Conduct a Penetration Test Like a Pro in 6 Phases [Tutorial]

Sdílet
Vložit
  • čas přidán 5. 09. 2024
  • Earn $$. Learn What You Need to Get Certified (90% Off): nulb.app/cwlshop
    How to Perform a Pentest like a Cybersecurity Specialist
    Full Tutorial: nulb.app/z6mnu
    Subscribe to Null Byte: goo.gl/J6wEnH
    Nick's Twitter: / nickgodshall
    Cyber Weapons Lab, Episode 185
    Pentesting is the process of simulating an attack on a network and is used to find vulnerabilities that could be exploited by a malicious actor. The main goal of a pentest, or penetration test, is to identify security holes and weaknesses so that the organization being tested can fix any potential issues. In a professional penetration test, there are six phases you should know. On this episode of Cyber Weapons Lab, we are going to take a look at those six steps.
    Related tutorials:
    Nessus: nulb.app/z3xqb
    Postenum: nulb.app/z5osm
    Nmap: nulb.app/x4eyg | • Use Nmap for Tactical ...
    To learn more, check out the article: nulb.app/z6mnu
    Follow Null Byte on:
    Twitter: / nullbyte
    Flipboard: flip.it/3.Gf_0
    Website: null-byte.com
    Weekly newsletter: eepurl.com/dE3Ovb
    Vimeo: vimeo.com/chan...

Komentáře • 209

  • @eyelessclowned
    @eyelessclowned Před 4 lety +382

    Can we just appreciate how he puts himself on FBI watchlist just give us good content!

    • @RETRO-DEV
      @RETRO-DEV Před 4 lety +67

      Lemme just *checks list*, yup.. you're on my list too

    • @eyelessclowned
      @eyelessclowned Před 4 lety +18

      @@RETRO-DEV wait what😶 😂😂😂😂

    • @RETRO-DEV
      @RETRO-DEV Před 4 lety +23

      @@eyelessclowned oops.. that was public? :/

    • @zyan983
      @zyan983 Před 4 lety +5

      Someone's in trouble xD
      Don't worry about me....

    • @RETRO-DEV
      @RETRO-DEV Před 4 lety +6

      @@zyan983 I'm watching you too buddy

  • @MapMavericks
    @MapMavericks Před 4 lety +141

    Ooo. A blinker! This is new

    • @duckypl8144
      @duckypl8144 Před 4 lety +1

      @Paul Lombard wdym no one blinks

    • @killabite620
      @killabite620 Před 4 lety +1

      Paul Lombard it’s a J O K E

    • @AssassinIronMan
      @AssassinIronMan Před 4 lety +3

      @Paul Lombard YOU SIR, DESERVEEEEEEEE r/wooooosh ( ͡° ͜ʖ ͡°)

    • @adelanaofficial
      @adelanaofficial Před 4 lety

      beats me

    • @AntZombie
      @AntZombie Před 3 lety +1

      What’s worse than people who reply seriously to jokes are people who delete their reply when they get humiliated.

  • @donaldlove4039
    @donaldlove4039 Před 4 lety +39

    If you study the CEH certification you will learn this more in-depth. Very informative content as always.

    • @khairulazahar5958
      @khairulazahar5958 Před 3 lety

      Which website do you use to study the CEH certification?

    • @Themusicbiz
      @Themusicbiz Před 2 lety +1

      @@khairulazahar5958 I have a course from 2017 that I have lifetime access to. It cost $4500, if you rly want to learn, I’ll hook u up

    • @sheaspin3239
      @sheaspin3239 Před 2 lety

      @@Themusicbiz I would love that!

    • @csmeby
      @csmeby Před 2 lety

      @@Themusicbiz slide that shit yo

    • @Themusicbiz
      @Themusicbiz Před 2 lety +1

      @@csmeby I will say though, it won’t qualify you for the cert. you need to take an updated one. Mine for example covers CEH 9 and they are on 10 now. All knowledge no cert.

  • @DBonacich
    @DBonacich Před 2 lety +23

    Awesome video. Quick and easy overview of the process and tools. My only criticism is that you should include steps to cover your tracks (clear logs, command history, etc on the target machine)

    • @0x2d2
      @0x2d2 Před 24 dny

      Do not clear logs on a pentest. Clear them on a red team engagement if you have confirmed it with the client.

  • @nekoespresso3676
    @nekoespresso3676 Před 4 lety +12

    I like how their replies to comments actually sound like a person is talking instead of a over the top professional bot reply.

    • @NullByteWHT
      @NullByteWHT  Před 4 lety +11

      I reply to comments when I'm avoiding work (Kody). Otherwise, it's Michael, who is less aggressive.

  • @MrTheRextoby
    @MrTheRextoby Před 4 lety +8

    Man this is the kind of videos we want xD, awesome. More like this but with more dificult vulnerabilities.

  • @donaldlove4039
    @donaldlove4039 Před 4 lety +31

    Allow me to remind you of the first and most important step, legal documentation. This includes a Business Impact Analysis (BIA), Rules of Engagement (ROE), and so on.

    • @JakeTheMDog
      @JakeTheMDog Před 4 lety +9

      Exactly. As a pentester myself, I do not start without any of these documents. Good addition.

    • @JakeTheMDog
      @JakeTheMDog Před 4 lety

      @Da Boss There are a lot of companies looking for pentesters and technical security people. However most companies tend to hire people who studied. OSCP is nice to have, but you must have luck to find a company willing to give them a chance.
      Best thing to do is to do an IT bachelor (or master, even better) and then get the OSCP certificate.

    • @forestriver437
      @forestriver437 Před 4 lety

      Yeah I'm sure a blackhat would get all of this first. Thanks for giving out that advice.

    • @JakeTheMDog
      @JakeTheMDog Před 4 lety +3

      Forest River Yeah I’m sure you should be a black hat hacker and parade it around. Luckily there are real specialized people who are taking care of their work, instead of internet heroes.

    • @tinagray9605
      @tinagray9605 Před rokem

      @@JakeTheMDog Please im new on this, how dp i set up my lab?

  • @backinyourcommentsectionag3191

    I think the quality of content has gone down tbh, there was way too many times he blinked. it's just unnecessary

    • @sum_andres31
      @sum_andres31 Před 4 lety +8

      U got me lol

    • @NullByteWHT
      @NullByteWHT  Před 4 lety +51

      I too hate wasted blinks

    • @Z8BLK
      @Z8BLK Před 4 lety +13

      Its Morse code...

    • @PB-eg2je
      @PB-eg2je Před 3 lety +6

      I think its his (unsuccessful) way to convince us he’s human.

    • @olamijiakeemodeyemi9320
      @olamijiakeemodeyemi9320 Před 3 lety +2

      @@PB-eg2je People complaint he hardly blink and now he blinks and they complain again. Human being can never be satisfied

  • @Phaser1980
    @Phaser1980 Před 4 lety +47

    Video on hacking is 13:37 long... I see what you did there. 🧐

  • @wendy_113
    @wendy_113 Před 11 měsíci

    You seem to have a gift for explaining difficult topics very well ty

  • @trishwhite8452
    @trishwhite8452 Před 3 lety +7

    I'm studying Cyber Security, at a government run College in Australia and I missed my Pen Testing class today due to illness, so I am just curious as to what I have missed, and how it works.

  • @zer0k4ge
    @zer0k4ge Před 3 lety +2

    Great video. I’m new and don’t understand a lot but I’m getting there! Just set up a raspberry pi with kali to do some experimenting.

  • @RaffaeleSellittoNiInF
    @RaffaeleSellittoNiInF Před 4 lety +9

    I don't understand why you say that SSH is usually associated with port 80. The SSH default port is 22, while 80 is Http default port. Anyhow, I enjoyed your video, really interesting.

  • @johndanielcepeda5393
    @johndanielcepeda5393 Před rokem

    Thank you for explaining this thoroughly!

  • @robinhood8302
    @robinhood8302 Před 2 lety +1

    Maaann this guy is the real G.O.A.T

  • @RakeshSingh-zo3zw
    @RakeshSingh-zo3zw Před 3 lety

    His blogs are awesome!!

  • @NaRToTiK2
    @NaRToTiK2 Před 4 lety +1

    Thanks for the great videos! good content and explanation.
    btw can you make a video on how to set a undetectable VM?

  • @spamlite
    @spamlite Před 4 lety +37

    Heh video time is 13:37 guess that makes you leet :D

  • @lalaineagsam2115
    @lalaineagsam2115 Před 4 lety +2

    Thank you nullbyte

  • @birdperson180
    @birdperson180 Před 4 lety +6

    i love it when my like makes something even
    i was the 500th like

  • @Blackdiamond.001
    @Blackdiamond.001 Před 4 lety +4

    Great

  • @addaboi
    @addaboi Před 2 měsíci

    A lot of these videos I see are already on the network, let's say you're not on the local network already how would you begin? Reason I ask is my manager has asked me to run a pentest as "someone who parked outside our office on a Saturday with a laptop and mobile hotspot. Appreciate the help!

  • @mrhappysmiley2968
    @mrhappysmiley2968 Před 4 lety

    I like to use linPEAS or winPEAS for to find anything we can use for privilege escalation

  • @nixcutus
    @nixcutus Před 4 lety

    Great Video thanks for this.

  • @MrGFYne1337357
    @MrGFYne1337357 Před 4 lety +3

    dig, host, rdns, nmap, metasploit

  • @martin_oconnor
    @martin_oconnor Před 4 lety +2

    How do you find out if someone is using these methods or similar against you? Thanks in advance!

    • @pianochannel100
      @pianochannel100 Před 4 lety

      In theory, you don't.

    • @ala_b2017
      @ala_b2017 Před 4 lety

      By monitoring you network To detect scans and weird trafic coming from someone. Also check your website and server logs every time.

    • @blender_wiki
      @blender_wiki Před 2 lety

      You have monitor tools that detect some kind of behavior that can be associated to different hack technique.
      You can monitor your .log server file or directly the network traffic inside a network especially if you search for inside attack.

  • @Ghost-by5zt
    @Ghost-by5zt Před 4 lety +3

    I want to click there website for full tutorial but then again they are hackers

    • @farhanazamchohan6924
      @farhanazamchohan6924 Před 3 lety

      I read their 8 courses details and they are convincing. but, buying and giving bank details to hacker mentor is not convincing.

  • @shreesharda7508
    @shreesharda7508 Před 4 lety +1

    700k soon❤️

  • @fahid3342
    @fahid3342 Před 2 lety

    And what about enumeration and establish foothold

  • @henrykissinger-ot5sx
    @henrykissinger-ot5sx Před rokem

    Really good

  • @bernardphlaxisk6454
    @bernardphlaxisk6454 Před 4 lety +1

    I'm here just because EC-Council says it is a 5 step process, the same way they say C|EH is practical n all.

  • @shaikhemad3556
    @shaikhemad3556 Před 4 lety

    Thanks you sir

  • @quintinwaterhouse5804

    Anyone notice the video length is 13:37

  • @soroushsafarzade5770
    @soroushsafarzade5770 Před 2 lety

    3:46 what does Galaxy-S10 do in your nmap scan???

  • @Adriana-em9dx
    @Adriana-em9dx Před rokem

    I tried to run nmap -sV -p 80 on my terminal but it shows error says the term 'nmap' is not recognised as the name of cmdlet, .... someone tell me why?

  • @Nino-xe3oj
    @Nino-xe3oj Před rokem

    How do I download the correct Nessus? My wont work for some reason

  • @MathaGoram
    @MathaGoram Před 4 lety

    Thx. Not your cup of tea but need Nessus on ARM hardware too.

  • @kabobz
    @kabobz Před 4 lety +9

    Hi, 2 things to help your skin, eat beats (sometimes skin problems mean something is wrong inside body) and mix yogurt with honey for outside on skin. Nice video, too advanced for me.

  • @amwin7
    @amwin7 Před 3 lety

    How can you tell that your being hacked, is there a live view software you can use?

  • @minibit0103
    @minibit0103 Před 4 lety +1

    Like a Boss

  • @dEExm702
    @dEExm702 Před 4 lety +4

    Bro im currently in the process of making a program out of cmd (cuz thats currently my only coding tool i know how to use). Currently with it you can track ips, ping ips, and manually shutdown computers on the same router as you. What do you suggest i add to it next?

    • @m1lkweed
      @m1lkweed Před 4 lety

      SƎNTIИƎL 髪 traceroute is handy, and don't worry if you can only write command scripts, a lot of simple tools are written like that.

    • @dEExm702
      @dEExm702 Před 4 lety

      @@m1lkweed hmm ok thx :)

    • @nero2k619
      @nero2k619 Před 4 lety

      What you mean manually shutdown computers on the same network ? Do you just send command to the router and it shutdowns another pc or what ?

    • @inxnite4071
      @inxnite4071 Před 2 lety

      Hey if you’re still interested, search up how to get kali Linux in a virtual machine I suggest virtual box and it gives you many tools to hack and such but you can use some of them for creating a program

  • @noorzaman474
    @noorzaman474 Před 3 lety

    So pen tests also have vulnerability scans already on them?

  • @pcislocked
    @pcislocked Před 4 lety

    yeah i know how to do this except step 6

  • @NashHazzard
    @NashHazzard Před 2 lety

    Null Noob question i need to set up a system on my network running Apache to pentest correct?

  • @laragonzalezcastilla2771

    2 years passed damn

  • @sahilbasia4571
    @sahilbasia4571 Před 4 lety +2

    Bro please can you make a video on installing gvm (openvas) vulnerability scanner fir Kali Linux 2020.3

  • @timetraveller4336
    @timetraveller4336 Před 4 lety +1

    It's really strange to watch a null byte video with someone who blinks

  • @gautamhacks5098
    @gautamhacks5098 Před 4 lety

    where is orginal null byte??!

  • @nicroxio681
    @nicroxio681 Před 4 lety +9

    SUP BOIS

  • @Marcothemillionaire
    @Marcothemillionaire Před 2 lety

    where can I get Nessus from I don't t have 3k???

  • @xAlbanianHackerx
    @xAlbanianHackerx Před 4 lety +2

    You skipped reporting!

    • @xAlbanianHackerx
      @xAlbanianHackerx Před 4 lety

      Hah, being in the field I was looking forward to that section 😬

  • @naturalsoundlab4307
    @naturalsoundlab4307 Před 4 lety

    Hey!! Where is cody?

  • @digitalvillage2333
    @digitalvillage2333 Před 2 lety

    Ffs can’t get the damn nessus scanner cause I need to pay for a friggin business email 🤦‍♂️

  • @k.eshwanth7752
    @k.eshwanth7752 Před 4 lety

    Hi bro. I am using kali in vmware in my laptop with contains Intel chip in it . When I try to run apache2 server in kali, it's not working. I have tried to restart it by uninstalling & installing it again. Can you help ee with this bro.

  • @zellers5423
    @zellers5423 Před 4 lety +1

    You can do this on any version of Ubuntu, right?

    • @NullByteWHT
      @NullByteWHT  Před 4 lety +1

      Yes, but you may have to install some required programs.

  • @hnachtv6555
    @hnachtv6555 Před 4 lety

    how did kody k evolve into this !!??

  • @andrewa7952
    @andrewa7952 Před 4 lety

    Step 6?

  • @riley530
    @riley530 Před 4 lety

    These comments are golden.

  • @alimonbanda6983
    @alimonbanda6983 Před 2 lety

    Link is down

  • @MidnightPixies
    @MidnightPixies Před 4 lety +1

    My Man

  • @mauliddifirmansyah252
    @mauliddifirmansyah252 Před 4 lety

    hi null byte can you help me to learn me from indonesia

  • @tienatnguyen3412
    @tienatnguyen3412 Před rokem

    Can you crack the online ID ransomware pls ?

  • @omegapsiphi1911
    @omegapsiphi1911 Před 3 lety

    Wait a minute Where is Cody? What did you guys do with Cody!?!?!?!?!? lol

  • @area-XXX
    @area-XXX Před 4 lety

    it could be psyarriasis

  • @youtubepro5932
    @youtubepro5932 Před 9 měsíci

    Dude been follow me since bros wanted to b in college

  • @LofilabLofiHipHop
    @LofilabLofiHipHop Před 4 lety

    Thank you for this amazing video. Please bring more content about hacking using android divese =)

  • @rectify2003
    @rectify2003 Před 4 lety

    Where has Codi gone?
    The other Guy?

  • @narcisakaparapet
    @narcisakaparapet Před 4 lety +2

    Blinking was never an option

  • @lesiostasio2542
    @lesiostasio2542 Před 3 lety +2

    Mmm, yes. I do feel like using this information for educational purposes ONLY. And I'm gonna do the sixth part for sure.

  • @cybercat1531
    @cybercat1531 Před 4 lety +1

    Step 6. No matter how 1337 a hacker you are takes the longest ;)

  • @uaman11
    @uaman11 Před rokem

    this is brilliant and i aint even a brit

  • @justrickacoustic
    @justrickacoustic Před 2 lety

    can we appreciate that the time of this video is 13:37? 1337

  • @moonmaan
    @moonmaan Před 4 lety +1

    Just casually using software that has a license that costs several thousand dollars, okay.

  • @enos5192
    @enos5192 Před 4 lety +1

    Where is Cody the Soul Ripper 😌

  • @adamodonoghue4812
    @adamodonoghue4812 Před 4 lety

    what happened to the guy that doesnt blink

  • @josephjefferson2617
    @josephjefferson2617 Před 2 lety

    P.S.: SSL is usually associated with port 443.

  • @RETRO-DEV
    @RETRO-DEV Před 4 lety +15

    I'm watching you...

    • @user-es2pd6he7l
      @user-es2pd6he7l Před 4 lety +2

      I’m watching you to...

    • @RETRO-DEV
      @RETRO-DEV Před 4 lety +2

      @@user-es2pd6he7l too* and no... No you're not...

    • @RETRO-DEV
      @RETRO-DEV Před 4 lety +1

      @@user-es2pd6he7l also wtf is your username supposed to be

    • @harambe2185
      @harambe2185 Před 4 lety +1

      @@RETRO-DEV longest name in Africa

    • @RETRO-DEV
      @RETRO-DEV Před 4 lety

      @@harambe2185 fair enough I suppose

  • @forestriver437
    @forestriver437 Před 4 lety

    well if it aint nick...haha ha haha

  • @tayyabrasul3807
    @tayyabrasul3807 Před 2 lety

    Vid is exactly 13:37 long

  • @rafaelnacha1788
    @rafaelnacha1788 Před 2 lety

    4:20

  • @redsol3629
    @redsol3629 Před 3 lety

    Get those daemons uploaded.

  • @GuNoZidE
    @GuNoZidE Před 2 lety

    Damn the video is exactly 1337 long 🤣

  • @mattnsac
    @mattnsac Před rokem

    The video is 13:37 long. Im sure it was a coincidence lol

  • @user-nw4gv9pf8x
    @user-nw4gv9pf8x Před 6 měsíci

    WANTED. Alive or Dead :)
    Amazing

  • @abhikdutta2848
    @abhikdutta2848 Před 4 lety

    Bro r u ok????

  • @basudhasworld5539
    @basudhasworld5539 Před 3 lety

    Evil or maybe a good copy of micheal reeves

  • @private_guapo
    @private_guapo Před 4 lety

    nice timeframe xddd

  • @edward7935
    @edward7935 Před 4 lety +4

    :)

  • @xanthusxiaobo6307
    @xanthusxiaobo6307 Před 4 lety

    Can you make a video on how to hack pubg

  • @0xSN1PE
    @0xSN1PE Před 4 lety +3

    print("Quality Content")

    • @lavishjaat
      @lavishjaat Před 4 lety +2

      cout

    • @BloodmansCrypt
      @BloodmansCrypt Před 4 lety

      java
      System.out.println("Quality Content");
      C
      printf("Quality Content");
      C#
      Console.WriteLine("Quality Content");

    • @nero2k619
      @nero2k619 Před 4 lety

      Assembly:
      section .text
      global _start
      _start:
      mov edx, len
      mov ecx, msg
      mov ebx, 1
      mov eax, 4
      int 0x80
      mov eax, 1
      int 0x80
      section .data
      msg db 'Quality Content',0xa
      len equ $ - msg
      BrainFuck:
      ++++++++++[>+>+++>+++++++>+++++++++++++++++++++++++++.---------.---.+++++++++++.+++++.----------.-.++++++.---------------.+++++++++.++++++.

  • @realhomy
    @realhomy Před 4 lety +2

    Ahh yes I remember 2 years ago when he used to stare straight into your soul without blinking

    • @MarcoMazziniYT
      @MarcoMazziniYT Před 4 lety

      Not the same guy.

    • @realhomy
      @realhomy Před 4 lety

      @@MarcoMazziniYT no im talking about the guy that was here 2 years ago

    • @realhomy
      @realhomy Před 4 lety

      hope u understand

    • @MarcoMazziniYT
      @MarcoMazziniYT Před 4 lety

      @@realhomy I misinterpreted your "he used to stare".
      You have to admit that it's a bit confusing.

    • @realhomy
      @realhomy Před 4 lety

      oh ok

  • @x0rc4t
    @x0rc4t Před 2 lety

    Pls add indonesian sub

  • @dydarjadmin
    @dydarjadmin Před 4 lety

    Круто, довай жги пакрышки🤣🤣🤣

  • @OzoneX4
    @OzoneX4 Před 4 lety

    way too basic, can we get something more advanced?

  • @user-ly4cm3dc3r
    @user-ly4cm3dc3r Před rokem

    =没有来自中国的评论=

  • @salemsalem3968
    @salemsalem3968 Před měsícem

    you move too fast. we are not all like you bro. Please take time and try using relatable language

  • @tubeDude48
    @tubeDude48 Před 4 lety +1

    *LOOSE* *THE* *CRAPPY* *MUSIC!!!!!!!!!!!!!!!!!!!!!!!!!!!*

  • @romangrace2507
    @romangrace2507 Před 4 lety

    i love not having a life and doing shit like this lol

    • @boristodorov779
      @boristodorov779 Před 4 lety

      Well u can have a life and still do it

    • @romangrace2507
      @romangrace2507 Před 4 lety

      @@boristodorov779 true true, but i write so many scripts that i do not have time for anything else....

  • @dEExm702
    @dEExm702 Před 4 lety

    OoOoooOOOOOOOoooOoooh 0 dislikes. ;)

  • @renganathanofficial
    @renganathanofficial Před 4 lety

    please don't talk about his face :(