CompTIA PenTest+ (PT0-003) flashcards
192 free flashcards. Tap a card to flip it.
Evil Twin Attack
Flip cardA rogue access point that impersonates a legitimate network's SSID, often paired with a fake captive portal, to capture credentials or traffic.
- Uses a stronger signal to lure clients away from the real AP
- Often paired with a fake login page to harvest credentials
- May be combined with deauth attacks to force reconnection
Memory trick: Twins look alike but one is evil in disguise.
Public Cloud Storage Misconfiguration
Flip cardA security flaw where cloud storage objects (e.g., AWS S3 buckets, Azure Blob containers) are configured with overly permissive access controls, exposing data to the public internet.
- Tools like S3Scanner or Grayhat Warfare can enumerate open buckets
- Public read exposes data; public write allows tampering/malware hosting
- Root cause is misconfigured bucket policies/ACLs, not code vulnerabilities
Memory trick: An open bucket lets anyone dip their hand in
Non-Disclosure Agreement (NDA)
Flip cardA legal contract that obligates parties to protect and not disclose confidential information exchanged during an engagement.
- Signed before sensitive discussions/testing begins
- Can be mutual (both parties) or one-way
- Breach can result in legal liability
Memory trick: NDA = 'No Divulging Allowed'
ARP Cache for Reconnaissance
Flip cardThe Address Resolution Protocol (ARP) cache stores IP-to-MAC address mappings of recently communicated devices on a local network segment, which can be inspected for passive host discovery.
- Provides information about directly connected devices.
- Does not generate new network traffic for discovery.
- Limited to devices the host has recently interacted with.
Memory trick: Internal recon: ARP cache quiet, Nmap loud, Metasploit active.
Burp Suite Intruder
Flip cardA Burp Suite tool used for automating customized attacks against web applications. It can fuzz parameters, brute-force credentials, and test for various vulnerabilities by systematically sending altered requests.
- Automates sending multiple requests with varied payloads.
- Useful for fuzzing, brute-forcing, and enumeration.
- Analyzes response lengths, status codes, and content for differences.
- Supports various payload types and attack configurations.
Memory trick: Burp's tools dissect web traffic.
CVSS Attack Complexity (AC)
Flip cardA CVSS base metric describing conditions beyond the attacker's control that must exist for successful exploitation.
- AC:L (Low) = no special conditions needed, higher score
- AC:H (High) = requires specific conditions, lower score
- Distinct from Privileges Required and User Interaction metrics
Memory trick: 'A Cat Prowls Under Streetlights' = AV, AC, PR, UI, Scope
Tailgating (Piggybacking)
Flip cardA physical social engineering technique where an unauthorized person follows an authorized individual through a secured access point without independently authenticating.
- Also called piggybacking
- Exploits courtesy/social norms (holding doors)
- Mitigated by mantraps and badge enforcement policies
Memory trick: Tail the badge, Clone the badge, Pick the lock, Dive the trash, Peek the screen
NTLM Hash Identification
Flip cardWindows credential dumps typically appear as LM:NTLM pairs; the constant aad3b435b51404eeaad3b435b51404ee indicates an empty/disabled LM hash, and the following 32 hex characters are the NTLM hash, cracked with hashcat mode 1000.
- LM hash constant aad3b435b51404eeaad3b435b51404ee means LM hashing is disabled or blank
- NTLM hashes are cracked using hashcat mode 1000
- NetNTLMv1/v2 (modes 5500/5600) are different — they're network authentication responses, not static hashes
Memory trick: aad3b435... = LM's ghost hash; the real NTLM hash follows the colon
Kerberoasting
Flip cardAn attack where a tester requests service tickets (TGS) for accounts with SPNs and cracks them offline to recover service account passwords.
- Requires only a valid domain user, not admin rights
- Cracked with hashcat mode 13100
- Mitigated by strong service account passwords and gMSA
Memory trick: 'Kerber-oast the ticket, then hash 13100 to crack it'
CloudEnum
Flip cardA tool used in reconnaissance to identify and enumerate publicly accessible cloud storage buckets (e.g., AWS S3, Azure Blob, Google Cloud Storage) and other cloud resources associated with a target.
- Specializes in cloud resource enumeration.
- Identifies misconfigured public cloud storage.
- Useful for discovering sensitive data in the cloud.
Memory trick: CloudEnum specifically enumerates cloud resources, not just subdomains.
Burp Suite Intruder Attack Types
Flip cardBurp Intruder offers four attack types that control how payload sets are applied to marked positions in a request.
- Sniper: one payload set, one position at a time
- Pitchfork: multiple sets, synced by index
- Cluster bomb: multiple sets, all combinations tested
Memory trick: Sniper hits one, Ram hits all same, Pitchfork syncs, Bomb explodes all combos
Vishing
Flip cardA social engineering technique that uses phone calls to trick a victim into revealing information or performing an unauthorized action.
- Voice + phishing = Vishing
- Often impersonates executives, IT, or vendors
- Effective against help desks due to urgency and authority
Memory trick: 'Vishing = Voice fishing on the phone'
Passive Reconnaissance
Flip cardInformation gathering without direct interaction with the target system or network, relying on publicly available data or third-party sources.
- Low risk of detection.
- Examples: OSINT, public records, social media analysis.
- Provides a foundational understanding before active engagement.
Memory trick: Recon: Passive hides, Active seeks.
Nmap's http-enum and Directory Listing
Flip cardNmap's `http-enum` script actively probes a web server for common directories and files. When it encounters a directory without an index page and directory listing is enabled, the server's response (e.g., an HTML page listing contents) will be detected and reported by the script.
- Automates discovery of common web paths.
- Can identify misconfigured directory listings.
- Provides quick insights into exposed web content.
Memory trick: Web enum: Nmap http-enum finds open directories.
Nmap UDP Host Discovery (-PU)
Flip cardAn Nmap technique for host discovery that sends UDP probes to common ports (e.g., 53, 161, 137) to elicit responses from live hosts, particularly effective when ICMP and TCP probes are blocked.
- Uses UDP packets for host discovery.
- Effective when ICMP and TCP pings are filtered.
- Often targets common UDP ports like DNS (53) or SNMP (161).
Memory trick: When ICMP is a ghost, UDP probes can still find the host.
IAM PassRole Privilege Escalation
Flip cardA cloud privilege escalation technique where a user with iam:PassRole and a resource-launching permission (like ec2:RunInstances) attaches a highly privileged role to a new resource to inherit its permissions.
- Requires iam:PassRole plus a launch permission (EC2, Lambda, etc.)
- Credentials retrieved via instance metadata service after launch
- Common AWS misconfiguration finding in cloud pentests
Memory trick: 'PassRole + RunInstances = pass the crown to a new instance and wear it yourself'
CVSS Qualitative Severity Scale
Flip cardA standardized mapping of CVSS v3.x base scores to severity labels used for prioritizing remediation.
- 0.0 = None
- 0.1-3.9 = Low, 4.0-6.9 = Medium
- 7.0-8.9 = High, 9.0-10.0 = Critical
Memory trick: None-Low-Medium-High-Critical: 'Nobody Likes Messy High Crises'
Scope Creep / Out-of-Scope Discovery
Flip cardThe situation where testing activities reveal systems or assets not covered by the signed scope agreement, requiring explicit written authorization before further action.
- Testing out-of-scope systems is a legal risk
- Written authorization must be obtained, not verbal
- Document discovery even if not tested
Memory trick: When in doubt, don't scope it out — get it in writing!
Limitation of Liability Clause
Flip cardA contract clause capping the maximum financial damages a party can be held responsible for, often tied to the contract's total value.
- Protects the testing firm from unlimited financial exposure
- Commonly capped at the total contract or SOW value
- Distinct from indemnification, which shifts responsibility for specific claims
Memory trick: ILNT: Indemnify, Limit liability, Non-compete, Terminate — four clause types to know.
RIPEstat
Flip cardA web-based tool provided by the RIPE NCC that offers a wide range of statistics and information about IP address space, ASNs, and BGP routing data.
- Provides BGP routing information, ASN details, and IP address allocations.
- A passive OSINT tool for network infrastructure reconnaissance.
- Leverages data from the RIPE NCC database.
Memory trick: Network maps, open sources, reveal the routes.
WHOIS Lookup
Flip cardA query protocol used to retrieve registration information for domain names and IP address blocks, often revealing contact details, registrars, and nameservers.
- Provides registrant contact information.
- Useful for identifying domain owners and network blocks.
- Considered a passive reconnaissance technique.
Memory trick: Who is behind that domain? WHOIS knows passively.
Adverse Event Notification via Communication Plan
Flip cardWhen testers discover unrelated real-world compromises or critical issues during an engagement, the rules of engagement's communication plan requires prompt notification of the designated point of contact rather than unilateral action.
- Communication plans define escalation contacts and methods
- Testers should not remediate or destroy evidence outside scope
- Prompt notification enables the client's incident response process
Memory trick: Found a fire? Call the fire department, don't grab the hose yourself
Adverse Event Handling
Flip cardThe required immediate response when testing unintentionally causes harm, such as a service outage, including halting activity and prompt client notification.
- RoE typically requires immediate notification of adverse events
- Testing on the affected system should stop right away
- Should never be concealed or delayed until a routine check-in
Memory trick: Stop, Call, Log, Assess, Resume-with-OK — the five-step adverse event drill.
Scope Change Management
Flip cardThe formal process of pausing testing on newly discovered out-of-scope assets and obtaining written client approval before proceeding.
- Even 'obviously related' assets require explicit written authorization
- Typically documented via a signed scope addendum to the SOW
- Protects both tester and client from legal exposure
Memory trick: See it, Stop it, Send it (to client), Sign it, Scan it — five steps for out-of-scope finds.
Burp Intruder Attack Types
Flip cardBurp Suite Intruder offers four attack types (Sniper, Battering ram, Pitchfork, Cluster bomb) that control how payload sets are applied across multiple positions.
- Cluster bomb = all combinations of multiple payload sets
- Pitchfork = parallel, index-matched payloads
- Sniper = single payload set, one position at a time
Memory trick: 'Cluster Bomb explodes into every combination' — think fireworks covering all pairs
Pass-the-Hash (PtH)
Flip cardA post-exploitation technique where an attacker authenticates to a remote system or service using the NTLM hash of a user's password, rather than the plaintext password. This bypasses the need for cracking the hash.
- Uses NTLM hash directly for authentication.
- Bypasses plaintext password requirement.
- Effective in Windows environments, especially with NTLM authentication.
Memory trick: Windows auth: Hash reuse, Ticket forge, Service crack, Preauth grab.
Time-Based Blind SQL Injection
Flip cardA SQL injection technique where the attacker infers data by measuring response delays caused by time-delay functions, since no visible output difference occurs.
- Uses functions like SLEEP() or WAITFOR DELAY
- Useful when application suppresses errors and output
- SQLMap automates detection and exploitation via --technique=T
Memory trick: No error, no visible change, just a pause — Time is Talking
PMKID Attack
Flip cardA WPA2-PSK attack that captures the Pairwise Master Key Identifier (PMKID) from a single frame sent by the access point, allowing offline password cracking without a full four-way handshake or client interaction.
- Captured with hcxdumptool, cracked with hashcat mode 16800 (or 22000 for the unified format)
- Does not require a connected client or deauthentication attack
- Only works against APs that include the PMKID in the first EAPOL message
Memory trick: PMKID: 'Peek at the Master Key ID' in one quiet frame
Log File Cleanup (Linux)
Flip cardThe process of identifying and removing or modifying specific entries in system log files (e.g., `/var/log/*`) to erase traces of attacker activity and prevent forensic analysis.
- Crucial for evading detection and hindering incident response.
- Requires root privileges to access and modify system logs.
- Can involve tools like `logrotate` manipulation, `zap` (for specific entries), or direct file editing.
Memory trick: Logs are the memory, erase them all.
Retest / Attestation of Findings
Flip cardA follow-up validation activity where the tester re-examines previously reported vulnerabilities to confirm that remediation efforts were effective.
- Focused only on previously identified findings, not a full new assessment
- Often documented in a short attestation letter or addendum report
- May be included in the original SOW or billed as an additional engagement
Memory trick: Deliver, Destroy, reDo (retest), Done: the four D's after the report.
Cloud Metadata Service (IMDS) Exploitation
Flip cardAn attack where SSRF or local access is used to query the cloud instance metadata service (e.g., AWS 169.254.169.254) to steal temporary IAM credentials attached to the instance role.
- AWS IMDS listens on the link-local address 169.254.169.254
- IMDSv1 accepts simple GET requests, making it SSRF-vulnerable; IMDSv2 requires token-based session headers
- Retrieved credentials can be reused to access other AWS resources the role permits
Memory trick: 169.254.169.254 is the cloud's secret credential drawer
Fixed-Price vs Time and Materials Contracts
Flip cardA fixed-price contract charges one agreed total for a clearly scoped deliverable, while a time and materials contract bills based on actual hours and resources consumed.
- Fixed-price suits well-defined, narrow scope work
- Time and materials suits open-ended or uncertain-scope work
- Retainers provide ongoing availability for future testing needs
Memory trick: Fixed scope = Fixed price; Fuzzy scope = pay by the hour
Nmap http-enum Script
Flip cardThe `http-enum` Nmap Scripting Engine (NSE) script attempts to enumerate common web directories and files on HTTP/HTTPS servers, often using a predefined wordlist.
- Part of the 'discovery' and 'safe' categories.
- Useful for finding hidden or forgotten web content.
- Can help identify potential attack vectors or information disclosure.
Memory trick: Nmap scripts: Auth, Vuln, Discovery, HTTP Enum.
nmap Service Version Scan
Flip cardThe -sV flag in nmap probes open ports to determine the application name and version running on them.
- -sV queries banners and behavior to fingerprint services
- Can be combined with -p for specific ports
- Increases scan time due to probing
Memory trick: 'Sassy Vixens Own Aggression' = -sS,-sV,-O,-A
Reverse Shell Port Selection
Flip cardChoosing a common, allowed outbound network port for a reverse shell connection to evade firewalls and blend with legitimate network traffic.
- Aims to mimic normal user activity (e.g., web browsing).
- Common choices include 80, 443, 53.
- Helps bypass egress filtering and basic IDS/IPS rules.
Memory trick: To connect secretly, pick a port that's always open for traffic.
NTLM Relay Attack
Flip cardAn attack where captured NTLM authentication attempts are forwarded to another server in real time to authenticate as the victim, bypassing the need to crack the hash.
- Often initiated with Responder for poisoning/capture
- ntlmrelayx forwards the captured auth session
- Effective when SMB signing is not enforced
Memory trick: Relay it live before it goes cold — no cracking needed.
Hashcat Rule-Based Attack
Flip cardA straight attack (mode 0) enhanced with a rules file (-r) that applies mutation patterns like case changes, appends, and character substitutions to wordlist entries.
- Common rule files include best64.rule and rockyou-30000.rule
- Greatly expands wordlist coverage without new files
- Rules are plaintext scripts defining mutation functions
Memory trick: 'Straight Combines Brute Hybrids' = 0,1,3,6/7
Metasploit WordPress Username Enumeration
Flip cardMetasploit's 'auxiliary/scanner/http/wordpress_login_enum' module is used to identify valid usernames on WordPress sites by analyzing differences in error messages when invalid usernames are submitted to the login page.
- Targets WordPress login forms.
- Exploits differences in error messages for valid vs. invalid usernames.
- A specific example of username enumeration vulnerability.
- Part of Metasploit's auxiliary scanner modules.
Memory trick: Metasploit scans web forms for secrets.
Nmap DNS Brute-Force
Flip cardA method using Nmap's 'dns-brute' script to discover subdomains by systematically guessing common subdomain names and querying DNS records.
- Uses a built-in wordlist of common subdomains.
- Checks for A, AAAA, and CNAME records.
- Can be slow if run against many domains or with large wordlists.
Memory trick: DNS Brute-force is your key to unlocking hidden subdomain doors.
Burp Suite Intruder (Path Traversal)
Flip cardUsing Burp Suite's Intruder tool to automate the testing of path traversal vulnerabilities by systematically injecting various directory traversal sequences (e.g., `../`, `..%2f`) into URL paths or parameters.
- Allows defining payload positions and types.
- Can use built-in or custom wordlists for payloads.
- Automates sending many requests and analyzing responses for indicators of success.
- Effective for brute-forcing and systematic fuzzing.
Memory trick: Intruder attacks with multiple payloads, methodically.
OWASP Testing Guide
Flip cardA comprehensive framework for testing web application security, organized into categories like authentication, session management, and injection.
- Maintained by OWASP community
- Complements the OWASP Top 10
- Provides detailed test cases per vulnerability category
Memory trick: OWASP = 'Only Web Apps' framework
Nmap Port States
Flip card`nmap` reports various states for ports (e.g., open, closed, filtered, unfiltered, open|filtered, closed|filtered) to describe their accessibility and the presence of services.
- Open: Application is actively accepting TCP connections/UDP datagrams.
- Closed: Port is accessible, but no application is listening.
- Filtered: Firewall or network device is blocking probes, state is unknown.
Memory trick: Open door, Closed door, Filtered to a mystery.
Certificate Transparency Logs
Flip cardPublic records of all SSL/TLS certificates issued by Certificate Authorities, designed to improve security by allowing domain owners to monitor for misissued certificates.
- Contains domain and subdomain names for which certificates were issued.
- Publicly accessible and searchable.
- Excellent source for passive subdomain enumeration.
Memory trick: Subdomains hide like branches on a digital tree.
Risk-Based Remediation Prioritization
Flip cardThe practice of prioritizing vulnerability fixes based on actual business impact and exploitability context, not solely on base CVSS scores.
- Considers asset value, data sensitivity, and exploitability
- A lower CVSS score can represent higher real-world risk
- CVSS environmental/temporal metrics can adjust base scores
Memory trick: Context is king — don't just trust the number!
OSSTMM Risk Assessment Value (RAV)
Flip cardA quantitative metric in OSSTMM that measures actual operational security by comparing existing controls to an ideal security state.
- Produces a normalized, comparable score
- Based on factors like porosity, limitations, controls
- Allows tracking of security improvement over time
Memory trick: RAV = 'Real Actual Value' of your security
DHCP Starvation Attack
Flip cardAn attack where an adversary floods a network with forged DHCP request packets to exhaust the available IP address pool, often followed by deploying a rogue DHCP server to control client network configuration.
- Exhausts legitimate DHCP server's lease pool with spoofed MAC addresses
- Often paired with a rogue DHCP server for MITM attacks
- Tools like Yersinia or dhcpstarv can automate the flood
Memory trick: Starve the pool, then serve poisoned addresses
LM Hash Cracking
Flip cardThe process of recovering plaintext passwords from Lan Manager (LM) hashes, which are very weak and susceptible to rapid cracking due to their design flaws.
- Case-insensitive passwords are converted to uppercase.
- Passwords longer than 7 characters are split into two 7-character halves.
- No salt is used, making them vulnerable to rainbow table attacks.
- Modern cracking tools like Hashcat can crack them in seconds.
Memory trick: Hashcat cracks fast, John rips, Mimikatz extracts, Responder sniffs.
Nmap Scripting Engine (NSE) Categories
Flip cardNSE scripts are grouped into categories that describe their purpose and intrusiveness, allowing testers to run targeted script sets with --script <category>.
- --script vuln targets known vulnerabilities
- --script safe scripts won't crash or disrupt services
- --script default runs a curated balanced set
Memory trick: 'Very Dangerous Scripts Are Vulnerable' - Default, Discovery, Safe, Auth, Vuln
Web Directory Brute-Forcing
Flip cardWeb directory brute-forcing involves systematically attempting to access common or guessed directory and file names on a web server using wordlists, aiming to discover hidden or unlinked resources.
- Uses wordlists for common paths/extensions
- Helps discover sensitive files (e.g., backups, configs)
- Tools like Dirb and Gobuster are specialized for this
Memory trick: Dirb and Gobuster are the Detectives of Directories.
False Negative
Flip cardA scan result where an actual vulnerability exists on the target but the scanning tool fails to identify or report it.
- Often caused by outdated plugin/signature databases
- More dangerous than false positives since risk goes unnoticed
- Manual validation and multiple scanners help reduce false negatives
Memory trick: 'Truth Tells, False Fools' — match reality vs. report
DNS Tunneling
Flip cardA technique that encapsulates data of other protocols within DNS queries and responses to bypass firewalls and network restrictions, often used for C2 and data exfiltration.
- Utilizes DNS protocol for covert communication.
- Effective in highly restricted network environments.
- Requires a DNS server controlled by the attacker.
Memory trick: DNS is Your Stealthy Data Guide.
Authorization Letter
Flip cardA signed document from the client granting explicit permission for specific testing activities, carried by testers as legal proof of authorization.
- Also called a 'get-out-of-jail-free card'
- Should be carried during on-site or physical engagements
- Distinct from the NDA, MSA, and SOW
Memory trick: NASOR: NDA, Authorization, SOW, MSA, RoE — each document plays a role.
Shodan
Flip cardA search engine that indexes banners and metadata from internet-connected devices, enabling passive reconnaissance of exposed assets.
- Searches by IP, port, service banner, or organization
- Useful for finding exposed IoT, cloud, and industrial devices
- No direct interaction with target required
Memory trick: 'Shodan Sees Without Touching'
WPA2-PSK Hashcat Cracking
Flip cardUsing Hashcat to perform an offline brute-force or dictionary attack against a captured WPA2-PSK 4-way handshake to recover the pre-shared key.
- Requires a captured 4-way handshake (e.g., in a .cap or .hccapx file).
- Hashcat mode `2500` is used for WPA/WPA2 PSK handshakes.
- Commonly performed with dictionary attacks (`-a 0`) or mask attacks (`-a 3`).
- The effectiveness depends on the strength of the pre-shared key and the quality of the wordlist.
Memory trick: Mode 2500 for the handshake, 22000 for PMKID, attack type for the strategy.
Reaver (WPS Attack Tool)
Flip cardA tool that exploits a design flaw in WiFi Protected Setup (WPS) by brute-forcing the 8-digit PIN in halves, ultimately recovering the WPA/WPA2 passphrase.
- Targets WPS-enabled routers
- Exploits reduced keyspace due to PIN checksum design flaw
- Often paired with monitor-mode interfaces set up via airmon-ng
Memory trick: Reaver 'reaps' the WPS PIN, one half at a time
Amass for Subdomain Enumeration
Flip cardA comprehensive open-source tool for attack surface mapping and subdomain enumeration, leveraging various techniques like DNS brute-forcing, scraping, and certificate transparency logs.
- Uses multiple data sources for subdomain discovery.
- Leverages certificate transparency logs.
- Effective for mapping a target's full attack surface.
Memory trick: Amass MASses together all subdomain data for you.
Wireless Discovery with Kismet
Flip cardKismet is a passive 802.11 wireless network detector, sniffer, and intrusion detection tool used to enumerate nearby wireless access points and clients.
- Passively captures beacon and probe frames
- Identifies SSID, BSSID, channel, and encryption type
- Useful for detecting rogue or unauthorized access points
Memory trick: Passive Scan, Channel Hop, Capture Beacons, Spot Rogues, Map Signal
Data Poisoning Attack
Flip cardAn AI attack that corrupts a model's training data, often with mislabeled or malicious samples, to degrade or manipulate the model's future behavior.
- Targets the training/retraining phase, not inference
- Can cause misclassification or backdoors in the model
- Differs from evasion attacks, which target already-trained models
Memory trick: Poison the well before anyone drinks from the model.
Meterpreter 'hashdump'
Flip cardA Meterpreter command used to extract NTLM password hashes from the Security Account Manager (SAM) database on a compromised Windows system.
- Requires SYSTEM privileges or equivalent.
- Outputs hashes in a format suitable for cracking tools like Hashcat.
- Automates the process of extracting local user hashes.
Memory trick: Meterpreter helps you unlock the computer's secrets with commands.
Deconfliction / Communication Plan
Flip cardA defined escalation path in the RoE identifying who to contact when testing activity triggers alerts or is mistaken for a real attack.
- Prevents wasted incident response effort on authorized activity
- Should list names, roles, and contact methods (phone/email)
- Used whenever defensive controls react unexpectedly to testing
Memory trick: When alarms ring, call the RoE contact, don't go silent or go to the top.