CompTIA PenTest+ (PT0-003) flashcards
192 free flashcards. Tap a card to flip it.
Hashcat Mask Attack
Flip cardA targeted brute-force technique that defines the character set for each position in a password based on a known or suspected pattern, drastically reducing keyspace versus full brute force.
- ?u = uppercase, ?l = lowercase, ?d = digit, ?s = special
- Keyspace = product of charset sizes per position
- Far more efficient than full charset brute force when policy/pattern is known
Memory trick: 'Mask the password's shape and hashcat needs far fewer guesses'
Local SSH Port Forwarding
Flip cardA technique to tunnel traffic from a local port on the attacker's machine, through an SSH connection established from a compromised host, to a specific port on a target host within a restricted network.
- Uses the `-L` option with SSH.
- Syntax: `ssh -L [attacker_port]:[target_ip]:[target_port] user@attacker_ip` (executed from compromised host).
- Allows the attacker to access services in the internal network as if they were on their local machine.
Memory trick: Local SSH tunnels bring the target closer.
ScoutSuite (Cloud Security Auditing)
Flip cardAn open-source, multi-cloud security auditing tool that assesses AWS, Azure, and GCP configurations to identify misconfigurations such as overly permissive IAM policies and exposed storage.
- Supports AWS, Azure, GCP, and other providers
- Generates HTML reports highlighting risky configurations
- Used for cloud security posture management (CSPM) style assessments
Memory trick: ScoutSuite 'scouts' every cloud provider's misconfigurations at once
Nmap Service Version Detection (-sV)
Flip cardThe Nmap '-sV' flag enables service version detection, where Nmap attempts to determine the exact service and its version running on open ports by probing the ports with various techniques.
- Identifies the specific application and its version.
- Crucial for identifying known vulnerabilities associated with specific software versions.
- Works by sending probes and analyzing responses.
- Can be combined with port specifications.
Memory trick: Nmap flags reveal target's secrets.
Metasploit Multi/Handler
Flip cardA Metasploit module used to set up a listener that matches a standalone payload (e.g., generated by msfvenom) to catch the resulting session.
- Must match payload type, LHOST, and LPORT exactly
- Commonly used with msfvenom-generated standalone payloads
- Run within msfconsole using exploit/multi/handler
Memory trick: Handler is the catcher's mitt waiting for the pitched payload.
Indirect Prompt Injection
Flip cardAn AI attack where malicious instructions are hidden in external data sources (webpages, documents, emails) that an LLM later processes, causing unintended behavior.
- Payload is hidden in content, not typed directly by the attacker
- Exploits AI agents that browse/summarize/process external data
- Can lead to data exfiltration or unauthorized actions
Memory trick: 'Indirect injection hides in the page, waiting for the bot to read it'
Adversarial Example (Evasion) Attack
Flip cardAn AI attack where an attacker crafts subtly perturbed inputs that are intentionally designed to fool a machine learning model, causing it to make incorrect predictions or classifications, often in a black-box setting.
- Subtly alters legitimate inputs.
- Aims to cause misclassification or evade detection.
- Can be performed in black-box (no model info) or white-box settings.
- Exploits model's blind spots or decision boundaries.
Memory trick: AI attacks: Poison data, Invert models, Evade with examples, Extract secrets.
Public Cloud Storage Misconfiguration (GetObject)
Flip cardA cloud storage misconfiguration where individual objects are publicly readable (via `GetObject` permission) even if the bucket's contents cannot be listed (via `ListBucket` permission), allowing data exfiltration of known or guessed object names.
- Often results from overly permissive `GetObject` policies.
- Attackers can download files if they can guess the object's path/name.
- Can lead to sensitive data exposure without prior enumeration.
- Distinct from full public read access where `ListBucket` is also allowed.
Memory trick: Buckets can be leaky, especially if GetObject is too easy.
Credentialed vs. Uncredentialed Scanning
Flip cardUncredentialed scans infer vulnerabilities externally via banners/responses, while credentialed scans authenticate to the host to directly verify installed software, patches, and configurations, reducing false positives/negatives.
- Credentialed scans use local admin/SSH/WinRM credentials
- Reduces false positives from inaccurate version banners
- Provides deeper visibility into local misconfigurations
Memory trick: Uncredentialed guesses from outside; Credentialed logs in and checks directly
Stored XSS
Flip cardA persistent cross-site scripting attack where malicious script is saved on the server (e.g., in a database) and executes for every user who views the affected content.
- Also called persistent XSS
- More dangerous than reflected XSS due to broad, automatic exposure
- Common in comment fields, forums, and user profiles
Memory trick: Stored = script sleeps in the database, wakes for every visitor
Authorized Testing Window
Flip cardA time period specified in the RoE during which active testing techniques are permitted, chosen to minimize business disruption.
- Often set during off-peak or overnight hours
- The opposite concept is a blackout window (prohibited testing times)
- Should be explicitly documented in the RoE
Memory trick: Green light window vs. red light blackout — know which hours you can scan.
Nmap TCP Connect Scan (-sT)
Flip cardAn 'nmap' scan type that performs a full TCP three-way handshake with the target port, making it less stealthy than a SYN scan but more reliable in certain network environments.
- Completes the full TCP handshake (SYN, SYN-ACK, ACK).
- Often used when SYN scans are blocked by firewalls or produce unreliable results.
- Leaves more traces in target logs than a SYN scan but is less aggressive than a full, unthrottled scan.
Memory trick: Nmap's scans vary; choose your stealth and reliability.
Maltego for OSINT
Flip cardMaltego is a proprietary software used for open-source intelligence and forensics, offering a graphical interface for visualizing links between data.
- Gathers information from various public sources (transforms).
- Visualizes relationships between disparate data points.
- Useful for mapping out networks, people, and organizations.
Memory trick: Openly gather intelligent links.
Pass-the-Hash
Flip cardA lateral movement technique where a captured NTLM hash is used directly to authenticate to other systems without needing the plaintext password.
- Exploits NTLM's acceptance of the hash itself as a credential
- Commonly performed with tools like Mimikatz and psexec/impacket
- Mitigated by disabling NTLM and enabling Credential Guard
Memory trick: Pass the hash like passing a keycard — no need to know the code.
Passive OS Fingerprinting
Flip cardThe process of identifying a target's operating system by analyzing existing network traffic, such as HTTP User-Agent strings, TCP window sizes, TTL values, and other network stack characteristics, without directly interacting with the target.
- Relies on analyzing existing traffic.
- Does not send probes to the target.
- User-Agent strings are a key indicator.
- Considered a reconnaissance technique.
Memory trick: Passive means you observe, Active means you probe.
Nmap http-methods script
Flip cardAn Nmap Scripting Engine (NSE) script used to discover the HTTP methods supported by a web server or specific web endpoint by sending an OPTIONS request.
- Part of the Nmap Scripting Engine (NSE).
- Sends an HTTP OPTIONS request to determine allowed methods.
- Useful for identifying potentially insecure methods like PUT or DELETE.
Memory trick: Nmap's HTTP scripts reveal web secrets.
Model Extraction Attack
Flip cardAn attack where an adversary queries a machine learning API extensively and uses the input-output pairs to train a substitute model that replicates the target's functionality, stealing intellectual property.
- Also called model stealing or model cloning
- Exploits publicly accessible prediction/inference APIs
- Mitigated by rate limiting, query monitoring, and output perturbation
Memory trick: Model extraction = photocopying a locked book one page-query at a time
DNS Zone Transfer Misconfiguration
Flip cardA vulnerability where a DNS server is configured to allow full zone transfers (AXFR) to unauthorized clients. This can expose sensitive internal network information, including hostnames and IP addresses.
- Uses `AXFR` (Asynchronous Zone Transfer Full Request).
- Exposes all DNS records for a domain.
- Provides a detailed map of the target's network infrastructure.
- Typically occurs due to improper `allow-transfer` settings.
Memory trick: DNS: Cache, Rebind, Transfer, Bypass – each a different way to mess with names.
Nmap Full Port Scan with Service Version Detection
Flip cardThe Nmap command `nmap -sV -p-` combines a scan of all 65535 TCP ports with aggressive service and version detection, enabling identification of services on non-standard ports.
- `-p-` scans all TCP ports (1-65535).
- `-sV` identifies service name and version.
- Comprehensive for discovering services on unusual ports.
Memory trick: To find ALL services and their Versions, scan ALL Ports.
Rules of Engagement (RoE)
Flip cardA document specifying the technical constraints of a penetration test, including timing, methods, and systems allowed.
- Includes approved testing windows/blackout periods
- Defines permitted techniques and tools
- Legally binding — deviations require client approval
Memory trick: RoE = 'Rules Over Everything' during testing
Server-Side Request Forgery (SSRF)
Flip cardA web security vulnerability that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing. This can be used to target internal systems behind firewalls or other protected networks.
- Server is tricked into making requests.
- Can target internal network resources.
- Often used to access cloud metadata services.
Memory trick: Server sees, Server fetches, Server spills secrets.
Burp Suite for Web Testing
Flip cardBurp Suite is an integrated platform for performing security testing of web applications, offering a proxy, scanner, intruder, repeater, and more.
- Intercepts HTTP/HTTPS traffic between browser and web server.
- Allows modification and replaying of requests.
- Includes tools for scanning, fuzzing, and brute-forcing web applications.
Memory trick: Web tools: Burp for proxy, Nmap for scan, Metasploit for exploit, Wireshark for sniff.
theHarvester for OSINT
Flip cardtheHarvester is a simple, yet effective, tool for gathering open-source intelligence (OSINT) about a target domain, including email addresses, subdomains, and hostnames.
- Queries public search engines (Google, Bing, Yahoo).
- Gathers email addresses, hostnames, and subdomains.
- Useful for initial reconnaissance to build target lists.
Memory trick: Recon tools: Harvester for emails, Dirb for web, Sublist3r for subdomains, Nikto for web vuln.
Nmap Service/OS Detection
Flip cardNmap's `-sV` flag probes open ports to determine the service name, version, and product, while `-O` attempts to identify the operating system, often by analyzing TCP/IP stack fingerprints.
- Adds significant time to scan duration.
- Increases network traffic and detection risk.
- Provides valuable intelligence for exploit selection.
Memory trick: Nmap flags: Service, OS, Ports, Stealth.
Nmap Host Discovery (-sn)
Flip cardAn Nmap scan type that quickly identifies active hosts on a network by sending various probes (ICMP echo requests, TCP SYN to common ports, ARP requests) without performing a full port scan on each discovered host.
- Also known as 'ping scan'.
- Uses diverse methods to detect live hosts.
- Much faster than full port scanning for large networks.
- Does not determine open ports or services.
Memory trick: Scan for Nothin' (-sn) if you just want to see who's there.
Golden Ticket Attack
Flip cardA Kerberos attack where an adversary uses the krbtgt account's NTLM hash to forge a Ticket Granting Ticket, granting persistent, domain-wide access that survives password resets.
- Requires the krbtgt hash, often obtained via DCSync
- Grants access to any service in the domain as any user
- Remediated by resetting the krbtgt password twice
Memory trick: Golden ticket = the master key to the whole Kerberos kingdom
Burp Intruder
Flip cardBurp Intruder is a powerful tool within Burp Suite used for automating customized attacks against web applications, such as brute-force attacks, dictionary attacks, and username enumeration.
- Automates repetitive requests
- Supports various attack types (e.g., Sniper, Battering Ram)
- Analyzes response differences for enumeration/vulnerability discovery
Memory trick: Intruder is the Bouncer for Bad Username Lists.
Hashcat Attack Modes
Flip cardHashcat supports multiple attack modes (-a) that define how candidate passwords are generated to match hashes, ranging from dictionary-based to brute-force approaches.
- -a 0: straight dictionary attack
- -a 3: brute-force/mask attack
- -a 0 -r applies rule files to mutate dictionary words efficiently
Memory trick: Straight beats Brute for known Patterns; Combinator combines, Association links
Proxmark3
Flip cardA portable RFID research tool capable of reading, sniffing, and cloning low- and high-frequency proximity card credentials.
- Supports both 125kHz (low-freq) and 13.56MHz (high-freq) cards
- Used in physical penetration tests to clone employee badges
- Requires proximity to the target card to capture signal
Memory trick: 'Proxmark Preys on Proximity cards'
SQL Injection (SQLi)
Flip cardA web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database, potentially leading to unauthorized data access, modification, or deletion.
- Occurs when user-supplied input is insecurely incorporated into SQL queries.
- Can be detected by injecting special characters (e.g., single quote, double dash).
- Blind SQLi relies on timing or boolean responses; error-based SQLi returns database errors.
Memory trick: SQLi is like a database whisperer, making it reveal its secrets.
Tomcat WAR File Deployment for Persistence
Flip cardDeploying a malicious Web Application Archive (WAR) file to a vulnerable Apache Tomcat server to maintain access or establish a backdoor.
- Requires access to Tomcat Manager or a vulnerability to upload WAR files.
- A WAR file can contain a web shell or a reverse shell payload.
- Metasploit provides modules for automating this process.
Memory trick: Tomcat WARs for persistent web access.
PTES Pre-engagement Interactions
Flip cardThe first phase of PTES where scope, objectives, legal agreements, and RoE are established between tester and client.
- Occurs before any technical testing
- Includes defining scope and success criteria
- Sets legal groundwork (contracts, NDA, RoE)
Memory trick: 'People Talk, Intelligence Threats, Vulnerabilities Exploited, Post, Report' - Pre-engagement first!
SUID Binary Exploitation
Flip cardExploiting legitimate binaries with the SUID bit set to gain elevated privileges, typically by executing a shell or another privileged command.
- SUID bit allows a program to run with the permissions of its owner.
- If a root-owned SUID binary can execute arbitrary commands, it can lead to privilege escalation.
- Common SUID binaries to check include 'find', 'nmap', 'vi', 'more', 'less'.
Memory trick: SUID finds a path to root.
Hashcat NTLM Cracking
Flip cardUsing Hashcat, a powerful password cracking utility, to break NTLM (NT LAN Manager) password hashes, typically through dictionary attacks, brute-force, or hybrid attacks.
- NTLM hashes are commonly found in Windows environments.
- Hashcat mode '1000' is used for NTLM hashes.
- The '-a 0' flag specifies a dictionary attack.
- Requires a wordlist for dictionary attacks.
Memory trick: Hashcat's modes unlock secrets.
Command Injection
Flip cardA web vulnerability that allows an attacker to execute arbitrary operating system commands on the server running a web application, typically by injecting commands into user-supplied input.
- Occurs when an application passes unsanitized user input to a system shell.
- Attackers can use various shell metacharacters (e.g., ;, &&, ||, |, `) to chain commands.
- Can lead to full system compromise if executed with sufficient privileges.
Memory trick: When input goes wild, system commands can be defiled.
netstat -tulnp
Flip cardA Linux command combination used to display all active network connections and listening ports for both TCP and UDP, including the associated process ID and program name.
- Displays TCP (-t) and UDP (-u) connections.
- Shows listening sockets (-l).
- Includes numeric addresses (-n) and process info (-p).
- Essential for internal network reconnaissance.
Memory trick: Netstat shows Network STatus, including Processes and Listening ports.
DLL Injection for Persistence
Flip cardA technique to maintain persistence on a compromised system by forcing a legitimate process to load and execute a malicious Dynamic Link Library (DLL).
- Malicious code runs within a trusted process's memory space.
- Difficult to detect as it mimics legitimate system behavior.
- Can re-establish command and control (C2) even if parent process terminates.
Memory trick: Remember, the ghost in the machine links deeply for persistence.
WPS PIN Brute-Force Vulnerability
Flip cardA design flaw in WPS where the 8-digit PIN is verified in two separate halves, allowing attackers like reaver to brute-force the PIN in roughly 11,000 attempts instead of 100 million.
- 8th PIN digit is a checksum, leaving 7 unknown digits
- AP validates first 4 digits and last 3 digits separately
- Reduces brute-force keyspace from 10^8 to about 11,000 combinations
Memory trick: Split the PIN in half and the lock cracks twice as easy.
Cloud Storage Enumeration
Flip cardThe process of discovering and assessing cloud object storage (e.g., AWS S3, Azure Blob) for public exposure or misconfigured access controls.
- Tools: S3Scanner, Bucket Finder, ScoutSuite, CloudBrute
- Checks bucket naming, DNS entries, and ACL/policy settings
- Common finding: publicly readable/writable buckets exposing sensitive data
Memory trick: Cloud Recon: DNS, Storage buckets, IAM policies, Metadata, Subdomains
Union-Based SQL Injection
Flip cardAn injection technique that appends a UNION SELECT statement to an existing query so attacker-chosen data is returned in the application's output.
- Requires matching the number of columns in the original query
- NULL is often used as a placeholder for unknown data types
- Effective when application output is directly visible to the tester
Memory trick: UNION shows you the data, Boolean whispers true/false, Time makes you wait.
TruffleHog
Flip cardA tool designed to search through Git repositories, commit history, and other data sources to find high-entropy strings, patterns, or sensitive data like API keys, credentials, and configuration files.
- Scans Git repositories (GitHub, GitLab, Bitbucket, local).
- Identifies sensitive data based on entropy and predefined patterns.
- Useful for discovering accidentally exposed secrets in code.
- A passive OSINT tool for code-related reconnaissance.
Memory trick: Code scanners dig for hidden treasures.
File Upload Vulnerability
Flip cardA vulnerability that allows an attacker to upload malicious files to a web server, which can then be executed by the server, leading to remote code execution or other compromises.
- Often results from inadequate file type, size, or content validation.
- Can lead to remote code execution (RCE), defacement, or data exfiltration.
- Bypasses include manipulating file extensions, content types (MIME), or using null bytes.
Memory trick: Web apps can be tricky, always check the upload policy.
Indemnification Clause
Flip cardA contract provision where one party agrees to compensate the other for losses, damages, or legal costs arising from claims related to actions performed under the agreement.
- Often shields the testing firm from third-party lawsuits stemming from authorized testing
- Differs from limitation of liability, which caps the tester's own exposure
- Commonly paired with authorization letters and NDAs in the SOW/MSA
Memory trick: Indemnify = 'I'll shield you' from outside lawsuits
WPS PIN Brute-Force (Reaver)
Flip cardAn attack exploiting a design flaw in Wi-Fi Protected Setup (WPS) that allows for the brute-forcing of the 8-digit PIN in two halves, significantly reducing the time required to recover the WPA2-PSK passphrase.
- Exploits a weak authentication mechanism in WPS.
- Typically uses the tool Reaver or similar.
- Can recover the WPA2-PSK passphrase within hours, even with strong passwords.
- Many modern routers disable WPS or implement lockouts to mitigate this.
Memory trick: WPS PIN: Reaver rips through the weak links.
Certificate Transparency (CT) Logs
Flip cardPublicly auditable logs that record all SSL/TLS certificates issued by Certificate Authorities. They are a valuable resource for passive subdomain enumeration.
- Maintains a public record of all issued SSL/TLS certificates.
- Can reveal subdomains associated with an organization's primary domain.
- A passive reconnaissance technique as it doesn't interact with the target.
Memory trick: Certificates Reveal Hidden Names.
Nmap SYN Scan (-sS)
Flip cardA half-open TCP scan that sends SYN packets and resets the connection before completion, providing fast, low-footprint port discovery.
- Also called a 'half-open' scan
- Requires raw socket privileges (root/admin)
- Default scan type when running Nmap with elevated privileges
Memory trick: 'Stop, You've Understood Access' = SYN, TCP-connect, UDP, ACK
theHarvester
Flip cardAn OSINT tool used to gather public information (emails, subdomains, hostnames, employee names, banners, open ports) from various public sources for a given target domain or company name.
- Automates collection of email addresses and subdomains.
- Leverages search engines (Google, Bing, Baidu), PGP key servers, LinkedIn, etc.
- Useful for initial reconnaissance to build a target profile.
- Command-line tool, easy to use.
Memory trick: Harvesters collect public data.
Staged vs. Stageless Metasploit Payloads
Flip cardStaged payloads send a small stager that downloads the full payload afterward (slash notation), while stageless payloads deliver the entire payload in a single package (underscore notation).
- Staged: windows/meterpreter/reverse_tcp
- Stageless: windows/meterpreter_reverse_tcp
- Stageless payloads are larger but more firewall-resilient
Memory trick: Underscore = 'Un-staged' — one solid package, no second delivery truck
Passive Web Fingerprinting
Flip cardIdentifying web technologies (server, CMS, libraries) by analyzing publicly available information like HTTP headers, HTML source code, and error messages, without sending specific probes.
- Relies on information sent during normal web requests.
- Minimizes detection risk.
- Examples: looking at 'Server' header, 'X-Powered-By' header, HTML comments.
Memory trick: Web fingerprint: Passive browse, Active scan.
DNS Tunneling for C2
Flip cardA technique that establishes a covert command and control (C2) channel by encapsulating attacker commands and victim responses within DNS queries and responses.
- Bypasses firewalls that block common C2 protocols (HTTP/S, SSH).
- Relies on the fact that DNS traffic is almost always allowed outbound.
- Requires a controlled DNS server to receive and process tunneled data.
Memory trick: For stealthy communication, use ghost signals through allowed channels.
Statement of Work (SOW)
Flip cardA contract document defining the specific scope, deliverables, timeline, and cost of an individual engagement, typically under an existing MSA.
- Created for each specific project/engagement
- References the overarching MSA terms
- Includes scope, deliverables, and schedule
Memory trick: MSA is the umbrella; SOW is each raindrop underneath
AS-REP Roasting
Flip cardAn Active Directory attack that targets accounts with Kerberos preauthentication disabled, allowing an attacker to request an AS-REP message without valid credentials and crack its encrypted portion offline.
- Requires the 'Do not require Kerberos preauthentication' UAC flag set
- No valid credentials needed to request the AS-REP
- Cracked offline with tools like hashcat (mode 18200)
Memory trick: AS-REP Roasting: 'Ask without asking permission first'
Burp Suite Repeater
Flip cardA Burp Suite tool that allows testers to manually modify and resend individual HTTP requests, viewing the server's response for each iteration.
- Ideal for manual business logic and parameter tampering tests
- Unlike Intruder, sends one request at a time under tester control
- Commonly used to test IDOR, privilege escalation, and workflow bypasses
Memory trick: Repeater = Repeat one shot, review it closely
netstat for Service Enumeration
Flip cardThe 'netstat' command with specific flags (e.g., -tulnp) is used on Linux systems to display network connections, routing tables, interface statistics, and most importantly, listening ports and the processes associated with them.
- '-t' shows TCP connections.
- '-u' shows UDP connections.
- '-l' shows only listening sockets.
- '-n' shows numeric addresses and port numbers.
Memory trick: Linux commands reveal open doors.
DNS Tunneling for Exfiltration
Flip cardA covert data exfiltration technique that encodes data within DNS queries and responses, allowing it to bypass firewalls and traditional network monitoring.
- Abuses legitimate DNS protocol for data transfer.
- Often bypasses IDS/IPS as DNS traffic is rarely deep-inspected.
- Typically slow due to DNS packet size limitations, but highly stealthy.
Memory trick: To steal data invisibly, you need clever packaging and a ghost path.
DNS Zone Transfer (AXFR) Misconfiguration
Flip cardA DNS server vulnerability where zone transfer requests (AXFR) are allowed from unauthorized hosts, leaking the entire DNS zone including internal hostnames and IPs.
- Zone transfers should be restricted to authorized secondary name servers only
- Tools: dig axfr, host -t axfr, nslookup
- Reveals internal infrastructure useful for further reconnaissance
Memory trick: AXFR leak = the phonebook for the entire company handed to a stranger
SUID Binary PATH Exploitation
Flip cardA privilege escalation technique where a SUID binary executes another command without specifying its full path, allowing an attacker to inject a malicious version of that command via the PATH environment variable.
- Relies on SUID binary executing external commands.
- Attacker creates a malicious executable with the same name as the called command.
- Modifies PATH to prioritize the malicious executable, leading to privileged execution.
Memory trick: To climb the Linux ladder, look for weak links.
Lock Picking
Flip cardA physical security bypass technique using a tension wrench and pick to manipulate individual pins in a pin tumbler lock until each sets at the shear line, allowing the lock to open without the correct key.
- Requires a tension wrench + pick set
- Tests physical access control effectiveness during assessments
- Different from bumping (impact-based) and shimming (latch bypass)
Memory trick: Pick pins one by one like plucking guitar strings until the tune (shear line) is right
Metasploit Module Types
Flip cardMetasploit organizes functionality into module types, each serving a distinct role in the exploitation lifecycle.
- Auxiliary: scanning, fuzzing, DoS (no payload)
- Exploit: delivers payload to compromise a target
- Post: runs after successful exploitation for further actions
Memory trick: Auxiliary checks, Exploit strikes, Payload rides along, Post digs deeper
Web Application Backdooring (Deep)
Flip cardEstablishing a resilient backdoor within a web application by modifying core application files, libraries, or framework components to maintain access even if primary web shells are removed.
- Blends malicious code within legitimate application logic.
- Difficult to detect without thorough code review or advanced integrity checks.
- Ensures persistence even after superficial cleanup efforts.
Memory trick: For web app persistence, go deep into the code's core.