|
EH-Net
|
|
May 21, 2013, 01:34:34 AM
|
Show Posts
|
|
Pages: [1] 2 3
|
|
6
|
Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / PWB/OSCP course related question
|
on: April 23, 2012, 01:50:20 PM
|
|
PWB course discourages using tools like Nessus and Metasploit for exploting the lab machines. I am fine with it. My question is what should be the approach to find the vulnerabilities. Do you follow any pattern or just go through each service and test them manually? I appreciate if someone can give insights on how much time to spend on each host. The course examples use ftp fuzzing but I am not sure how to apply that technique to other services/ports that are open. Please share your thoughts.
|
|
|
|
|
12
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Planning a NMAP Scan
|
on: October 27, 2011, 03:56:55 PM
|
|
MeXe - Thank you very much for your inputs. So it appears the following strategy would be a good start.
1. Pick a host, scan for all TCP ports. Of course with timing options enabled. 2. Repeat step 1 for all the remaining hosts. 3. Pick a host, scan for all UDP ports. 4. Repeat step 3 for all the remaining hosts. 5. Selectively run -sV after analyzing results from step 1 through 4.
Does that sound correct?
Hmm...as I am writing this a question pops.
How do I manage the output? database? text file? greppable format?
Thanks in advance!
|
|
|
|
|
Loading...
|