
Penetration Testing: Create a DNS Zone Transfer Lab
DNS zone transfers use the AXFR protocol to replicate DNS records across DNS servers. If you do not protect your name servers, attackers can get information about all your hosts with AXFR.
34 articles

DNS zone transfers use the AXFR protocol to replicate DNS records across DNS servers. If you do not protect your name servers, attackers can get information about all your hosts with AXFR.

Social media platforms can betray a considerable amount of information on a person or organization which can be useful during a pentest information gathering.

How can you detect the Log4j zero day vulnerability (known as Log4shell)? Here's a list of FREE Log4j vulnerability scanner tools.

You can build a pentest lab on a raspberry pi with DVWA to test your skills and also learn new tricks on how to attack and/or secure web applications.

Many users register themselves on websites using the same username. If you are performing an investigation on a person, and especially if you know a username or handle they are usually using online, you may hunt for usernames on social media platforms with Sherlock.

WebMap is a web dashboard for your nmap scans. This tool, which is free, can provide you with more management capabilities of your scan results.

During a black box, or grey box penetration testing engagement for a company, one of the main things you will need to find domains owned by the company.

Nikto is an open source scanner capable of scanning for over 6700 items to detect any misconfigurations on web servers like Apache, Nginx, Litespeed etc. as well as discovery of exposed files, user enumeration and outdated components.

During an external penetration test, and especially if it is a black-box engagement, one of the most important steps is to find subdomains used by the target company.

Many organizations are uploading files on their websites like pdf, word and excel without being aware that they are exposing sensitive information. You can enumerate and capture the files and its metadata.

A list of not so commonly used but powerful Nmap commands to help you bring your enumeration skills to the next level.

Penetration Test Reports must bring value to your clients. There are key elements every proper pentest report must include.

What is a Man-In-The-Middle attack and how the attacker can use it against you. Is there a way to protect yourself from such attacks?

The most important, free and powerful security tools which you should be using right now to assess your systems and network and uncover vulnerabilities.

There are many important actions you should focus on prior to diving into a penetration test. PenTests are not just point-and-shoot activities.

Which are the best frameworks for penetration testing? What are the attributes of each and which one is best for your organization?