Important Codes for Vulnerable Assessment and Penetration Testing




For Cyber Attack we need to focus for website hacking, Network hacking, Email hacking, Ethical hacking, Password hacking, and computer hacking


Top Websites to refer
https://www.hackthebox.eu/    -  Pen Testing Lab
https://www.vulnhub.com/       -  Pen Testing Lab
http://overthewire.org/wargames/  - Pen Testing Lab
https://www.tutorialspoint.com/     -  All IT courses
https://www.cybrary.it/                       -  Cyber Security Courses
https://www.offensive-security.com/  - Cyber Security Pro. Courses
https://www.exploit-db.com/ - Google Hacking Database
https://www.hackerone.com/   - Courses, Events, Challenges
https://www.bugcrowd.com/    - Pen Test, Vulnerable assessment
https://www.shodan.io/              - Search engine for Cyber Security
https://www.sans.org/                 - certifications, defense, forensic
https://www.isaca.org/pages/default.aspx   - Security Frameworks
https://resources.infosecinstitute.com/       - certification training
https://www.slideshare.net/                   - Presentation courses
http://www.securitytube.net/                 - cyber security training
https://www.redteamsecure.com/        - Pen Test Training
https://advisera.com/                                   - IT Governance
https://sectools.org/                                    - cyber security tools
https://thehackernews.com/                    - Hacking News
https://www.nirsoft.net/                                     - Cyber Security Tools      
https://www.owasp.org/index.php/                - cyber security software
https://ryanstutorials.net/                                  - Cyber Security tutorial
http://z-shadow.info/                                               - Phishing Attack
https://pentesterlab.com/                              - Pen Test Lab
https://www.theregister.co.uk/                   -  Hacking News
http://hackingscripts.com/                        - Hacking Scripts

https://www.sourcecodester.com/          - software source code
https://medium.com/                                   - Technology News
https://picoctf.com/                                      - computer security game
https://www.wifipineapple.com/             - WiFi hardware
https://uscc.cyberquests.org/                   - cyber challenges
https://www.nist.gov/                                  - security standards
https://www.nsa.gov/                                   - US security
https://www.cvedetails.com/                    - Vulnerability data source
https://roar.media/sinhala/main/science-tech/  - Tech News 
https://www.tripwire.com/                       - Cyber Security Tools
https://hackertarget.com/                          - Cyber Security Tools
http://www.anonymoushackers.net/     - Anonymous team news
https://hacked.com/hacking/                   - Hacking Groups
https://www.hackingarticles.in/             - Hacking Articles
https://www.enisa.europa.eu/                 - Information security
https://www.hacker101.com/                   - Hacking Videos
https://vimeo.com/                                      - Video Tutorials
https://www.securityweek.com/            - Security News
http://www.infosecisland.com/             - Security News
https://www.anonews.co/                        - Anonymous news
https://mxtoolbox.com/
https://archive.org/web/
http://hackertyper.com/
10MinuteMail.com
https://www.virustotal.com/#/home/upload
https://www.nomoreransom.org/
https://www.enigmagroup.org/
https://bookboon.com/
https://www.pentesteracademy.com/
https://haxf4rall.com/
https://www.hackingarticles.in/ 
https://www.enisa.europa.eu/
https://www.us-cert.gov/ncas/alerts
https://www.ncsc.gov.uk/report/weekly-threat-report-17th-may-2019
Network Administrator tools - https://www.netadmintools.com/
Dark web sites list - https://techincidents.com/dark-web-websites/
https://blog.elearnsecurity.com/
https://hack.me/
https://www.hackthissite.org/pages/index/index.php
http://www.try2hack.nl/
https://www.hackthis.co.uk/levels/
https://ctf365.com/
https://www.hacking-lab.com/index.html
http://pwnable.kr/
http://smashthestack.org/
http://io.netgarage.org/
https://microcorruption.com/login
https://w3challs.com/
https://pwn0.com/
https://www.hellboundhackers.org/
http://damnvulnerableiosapp.com/
https://www.root-me.org/?lang=en
https://ctftime.org/
http://webappsecmovies.sourceforge.net/webgoat/
https://hackxor.net/
http://google-gruyere.appspot.com/
https://gbhackers.com/hacking-tools-list/
https://www.hackingarticles.in/web-penetration-testing/
https://hackedon.com/
https://www.nomoreransom.org/en/index.html
https://www.isocertificationtrainingcourse.org/iso-27001-checklist
https://www.iso27001security.com/html/toolkit.html
http://www.forensicfocus.com/
https://www.mitec.cz/
https://www.certifiedinfosec.com/
https://www.computernetworkingnotes.com/
http://www.iacertification.org/ 
https://www.mcafeeinstitute.com/
https://www.itgovernance.eu/en-ie 
https://www.linkedin.com/learning/me
https://shop.hak5.org/
https://logrhythm.com/index.html
https://www.sisainfosec.com/asia-pacific/
https://findbug.io/ 
https://hackercombat.com/
https://certikit.com/
https://securitytrails.com/blog/nmap-vulnerability-scan
https://www.stationx.net/nmap-cheat-sheet/
https://redteamtutorials.com/2018/10/24/msfvenom-cheatsheet/
https://www.robvanderwoude.com/batexamples.php      - Batch files
https://gdpr.eu/checklist/
https://www.privacytools.io/
https://www.gchq-careers.co.uk/index.html 
https://www.mi5.gov.uk/
https://www.sis.gov.uk/user-information.html
https://www.scrumstudy.com/
https://www.cwnp.com/
https://linuxacademy.com/
https://docs.microsoft.com/en-us/learn/
https://cs.lpi.org/
https://www.securityforum.org/
https://www.ftuforums.com/
https://www.virtualhackinglabs.com/
http://www.computersecuritystudent.com/
http://zqktlwi4fecvo6ri.onion/wiki/index.php/Main_Page    - Dark web sites
http://www.securityidiots.com/
https://kalilinuxtutorials.com/
https://www.itechtics.com/
https://www.scip.ch/
https://www.sans.org/security-resources/policies
https://syhack.wordpress.com/2019/10/01/active-directory-kill-chain-attack-101/
https://www.threathunting.net/ 
https://developers.google.com/machine-learning/crash-course/
https://cybersecurityventures.com/
https://www.digicert.com/
https://cmdchallenge.com/
https://tryhackme.com/
https://gchq.github.io/CyberChef/
https://bkimminich.gitbooks.io/pwning-owasp-juice shop/content/part1/rules.html                                               - Pentesting Guidance
https://whatcms.org/
https://talosintelligence.com/software
https://adsecurity.org/
https://www.wonderhowto.com/
https://altmails.com/
https://osintframework.com/
https://cheatsheetseries.owasp.org/
https://www.chasms.com/
https://gdpr-info.eu/
https://opensource.com/
https://owasp-academy.teachable.com/
https://ired.team/
https://www.4itsec.com/
https://ctfbook.hoppersroppers.org/
https://www.hackingarticles.in/red-teaming/
https://sushant747.gitbooks.io/total-oscp-guide/privilege_escalation_windows.html
https://blog.stealthbits.com/performing-domain-reconnaissance-using-powershell
https://www.openstego.com/
https://jhalon.github.io/

https://github.com/Muhammd/Awesome-Pentest
https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE
https://github.com/nixawk/pentest-wiki
https://github.com/ND13/Penetration-Testing-and-Hacking
https://www.amanhardikar.com/mindmaps/Practice.html
https://hausec.com/pentesting-cheatsheet/
https://en.kali.tools/all/
https://medium.com/@hakluke/haklukes-ultimate-oscp-guide-part-3-practical-hacking-tips-and-tricks-c38486f5fc97
https://github.com/RihaMaheshwari/OSCP-Preparation-Material
https://github.com/lorenzoinvidia/HackTheBox-CheatSheets
https://www.gullynetworkers.com/
https://ech1.netlify.app/htb.html
https://cuckoo.cert.ee/
https://twelvesec.com/free-tools/

https://www.reddit.com/r/cybersecurity/comments/iu17uu/cybersec_cheat_sheets_in_all_flavors_huge_list/?utm_source=amp&utm_medium=&utm_content=post_body

https://onedrive.live.com/view.aspx?resid=42005F2B73E92A16!16546&authkey=!ACt7HgbJMllFQ8o

How to find the wifi password using cmd (we will able to get saved wifi passwords on pc or laptop)
Cmd – netsh wlan show profile, netsh wlan show profile name=””  key=clear

Identify OS according to TTL value (ping to other host or localy)
Windows – 128
Linux/ Redhat  - 64
More than 128 > Network Infrastructure

To find DNS server IP address (to get ip address)
Terminal – nslookup                                       cmd – nslookup

To find character repeat of domain,missing dot, strip dashes (all the possible url with this name)
Terminal – urlcrazy www.google.com

To find metadata / Read metadata of a file ()
Terminal – sudo apt-get install exif          , Terminal – exif file path

To find more details about domain name (of a website)

To get more information about website or domain name or public ip address.

To information gathering from victim
Google -Send anonymous emails. www.Anonymousemail.me

To check all NS records (To identify domain name servers’ IP and ports)
Terminal – dnsrecon –t std –d google.com

How to ping public IP address (To know is it available Public IP address)

To find reverse DNS, IP geo location, traceroute

To find DNS Zone Transfer
Terminal – dnsrecon –t axfr –d durgapurcity.co.in

To find DNS records further more
Terminal – dnsrecon –t tld –d facebook.com

To find Name server’s and Ip address
Terminal – dnsenum facebook.com

To find domain health, investigation, DNS, Network Tools, Monitoring tools, DMARC, MX, CNAME
Google – Mx Tool box

To create temporary email using another domain

To shorten url
Google – bitly

To know about email, DNS, Domain etc.
To Vulnerability about Exploits information, vulnerability information, security scanners, web application scanners, oracle, wireless, Information security blogs


To identify DNS tools


To report malicious site, SSL, CA, Hosting performance


To get some computer forensic software


To get Domain name information


To finding hosting company


To know history of web site


Several Tools for Information gathering - DNS, Trace route, and open ports scan, Google Hacking, Email, Encode or Decode


Find supplemental information Google may have on this page
Ex: info:www.usgs.gov


Find other pages indexed by Google that reference this link

Download Youtube videos using youtube-dl.exe
Open cmd and youtube-dl -U
youtube-dl (paste url)

25 comments:

  1. Thank you for this detailed information! This is some of the highest quality content I’ve ever come across....

    ReplyDelete
  2. I am been blackmailed by someone i don't know and i was scared that it might affect my marriage so

    in other to save my marriage i contacted WISETECHHACKER (AT) GMAIL DOT COM  to help me fish out the

    person be hide this blackmail in 2 hours time i got results and full details of the person trying to

    blackmail me and i found out it was my ex. Thank God i came in contact with wisetechhacker

    ReplyDelete
  3. I could say it anywhere that i met my wife on this App, All thanks to Henry(onlinehacker4hire @ gmail. com) who helped cleared my loans and introduced me to OkCupid. I know when it comes to love or investments everyone has their choice, to be professionally guarded or for hack jobs contact him. He the best.

    ReplyDelete
    Replies
    1. Thanks for your comment guys. Your words made me stronger.

      Delete
  4. Do you require a hacker to do any of the following for you:
    Hack Western Union/ MoneyGram, Hack mail, social networks
    Hack Airlines and book tickets, Hack CC and cashing out
    Hack Whatsapp, mobile phones, Clear Bad Records,Hack Schools (any school)
    American Citizenship.......e.t.c
    I recommend you get to contact this Hacker is very good and trustworthy too
    Mail: Onlinehacker4hire @ gmail .com
    Text: +1 347 619 1304

    ReplyDelete
    Replies
    1. Thanks for your comment guys. Your words made me stronger.

      Delete
  5. This blog is the Best place for learning and contribution.

    Certifica??o ISO 27001 Pre

    ReplyDelete
    Replies
    1. Thanks for your comment guys. Your words made me stronger.

      Delete
  6. After so long I’ve been doing this I finally got a chance to smile again. I've lost so much to scammers, I basically thought binary/forex/bitcoin option was a scam until I met Mrs Van Yoelle. he has a reliable broker, gave me access to the account and I was able to monitor the trading and with an initial capital of $500 she generated a profit of $7500 in a trading week, I'm sharing this to encourage every beginner and trader having difficulties and have lost so much to scammers. You can contact Mr Van Yoelle on him
    contact: cryptobusiness.tradings @ gmail . com
    telegram: +66992414469

    ReplyDelete
    Replies
    1. Thanks for your comment guys. Your words made me stronger.

      Delete
  7. ****Contact Me****
    *ICQ :748957107
    *Gmail :taimoorh944@gmail.com
    *Telegram :@James307


    (Selling SSN Fullz/Pros)

    *High quality and connectivity
    *If you have any trust issue before any deal you may get few to test
    *Every leads are well checked and available 24 hours
    *Fully cooperate with clients
    *Any invalid info found will be replaced
    *Credit score above 700 every fullz
    *Payment Method
    (BTC&Paypal)

    *Fullz available according to demand too i.e (format,specific state,specific zip code & specifc name etc..)

    *Format of Fullz/leads/profiles
    °First & last Name
    °SSN
    °DOB
    °(DRIVING LICENSE NUMBER)
    °ADDRESS
    (ZIP CODE,STATE,CITY)
    °PHONE NUMBER
    °EMAIL ADDRESS
    °Relative Details
    °Employment status
    °Previous Address
    °Income Details
    °Husband/Wife info
    °Mortgage Info


    $2 for each fullz/lead with DL num
    $1 for each SSN+DOB
    $5 for each with Premium info
    (Price can be negotiable if order in bulk)


    OTHER SERVICES ProvIDING

    *(Dead Fullz)
    *(Email leads with Password)

    *(Dumps track 1 & 2 with pin and without pin)

    *Hacking Tutorials
    *Smtp Linux
    *Safe Sock

    *Let's come for a long term Business


    ****Contact Me****
    *ICQ :748957107
    *Gmail :taimoorh944@gmail.com
    *Telegram :@James307

    ReplyDelete
    Replies
    1. Thanks for your comment guys. Your words made me stronger.

      Delete
  8. Thank you for this detailed information! This is some of the highest quality content. We updated all the trending new information related to any topics.
    To be more updated about all the news around you, you can check this website
    honda cbr650r

    ReplyDelete
    Replies
    1. Thanks for your comment guys. Your words made me stronger.

      Delete
  9. Pentesting Thanks for taking the time to discuss this, I feel strongly about it and love learning more on this topic. If possible, as you gain expertise, would you mind updating your blog with extra information? It is extremely helpful for me.

    ReplyDelete
    Replies
    1. Thanks for your comment guys. Your words made me stronger.

      Delete
  10. Very informative and impressive post you have written, this is quite interesting and i have went through it completely, an upgraded information is shared, keep sharing such valuable information.
    i really learned something new thanks for giving this information. We updated all the trending new information related to any topics.To be more updated about all the news around you, you can check this websiteroyal enfield speedometer

    ReplyDelete
    Replies
    1. Thanks for your comment guys. Your words made me stronger.

      Delete
  11. Thanks for your comment guys. Your words made me stronger.

    ReplyDelete
  12. Thanks for your comment guys. Your words made me stronger.

    ReplyDelete
  13. Thanks for your comment guys. Your words made me stronger.

    ReplyDelete
  14. Thanks for your comment guys. Your words made me stronger.

    ReplyDelete
  15. Thanks for your comment guys. Your words made me stronger.

    ReplyDelete