My Process
- nmap all ports first
- if nothing,
nmap -sU
- if nothing
nmap -Pn
- if nothing,
nmap -Pn -sU
- try the available ports for any vulnerabilities
- Check 10. Common Services and Ports
- For Web apps:
- try directory listing, subdomains, vhosts, recursive dir listing
- If DNS - zone transfer
- Check 14. Web Apps and try all
- Based on the type of webapp - check 15. Attacking Common Apps.
- Gather usernames and create
cewl passwords from website pages
- Spray username, passwords on logins.
- Register a new user and try to upload a reverse shell