Skip to content
lethanhtung01011980 edited this page Apr 12, 2020 · 25 revisions

Goal

Quick scan ALL ports!!!

  • nmap -p- -T4 -A -v victim-ip <======= MUST DO THIS FIRST
  • zenmap => Intensive scan, all TCP ports <======= OR MUST DO THIS FIRST

Target a port !!!

  • nmap -sC -sV -p$ports victim-ip <========== TARGET A PORT

Scan for OS

  • Seldom have good result: nmap -O -Pn victim_ip
  • Check output of SMB vulnerabilities
  • Windows 5.0 = Windows 2000
  • Windows 5.1 = Windows XP

Sidebar

0. COMMON exploits

1. Scan Info

1.2 Passive Gathering

1.3 Active Gathering

2. Pre-attack

2.2 File transfer

3. Get Reverse Shell

4. Exploits

4.2 Windows Exploits

4.3 Linux Exploits

4.4 Password crack

4.5 Buffer Overflow

4.6 Web attacks

6. Escalate Privilege

6.1 Escalate in Windows

6.2 Escalate in Linux

7. Access and further attacks

8. Port redirection and Tunnelling

9. Metasploit

10. Kali

11. Thirdparty scripts

Clone this wiki locally