CompTIA PenTest+ (PT0-003) flashcards
192 free flashcards. Tap a card to flip it.
Metasploit dir_scanner
Flip cardA Metasploit auxiliary module (`auxiliary/scanner/http/dir_scanner`) used to perform dictionary-based brute-force attacks against web servers to discover hidden directories and files.
- Part of Metasploit Framework.
- Performs dictionary-based directory brute-forcing.
- Aims to discover hidden web paths.
- Useful for finding sensitive information or misconfigurations.
Memory trick: METASPLOIT Scans DIRS for Hidden Paths
Metadata Extraction (OSINT)
Flip cardA passive OSINT technique involving the analysis of embedded data (metadata) within publicly available files (e.g., PDFs, Word documents, images). This metadata can include author names, creation dates, software versions, comments, or geographic coordinates, potentially revealing sensitive information about an organization or individuals.
- Targets publicly available files (PDF, DOCX, XLSX, JPG, etc.).
- Extracts embedded data like author, creation date, software.
- Can reveal usernames, email addresses, internal system info.
- Tools like ExifTool or FOCA are used for this purpose.
Memory trick: Metadata is the hidden story behind the document's cover.
Burp Suite Intruder (Sniper Attack)
Flip cardA Burp Suite Intruder attack type that uses a single payload set and inserts each payload into a single defined insertion point in the base request. Ideal for testing individual parameters for vulnerabilities.
- Uses one payload set.
- One insertion point per request.
- Efficient for testing single parameters.
- Generates a separate request for each payload.
Memory trick: SNIPER Targets One Parameter
Hashcat Hash Identification (MD5)
Flip cardIdentifying the hashing algorithm is crucial for cracking. A common characteristic is hash length; a 32-character hexadecimal string often indicates an MD5 hash (128-bit). Hashcat uses specific modes for each algorithm, with Mode 0 for MD5.
- MD5 produces a 128-bit hash (32 hex characters).
- SHA1 produces a 160-bit hash (40 hex characters).
- NTLM is also 32 hex characters but specific to Windows.
- Hashcat 'mode 0' is for MD5.
Memory trick: Hash length is the key to identifying the algorithm.
Passive Dark-Web Reconnaissance
Flip cardGathering information from dark-web sources without direct interaction with the target platform, typically by querying publicly available archives, search engine indexes, or third-party data repositories.
- No direct interaction with the target.
- Relies on existing data from third parties.
- Minimizes detection risk.
- Examples: specialized dark-web search engines, archived content.
Memory trick: ARCHIVES hide, but can be searched passively
Nmap Aggressive Scan (-A)
Flip cardThe Nmap '-A' option enables an aggressive scan, which is a combination of several advanced scan features: OS detection (-O), version detection (-sV), script scanning using the default script set (-sC), and traceroute (--traceroute). It's used for comprehensive information gathering.
- Shorthand for -sV -sC -O --traceroute.
- Provides comprehensive information about services, OS, and common vulnerabilities.
- More noisy and time-consuming than basic scans.
Memory trick: Aggressive mode gathers ALL the details.
Windows Command Line Ping Sweep
Flip cardA native Windows command-line technique to perform host discovery (a ping sweep) across a local subnet. It uses a `for` loop to iterate through a range of IP addresses, sending an ICMP echo request (ping) to each and filtering the output to identify active hosts.
- Uses `for /L` loop for iteration.
- Leverages `ping` command for ICMP echo requests.
- Filters output with `findstr` to show only replies.
- Native to Windows, no external tools required.
Memory trick: The 'for' loop pings through the network, finding replies like treasure.
Certificate Transparency (CT) Logs for Subdomain Enumeration
Flip cardCertificate Transparency (CT) logs are public, auditable records of all SSL/TLS certificates issued by Certificate Authorities. Penetration testers can query these logs to passively discover subdomains that have had certificates issued for them, without directly interacting with the target's network.
- Publicly accessible databases of SSL/TLS certificates.
- Contains subdomain names from 'Subject Alternative Name' (SAN) fields.
- A passive reconnaissance technique, as it doesn't touch the target's infrastructure.
Memory trick: CT logs quietly reveal subdomains from public certificates.
Nmap SYN Stealth Scan
Flip cardA type of Nmap port scan that sends a SYN packet and waits for a SYN/ACK or RST, without completing the full TCP three-way handshake. This 'half-open' technique makes it less detectable by firewalls and intrusion detection systems (IDS) compared to a full TCP Connect Scan.
- Does not complete the TCP three-way handshake.
- Sends only a SYN packet and analyzes the response.
- Less likely to be logged by target systems.
- Requires raw packet privileges.
Memory trick: Stealthy SYN avoids the full handshake, like a ninja slipping through the door.
Nmap dns-brute script
Flip cardThe Nmap 'dns-brute' script attempts to discover subdomains for a target domain by brute-forcing common subdomain names using a built-in wordlist or a user-provided one.
- Used for subdomain enumeration.
- Leverages wordlists for brute-forcing.
- Helps expand the attack surface by finding hidden hosts.
Memory trick: DNS-brute force opens new doors to subdomains.
Meterpreter Persistence
Flip cardEstablishing a mechanism on a compromised system that ensures continued access, even after system reboots or session termination, often by creating services, scheduled tasks, or startup entries.
- Meterpreter's 'run persistence' script automates common persistence techniques.
- Persistence can be userland or system-level.
- Hidden services or scheduled tasks are common methods.
Memory trick: Meterpreter's Run Persistence: 'R'eally 'P'owerful 'S'tealth for Reboots!
Open Redirect
Flip cardAn Open Redirect vulnerability allows an attacker to redirect users to an arbitrary external URL by manipulating an unvalidated redirect parameter in a web application.
- Exploits lack of validation on URL redirect parameters.
- Commonly used in phishing campaigns.
- Can lead to credential theft or malware downloads.
Memory trick: An open gate leads straight to a phishing bait.