My Process

  • nmap all ports first
    • if nothing, nmap -sU
    • if nothing nmap -Pn
    • if nothing, nmap -Pn -sU
  • try the available ports for any vulnerabilities
    • Check 10. Common Services and Ports
  • For Web apps:
    • try directory listing, subdomains, vhosts, recursive dir listing
    • If DNS - zone transfer
    • Check 14. Web Apps and try all
    • Based on the type of webapp - check 15. Attacking Common Apps.
    • Gather usernames and create cewl passwords from website pages
    • Spray username, passwords on logins.
    • Register a new user and try to upload a reverse shell