payload
-
12.5.3.4Establishing the Meterpreter session
-
-
-
12.6
Socat Redirection with a Reverse Shell 1 topic-
12.6.1
Starting Socat Listener 4 topics-
12.6.1.1Creating the Windows Payload
-
12.6.1.2Starting MSF Console
-
12.6.1.3Configuring & Starting the multi/handler
-
12.6.1.4Establishing the Meterpreter Session
-
-
-
12.7
Socat Redirection with a Bind Shell 1 topic-
12.7.1
Creating the Windows Payload 3 topics-
12.7.1.1Starting Socat Bind Shell Listener
-
12.7.1.2Configuring & Starting the Bind multi/handler
-
12.7.1.3Establishing Meterpreter Session
-
-
-
12.8
SSH for Windows: plink.exe 1 topic-
12.8.1
Getting To Know Plink 1 topic-
12.8.1.1Using Plink.exe
-
-
-
12.9
SSH Pivoting with Sshuttle 1 topic-
12.9.1
Installing sshuttle 2 topics-
12.9.1.1Running sshuttle
-
12.9.1.2Traffic Routing through iptables Routes
-
-
-
12.10
Web Server Pivoting with Rpivot 1 topic-
12.10.1
Cloning rpivot 8 topics-
12.10.1.1Installing Python2.7
-
12.10.1.2Alternative Installation of Python2.7
-
12.10.1.3Running server.py from the Attack Host
-
12.10.1.4Transfering rpivot to the Target
-
12.10.1.5Running client.py from Pivot Target
-
12.10.1.6Confirming Connection is Established
-
12.10.1.7Browsing to the Target Webserver using Proxychains
-
12.10.1.8Connecting to a Web Server using HTTP-Proxy & NTLM Auth
-
-
-
12.11
Port Forwarding with Windows Netsh 1 topic-
12.11.1
Using Netsh.exe to Port Forward 2 topics-
12.11.1.1Verifying Port Forward
-
12.11.1.2Connecting to the Internal Host through the Port Forward
-
-
-
12.12
DNS Tunneling with Dnscat2 1 topic-
12.12.1
Setting Up & Using dnscat2 7 topics-
12.12.1.1Cloning dnscat2 and Setting Up the Server
-
12.12.1.2Starting the dnscat2 server
-
12.12.1.3Cloning dnscat2-powershell to the Attack Host
-
12.12.1.4Importing dnscat2.ps1
-
12.12.1.5Confirming Session Establishment
-
12.12.1.6Listing dnscat2 Options
-
12.12.1.7Interacting with the Established Session
-
-
-
12.13
SOCKS5 Tunneling with Chisel 2 topics-
12.13.1
Setting Up & Using Chisel 7 topics-
12.13.1.1Cloning Chisel
-
12.13.1.2Building the Chisel Binary
-
12.13.1.3Transferring Chisel Binary to Pivot Host
-
12.13.1.4Running the Chisel Server on the Pivot Host
-
12.13.1.5Connecting to the Chisel Server
-
12.13.1.6Editing & Confirming proxychains.conf
-
12.13.1.7Pivoting to the DC
-
-
12.13.2
Chisel Reverse Pivot 3 topics-
12.13.2.1Starting the Chisel Server on our Attack Host
-
12.13.2.2Connecting the Chisel Client to our Attack Host
-
12.13.2.3Editing & Confirming proxychains.conf
-
-
-
12.14
ICMP Tunneling with SOCKS 2 topics-
12.14.1
Setting Up & Using ptunnel-ng 10 topics-
12.14.1.1Cloning Ptunnel-ng
-
12.14.1.2Building Ptunnel-ng with Autogen.sh
-
12.14.1.3Alternative approach of building a static binary
-
12.14.1.4Transferring Ptunnel-ng to the Pivot Host
-
12.14.1.5Starting the ptunnel-ng Server on the Target Host
-
12.14.1.6Connecting to ptunnel-ng Server from Attack Host
-
12.14.1.7Tunneling an SSH connection through an ICMP Tunnel
-
12.14.1.8Viewing Tunnel Traffic Statistics
-
12.14.1.9Enabling Dynamic Port Forwarding over SSH
-
12.14.1.10Proxychaining through the ICMP Tunnel
-
-
12.14.2Network Traffic Analysis Considerations
-
-
12.15
RDP and SOCKS Tunneling with SocksOverRDP 1 topic-
12.15.1
Loading SocksOverRDP.dll using regsvr32.exe 3 topics-
12.15.1.1Confirming the SOCKS Listener is Started
-
12.15.1.2Configuring Proxifier
-
12.15.1.3RDP Performance Considerations
-
-
-
12.16
Skills Assessment 3 topics-
12.16.1Scenario
-
12.16.2Objectives
-
12.16.3Connection Info
-
-
12.17
Detection & Prevention 4 topics-
12.17.1
Setting a Baseline 1 topic-
12.17.1.1Things to Document and Track
-
-
12.17.2
People, Processes, and Technology 4 topics-
12.17.2.1People
-
12.17.2.2BYOD and Other Concerns
-
12.17.2.3Processes
-
12.17.2.4Technology
-
-
12.17.3
From the Outside Moving In 2 topics-
12.17.3.1Perimeter First
-
12.17.3.2Internal Considerations
-
-
12.17.4MITRE Breakdown
-
-
12.18
Beyond this Module 4 topics-
12.18.1Real World
-
12.18.2What's Next?
-
12.18.3
Pivoting & Tunneling Into Other Learning Opportunities 4 topics-
12.18.3.1Boxes To Pwn
-
12.18.3.2ProLabs
-
12.18.3.3Endgames
-
12.18.3.4Writers/Educational Creators and Blogs To Follow
-
-
12.18.4Closing Thoughts
-
13 Active Directory Enumeration & Attacks Active Directory Enumeration & Attacks module 564 topics Module 13
-
13.1
Introduction to Active Directory Enumeration & Attacks 6 topics-
13.1.1Active Directory Explained
-
13.1.2Why Should We Care About AD?
-
13.1.3Real-World Examples
-
13.1.4This Is The Way
-
13.1.5
Practical Examples 3 topics-
13.1.5.1Connecting via FreeRDP
-
13.1.5.2Connecting via SSH
-
13.1.5.3Xfreerdp to the ATTACK01 Parrot Host
-
-
13.1.6Toolkit
-
-
13.2Tools of the Trade
-
13.3
Scenario 4 topics-
13.3.1Tasking Email
-
13.3.2
Assessment Scope 2 topics-
13.3.2.1In Scope For Assessment
-
13.3.2.2Out Of Scope
-
-
13.3.3
Methods Used 3 topics-
13.3.3.1External Information Gathering (Passive Checks)
-
13.3.3.2Internal Testing
-
13.3.3.3Password Testing
-
-
13.3.4The Stage Is Set
-
-
13.4
External Recon and Enumeration Principles 4 topics-
13.4.1What Are We Looking For?
-
13.4.2
Where Are We Looking? 5 topics-
13.4.2.1Finding Address Spaces
-
13.4.2.2DNS
-
13.4.2.3Viewdns.info
-
13.4.2.4Public Data
-
13.4.2.5Sharepoint Admin Job Listing
-
-
13.4.3Overarching Enumeration Principles
-
13.4.4
Example Enumeration Process 7 topics-
13.4.4.1Check for ASN/IP & Domain Data
-
13.4.4.2Viewdns Results
-
13.4.4.3Hunting For Files
-
13.4.4.4Hunting E-mail Addresses
-
13.4.4.5E-mail Dork Results
-
13.4.4.6Username Harvesting
-
13.4.4.7Credential Hunting
-
-
-
13.5
Initial Enumeration of the Domain 7 topics-
13.5.1Setting Up
-
13.5.2
Tasks 1 topic-
13.5.2.1Key Data Points
-
-
13.5.3
TTPs 9 topics-
13.5.3.1Identifying Hosts
-
13.5.3.2Start Wireshark on ea-attack01
-
13.5.3.3Wireshark Output
-
13.5.3.4Tcpdump Output
-
13.5.3.5Starting Responder
-
13.5.3.6Responder Results
-
13.5.3.7FPing Active Checks
-
13.5.3.8Nmap Scanning
-
13.5.3.9NMAP Result Highlights
-
-
13.5.4
Identifying Users 9 topics-
13.5.4.1Kerbrute - Internal AD Username Enumeration
-
13.5.4.2Cloning Kerbrute GitHub Repo
-
13.5.4.3Listing Compiling Options
-
13.5.4.4Compiling for Multiple Platforms and Architectures
-
13.5.4.5Listing the Compiled Binaries in dist
-
13.5.4.6Testing the kerbrute_linux_amd64 Binary
-
13.5.4.7Adding the Tool to our Path
-
13.5.4.8Moving the Binary
-
13.5.4.9Enumerating Users with Kerbrute
-
-
13.5.5Identifying Potential Vulnerabilities
-
13.5.6A Word Of Caution
-
13.5.7Let's Find a User
-
-
13.6
LLMNR/NBT-NS Poisoning - from Linux 4 topics-
13.6.1LLMNR & NBT-NS Primer
-
13.6.2Quick Example - LLMNR/NBT-NS Poisoning
-
13.6.3
TTPs 5 topics-
13.6.3.1Responder In Action
-
13.6.3.2Responder Logs
-
13.6.3.3Starting Responder with Default Settings
-
13.6.3.4Capturing with Responder
-
13.6.3.5Cracking an NTLMv2 Hash With Hashcat
-
-
13.6.4Moving On
-
-
13.7
LLMNR/NBT-NS Poisoning - from Windows 6 topics-
13.7.1Inveigh - Overview
-
13.7.2Using Inveigh
-
13.7.3C# Inveigh (InveighZero)
-
13.7.4Remediation
-
13.7.5Detection
-
13.7.6Moving On
-
-
13.8
Password Spraying Overview 2 topics-
13.8.1
Story Time 2 topics-
13.8.1.1Scenario 1
-
13.8.1.2Scenario 2
-
-
13.8.2
Password Spraying Considerations 1 topic-
13.8.2.1Password Spray Visualization
-
-
-
13.9
Enumerating & Retrieving Password Policies 7 topics-
13.9.1Enumerating the Password Policy - from Linux - Credentialed
-
13.9.2
Enumerating the Password Policy - from Linux - SMB NULL Sessions 5 topics-
13.9.2.1Using rpcclient
-
13.9.2.2Obtaining the Password Policy using rpcclient
-
13.9.2.3Using enum4linux
-
13.9.2.4Using enum4linux-ng
-
13.9.2.5Displaying the contents of ilfreight.json
-
-
13.9.3
Enumerating Null Session - from Windows 4 topics-
13.9.3.1Establish a null session from windows
-
13.9.3.2Error: Account is Disabled
-
13.9.3.3Error: Password is Incorrect
-
13.9.3.4Error: Account is locked out (Password Policy)
-
-
13.9.4
Enumerating the Password Policy - from Linux - LDAP Anonymous Bind 1 topic-
13.9.4.1Using ldapsearch
-
-
13.9.5
Enumerating the Password Policy - from Windows 2 topics-
13.9.5.1Using net.exe
-
13.9.5.2Using PowerView
-
-
13.9.6Analyzing the Password Policy
-
13.9.7Next Steps
-
-
13.10
Password Spraying - Making a Target User List 6 topics-
13.10.1Detailed User Enumeration
-
13.10.2
SMB NULL Session to Pull User List 3 topics-
13.10.2.1Using enum4linux
-
13.10.2.2Using rpcclient
-
13.10.2.3Using CrackMapExec --users Flag
-
-
13.10.3
Gathering Users with LDAP Anonymous 2 topics-
13.10.3.1Using ldapsearch
-
13.10.3.2Using windapsearch
-
-
13.10.4
Enumerating Users with Kerbrute 1 topic-
13.10.4.1Kerbrute User Enumeration
-
-
13.10.5
Credentialed Enumeration to Build our User List 1 topic-
13.10.5.1Using CrackMapExec with Valid Credentials
-
-
13.10.6Now for the Fun
-
-
13.11
Internal Password Spraying - from Linux 2 topics-
13.11.1
Internal Password Spraying from a Linux Host 4 topics-
13.11.1.1Using a Bash one-liner for the Attack
-
13.11.1.2Using Kerbrute for the Attack
-
13.11.1.3Using CrackMapExec & Filtering Logon Failures
-
13.11.1.4Validating the Credentials with CrackMapExec
-
-
13.11.2
Local Administrator Password Reuse 1 topic-
13.11.2.1Local Admin Spraying with CrackMapExec
-
-
-
13.12
Internal Password Spraying - from Windows 6 topics-
13.12.1Using DomainPasswordSpray.ps1
-
13.12.2Mitigations
-
13.12.3Other Considerations
-
13.12.4Detection
-
13.12.5External Password Spraying
-
13.12.6Moving Deeper
-
-
13.13
Enumerating Security Controls 5 topics-
13.13.1
Windows Defender 1 topic-
13.13.1.1Checking the Status of Defender with Get-MpComputerStatus
-
-
13.13.2
AppLocker 1 topic-
13.13.2.1Using Get-AppLockerPolicy cmdlet
-
-
13.13.3
PowerShell Constrained Language Mode 1 topic-
13.13.3.1Enumerating Language Mode
-
-
13.13.4
LAPS 3 topics-
13.13.4.1Using Find-LAPSDelegatedGroups
-
13.13.4.2Using Find-AdmPwdExtendedRights
-
13.13.4.3Using Get-LAPSComputers
-
-
13.13.5Conclusion
-
-
13.14
Credentialed Enumeration - from Linux 6 topics-
13.14.1
CrackMapExec 8 topics-
13.14.1.1CME Help Menu
-
13.14.1.2CME Options (SMB)
-
13.14.1.3CME - Domain User Enumeration
-
13.14.1.4CME - Domain Group Enumeration
-
13.14.1.5CME - Logged On Users
-
13.14.1.6CME Share Searching
-
13.14.1.7Share Enumeration - Domain Controller
-
13.14.1.8Spider_plus
-
-
13.14.2
SMBMap 2 topics-
13.14.2.1SMBMap To Check Access
-
13.14.2.2Recursive List Of All Directories
-
-
13.14.3
rpcclient 4 topics-
13.14.3.1SMB NULL Session with rpcclient
-
13.14.3.2rpcclient Enumeration
-
13.14.3.3RPCClient User Enumeration By RID
-
13.14.3.4Enumdomusers
-
-
13.14.4
Impacket Toolkit 4 topics-
13.14.4.1Psexec.py
-
13.14.4.2Using psexec.py
-
13.14.4.3wmiexec.py
-
13.14.4.4Using wmiexec.py
-
-
13.14.5
Windapsearch 3 topics-
13.14.5.1Windapsearch Help
-
13.14.5.2Windapsearch - Domain Admins
-
13.14.5.3Windapsearch - Privileged Users
-
-
13.14.6
Bloodhound.py 6 topics-
13.14.6.1BloodHound.py Options
-
13.14.6.2Executing BloodHound.py
-
13.14.6.3Viewing the Results
-
13.14.6.4Upload the Zip File into the BloodHound GUI
-
13.14.6.5Uploading the Zip File
-
13.14.6.6Searching for Relationships
-
-
-
13.15
Credentialed Enumeration - from Windows 6 topics-
13.15.1TTPs
-
13.15.2
ActiveDirectory PowerShell Module 8 topics-
13.15.2.1Discover Modules
-
13.15.2.2Load ActiveDirectory Module
-
13.15.2.3Get Domain Info
-
13.15.2.4Get-ADUser
-
13.15.2.5Checking For Trust Relationships
-
13.15.2.6Group Enumeration
-
13.15.2.7Detailed Group Info
-
13.15.2.8Group Membership
-
-
13.15.3
PowerView 5 topics-
13.15.3.1Domain User Information
-
13.15.3.2Recursive Group Membership
-
13.15.3.3Trust Enumeration
-
13.15.3.4Testing for Local Admin Access
-
13.15.3.5Finding Users With SPN Set
-
-
13.15.4SharpView
-
13.15.5Shares
-
13.15.6
Snaffler 6 topics-
13.15.6.1Snaffler Execution
-
13.15.6.2Snaffler in Action
-
13.15.6.3BloodHound
-
13.15.6.4SharpHound in Action
-
13.15.6.5Unsupported Operating Systems
-
13.15.6.6Local Admins
-
-
-
13.16
Living Off the Land 8 topics-
13.16.1Scenario
-
13.16.2
Env Commands For Host & Network Recon 3 topics-
13.16.2.1Basic Enumeration Commands
-
13.16.2.2Basic Enumeration
-
13.16.2.3Systeminfo
-
-
13.16.3
Harnessing PowerShell 8 topics-
13.16.3.1Quick Checks Using PowerShell
-
13.16.3.2Downgrade Powershell
-
13.16.3.3Examining the Powershell Event Log
-
13.16.3.4Starting V2 Logs
-
13.16.3.5Checking Defenses
-
13.16.3.6Firewall Checks
-
13.16.3.7Windows Defender Check (from CMD.exe)
-
13.16.3.8Get-MpComputerStatus
-
-
13.16.4
Am I Alone? 1 topic-
13.16.4.1Using qwinsta
-
-
13.16.5
Network Information 2 topics-
13.16.5.1Using arp -a
-
13.16.5.2Viewing the Routing Table
-
-
13.16.6
Windows Management Instrumentation (WMI) 1 topic-
13.16.6.1Quick WMI checks
-
-
13.16.7
Net Commands 5 topics-
13.16.7.1Table of Useful Net Commands
-
13.16.7.2Listing Domain Groups
-
13.16.7.3Information about a Domain User
-
13.16.7.4Net Commands Trick
-
13.16.7.5Running Net1 Command
-
-
13.16.8
Dsquery 10 topics-
13.16.8.1Dsquery DLL
-
13.16.8.2User Search
-
13.16.8.3Computer Search
-
13.16.8.4Wildcard Search
-
13.16.8.5Users With Specific Attributes Set (PASSWD_NOTREQD)
-
13.16.8.6Searching for Domain Controllers
-
13.16.8.7LDAP Filtering Explained
-
13.16.8.8UAC Values
-
13.16.8.9OID match strings
-
13.16.8.10Logical Operators
-
-
-
13.17
Kerberoasting - from Linux 6 topics-
13.17.1Kerberoasting Overview
-
13.17.2Kerberoasting - Performing the Attack
-
13.17.3Efficacy of the Attack
-
13.17.4Performing the Attack
-
13.17.5
Kerberoasting with GetUserSPNs.py 8 topics-
13.17.5.1Installing Impacket using Pip
-
13.17.5.2Listing GetUserSPNs.py Help Options
-
13.17.5.3Listing SPN Accounts with GetUserSPNs.py
-
13.17.5.4Requesting all TGS Tickets
-
13.17.5.5Requesting a Single TGS ticket
-
13.17.5.6Saving the TGS Ticket to an Output File
-
13.17.5.7Cracking the Ticket Offline with Hashcat
-
13.17.5.8Testing Authentication against a Domain Controller
-
-
13.17.6More Roasting
-
-
13.18
Kerberoasting - from Windows 6 topics-
13.18.1
Kerberoasting - Semi Manual method 3 topics-
13.18.1.1Enumerating SPNs with setspn.exe
-
13.18.1.2Targeting a Single User
-
13.18.1.3Retrieving All Tickets Using setspn.exe
-
-
13.18.2
Extracting Tickets from Memory with Mimikatz 6 topics-
13.18.2.1Preparing the Base64 Blob for Cracking
-
13.18.2.2Placing the Output into a File as .kirbi
-
13.18.2.3Extracting the Kerberos Ticket using kirbi2john.py
-
13.18.2.4Modifiying crack_file for Hashcat
-
13.18.2.5Viewing the Prepared Hash
-
13.18.2.6Cracking the Hash with Hashcat
-
-
13.18.3
Automated / Tool Based Route 8 topics-
13.18.3.1Using PowerView to Extract TGS Tickets
-
13.18.3.2Using PowerView to Target a Specific User
-
13.18.3.3Exporting All Tickets to a CSV File
-
13.18.3.4Viewing the Contents of the .CSV File
-
13.18.3.5Using Rubeus
-
13.18.3.6Viewing Rubeus's Capabilities
-
13.18.3.7Using the /stats Flag
-
13.18.3.8Using the /nowrap Flag
-
-
13.18.4
A Note on Encryption Types 6 topics-
13.18.4.1Cracking the Ticket with Hashcat & rockyou.txt
-
13.18.4.2Checking Supported Encryption Types
-
13.18.4.3Requesting a New Ticket
-
13.18.4.4Running Hashcat & Checking the Status of the Cracking Job
-
13.18.4.5Viewing the Length of Time it Took to Crack
-
13.18.4.6Using the /tgtdeleg Flag
-
-
13.18.5Mitigation & Detection
-
13.18.6Continuing Onwards
-
-
13.19
Access Control List (ACL) Abuse Primer 4 topics-
13.19.1
Access Control List (ACL) Overview 2 topics-
13.19.1.1Viewing forend's ACL
-
13.19.1.2Viewing the SACLs through the Auditing Tab
-
-
13.19.2
Access Control Entries (ACEs) 1 topic-
13.19.2.1Viewing Permissions through Active Directory Users & Computers
-
-
13.19.3Why are ACEs Important?
-
13.19.4
ACL Attacks in the Wild 1 topic-
13.19.4.1Questions
-
-
-
13.20
ACL Enumeration 2 topics-
13.20.1
Enumerating ACLs with PowerView 10 topics-
13.20.1.1Using Find-InterestingDomainAcl
-
13.20.1.2Using Get-DomainObjectACL
-
13.20.1.3Performing a Reverse Search & Mapping to a GUID Value
-
13.20.1.4Using the -ResolveGUIDs Flag
-
13.20.1.5Creating a List of Domain Users
-
13.20.1.6A Useful foreach Loop
-
13.20.1.7Further Enumeration of Rights Using damundsen
-
13.20.1.8Investigating the Help Desk Level 1 Group with Get-DomainGroup
-
13.20.1.9Investigating the Information Technology Group
-
13.20.1.10Looking for Interesting Access
-
-
13.20.2
Enumerating ACLs with BloodHound 4 topics-
13.20.2.1Viewing Node Info through BloodHound
-
13.20.2.2Investigating ForceChangePassword Further
-
13.20.2.3Viewing Potential Attack Paths through BloodHound
-
13.20.2.4Viewing Pre-Build queries through BloodHound
-
-
-
13.21
ACL Abuse Tactics 3 topics-
13.21.1
Abusing ACLs 8 topics-
13.21.1.1Creating a PSCredential Object
-
13.21.1.2Creating a SecureString Object
-
13.21.1.3Changing the User's Password
-
13.21.1.4Creating a SecureString Object using damundsen
-
13.21.1.5Adding damundsen to the Help Desk Level 1 Group
-
13.21.1.6Confirming damundsen was Added to the Group
-
13.21.1.7Creating a Fake SPN
-
13.21.1.8Kerberoasting with Rubeus
-
-
13.21.2
Cleanup 3 topics-
13.21.2.1Removing the Fake SPN from adunn's Account
-
13.21.2.2Removing damundsen from the Help Desk Level 1 Group
-
13.21.2.3Confirming damundsen was Removed from the Group
-
-
13.21.3
Detection and Remediation 3 topics-
13.21.3.1Viewing Event ID 5136
-
13.21.3.2Viewing Associated SDDL
-
13.21.3.3Converting the SDDL String into a Readable Format
-
-
-
13.22
DCSync 3 topics-
13.22.1Scenario Setup
-
13.22.2
What is DCSync and How Does it Work? 11 topics-
13.22.2.1Viewing adunn's Replication Privileges through ADSI Edit
-
13.22.2.2Using Get-DomainUser to View adunn's Group Membership
-
13.22.2.3Using Get-ObjectAcl to Check adunn's Replication Rights
-
13.22.2.4Extracting NTLM Hashes and Kerberos Keys Using secretsdump.py
-
13.22.2.5Listing Hashes, Kerberos Keys, and Cleartext Passwords
-
13.22.2.6Viewing an Account with Reversible Encryption Password Storage Set
-
13.22.2.7Enumerating Further using Get-ADUser
-
13.22.2.8Checking for Reversible Encryption Option using Get- DomainUser
-
13.22.2.9Displaying the Decrypted Password
-
13.22.2.10Using runas.exe
-
13.22.2.11Performing the Attack with Mimikatz
-
-
13.22.3Moving On
-
-
13.23
Privileged Access 5 topics-
13.23.1Scenario Setup
-
13.23.2
Remote Desktop 3 topics-
13.23.2.1Enumerating the Remote Desktop Users Group
-
13.23.2.2Checking the Domain Users Group's Local Admin & Execution Rights using BloodHound
-
13.23.2.3Checking Remote Access Rights using BloodHound
-
-
13.23.3
WinRM 7 topics-
13.23.3.1Enumerating the Remote Management Users Group
-
13.23.3.2Using the Cypher Query in BloodHound
-
13.23.3.3Adding the Cypher Query as a Custom Query in BloodHound
-
13.23.3.4Establishing WinRM Session from Windows
-
13.23.3.5Installing Evil-WinRM
-
13.23.3.6Viewing Evil-WinRM's Help Menu
-
13.23.3.7Connecting to a Target with Evil-WinRM and Valid Credentials
-
-
13.23.4
SQL Server Admin 7 topics-
13.23.4.1Using a Custom Cypher Query to Check for SQL Admin Rights in BloodHound
-
13.23.4.2Enumerating MSSQL Instances with PowerUpSQL
-
13.23.4.3Displaying mssqlclient.py Options
-
13.23.4.4Running mssqlclient.py Against the Target
-
13.23.4.5Viewing our Options with Access to the SQL Server
-
13.23.4.6Choosing enable_xp_cmdshell
-
13.23.4.7Enumerating our Rights on the System using xp_cmdshell
-
-
13.23.5Moving On
-
-
13.24
Kerberos "Double Hop" Problem 5 topics-
13.24.1Background
-
13.24.2Workarounds
-
13.24.3Workaround #1: PSCredential Object
-
13.24.4Workaround #2: Register PSSession Configuration
-
13.24.5Wrap Up
-
-
13.25
Bleeding Edge Vulnerabilities 7 topics-
13.25.1Scenario Setup
-
13.25.2
NoPac (SamAccountName Spoofing) 6 topics-
13.25.2.1Ensuring Impacket is Installed
-
13.25.2.2Cloning the NoPac Exploit Repo
-
13.25.2.3Scanning for NoPac
-
13.25.2.4Running NoPac & Getting a Shell
-
13.25.2.5Confirming the Location of Saved Tickets
-
13.25.2.6Using noPac to DCSync the Built-in Administrator Account
-
-
13.25.3
Windows Defender & SMBEXEC.py Considerations 1 topic-
13.25.3.1Windows Defender Quarantine Log
-
-
13.25.4
PrintNightmare 8 topics-
13.25.4.1Cloning the Exploit
-
13.25.4.2Install cube0x0's Version of Impacket
-
13.25.4.3Enumerating for MS-RPRN
-
13.25.4.4Generating a DLL Payload
-
13.25.4.5Creating a Share with smbserver.py
-
13.25.4.6Configuring & Starting MSF multi/handler
-
13.25.4.7Running the Exploit
-
13.25.4.8Getting the SYSTEM Shell
-
-
13.25.5
PetitPotam (MS-EFSRPC) 13 topics-
13.25.5.1Starting ntlmrelayx.py
-
13.25.5.2Running PetitPotam.py
-
13.25.5.3Catching Base64 Encoded Certificate for DC01
-
13.25.5.4Requesting a TGT Using gettgtpkinit.py
-
13.25.5.5Setting the KRB5CCNAME Environment Variable
-
13.25.5.6Using Domain Controller TGT to DCSync
-
13.25.5.7Running klist
-
13.25.5.8Confirming Admin Access to the Domain Controller
-
13.25.5.9Submitting a TGS Request for Ourselves Using getnthash.py
-
13.25.5.10Using Domain Controller NTLM Hash to DCSync
-
13.25.5.11Requesting TGT and Performing PTT with DC01$ Machine Account
-
13.25.5.12Confirming the Ticket is in Memory
-
13.25.5.13Performing DCSync with Mimikatz
-
-
13.25.6PetitPotam Mitigations
-
13.25.7Recap
-
-
13.26
Miscellaneous Misconfigurations 14 topics-
13.26.1Scenario Setup
-
13.26.2
Exchange Related Group Membership 1 topic-
13.26.2.1Viewing Organization Management's Permissions
-
-
13.26.3PrivExchange
-
13.26.4
Printer Bug 1 topic-
13.26.4.1Enumerating for MS-PRN Printer Bug
-
-
13.26.5MS14-068
-
13.26.6Sniffing LDAP Credentials
-
13.26.7
Enumerating DNS Records 4 topics-
13.26.7.1Using adidnsdump
-
13.26.7.2Viewing the Contents of the records.csv File
-
13.26.7.3Using the -r Option to Resolve Unknown Records
-
13.26.7.4Finding Hidden Records in the records.csv File
-
-
13.26.8
Other Misconfigurations 2 topics-
13.26.8.1Password in Description Field
-
13.26.8.2Finding Passwords in the Description Field using Get-Domain User
-
-
13.26.9
PASSWD_NOTREQD Field 1 topic-
13.26.9.1Checking for PASSWD_NOTREQD Setting using Get-DomainUser
-
-
13.26.10
Credentials in SMB Shares and SYSVOL Scripts 2 topics-
13.26.10.1Discovering an Interesting Script
-
13.26.10.2Finding a Password in the Script
-
-
13.26.11
Group Policy Preferences (GPP) Passwords 4 topics-
13.26.11.1Viewing Groups.xml
-
13.26.11.2Decrypting the Password with gpp-decrypt
-
13.26.11.3Locating & Retrieving GPP Passwords with CrackMapExec
-
13.26.11.4Using CrackMapExec's gpp_autologin Module
-
-
13.26.12
ASREPRoasting 6 topics-
13.26.12.1Viewing an Account with the Do not Require Kerberos Preauthentication Option
-
13.26.12.2Enumerating for DONT_REQ_PREAUTH Value using Get- DomainUser
-
13.26.12.3Retrieving AS-REP in Proper Format using Rubeus
-
13.26.12.4Cracking the Hash Offline with Hashcat
-
13.26.12.5Retrieving the AS-REP Using Kerbrute
-
13.26.12.6Hunting for Users with Kerberoast Pre-auth Not Required
-
-
13.26.13
Group Policy Object (GPO) Abuse 4 topics-
13.26.13.1Enumerating GPO Names with PowerView
-
13.26.13.2Enumerating GPO Names with a Built-In Cmdlet
-
13.26.13.3Enumerating Domain User GPO Rights
-
13.26.13.4Converting GPO GUID to Name
-
-
13.26.14Onwards
-
-
13.27
Domain Trusts Primer 4 topics-
13.27.1Scenario
-
13.27.2
Domain Trusts Overview 1 topic-
13.27.2.1Trust Table Side By Side
-
-
13.27.3
Enumerating Trust Relationships 8 topics-
13.27.3.1Using Get-ADTrust
-
13.27.3.2Checking for Existing Trusts using Get-DomainTrust
-
13.27.3.3Using Get-DomainTrustMapping
-
13.27.3.4Checking Users in the Child Domain using Get-DomainUser
-
13.27.3.5Using netdom to query domain trust
-
13.27.3.6Using netdom to query domain controllers
-
13.27.3.7Using netdom to query workstations and servers
-
13.27.3.8Visualizing Trust Relationships in BloodHound
-
-
13.27.4Onwards
-
-
13.28
Attacking Domain Trusts - Child -> Parent Trusts - from Windows 4 topics-
13.28.1SID History Primer
-
13.28.2
ExtraSids Attack - Mimikatz 7 topics-
13.28.2.1Obtaining the KRBTGT Account's NT Hash using Mimikatz
-
13.28.2.2Using Get-DomainSID
-
13.28.2.3Obtaining Enterprise Admins Group's SID using Get- DomainGroup
-
13.28.2.4Using ls to Confirm No Access
-
13.28.2.5Creating a Golden Ticket with Mimikatz
-
13.28.2.6Confirming a Kerberos Ticket is in Memory Using klist
-
13.28.2.7Listing the Entire C: Drive of the Domain Controller
-
-
13.28.3
ExtraSids Attack - Rubeus 4 topics-
13.28.3.1Using ls to Confirm No Access Before Running Rubeus
-
13.28.3.2Creating a Golden Ticket using Rubeus
-
13.28.3.3Confirming the Ticket is in Memory Using klist
-
13.28.3.4Performing a DCSync Attack
-
-
13.28.4Next Steps
-
-
13.29
Attacking Domain Trusts - Child -> Parent Trusts - from Linux 2 topics-
13.29.1
Performing DCSync with secretsdump.py 7 topics-
13.29.1.1Performing SID Brute Forcing using lookupsid.py
-
13.29.1.2Looking for the Domain SID
-
13.29.1.3Grabbing the Domain SID & Attaching to Enterprise Admin's RID
-
13.29.1.4Constructing a Golden Ticket using ticketer.py
-
13.29.1.5Setting the KRB5CCNAME Environment Variable
-
13.29.1.6Getting a SYSTEM shell using Impacket's psexec.py
-
13.29.1.7Performing the Attack with raiseChild.py
-
-
13.29.2More Fun
-
-
13.30
Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows 4 topics-
13.30.1
Cross-Forest Kerberoasting 3 topics-
13.30.1.1Enumerating Accounts for Associated SPNs Using Get- DomainUser
-
13.30.1.2Enumerating the mssqlsvc Account
-
13.30.1.3Performing a Kerberoasting Attacking with Rubeus Using /domain Flag
-
-
13.30.2
Admin Password Re-Use & Group Membership 2 topics-
13.30.2.1Using Get-DomainForeignGroupMember
-
13.30.2.2Accessing DC03 Using Enter-PSSession
-
-
13.30.3SID History Abuse - Cross Forest
-
13.30.4Onwards
-
-
13.31
Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux 3 topics-
13.31.1
Cross-Forest Kerberoasting 2 topics-
13.31.1.1Using GetUserSPNs.py
-
13.31.1.2Using the -request Flag
-
-
13.31.2
Hunting Foreign Group Membership with Bloodhound- python 6 topics-
13.31.2.1Adding INLANEFREIGHT.LOCAL Information to /etc/resolv.conf
-
13.31.2.2Running bloodhound-python Against INLANEFREIGHT.LOCAL
-
13.31.2.3Compressing the File with zip -r
-
13.31.2.4Adding FREIGHTLOGISTICS.LOCAL Information to /etc/resolv.conf
-
13.31.2.5Running bloodhound-python Against FREIGHTLOGISTICS.LOCAL
-
13.31.2.6Viewing Dangerous Rights through BloodHound
-
-
13.31.3Closing Thoughts on Trusts
-
-
13.32
Hardening Active Directory 3 topics-
13.32.1
Step One: Document and Audit 1 topic-
13.32.1.1Things To Document and Track
-
-
13.32.2
People, Processes, and Technology 5 topics-
13.32.2.1People
-
13.32.2.2Protected Users Group
-
13.32.2.3Viewing the Protected Users Group with Get-ADGroup
-
13.32.2.4Processes
-
13.32.2.5Technology
-
-
13.32.3
Protections By Section 1 topic-
13.32.3.1MITRE ATT&CK Breakdown
-
-
-
13.33
Additional AD Auditing Techniques 4 topics-
13.33.1
Creating an AD Snapshot with Active Directory Explorer 3 topics-
13.33.1.1Logging in with AD Explorer
-
13.33.1.2Browsing AD with AD Explorer
-
13.33.1.3Creating a Snapshot of AD with AD Explorer
-
-
13.33.2
PingCastle 6 topics-
13.33.2.1Viewing the PingCastle Help Menu
-
13.33.2.2Running PingCastle
-
13.33.2.3PingCastle Interactive TUI
-
13.33.2.4Scanner Options
-
13.33.2.5Viewing The Report
-
13.33.2.6Group Policy
-
-
13.33.3
Group3r 3 topics-
13.33.3.1Group3r Basic Usage
-
13.33.3.2Reading Output
-
13.33.3.3Group3r Finding
-
-
13.33.4
ADRecon 2 topics-
13.33.4.1Running ADRecon
-
13.33.4.2Reporting
-
-
-
13.34
AD Enumeration & Attacks - Skills Assessment Part I 1 topic-
13.34.1Scenario
-
-
13.35
AD Enumeration & Attacks - Skills Assessment Part II 1 topic-
13.35.1Scenario
-
-
13.36
Beyond this Module 5 topics-
13.36.1Status Update
-
13.36.2Real World
-
13.36.3What's Next?
-
13.36.4
More AD Learning Opportunities 5 topics-
13.36.4.1Boxes To Pwn
-
13.36.4.2ProLabs
-
13.36.4.3Endgames
-
13.36.4.4Great Videos to Check Out
-
13.36.4.5Writers and Blogs To Follow
-
-
13.36.5Closing Thoughts
-
14 Using Web Proxies Using Web Proxies module 71 topics Module 14
-
14.1
Intro to Web Proxies 4 topics-
14.1.1What Are Web Proxies?
-
14.1.2Uses of Web Proxies
-
14.1.3Burp Suite
-
14.1.4OWASP Zed Attack Proxy (ZAP)
-
-
14.2
Setting Up 2 topics-
14.2.1Burp Suite
-
14.2.2ZAP
-
-
14.3
Proxy Setup 3 topics-
14.3.1Pre-Configured Browser
-
14.3.2Proxy Setup
-
14.3.3Installing CA Certificate
-
-
14.4
Intercepting Web Requests 2 topics-
14.4.1
Intercepting Requests 2 topics-
14.4.1.1Burp
-
14.4.1.2ZAP
-
-
14.4.2Manipulating Intercepted Requests
-
-
14.5
Intercepting Responses 2 topics-
14.5.1Burp
-
14.5.2ZAP
-
-
14.6
Automatic Modification 2 topics-
14.6.1
Automatic Request Modification 2 topics-
14.6.1.1Burp Match and Replace
-
14.6.1.2ZAP Replacer
-
-
14.6.2Automatic Response Modification
-
-
14.7
Repeating Requests 2 topics-
14.7.1Proxy History
-
14.7.2
Repeating Requests 2 topics-
14.7.2.1Burp
-
14.7.2.2ZAP
-
-
-
14.8
Encoding/Decoding 3 topics-
14.8.1URL Encoding
-
14.8.2Decoding
-
14.8.3Encoding
-
-
14.9
Proxying Tools 3 topics-
14.9.1Proxychains
-
14.9.2Nmap
-
14.9.3Metasploit
-
-
14.10
Burp Intruder 5 topics-
14.10.1Target
-
14.10.2Positions
-
14.10.3
Payloads 4 topics-
14.10.3.1Payload Sets
-
14.10.3.2Payload Options
-
14.10.3.3Payload Processing
-
14.10.3.4Payload Encoding
-
-
14.10.4Options
-
14.10.5Attack
-
-
14.11
ZAP Fuzzer 6 topics-
14.11.1Fuzz
-
14.11.2Locations
-
14.11.3Payloads
-
14.11.4Processors
-
14.11.5Options
-
14.11.6Start
-
-
14.12
Burp Scanner 5 topics-
14.12.1Target Scope
-
14.12.2Crawler
-
14.12.3Passive Scanner
-
14.12.4Active Scanner
-
14.12.5Reporting
-
-
14.13
ZAP Scanner 4 topics-
14.13.1Spider
-
14.13.2Passive Scanner
-
14.13.3Active Scanner
-
14.13.4Reporting
-
-
14.14
Extensions 3 topics-
14.14.1BApp Store
-
14.14.2ZAP Marketplace
-
14.14.3Closing Thoughts
-
-
14.15Skills Assessment - Using Web Proxies
15 Attacking Web Applications with Ffuf Attacking Web Applications with Ffuf module 28 topics Module 15
-
15.1Introduction
-
15.2
Web Fuzzing 2 topics-
15.2.1Fuzzing
-
15.2.2Wordlists
-
-
15.3
Directory Fuzzing 2 topics-
15.3.1Ffuf
-
15.3.2Directory Fuzzing
-
-
15.4
Page Fuzzing 2 topics-
15.4.1Extension Fuzzing
-
15.4.2Page Fuzzing
-
-
15.5
Recursive Fuzzing 2 topics-
15.5.1Recursive Flags
-
15.5.2Recursive Scanning
-
-
15.6DNS Records
-
15.7
Sub-domain Fuzzing 1 topic-
15.7.1Sub-domains
-
-
15.8
Vhost Fuzzing 2 topics-
15.8.1Vhosts vs. Sub-domains
-
15.8.2Vhosts Fuzzing
-
-
15.9
Filtering Results 1 topic-
15.9.1Filtering
-
-
15.10
Parameter Fuzzing - GET 1 topic-
15.10.1GET Request Fuzzing
-
-
15.11Parameter Fuzzing - POST
-
15.12
Value Fuzzing 2 topics-
15.12.1Custom Wordlist
-
15.12.2Value Fuzzing
-
-
15.13Skills Assessment - Web Fuzzing
16 Login Brute Forcing Login Brute Forcing module 62 topics Module 16
-
16.1
Introduction 4 topics-
16.1.1What is Brute Forcing?
-
16.1.2How Brute Forcing Works
-
16.1.3Types of Brute Forcing
-
16.1.4The Role of Brute Forcing in Penetration Testing
-
-
16.2
Password Security Fundamentals 5 topics-
16.2.1The Importance of Strong Passwords
-
16.2.2The Anatomy of a Strong Password
-
16.2.3Common Password Weaknesses
-
16.2.4Password Policies
-
16.2.5
The Perils of Default Credentials 1 topic-
16.2.5.1Brute-forcing and Password Security
-
-
-
16.3
Brute Force Attacks 1 topic-
16.3.1Cracking the PIN
-
-
16.4
Dictionary Attacks 4 topics-
16.4.1The Power of Words
-
16.4.2Brute Force vs. Dictionary Attack
-
16.4.3Building and Utilizing Wordlists
-
16.4.4Throwing a dictionary at the problem
-
-
16.5
Hybrid Attacks 2 topics-
16.5.1
Hybrid Attacks in Action 1 topic-
16.5.1.1The Power of Hybrid Attacks
-
-
16.5.2
Credential Stuffing: Leveraging Stolen Data for Unauthorized Access 1 topic-
16.5.2.1The Password Reuse Problem
-
-
-
16.6
Hydra 2 topics-
16.6.1Installation
-
16.6.2
Basic Usage 6 topics-
16.6.2.1Hydra Services
-
16.6.2.2Brute-Forcing HTTP Authentication
-
16.6.2.3Targeting Multiple SSH Servers
-
16.6.2.4Testing FTP Credentials on a Non-Standard Port
-
16.6.2.5Brute-Forcing a Web Login Form
-
16.6.2.6Advanced RDP Brute-Forcing
-
-
-
16.7
Basic HTTP Authentication 1 topic-
16.7.1Exploiting Basic Auth with Hydra
-
-
16.8
Login Forms 4 topics-
16.8.1Understanding Login Forms
-
16.8.2A Basic Login Form Example
-
16.8.3
http-post-form 4 topics-
16.8.3.1Understanding the Condition String
-
16.8.3.2Manual Inspection
-
16.8.3.3Browser Developer Tools
-
16.8.3.4Proxy Interception
-
-
16.8.4Constructing the params String for Hydra
-
-
16.9
Medusa 2 topics-
16.9.1Installation
-
16.9.2
Command Syntax and Parameter Table 4 topics-
16.9.2.1Medusa Modules
-
16.9.2.2Targeting an SSH Server
-
16.9.2.3Targeting Multiple Web Servers with Basic HTTP Authentication
-
16.9.2.4Testing for Empty or Default Passwords
-
-
-
16.10
Web Services 2 topics-
16.10.1Kick-off
-
16.10.2
Gaining Access 3 topics-
16.10.2.1Expanding the Attack Surface
-
16.10.2.2Targeting the FTP Server
-
16.10.2.3Retrieving The Flag
-
-
-
16.11
Custom Wordlists 2 topics-
16.11.1Username Anarchy
-
16.11.2CUPP
-
-
16.12Skills Assessment Part 1
-
16.13Skills Assessment Part 2
17 SQL Injection Fundamentals SQL Injection Fundamentals module 85 topics Module 17
-
17.1
Introduction 3 topics-
17.1.1SQL Injection (SQLi)
-
17.1.2Use Cases and Impact
-
17.1.3Prevention
-
-
17.2
Intro to Databases 2 topics-
17.2.1Database Management Systems
-
17.2.2Architecture
-
-
17.3
Types of Databases 2 topics-
17.3.1Relational Databases
-
17.3.2Non-relational Databases
-
-
17.4
Intro to MySQL 4 topics-
17.4.1Structured Query Language (SQL)
-
17.4.2Command Line
-
17.4.3Creating a database
-
17.4.4
Tables 1 topic-
17.4.4.1Table Properties
-
-
-
17.5
SQL Statements 5 topics-
17.5.1INSERT Statement
-
17.5.2SELECT Statement
-
17.5.3DROP Statement
-
17.5.4ALTER Statement
-
17.5.5UPDATE Statement
-
-
17.6
Query Results 4 topics-
17.6.1Sorting Results
-
17.6.2LIMIT results
-
17.6.3WHERE Clause
-
17.6.4LIKE Clause
-
-
17.7
SQL Operators 6 topics-
17.7.1AND Operator
-
17.7.2OR Operator
-
17.7.3NOT Operator
-
17.7.4Symbol Operators
-
17.7.5Operators in queries
-
17.7.6Multiple Operator Precedence
-
-
17.8
Intro to SQL Injections 5 topics-
17.8.1Use of SQL in Web Applications
-
17.8.2What is an Injection?
-
17.8.3SQL Injection
-
17.8.4Syntax Errors
-
17.8.5Types of SQL Injections
-
-
17.9
Subverting Query Logic 4 topics-
17.9.1Authentication Bypass
-
17.9.2SQLi Discovery
-
17.9.3OR Injection
-
17.9.4Auth Bypass with OR operator
-
-
17.10
Using Comments 3 topics-
17.10.1Comments
-
17.10.2Auth Bypass with comments
-
17.10.3Another Example
-
-
17.11
Union Clause 3 topics-
17.11.1Union
-
17.11.2Even Columns
-
17.11.3Un-even Columns
-
-
17.12
Union Injection 2 topics-
17.12.1
Detect number of columns 2 topics-
17.12.1.1Using ORDER BY
-
17.12.1.2Using UNION
-
-
17.12.2Location of Injection
-
-
17.13
Database Enumeration 6 topics-
17.13.1MySQL Fingerprinting
-
17.13.2INFORMATION_SCHEMA Database
-
17.13.3SCHEMATA
-
17.13.4TABLES
-
17.13.5COLUMNS
-
17.13.6Data
-
-
17.14
Reading Files 3 topics-
17.14.1
Privileges 2 topics-
17.14.1.1DB User
-
17.14.1.2User Privileges
-
-
17.14.2LOAD_FILE
-
17.14.3Another Example
-
-
17.15
Writing Files 4 topics-
17.15.1
Write File Privileges 1 topic-
17.15.1.1secure_file_priv
-
-
17.15.2SELECT INTO OUTFILE
-
17.15.3Writing Files through SQL Injection
-
17.15.4Writing a Web Shell
-
-
17.16
Mitigating SQL Injection 6 topics-
17.16.1Input Sanitization
-
17.16.2Input Validation
-
17.16.3User Privileges
-
17.16.4Web Application Firewall
-
17.16.5Parameterized Queries
-
17.16.6Conclusion
-
-
17.17Skills Assessment - SQL Injection Fundamentals
18 SQLMap Essentials SQLMap Essentials module 79 topics Module 18
-
18.1
SQLMap Overview 10 topics-
18.1.1SQLMap Installation
-
18.1.2Supported Databases
-
18.1.3Supported SQL Injection Types
-
18.1.4Boolean-based blind SQL Injection
-
18.1.5Error-based SQL Injection
-
18.1.6UNION query-based
-
18.1.7Stacked queries
-
18.1.8Time-based blind SQL Injection
-
18.1.9Inline queries
-
18.1.10
Out-of-band SQL Injection 1 topic-
18.1.10.1Questions
-
-
-
18.2
Getting Started with SQLMap 1 topic-
18.2.1Basic Scenario
-
-
18.3
SQLMap Output Description 1 topic-
18.3.1
Log Messages Description 14 topics-
18.3.1.1URL content is stable
-
18.3.1.2Parameter appears to be dynamic
-
18.3.1.3Parameter might be injectable
-
18.3.1.4Parameter might be vulnerable to XSS attacks
-
18.3.1.5Back-end DBMS is '...'
-
18.3.1.6Level/risk values
-
18.3.1.7Reflective values found
-
18.3.1.8Parameter appears to be injectable
-
18.3.1.9Time-based comparison statistical model
-
18.3.1.10Extending UNION query injection technique tests
-
18.3.1.11Technique appears to be usable
-
18.3.1.12Parameter is vulnerable
-
18.3.1.13Sqlmap identified injection points
-
18.3.1.14Data logged to text files
-
-
-
18.4
Running SQLMap on an HTTP Request 5 topics-
18.4.1Curl Commands
-
18.4.2GET/POST Requests
-
18.4.3Full HTTP Requests
-
18.4.4Custom SQLMap Requests
-
18.4.5Custom HTTP Requests
-
-
18.5
Handling SQLMap Errors 4 topics-
18.5.1Display Errors
-
18.5.2Store the Traffic
-
18.5.3Verbose Output
-
18.5.4Using Proxy
-
-
18.6
Attack Tuning 3 topics-
18.6.1Prefix/Suffix
-
18.6.2Level/Risk
-
18.6.3
Advanced Tuning 6 topics-
18.6.3.1Status Codes
-
18.6.3.2Titles
-
18.6.3.3Strings
-
18.6.3.4Text-only
-
18.6.3.5Techniques
-
18.6.3.6UNION SQLi Tuning
-
-
-
18.7
Database Enumeration 6 topics-
18.7.1SQLMap Data Exfiltration
-
18.7.2Basic DB Data Enumeration
-
18.7.3Table Enumeration
-
18.7.4Table/Row Enumeration
-
18.7.5Conditional Enumeration
-
18.7.6Full DB Enumeration
-
-
18.8
Advanced Database Enumeration 4 topics-
18.8.1DB Schema Enumeration
-
18.8.2Searching for Data
-
18.8.3Password Enumeration and Cracking
-
18.8.4DB Users Password Enumeration and Cracking
-
-
18.9
Bypassing Web Application Protections 8 topics-
18.9.1Anti-CSRF Token Bypass
-
18.9.2Unique Value Bypass
-
18.9.3Calculated Parameter Bypass
-
18.9.4IP Address Concealing
-
18.9.5WAF Bypass
-
18.9.6User-agent Blacklisting Bypass
-
18.9.7Tamper Scripts
-
18.9.8Miscellaneous Bypasses
-
-
18.10
OS Exploitation 6 topics-
18.10.1File Read/Write
-
18.10.2Checking for DBA Privileges
-
18.10.3Reading Local Files
-
18.10.4Writing Local Files
-
18.10.5OS Command Execution
-
18.10.6Skills Assessment
-
19 Cross-Site Scripting (XSS) Cross-Site Scripting (XSS) module 40 topics Module 19
-
19.1
Introduction 3 topics-
19.1.1What is XSS
-
19.1.2XSS Attacks
-
19.1.3Types of XSS
-
-
19.2
Stored XSS 1 topic-
19.2.1XSS Testing Payloads
-
-
19.3Reflected XSS
-
19.4
DOM XSS 2 topics-
19.4.1Source & Sink
-
19.4.2DOM Attacks
-
-
19.5
XSS Discovery 3 topics-
19.5.1Automated Discovery
-
19.5.2
Manual Discovery 1 topic-
19.5.2.1XSS Payloads
-
-
19.5.3Code Review
-
-
19.6
Defacing 4 topics-
19.6.1Defacement Elements
-
19.6.2Changing Background
-
19.6.3Changing Page Title
-
19.6.4Changing Page Text
-
-
19.7
Phishing 4 topics-
19.7.1XSS Discovery
-
19.7.2Login Form Injection
-
19.7.3Cleaning Up
-
19.7.4Credential Stealing
-
-
19.8
Session Hijacking 3 topics-
19.8.1Blind XSS Detection
-
19.8.2Loading a Remote Script
-
19.8.3Session Hijacking
-
-
19.9
XSS Prevention 2 topics-
19.9.1
Front-end 3 topics-
19.9.1.1Input Validation
-
19.9.1.2Input Sanitization
-
19.9.1.3Direct Input
-
-
19.9.2
Back-end 4 topics-
19.9.2.1Input Validation
-
19.9.2.2Input Sanitization
-
19.9.2.3Output HTML Encoding
-
19.9.2.4Server Configuration
-
-
-
19.10Skills Assessment
20 File Inclusion File Inclusion module 62 topics Module 20
-
20.1
Intro to File Inclusions 3 topics-
20.1.1Local File Inclusion (LFI)
-
20.1.2
Examples of Vulnerable Code 4 topics-
20.1.2.1PHP
-
20.1.2.2NodeJS
-
20.1.2.3Java
-
20.1.2.4.NET
-
-
20.1.3Read vs Execute
-
-
20.2
Local File Inclusion (LFI) 5 topics-
20.2.1Basic LFI
-
20.2.2Path Traversal
-
20.2.3Filename Prefix
-
20.2.4Appended Extensions
-
20.2.5Second-Order Attacks
-
-
20.3
Basic Bypasses 4 topics-
20.3.1Non-Recursive Path Traversal Filters
-
20.3.2Encoding
-
20.3.3Approved Paths
-
20.3.4
Appended Extension 2 topics-
20.3.4.1Path Truncation
-
20.3.4.2Null Bytes
-
-
-
20.4
PHP Filters 4 topics-
20.4.1Input Filters
-
20.4.2Fuzzing for PHP Files
-
20.4.3Standard PHP Inclusion
-
20.4.4Source Code Disclosure
-
-
20.5
PHP Wrappers 3 topics-
20.5.1
Data 2 topics-
20.5.1.1Checking PHP Configurations
-
20.5.1.2Remote Code Execution
-
-
20.5.2Input
-
20.5.3Expect
-
-
20.6
Remote File Inclusion (RFI) 6 topics-
20.6.1Local vs. Remote File Inclusion
-
20.6.2Verify RFI
-
20.6.3Remote Code Execution with RFI
-
20.6.4HTTP
-
20.6.5FTP
-
20.6.6SMB
-
-
20.7
LFI and File Uploads 3 topics-
20.7.1
Image upload 2 topics-
20.7.1.1Crafting Malicious Image
-
20.7.1.2Uploaded File Path
-
-
20.7.2Zip Upload
-
20.7.3Phar Upload
-
-
20.8
Log Poisoning 2 topics-
20.8.1PHP Session Poisoning
-
20.8.2Server Log Poisoning
-
-
20.9
Automated Scanning 4 topics-
20.9.1Fuzzing Parameters
-
20.9.2LFI wordlists
-
20.9.3
Fuzzing Server Files 2 topics-
20.9.3.1Server Webroot
-
20.9.3.2Server Logs/Configurations
-
-
20.9.4LFI Tools
-
-
20.10
File Inclusion Prevention 4 topics-
20.10.1File Inclusion Prevention
-
20.10.2Preventing Directory Traversal
-
20.10.3Web Server Configuration
-
20.10.4Web Application Firewall (WAF)
-
-
20.11
Skills Assessment - File Inclusion 1 topic-
20.11.1Scenario
-
21 File Upload Attacks File Upload Attacks module 43 topics Module 21
-
21.1
Intro to File Upload Attacks 1 topic-
21.1.1Types of File Upload Attacks
-
-
21.2
Absent Validation 3 topics-
21.2.1Arbitrary File Upload
-
21.2.2Identifying Web Framework
-
21.2.3Vulnerability Identification
-
-
21.3
Upload Exploitation 4 topics-
21.3.1Web Shells
-
21.3.2Writing Custom Web Shell
-
21.3.3Reverse Shell
-
21.3.4Generating Custom Reverse Shell Scripts
-
-
21.4
Client-Side Validation 3 topics-
21.4.1Client-Side Validation
-
21.4.2Back-end Request Modification
-
21.4.3Disabling Front-end Validation
-
-
21.5
Blacklist Filters 3 topics-
21.5.1Blacklisting Extensions
-
21.5.2Fuzzing Extensions
-
21.5.3Non-Blacklisted Extensions
-
-
21.6
Whitelist Filters 4 topics-
21.6.1Whitelisting Extensions
-
21.6.2Double Extensions
-
21.6.3Reverse Double Extension
-
21.6.4Character Injection
-
-
21.7
Type Filters 2 topics-
21.7.1Content-Type
-
21.7.2MIME-Type
-
-
21.8
Limited File Uploads 3 topics-
21.8.1XSS
-
21.8.2XXE
-
21.8.3DoS
-
-
21.9
Other Upload Attacks 4 topics-
21.9.1Injections in File Name
-
21.9.2Upload Directory Disclosure
-
21.9.3Windows-specific Attacks
-
21.9.4Advanced File Upload Attacks
-
-
21.10
Preventing File Upload Vulnerabilities 4 topics-
21.10.1Extension Validation
-
21.10.2Content Validation
-
21.10.3Upload Disclosure
-
21.10.4Further Security
-
-
21.11
Skills Assessment - File Upload Attacks 1 topic-
21.11.1Extra Exercise
-
22 Command Injections Command Injections module 51 topics Module 22
-
22.1
Intro to Command Injections 2 topics-
22.1.1What are Injections
-
22.1.2
OS Command Injections 2 topics-
22.1.2.1PHP Example
-
22.1.2.2NodeJS Example
-
-
-
22.2
Detection 2 topics-
22.2.1Command Injection Detection
-
22.2.2Command Injection Methods
-
-
22.3
Injecting Commands 2 topics-
22.3.1Injecting Our Command
-
22.3.2
Bypassing Front-End Validation 1 topic-
22.3.2.1Burp POST Request
-
-
-
22.4
Other Injection Operators 2 topics-
22.4.1AND Operator
-
22.4.2OR Operator
-
-
22.5
Identifying Filters 3 topics-
22.5.1Filter/WAF Detection
-
22.5.2Blacklisted Characters
-
22.5.3Identifying Blacklisted Character
-
-
22.6
Bypassing Space Filters 2 topics-
22.6.1Bypass Blacklisted Operators
-
22.6.2
Bypass Blacklisted Spaces 3 topics-
22.6.2.1Using Tabs
-
22.6.2.2Using $IFS
-
22.6.2.3Using Brace Expansion
-
-
-
22.7
Bypassing Other Blacklisted Characters 3 topics-
22.7.1Linux
-
22.7.2Windows
-
22.7.3Character Shifting
-
-
22.8
Bypassing Blacklisted Commands 4 topics-
22.8.1Commands Blacklist
-
22.8.2
Linux & Windows 1 topic-
22.8.2.1Burp POST Request
-
-
22.8.3Linux Only
-
22.8.4Windows Only
-
-
22.9
Advanced Command Obfuscation 3 topics-
22.9.1
Case Manipulation 1 topic-
22.9.1.1Burp POST Request
-
-
22.9.2
Reversed Commands 1 topic-
22.9.2.1Burp POST Request
-
-
22.9.3
Encoded Commands 1 topic-
22.9.3.1Burp POST Request
-
-
-
22.10
Evasion Tools 2 topics-
22.10.1Linux (Bashfuscator)
-
22.10.2Windows (DOSfuscation)
-
-
22.11
Command Injection Prevention 4 topics-
22.11.1System Commands
-
22.11.2Input Validation
-
22.11.3Input Sanitization
-
22.11.4Server Configuration
-
-
22.12Skills Assessment
23 Web Attacks Web Attacks module 63 topics Module 23
-
23.1
Introduction to Web Attacks 1 topic-
23.1.1
Web Attacks 3 topics-
23.1.1.1HTTP Verb Tampering
-
23.1.1.2Insecure Direct Object References (IDOR)
-
23.1.1.3XML External Entity (XXE) Injection
-
-
-
23.2
Intro to HTTP Verb Tampering 3 topics-
23.2.1HTTP Verb Tampering
-
23.2.2Insecure Configurations
-
23.2.3Insecure Coding
-
-
23.3
Bypassing Basic Authentication 2 topics-
23.3.1Identify
-
23.3.2Exploit
-
-
23.4
Bypassing Security Filters 2 topics-
23.4.1Identify
-
23.4.2Exploit
-
-
23.5
Verb Tampering Prevention 2 topics-
23.5.1Insecure Configuration
-
23.5.2Insecure Coding
-
-
23.6
Intro to IDOR 2 topics-
23.6.1What Makes an IDOR Vulnerability
-
23.6.2Impact of IDOR Vulnerabilities
-
-
23.7
Identifying IDORs 4 topics-
23.7.1URL Parameters & APIs
-
23.7.2AJAX Calls
-
23.7.3Understand Hashing/Encoding
-
23.7.4Compare User Roles
-
-
23.8
Mass IDOR Enumeration 2 topics-
23.8.1Insecure Parameters
-
23.8.2Mass Enumeration
-
-
23.9
Bypassing Encoded References 2 topics-
23.9.1Function Disclosure
-
23.9.2Mass Enumeration
-
-
23.10
IDOR in Insecure APIs 2 topics-
23.10.1Identifying Insecure APIs
-
23.10.2Exploiting Insecure APIs
-
-
23.11
Chaining IDOR Vulnerabilities 3 topics-
23.11.1Information Disclosure
-
23.11.2Modifying Other Users' Details
-
23.11.3Chaining Two IDOR Vulnerabilities
-
-
23.12
IDOR Prevention 2 topics-
23.12.1Object-Level Access Control
-
23.12.2Object Referencing
-
-
23.13
Intro to XXE 3 topics-
23.13.1XML
-
23.13.2XML DTD
-
23.13.3XML Entities
-
-
23.14
Local File Disclosure 5 topics-
23.14.1Identifying
-
23.14.2Reading Sensitive Files
-
23.14.3Reading Source Code
-
23.14.4Remote Code Execution with XXE
-
23.14.5Other XXE Attacks
-
-
23.15
Advanced File Disclosure 2 topics-
23.15.1Advanced Exfiltration with CDATA
-
23.15.2Error Based XXE
-
-
23.16
Blind Data Exfiltration 2 topics-
23.16.1Out-of-band Data Exfiltration
-
23.16.2Automated OOB Exfiltration
-
-
23.17
XXE Prevention 2 topics-
23.17.1Avoiding Outdated Components
-
23.17.2Using Safe XML Configurations
-
-
23.18
Web Attacks - Skills Assessment 1 topic-
23.18.1Scenario
-
24 Attacking Common Applications Attacking Common Applications module 150 topics Module 24
-
24.1
Introduction to Attacking Common Applications 4 topics-
24.1.1Application Data
-
24.1.2A Quick Story
-
24.1.3Common Applications
-
24.1.4Module Targets
-
-
24.2
Application Discovery & Enumeration 7 topics-
24.2.1Nmap - Web Discovery
-
24.2.2Getting Organized
-
24.2.3Initial Enumeration
-
24.2.4Using EyeWitness
-
24.2.5Using Aquatone
-
24.2.6Interpreting the Results
-
24.2.7Moving On
-
-
24.3
WordPress - Discovery & Enumeration 5 topics-
24.3.1Discovery/Footprinting
-
24.3.2Enumeration
-
24.3.3Enumerating Users
-
24.3.4WPScan
-
24.3.5Moving On
-
-
24.4
Attacking WordPress 4 topics-
24.4.1Login Bruteforce
-
24.4.2Code Execution
-
24.4.3
Leveraging Known Vulnerabilities 2 topics-
24.4.3.1Vulnerable Plugins - mail-masta
-
24.4.3.2Vulnerable Plugins - wpDiscuz
-
-
24.4.4Moving On
-
-
24.5
Joomla - Discovery & Enumeration 2 topics-
24.5.1Discovery/Footprinting
-
24.5.2Enumeration
-
-
24.6
Attacking Joomla 3 topics-
24.6.1Abusing Built-In Functionality
-
24.6.2Leveraging Known Vulnerabilities
-
24.6.3Moving On
-
-
24.7
Drupal - Discovery & Enumeration 2 topics-
24.7.1Discovery/Footprinting
-
24.7.2Enumeration
-
-
24.8
Attacking Drupal 7 topics-
24.8.1Leveraging the PHP Filter Module
-
24.8.2Uploading a Backdoored Module
-
24.8.3Leveraging Known Vulnerabilities
-
24.8.4Drupalgeddon
-
24.8.5Drupalgeddon2
-
24.8.6Drupalgeddon3
-
24.8.7Onwards
-
-
24.9
Tomcat - Discovery & Enumeration 2 topics-
24.9.1Discovery/Footprinting
-
24.9.2Enumeration
-
-
24.10
Attacking Tomcat 5 topics-
24.10.1Tomcat Manager - Login Brute Force
-
24.10.2Tomcat Manager - WAR File Upload
-
24.10.3A Quick Note on Web shells
-
24.10.4CVE-2020-1938 : Ghostcat
-
24.10.5Moving On
-
-
24.11
Jenkins - Discovery & Enumeration 2 topics-
24.11.1Discovery/Footprinting
-
24.11.2Enumeration
-
-
24.12
Attacking Jenkins 3 topics-
24.12.1Script Console
-
24.12.2Miscellaneous Vulnerabilities
-
24.12.3Shifting Gears
-
-
24.13
Splunk - Discovery & Enumeration 2 topics-
24.13.1Discovery/Footprinting
-
24.13.2Enumeration
-
-
24.14
Attacking Splunk 1 topic-
24.14.1Abusing Built-In Functionality
-
-
24.15
PRTG Network Monitor 3 topics-
24.15.1Discovery/Footprinting/Enumeration
-
24.15.2Leveraging Known Vulnerabilities
-
24.15.3Onwards
-
-
24.16
osTicket 4 topics-
24.16.1
Footprinting/Discovery/Enumeration 3 topics-
24.16.1.1User Input
-
24.16.1.2Processing
-
24.16.1.3Solution
-
-
24.16.2Attacking osTicket
-
24.16.3osTicket - Sensitive Data Exposure
-
24.16.4Closing Thoughts
-
-
24.17
Gitlab - Discovery & Enumeration 3 topics-
24.17.1Footprinting & Discovery
-
24.17.2Enumeration
-
24.17.3Onwards
-
-
24.18
Attacking GitLab 2 topics-
24.18.1Username Enumeration
-
24.18.2Authenticated Remote Code Execution
-
-
24.19
Attacking Tomcat CGI 2 topics-
24.19.1
Enumeration 4 topics-
24.19.1.1Nmap - Open Ports
-
24.19.1.2Finding a CGI script
-
24.19.1.3Fuzzing Extentions - .CMD
-
24.19.1.4Fuzzing Extentions - .BAT
-
-
24.19.2Exploitation
-
-
24.20
Attacking Common Gateway Interface (CGI) Applications - Shellshock 5 topics-
24.20.1CGI Attacks
-
24.20.2Shellshock via CGI
-
24.20.3
Hands-on Example 3 topics-
24.20.3.1Enumeration - Gobuster
-
24.20.3.2Confirming the Vulnerability
-
24.20.3.3Exploitation to Reverse Shell Access
-
-
24.20.4Mitigation
-
24.20.5Closing Thoughts
-
-
24.21
Attacking Thick Client Applications 2 topics-
24.21.1
Penetration Testing Steps 4 topics-
24.21.1.1Information Gathering
-
24.21.1.2Client Side attacks
-
24.21.1.3Network Side Attacks
-
24.21.1.4Server Side Attacks
-
-
24.21.2Retrieving hardcoded Credentials from Thick-Client Applications
-
-
24.22
Exploiting Web Vulnerabilities in Thick-Client Applications 3 topics-
24.22.1Foothold
-
24.22.2Path Traversal
-
24.22.3SQL Injection
-
-
24.23
ColdFusion - Discovery & Enumeration 1 topic-
24.23.1
Enumeration 1 topic-
24.23.1.1NMap ports and service scan results
-
-
-
24.24
Attacking ColdFusion 3 topics-
24.24.1Searchsploit
-
24.24.2
Directory Traversal 1 topic-
24.24.2.1Coldfusion - Exploitation
-
-
24.24.3
Unauthenticated RCE 4 topics-
24.24.3.1Searchsploit
-
24.24.3.2Exploit Modification
-
24.24.3.3Exploitation
-
24.24.3.4Reverse Shell
-
-
-
24.25
IIS Tilde Enumeration 1 topic-
24.25.1
Enumeration 4 topics-
24.25.1.1Nmap - Open ports
-
24.25.1.2Tilde Enumeration using IIS ShortName Scanner
-
24.25.1.3Generate Wordlist
-
24.25.1.4Gobuster Enumeration
-
-
-
24.26
LDAP 3 topics-
24.26.1ldapsearch
-
24.26.2LDAP Injection
-
24.26.3
Enumeration 2 topics-
24.26.3.1nmap
-
24.26.3.2Injection
-
-
-
24.27
Web Mass Assignment Vulnerabilities 2 topics-
24.27.1Exploiting Mass Assignment Vulnerability
-
24.27.2Prevention
-
-
24.28
Attacking Applications Connecting to Services 2 topics-
24.28.1ELF Executable Examination
-
24.28.2DLL File Examination
-
-
24.29
Other Notable Applications 1 topic-
24.29.1Honorable Mentions
-
-
24.30
Application Hardening 3 topics-
24.30.1General Hardening Tips
-
24.30.2Application-Specific Hardening Tips
-
24.30.3Conclusion
-
-
24.31Attacking Common Applications - Skills Assessment I
-
24.32Attacking Common Applications - Skills Assessment II
-
24.33Attacking Common Applications - Skills Assessment III
25 Linux Privilege Escalation Linux Privilege Escalation module 162 topics Module 25
-
25.1
Introduction to Linux Privilege Escalation 2 topics-
25.1.1
Enumeration 11 topics-
25.1.1.1List Current Processes
-
25.1.1.2Home Directory Contents
-
25.1.1.3User's Home Directory Contents
-
25.1.1.4SSH Directory Contents
-
25.1.1.5Bash History
-
25.1.1.6Sudo - List User's Privileges
-
25.1.1.7Passwd
-
25.1.1.8Cron Jobs
-
25.1.1.9File Systems & Additional Drives
-
25.1.1.10Find Writable Directories
-
25.1.1.11Find Writable Files
-
-
25.1.2Moving on
-
-
25.2
Environment Enumeration 2 topics-
25.2.1
Gaining Situational Awareness 7 topics-
25.2.1.1Existing Users
-
25.2.1.2Existing Groups
-
25.2.1.3Mounted File Systems
-
25.2.1.4Unmounted File Systems
-
25.2.1.5All Hidden Files
-
25.2.1.6All Hidden Directories
-
25.2.1.7Temporary Files
-
-
25.2.2Moving On
-
-
25.3
Linux Services & Internals Enumeration 2 topics-
25.3.1
Internals 8 topics-
25.3.1.1Network Interfaces
-
25.3.1.2Hosts
-
25.3.1.3User's Last Login
-
25.3.1.4Logged In Users
-
25.3.1.5Command History
-
25.3.1.6Finding History Files
-
25.3.1.7Cron
-
25.3.1.8Proc
-
-
25.3.2
Services 8 topics-
25.3.2.1Installed Packages
-
25.3.2.2Sudo Version
-
25.3.2.3Binaries
-
25.3.2.4GTFObins
-
25.3.2.5Trace System Calls
-
25.3.2.6Configuration Files
-
25.3.2.7Scripts
-
25.3.2.8Running Services by User
-
-
-
25.4
Credential Hunting 1 topic-
25.4.1SSH Keys
-
-
25.5Path Abuse
-
25.6Wildcard Abuse
-
25.7
Escaping Restricted Shells 2 topics-
25.7.1
RBASH 2 topics-
25.7.1.1RKSH
-
25.7.1.2RZSH
-
-
25.7.2
Escaping 5 topics-
25.7.2.1Command injection
-
25.7.2.2Command Substitution
-
25.7.2.3Command Chaining
-
25.7.2.4Environment Variables
-
25.7.2.5Shell Functions
-
-
-
25.8
Special Permissions 1 topic-
25.8.1GTFOBins
-
-
25.9Sudo Rights Abuse
-
25.10
Privileged Groups 4 topics-
25.10.1LXC / LXD
-
25.10.2Docker
-
25.10.3Disk
-
25.10.4ADM
-
-
25.11
Capabilities 3 topics-
25.11.1Set Capability
-
25.11.2
Enumerating Capabilities 1 topic-
25.11.2.1Enumerating Capabilities
-
-
25.11.3
Exploitation 1 topic-
25.11.3.1Exploiting Capabilities
-
-
-
25.12
Vulnerable Services 1 topic-
25.12.1
Screen Version Identification 2 topics-
25.12.1.1Privilege Escalation - Screen_Exploit.sh
-
25.12.1.2Screen_Exploit_POC.sh
-
-
-
25.13Cron Job Abuse
-
25.14
Containers 1 topic-
25.14.1
Linux Containers 1 topic-
25.14.1.1Linux Daemon
-
-
-
25.15
Docker 3 topics-
25.15.1
Docker Architecture 5 topics-
25.15.1.1Docker Daemon
-
25.15.1.2Managing Docker Containers
-
25.15.1.3Network and Storage
-
25.15.1.4Docker Clients
-
25.15.1.5Docker Desktop
-
-
25.15.2Docker Images and Containers
-
25.15.3
Docker Privilege Escalation 4 topics-
25.15.3.1Docker Shared Directories
-
25.15.3.2Docker Sockets
-
25.15.3.3Docker Group
-
25.15.3.4Docker Socket
-
-
-
25.16
Kubernetes 3 topics-
25.16.1
K8s Concept 4 topics-
25.16.1.1Nodes
-
25.16.1.2Control Plane
-
25.16.1.3Minions
-
25.16.1.4K8's Security Measures
-
-
25.16.2
Kubernetes API 6 topics-
25.16.2.1Authentication
-
25.16.2.2K8's API Server Interaction
-
25.16.2.3Kubelet API - Extracting Pods
-
25.16.2.4Kubeletctl - Extracting Pods
-
25.16.2.5Kubelet API - Available Commands
-
25.16.2.6Kubelet API - Executing Commands
-
-
25.16.3
Privilege Escalation 6 topics-
25.16.3.1Kubelet API - Extracting Tokens
-
25.16.3.2Kubelet API - Extracting Certificates
-
25.16.3.3List Privileges
-
25.16.3.4Pod YAML
-
25.16.3.5Creating a new Pod
-
25.16.3.6Extracting Root's SSH Key
-
-
-
25.17Logrotate
-
25.18
Miscellaneous Techniques 3 topics-
25.18.1Passive Traffic Capture
-
25.18.2Weak NFS Privileges
-
25.18.3Hijacking Tmux Sessions
-
-
25.19
Kernel Exploits 1 topic-
25.19.1Kernel Exploit Example
-
-
25.20
Shared Libraries 1 topic-
25.20.1LD_PRELOAD Privilege Escalation
-
-
25.21Shared Object Hijacking
-
25.22
Python Library Hijacking 4 topics-
25.22.1Importing Modules
-
25.22.2
Wrong Write Permissions 6 topics-
25.22.2.1Python Script
-
25.22.2.2Python Script - Contents
-
25.22.2.3Module Permissions
-
25.22.2.4Module Contents
-
25.22.2.5Module Contents - Hijacking
-
25.22.2.6Privilege Escalation
-
-
25.22.3
Library Path 5 topics-
25.22.3.1PYTHONPATH Listing
-
25.22.3.2Psutil Default Installation Location
-
25.22.3.3Misconfigured Directory Permissions
-
25.22.3.4Hijacked Module Contents - psutil.py
-
25.22.3.5Privilege Escalation via Hijacking Python Library Path
-
-
25.22.4
PYTHONPATH Environment Variable 2 topics-
25.22.4.1Checking sudo permissions
-
25.22.4.2Privilege Escalation using PYTHONPATH Environment Variable
-
-
-
25.23
Sudo 1 topic-
25.23.1Sudo Policy Bypass
-
-
25.24Polkit
-
25.25
Dirty Pipe 1 topic-
25.25.1
Download Dirty Pipe Exploit 4 topics-
25.25.1.1Verify Kernel Version
-
25.25.1.2Exploitation
-
25.25.1.3Find SUID Binaries
-
25.25.1.4Exploitation
-
-
-
25.26
Netfilter 1 topic-
25.26.1
CVE-2021-22555 4 topics-
25.26.1.1CVE-2022-25636
-
25.26.1.2CVE-2023-32233
-
25.26.1.3Proof-Of-Concept
-
25.26.1.4Exploitation
-
-
-
25.27
Linux Hardening 5 topics-
25.27.1Updates and Patching
-
25.27.2Configuration Management
-
25.27.3User Management
-
25.27.4Audit
-
25.27.5Conclusion
-
-
25.28Linux Local Privilege Escalation - Skills Assessment
26 Windows Privilege Escalation Windows Privilege Escalation module 402 topics Module 26
-
26.1
Introduction to Windows Privilege Escalation 6 topics-
26.1.1Scenario 1 - Overcoming Network Restrictions
-
26.1.2Scenario 2 - Pillaging Open Shares
-
26.1.3Scenario 3 - Hunting Credentials and Abusing Account Privileges
-
26.1.4Why does Privilege Escalation Happen?
-
26.1.5Moving On
-
26.1.6
Practical Examples 1 topic-
26.1.6.1Connecting via FreeRDP
-
-
-
26.2Useful Tools
-
26.3
Situational Awareness 3 topics-
26.3.1
Network Information 3 topics-
26.3.1.1Interface(s), IP Address(es), DNS Information
-
26.3.1.2ARP Table
-
26.3.1.3Routing Table
-
-
26.3.2
Enumerating Protections 3 topics-
26.3.2.1Check Windows Defender Status
-
26.3.2.2List AppLocker Rules
-
26.3.2.3Test AppLocker Policy
-
-
26.3.3Next Steps
-
-
26.4
Initial Enumeration 4 topics-
26.4.1Key Data Points
-
26.4.2
System Information 7 topics-
26.4.2.1Tasklist
-
26.4.2.2Display All Environment Variables
-
26.4.2.3View Detailed Configuration Information
-
26.4.2.4Patches and Updates
-
26.4.2.5Installed Programs
-
26.4.2.6Display Running Processes
-
26.4.2.7Netstat
-
-
26.4.3
User & Group Information 8 topics-
26.4.3.1Logged-In Users
-
26.4.3.2Current User
-
26.4.3.3Current User Privileges
-
26.4.3.4Current User Group Information
-
26.4.3.5Get All Users
-
26.4.3.6Get All Groups
-
26.4.3.7Details About a Group
-
26.4.3.8Get Password Policy & Other Account Information
-
-
26.4.4Moving On
-
-
26.5
Communication with Processes 4 topics-
26.5.1Access Tokens
-
26.5.2
Enumerating Network Services 2 topics-
26.5.2.1Display Active Network Connections
-
26.5.2.2More Examples
-
-
26.5.3
Named Pipes 4 topics-
26.5.3.1More on Named Pipes
-
26.5.3.2Listing Named Pipes with Pipelist
-
26.5.3.3Listing Named Pipes with PowerShell
-
26.5.3.4Reviewing LSASS Named Pipe Permissions
-
-
26.5.4
Named Pipes Attack Example 1 topic-
26.5.4.1Checking WindscribeService Named Pipe Permissions
-
-
-
26.6
Windows Privileges Overview 5 topics-
26.6.1Windows Authorization Process
-
26.6.2Rights and Privileges in Windows
-
26.6.3
User Rights Assignment 3 topics-
26.6.3.1Local Admin User Rights - Elevated
-
26.6.3.2Standard User Rights
-
26.6.3.3Backup Operators Rights
-
-
26.6.4Detection
-
26.6.5Moving On
-
-
26.7
SeImpersonate and SeAssignPrimaryToken 2 topics-
26.7.1
SeImpersonate Example - JuicyPotato 6 topics-
26.7.1.1Connecting with MSSQLClient.py
-
26.7.1.2Enabling xp_cmdshell
-
26.7.1.3Confirming Access
-
26.7.1.4Checking Account Privileges
-
26.7.1.5Escalating Privileges Using JuicyPotato
-
26.7.1.6Catching SYSTEM Shell
-
-
26.7.2
PrintSpoofer and RoguePotato 2 topics-
26.7.2.1Escalating Privileges using PrintSpoofer
-
26.7.2.2Catching Reverse Shell as SYSTEM
-
-
-
26.8
SeDebugPrivilege 1 topic-
26.8.1Remote Code Execution as SYSTEM
-
-
26.9
SeTakeOwnershipPrivilege 2 topics-
26.9.1
Leveraging the Privilege 8 topics-
26.9.1.1Reviewing Current User Privileges
-
26.9.1.2Enabling SeTakeOwnershipPrivilege
-
26.9.1.3Choosing a Target File
-
26.9.1.4Checking File Ownership
-
26.9.1.5Taking Ownership of the File
-
26.9.1.6Confirming Ownership Changed
-
26.9.1.7Modifying the File ACL
-
26.9.1.8Reading the File
-
-
26.9.2
When to Use? 1 topic-
26.9.2.1Files of Interest
-
-
-
26.10
Windows Built-in Groups 2 topics-
26.10.1
Backup Operators 9 topics-
26.10.1.1Importing Libraries
-
26.10.1.2Verifying SeBackupPrivilege is Enabled
-
26.10.1.3Enabling SeBackupPrivilege
-
26.10.1.4Copying a Protected File
-
26.10.1.5Attacking a Domain Controller - Copying NTDS.dit
-
26.10.1.6Copying NTDS.dit Locally
-
26.10.1.7Backing up SAM and SYSTEM Registry Hives
-
26.10.1.8Extracting Credentials from NTDS.dit
-
26.10.1.9Extracting Hashes Using SecretsDump
-
-
26.10.2
Robocopy 1 topic-
26.10.2.1Copying Files with Robocopy
-
-
-
26.11
Event Log Readers 1 topic-
26.11.1
Confirming Group Membership 3 topics-
26.11.1.1Searching Security Logs Using wevtutil
-
26.11.1.2Passing Credentials to wevtutil
-
26.11.1.3Searching Security Logs Using Get-WinEvent
-
-
-
26.12
DnsAdmins 4 topics-
26.12.1
Leveraging DnsAdmins Access 11 topics-
26.12.1.1Generating Malicious DLL
-
26.12.1.2Starting Local HTTP Server
-
26.12.1.3Downloading File to Target
-
26.12.1.4Loading DLL as Non-Privileged User
-
26.12.1.5Loading DLL as Member of DnsAdmins
-
26.12.1.6Loading Custom DLL
-
26.12.1.7Finding User's SID
-
26.12.1.8Checking Permissions on DNS Service
-
26.12.1.9Stopping the DNS Service
-
26.12.1.10Starting the DNS Service
-
26.12.1.11Confirming Group Membership
-
-
26.12.2
Cleaning Up 4 topics-
26.12.2.1Confirming Registry Key Added
-
26.12.2.2Deleting Registry Key
-
26.12.2.3Starting the DNS Service Again
-
26.12.2.4Checking DNS Service Status
-
-
26.12.3Using Mimilib.dll
-
26.12.4
Creating a WPAD Record 2 topics-
26.12.4.1Disabling the Global Query Block List
-
26.12.4.2Adding a WPAD Record
-
-
-
26.13
Hyper-V Administrators 1 topic-
26.13.1
Target File 2 topics-
26.13.1.1Taking Ownership of the File
-
26.13.1.2Starting the Mozilla Maintenance Service
-
-
-
26.14
Print Operators 4 topics-
26.14.1
Confirming Privileges 7 topics-
26.14.1.1Checking Privileges Again
-
26.14.1.2Compile with cl.exe
-
26.14.1.3Add Reference to Driver
-
26.14.1.4Verify Driver is not Loaded
-
26.14.1.5Verify Privilege is Enabled
-
26.14.1.6Verify Capcom Driver is Listed
-
26.14.1.7Use ExploitCapcom Tool to Escalate Privileges
-
-
26.14.2Alternate Exploitation - No GUI
-
26.14.3
Automating the Steps 1 topic-
26.14.3.1Automating with EopLoadDriver
-
-
26.14.4
Clean-up 1 topic-
26.14.4.1Removing Registry Key
-
-
-
26.15
Server Operators 1 topic-
26.15.1
Querying the AppReadiness Service 7 topics-
26.15.1.1Checking Service Permissions with PsService
-
26.15.1.2Checking Local Admin Group Membership
-
26.15.1.3Modifying the Service Binary Path
-
26.15.1.4Starting the Service
-
26.15.1.5Confirming Local Admin Group Membership
-
26.15.1.6Confirming Local Admin Access on Domain Controller
-
26.15.1.7Retrieving NTLM Password Hashes from the Domain Controller
-
-
-
26.16
User Account Control 1 topic-
26.16.1
Checking Current User 13 topics-
26.16.1.1Confirming Admin Group Membership
-
26.16.1.2Reviewing User Privileges
-
26.16.1.3Confirming UAC is Enabled
-
26.16.1.4Checking UAC Level
-
26.16.1.5Checking Windows Version
-
26.16.1.6Reviewing Path Variable
-
26.16.1.7Generating Malicious srrstr.dll DLL
-
26.16.1.8Starting Python HTTP Server on Attack Host
-
26.16.1.9Downloading DLL Target
-
26.16.1.10Starting nc Listener on Attack Host
-
26.16.1.11Testing Connection
-
26.16.1.12Executing SystemPropertiesAdvanced.exe on Target Host
-
26.16.1.13Receiving Connection Back
-
-
-
26.17
Weak Permissions 6 topics-
26.17.1
Permissive File System ACLs 3 topics-
26.17.1.1Running SharpUp
-
26.17.1.2Checking Permissions with icacls
-
26.17.1.3Replacing Service Binary
-
-
26.17.2
Weak Service Permissions 7 topics-
26.17.2.1Reviewing SharpUp Again
-
26.17.2.2Checking Permissions with AccessChk
-
26.17.2.3Check Local Admin Group
-
26.17.2.4Changing the Service Binary Path
-
26.17.2.5Stopping Service
-
26.17.2.6Starting the Service
-
26.17.2.7Confirming Local Admin Group Addition
-
-
26.17.3
Weak Service Permissions - Cleanup 3 topics-
26.17.3.1Reverting the Binary Path
-
26.17.3.2Starting the Service Again
-
26.17.3.3Verifying Service is Running
-
-
26.17.4
Unquoted Service Path 3 topics-
26.17.4.1Service Binary Path
-
26.17.4.2Querying Service
-
26.17.4.3Searching for Unquoted Service Paths
-
-
26.17.5
Permissive Registry ACLs 2 topics-
26.17.5.1Checking for Weak Service ACLs in Registry
-
26.17.5.2Changing ImagePath with PowerShell
-
-
26.17.6
Modifiable Registry Autorun Binary 1 topic-
26.17.6.1Check Startup Programs
-
-
-
26.18
Kernel Exploits 3 topics-
26.18.1
Notable Vulnerabilities 5 topics-
26.18.1.1Checking Permissions on the SAM File
-
26.18.1.2Performing Attack and Parsing Password Hashes
-
26.18.1.3Checking for Spooler Service
-
26.18.1.4Adding Local Admin with PrintNightmare PowerShell PoC
-
26.18.1.5Confirming New Admin User
-
-
26.18.2
Enumerating Missing Patches 2 topics-
26.18.2.1Examining Installed Updates
-
26.18.2.2Viewing Installed Updates with WMI
-
-
26.18.3
CVE-2020-0668 Example 13 topics-
26.18.3.1Checking Current User Privileges
-
26.18.3.2After Building Solution
-
26.18.3.3Checking Permissions on Binary
-
26.18.3.4Generating Malicious Binary
-
26.18.3.5Hosting the Malicious Binary
-
26.18.3.6Downloading the Malicious Binary
-
26.18.3.7Running the Exploit
-
26.18.3.8Checking Permissions of New File
-
26.18.3.9Replacing File with Malicious Binary
-
26.18.3.10Metasploit Resource Script
-
26.18.3.11Launching Metasploit with Resource Script
-
26.18.3.12Starting the Service
-
26.18.3.13Receiving a Meterpreter Session
-
-
-
26.19
Vulnerable Services 3 topics-
26.19.1
Enumerating Installed Programs 3 topics-
26.19.1.1Enumerating Local Ports
-
26.19.1.2Enumerating Process ID
-
26.19.1.3Enumerating Running Service
-
-
26.19.2
Druva inSync Windows Client Local Privilege Escalation Example 4 topics-
26.19.2.1Druva inSync PowerShell PoC
-
26.19.2.2Modifying PowerShell PoC
-
26.19.2.3Starting a Python Web Server
-
26.19.2.4Catching a SYSTEM Shell
-
-
26.19.3Moving On
-
-
26.20
DLL Injection 4 topics-
26.20.1LoadLibrary
-
26.20.2Manual Mapping
-
26.20.3Reflective DLL Injection
-
26.20.4
DLL Hijacking 2 topics-
26.20.4.1Proxying
-
26.20.4.2Invalid Libraries
-
-
-
26.21
Credential Hunting 5 topics-
26.21.1
Application Configuration Files 1 topic-
26.21.1.1Searching for Files
-
-
26.21.2
Dictionary Files 1 topic-
26.21.2.1Chrome Dictionary Files
-
-
26.21.3
Unattended Installation Files 1 topic-
26.21.3.1Unattend.xml
-
-
26.21.4
PowerShell History File 3 topics-
26.21.4.1Command to
-
26.21.4.2Confirming PowerShell History Save Path
-
26.21.4.3Reading PowerShell History File
-
-
26.21.5
PowerShell Credentials 1 topic-
26.21.5.1Decrypting PowerShell Credentials
-
-
-
26.22
Other Files 3 topics-
26.22.1
Manually Searching the File System for Credentials 7 topics-
26.22.1.1Search File Contents for String - Example 1
-
26.22.1.2Search File Contents for String - Example 2
-
26.22.1.3Search File Contents for String - Example 3
-
26.22.1.4Search File Contents with PowerShell
-
26.22.1.5Search for File Extensions - Example 1
-
26.22.1.6Search for File Extensions - Example 2
-
26.22.1.7Search for File Extensions Using PowerShell
-
-
26.22.2
Sticky Notes Passwords 3 topics-
26.22.2.1Looking for StickyNotes DB Files
-
26.22.2.2Viewing Sticky Notes Data Using PowerShell
-
26.22.2.3Strings to View DB File Contents
-
-
26.22.3
Other Files of Interest 1 topic-
26.22.3.1Other Interesting Files
-
-
-
26.23
Further Credential Theft 8 topics-
26.23.1
Cmdkey Saved Credentials 2 topics-
26.23.1.1Listing Saved Credentials
-
26.23.1.2Run Commands as Another User
-
-
26.23.2
Browser Credentials 1 topic-
26.23.2.1Retrieving Saved Credentials from Chrome
-
-
26.23.3
Password Managers 2 topics-
26.23.3.1Extracting KeePass Hash
-
26.23.3.2Cracking Hash Offline
-
-
26.23.4Email
-
26.23.5
More Fun with Credentials 2 topics-
26.23.5.1Viewing LaZagne Help Menu
-
26.23.5.2Running All LaZagne Modules
-
-
26.23.6
Even More Fun with Credentials 1 topic-
26.23.6.1Running SessionGopher as Current User
-
-
26.23.7
Clear-Text Password Storage in the Registry 4 topics-
26.23.7.1Windows AutoLogon
-
26.23.7.2Enumerating Autologon with reg.exe
-
26.23.7.3Putty
-
26.23.7.4Enumerating Sessions and Finding Credentials:
-
-
26.23.8
Wifi Passwords 2 topics-
26.23.8.1Viewing Saved Wireless Networks
-
26.23.8.2Retrieving Saved Wireless Passwords
-
-
-
26.24
Citrix Breakout 8 topics-
26.24.1Bypassing Path Restrictions
-
26.24.2Accessing SMB share from restricted environment
-
26.24.3Alternate Explorer
-
26.24.4Alternate Registry Editors
-
26.24.5Modify existing shortcut file
-
26.24.6Script Execution
-
26.24.7Escalating Privileges
-
26.24.8
Bypassing UAC 1 topic-
26.24.8.1Additional resources worth checking:
-
-
-
26.25
Interacting with Users 5 topics-
26.25.1Traffic Capture
-
26.25.2
Process Command Lines 2 topics-
26.25.2.1Monitoring for Process Command Lines
-
26.25.2.2Running Monitor Script on Target Host
-
-
26.25.3Vulnerable Services
-
26.25.4
SCF on a File Share 3 topics-
26.25.4.1Malicious SCF File
-
26.25.4.2Starting Responder
-
26.25.4.3Cracking NTLMv2 Hash with Hashcat
-
-
26.25.5
Capturing Hashes with a Malicious .lnk File 1 topic-
26.25.5.1Generating a Malicious .lnk File
-
-
-
26.26
Pillaging 7 topics-
26.26.1Data Sources
-
26.26.2Scenario
-
26.26.3
Installed Applications 10 topics-
26.26.3.1Identifying Common Applications
-
26.26.3.2Get Installed Programs via PowerShell & Registry Keys
-
26.26.3.3mRemoteNG
-
26.26.3.4Discover mRemoteNG Configuration Files
-
26.26.3.5mRemoteNG Configuration File - confCons.xml
-
26.26.3.6Decrypt the Password with mremoteng_decrypt
-
26.26.3.7mRemoteNG Configuration File - confCons.xml
-
26.26.3.8Attempt to Decrypt the Password with a Custom Password
-
26.26.3.9Decrypt the Password with mremoteng_decrypt and a Custom Password
-
26.26.3.10For Loop to Crack the Master Password with mremoteng_decrypt
-
-
26.26.4
Abusing Cookies to Get Access to IM Clients 5 topics-
26.26.4.1Copy Firefox Cookies Database
-
26.26.4.2Extract Slack Cookie from Firefox Cookies Database
-
26.26.4.3PowerShell Script - Invoke-SharpChromium
-
26.26.4.4Copy Cookies to SharpChromium Expected Location
-
26.26.4.5Invoke-SharpChromium Cookies Extraction
-
-
26.26.5
Clipboard 2 topics-
26.26.5.1Monitor the Clipboard with PowerShell
-
26.26.5.2Capture Credentials from the Clipboard with Invoke- ClipboardLogger
-
-
26.26.6
Roles and Services 6 topics-
26.26.6.1Attacking Backup Servers
-
26.26.6.2restic - Initialize Backup Directory
-
26.26.6.3restic - Back up a Directory
-
26.26.6.4restic - Back up a Directory with VSS
-
26.26.6.5restic - Check Backups Saved in a Repository
-
26.26.6.6restic - Restore a Backup with ID
-
-
26.26.7Conclusion
-
-
26.27
Miscellaneous Techniques 6 topics-
26.27.1
Living Off The Land Binaries and Scripts (LOLBAS) 3 topics-
26.27.1.1Transferring File with Certutil
-
26.27.1.2Encoding File with Certutil
-
26.27.1.3Decoding File with Certutil
-
-
26.27.2
Always Install Elevated 4 topics-
26.27.2.1Enumerating Always Install Elevated Settings
-
26.27.2.2Generating MSI Package
-
26.27.2.3Executing MSI Package
-
26.27.2.4Catching Shell
-
-
26.27.3CVE-2019-1388
-
26.27.4
Scheduled Tasks 3 topics-
26.27.4.1Enumerating Scheduled Tasks
-
26.27.4.2Enumerating Scheduled Tasks with PowerShell
-
26.27.4.3Checking Permissions on C:\Scripts Directory
-
-
26.27.5
User/Computer Description Field 2 topics-
26.27.5.1Checking Local User Description Field
-
26.27.5.2Enumerating Computer Description Field with Get-WmiObject Cmdlet
-
-
26.27.6
Mount VHDX/VMDK 3 topics-
26.27.6.1Mount VMDK on Linux
-
26.27.6.2Mount VHD/VHDX on Linux
-
26.27.6.3Retrieving Hashes using Secretsdump.py
-
-
-
26.28
Legacy Operating Systems 2 topics-
26.28.1
End of Life Systems (EOL) 2 topics-
26.28.1.1Windows Desktop - EOL Dates by Version
-
26.28.1.2Windows Server - EOL Dates by Version
-
-
26.28.2Impact
-
-
26.29
Windows Server 3 topics-
26.29.1Server 2008 vs. Newer Versions
-
26.29.2
Server 2008 Case Study 9 topics-
26.29.2.1Querying Current Patch Level
-
26.29.2.2Running Sherlock
-
26.29.2.3Obtaining a Meterpreter Shell
-
26.29.2.4Rundll Command on Target Host
-
26.29.2.5Receiving Reverse Shell
-
26.29.2.6Searching for Local Privilege Escalation Exploit
-
26.29.2.7Migrating to a 64-bit Process
-
26.29.2.8Setting Privilege Escalation Module Options
-
26.29.2.9Receiving Elevated Reverse Shell
-
-
26.29.3Attacking Server 2008
-
-
26.30
Windows Desktop Versions 3 topics-
26.30.1Windows 7 vs. Newer Versions
-
26.30.2
Windows 7 Case Study 6 topics-
26.30.2.1Install Python Dependencies (local VM only)
-
26.30.2.2Gathering Systeminfo Command Output
-
26.30.2.3Updating the Local Microsoft Vulnerability Database
-
26.30.2.4Running Windows Exploit Suggester
-
26.30.2.5Exploiting MS16-032 with PowerShell PoC
-
26.30.2.6Spawning a SYSTEM Console
-
-
26.30.3Attacking Windows 7
-
-
26.31
Windows Hardening 10 topics-
26.31.1Secure Clean OS Installation
-
26.31.2Updates and Patching
-
26.31.3Configuration Management
-
26.31.4User Management
-
26.31.5Audit
-
26.31.6Logging
-
26.31.7Sysmon
-
26.31.8Network and Host Logs.
-
26.31.9Key Hardening Measures
-
26.31.10Conclusion
-
-
26.32Windows Privilege Escalation Skills Assessment - Part I
-
26.33Windows Privilege Escalation Skills Assessment - Part II
27 Documentation & Reporting Documentation & Reporting module 120 topics Module 27
-
27.1Introduction to Documentation and Reporting
-
27.2Documentation & Reporting in Practice
-
27.3About this Module
-
27.4
Notetaking & Organization 9 topics-
27.4.1Notetaking Sample Structure
-
27.4.2
Notetaking Tools 1 topic-
27.4.2.1Obsidian
-
-
27.4.3
Logging 2 topics-
27.4.3.1Exploitation Attempts
-
27.4.3.2Tmux.conf
-
-
27.4.4
Artifacts Left Behind 1 topic-
27.4.4.1Account Creation/System Modifications
-
-
27.4.5
Evidence 2 topics-
27.4.5.1What to Capture
-
27.4.5.2Storage
-
-
27.4.6
Formatting and Redaction 4 topics-
27.4.6.1Screenshots
-
27.4.6.2Blurring Password Data
-
27.4.6.3Blanking Out Password with Solid Shape
-
27.4.6.4Terminal
-
-
27.4.7What Not to Archive
-
27.4.8Module Exercises
-
27.4.9Onwards
-
-
27.5
Types of Reports 11 topics-
27.5.1
Differences Across Assessment Types 3 topics-
27.5.1.1Vulnerability Assessment
-
27.5.1.2Internal vs External
-
27.5.1.3Report Contents
-
-
27.5.2
Penetration Testing 1 topic-
27.5.2.1Internal vs External
-
-
27.5.3
Inter-Disciplinary Assessments 3 topics-
27.5.3.1Purple Team Style Assessments
-
27.5.3.2Cloud Focused Penetration Testing
-
27.5.3.3Comprehensive IoT Testing
-
-
27.5.4Web Application Penetration Testing
-
27.5.5Hardware Penetration Testing
-
27.5.6Draft Report
-
27.5.7
Final Report 1 topic-
27.5.7.1Post-Remediation Report
-
-
27.5.8Attestation Report
-
27.5.9
Other Deliverables 2 topics-
27.5.9.1Slide Deck
-
27.5.9.2Spreadsheet of Findings
-
-
27.5.10
Vulnerability Notifications 2 topics-
27.5.10.1When to Draft One
-
27.5.10.2Contents
-
-
27.5.11
Piecing it Together 1 topic-
27.5.11.1Questions
-
-
-
27.6
Components of a Report 11 topics-
27.6.1Prioritizing Our Efforts
-
27.6.2Writing an Attack Chain
-
27.6.3
Sample Attack Chain - INLANEFREIGHT.LOCAL Internal Penetration Test 14 topics-
27.6.3.1Detailed reproduction steps for this attack chain are as follows:
-
27.6.3.2Responder
-
27.6.3.3Hashcat
-
27.6.3.4GetUserSPNs
-
27.6.3.5Bloodhound
-
27.6.3.6GetUserSPNs
-
27.6.3.7Hashcat
-
27.6.3.8CrackMapExec
-
27.6.3.9Logged In Users
-
27.6.3.10Rubeus
-
27.6.3.11Cached Kerberos Tickets
-
27.6.3.12Mimikatz
-
27.6.3.13CrackMapExec
-
27.6.3.14Dumping NTDS with SecretsDump
-
-
27.6.4
Writing a Strong Executive Summary 4 topics-
27.6.4.1Key Concepts
-
27.6.4.2Do
-
27.6.4.3Do Not
-
27.6.4.4Vocabulary Changes
-
-
27.6.5
Example Executive Summary 1 topic-
27.6.5.1Anatomy of the Executive Summary
-
-
27.6.6Summary of Recommendations
-
27.6.7Findings
-
27.6.8Appendices
-
27.6.9
Static Appendices 4 topics-
27.6.9.1Scope
-
27.6.9.2Methodology
-
27.6.9.3Severity Ratings
-
27.6.9.4Biographies
-
-
27.6.10
Dynamic Appendices 6 topics-
27.6.10.1Exploitation Attempts and Payloads
-
27.6.10.2Compromised Credentials
-
27.6.10.3Configuration Changes
-
27.6.10.4Additional Affected Scope
-
27.6.10.5Information Gathering
-
27.6.10.6Domain Password Analysis
-
-
27.6.11
Report Type Differences 1 topic-
27.6.11.1Questions
-
-
-
27.7
How to Write Up a Finding 7 topics-
27.7.1Breakdown of a Finding
-
27.7.2Showing Finding Reproduction Steps Adequately
-
27.7.3
Effective Remediation Recommendations 4 topics-
27.7.3.1Example 1
-
27.7.3.2Rationale
-
27.7.3.3Example 2
-
27.7.3.4Rationale
-
-
27.7.4Selecting Quality References
-
27.7.5
Example Findings 3 topics-
27.7.5.1Weak Kerberos Authentication (“Kerberoasting”)
-
27.7.5.2Tomcat Manager Weak/Default Credentials
-
27.7.5.3Poorly Written Finding
-
-
27.7.6Hands-On Practice
-
27.7.7Nearly There
-
-
27.8
Reporting Tips and Tricks 9 topics-
27.8.1Templates
-
27.8.2MS Word Tips & Tricks
-
27.8.3Automation
-
27.8.4Reporting Tools/Findings Database
-
27.8.5Misc Tips/Tricks
-
27.8.6Client Communication
-
27.8.7
Presenting Your Report - The Final Product 1 topic-
27.8.7.1QA Process
-
-
27.8.8Report Review Meeting
-
27.8.9Wrap Up
-
-
27.9Documentation & Reporting Practice Lab
-
27.10
Beyond this Module - Documentation & Reporting 2 topics-
27.10.1Practicing
-
27.10.2Next Steps
-
28 Attacking Enterprise Networks Attacking Enterprise Networks module 80 topics Module 28
-
28.1Intro to Attacking Enterprise Networks
-
28.2
Scenario & Kickoff 2 topics-
28.2.1Project Kickoff
-
28.2.2Start of Testing
-
-
28.3
External Information Gathering 1 topic-
28.3.1Enumeration Results
-
-
28.4
Service Enumeration & Exploitation 4 topics-
28.4.1Listening Services
-
28.4.2FTP
-
28.4.3
SSH 1 topic-
28.4.3.1Email Services
-
-
28.4.4Moving On
-
-
28.5
Web Enumeration & Exploitation 14 topics-
28.5.1Web Application Enumeration
-
28.5.2blog.inlanefreight.local
-
28.5.3careers.inlanefreight.local
-
28.5.4dev.inlanefreight.local
-
28.5.5ir.inlanefreight.local
-
28.5.6status.inlanefreight.local
-
28.5.7support.inlanefreight.local
-
28.5.8tracking.inlanefreight.local
-
28.5.9Dealing with The Unexpected
-
28.5.10vpn.inlanefreight.local
-
28.5.11gitlab.inlanefreight.local
-
28.5.12shopdev2.inlanefreight.local
-
28.5.13monitoring.inlanefreight.local
-
28.5.14Next Steps
-
-
28.6
Initial Access 1 topic-
28.6.1Getting a Reverse Shell
-
-
28.7
Post-Exploitation Persistence 3 topics-
28.7.1Sinking Our Hooks In
-
28.7.2Local Privilege Escalation
-
28.7.3Establishing Persistence
-
-
28.8
Internal Information Gathering 9 topics-
28.8.1Setting Up Pivoting - SSH
-
28.8.2Setting Up Pivoting - Metasploit
-
28.8.3Host Discovery - 172.16.8.0/23 Subnet - Metasploit
-
28.8.4Host Discovery - 172.16.8.0/23 Subnet - SSH Tunnel
-
28.8.5Host Enumeration
-
28.8.6Active Directory Quick Hits - SMB NULL SESSION
-
28.8.7172.16.8.50 - Tomcat
-
28.8.8Enumerating 172.16.8.20 - DotNetNuke (DNN)
-
28.8.9Moving On
-
-
28.9
Exploitation & Privilege Escalation 4 topics-
28.9.1Attacking DNN
-
28.9.2Privilege Escalation
-
28.9.3Alternate Method - Reverse Port Forwarding
-
28.9.4Off to a Good Start
-
-
28.10Lateral Movement
-
28.11
Share Hunting 6 topics-
28.11.1Kerberoasting
-
28.11.2Password Spraying
-
28.11.3Misc Techniques
-
28.11.4Next Steps
-
28.11.5Post-Exploitation/Pillaging
-
28.11.6Closing In
-
-
28.12
Active Directory Compromise 1 topic-
28.12.1Next Steps
-
-
28.13
Post-Exploitation 7 topics-
28.13.1Domain Password Analysis - Cracking NTDS
-
28.13.2Active Directory Security Audit
-
28.13.3Hunting for Sensitive Data/Hosts
-
28.13.4The Double Pivot - MGMT01
-
28.13.5Data Exfiltration Simulation
-
28.13.6Attacking Domain Trusts
-
28.13.7Closing Thoughts
-
-
28.14
Engagement Closeout 6 topics-
28.14.1Attack Path Recap
-
28.14.2Structuring our Findings
-
28.14.3Post-Engagement Cleanup
-
28.14.4Client Communication
-
28.14.5Internal Project Closeout
-
28.14.6Next Steps
-
-
28.15
Beyond This Module 3 topics-
28.15.1
Practice on the Main Platform 3 topics-
28.15.1.1Starting Point
-
28.15.1.2Tracks
-
28.15.1.3Pro Labs
-
-
28.15.2Give Back
-
28.15.3Start Looking for Work
-
Student Feedback
What Students Say About This Course
No reviews yet.
Login to your account to write a review or reply to others.
Login to Review