Conduct a Penetration Test Like a Pro in 6 Phases [Tutorial]

Поділитися
Вставка
  • Опубліковано 23 сер 2020
  • Earn $$. Learn What You Need to Get Certified (90% Off): nulb.app/cwlshop
    How to Perform a Pentest like a Cybersecurity Specialist
    Full Tutorial: nulb.app/z6mnu
    Subscribe to Null Byte: goo.gl/J6wEnH
    Nick's Twitter: / nickgodshall
    Cyber Weapons Lab, Episode 185
    Pentesting is the process of simulating an attack on a network and is used to find vulnerabilities that could be exploited by a malicious actor. The main goal of a pentest, or penetration test, is to identify security holes and weaknesses so that the organization being tested can fix any potential issues. In a professional penetration test, there are six phases you should know. On this episode of Cyber Weapons Lab, we are going to take a look at those six steps.
    Related tutorials:
    Nessus: nulb.app/z3xqb
    Postenum: nulb.app/z5osm
    Nmap: nulb.app/x4eyg | • Use Nmap for Tactical ...
    To learn more, check out the article: nulb.app/z6mnu
    Follow Null Byte on:
    Twitter: / nullbyte
    Flipboard: flip.it/3.Gf_0
    Website: null-byte.com
    Weekly newsletter: eepurl.com/dE3Ovb
    Vimeo: vimeo.com/channels/nullbyte
  • Навчання та стиль

КОМЕНТАРІ • 205

  • @eyelessclowned
    @eyelessclowned 3 роки тому +375

    Can we just appreciate how he puts himself on FBI watchlist just give us good content!

    • @RETRO-DEV
      @RETRO-DEV 3 роки тому +67

      Lemme just *checks list*, yup.. you're on my list too

    • @eyelessclowned
      @eyelessclowned 3 роки тому +18

      @@RETRO-DEV wait what😶 😂😂😂😂

    • @RETRO-DEV
      @RETRO-DEV 3 роки тому +23

      @@eyelessclowned oops.. that was public? :/

    • @zyan983
      @zyan983 3 роки тому +5

      Someone's in trouble xD
      Don't worry about me....

    • @RETRO-DEV
      @RETRO-DEV 3 роки тому +6

      @@zyan983 I'm watching you too buddy

  • @MapMavericks
    @MapMavericks 3 роки тому +140

    Ooo. A blinker! This is new

    • @duckypl8144
      @duckypl8144 3 роки тому +1

      @Paul Lombard wdym no one blinks

    • @killabite620
      @killabite620 3 роки тому +1

      Paul Lombard it’s a J O K E

    • @AssassinIronMan
      @AssassinIronMan 3 роки тому +3

      @Paul Lombard YOU SIR, DESERVEEEEEEEE r/wooooosh ( ͡° ͜ʖ ͡°)

    • @adelanaofficial
      @adelanaofficial 3 роки тому

      beats me

    • @AntZombie
      @AntZombie 2 роки тому +1

      What’s worse than people who reply seriously to jokes are people who delete their reply when they get humiliated.

  • @dragobonacich2434
    @dragobonacich2434 2 роки тому +22

    Awesome video. Quick and easy overview of the process and tools. My only criticism is that you should include steps to cover your tracks (clear logs, command history, etc on the target machine)

  • @MrTheRextoby
    @MrTheRextoby 3 роки тому +7

    Man this is the kind of videos we want xD, awesome. More like this but with more dificult vulnerabilities.

  • @wendy_113
    @wendy_113 7 місяців тому

    You seem to have a gift for explaining difficult topics very well ty

  • @johndanielcepeda5393
    @johndanielcepeda5393 Рік тому

    Thank you for explaining this thoroughly!

  • @NaRToTiK2
    @NaRToTiK2 3 роки тому +1

    Thanks for the great videos! good content and explanation.
    btw can you make a video on how to set a undetectable VM?

  • @nekoespresso3676
    @nekoespresso3676 3 роки тому +12

    I like how their replies to comments actually sound like a person is talking instead of a over the top professional bot reply.

    • @NullByteWHT
      @NullByteWHT  3 роки тому +11

      I reply to comments when I'm avoiding work (Kody). Otherwise, it's Michael, who is less aggressive.

  • @RakeshSingh-zo3zw
    @RakeshSingh-zo3zw 3 роки тому

    His blogs are awesome!!

  • @consolek1d
    @consolek1d 3 роки тому +2

    Great video. I’m new and don’t understand a lot but I’m getting there! Just set up a raspberry pi with kali to do some experimenting.

  • @lalaineagsam2115
    @lalaineagsam2115 3 роки тому +2

    Thank you nullbyte

  • @donaldlove4039
    @donaldlove4039 3 роки тому +37

    If you study the CEH certification you will learn this more in-depth. Very informative content as always.

    • @khairulazahar5958
      @khairulazahar5958 3 роки тому

      Which website do you use to study the CEH certification?

    • @Themusicbiz
      @Themusicbiz 2 роки тому +1

      @@khairulazahar5958 I have a course from 2017 that I have lifetime access to. It cost $4500, if you rly want to learn, I’ll hook u up

    • @sheaspin3239
      @sheaspin3239 2 роки тому

      @@Themusicbiz I would love that!

    • @csmeby
      @csmeby 2 роки тому

      @@Themusicbiz slide that shit yo

    • @Themusicbiz
      @Themusicbiz 2 роки тому +1

      @@csmeby I will say though, it won’t qualify you for the cert. you need to take an updated one. Mine for example covers CEH 9 and they are on 10 now. All knowledge no cert.

  • @nixcutus
    @nixcutus 3 роки тому

    Great Video thanks for this.

  • @trishwhite8452
    @trishwhite8452 3 роки тому +7

    I'm studying Cyber Security, at a government run College in Australia and I missed my Pen Testing class today due to illness, so I am just curious as to what I have missed, and how it works.

  • @robinhood8302
    @robinhood8302 2 роки тому +1

    Maaann this guy is the real G.O.A.T

  • @NashHazzard
    @NashHazzard 2 роки тому

    Null Noob question i need to set up a system on my network running Apache to pentest correct?

  • @amwin7
    @amwin7 3 роки тому

    How can you tell that your being hacked, is there a live view software you can use?

  • @Adriana-em9dx
    @Adriana-em9dx 8 місяців тому

    I tried to run nmap -sV -p 80 on my terminal but it shows error says the term 'nmap' is not recognised as the name of cmdlet, .... someone tell me why?

  • @soroushsafarzade5770
    @soroushsafarzade5770 2 роки тому

    3:46 what does Galaxy-S10 do in your nmap scan???

  • @shreesharda7508
    @shreesharda7508 3 роки тому +1

    700k soon❤️

  • @shaikhemad3556
    @shaikhemad3556 3 роки тому

    Thanks you sir

  • @henrykissinger-ot5sx
    @henrykissinger-ot5sx Рік тому

    Really good

  • @noorzaman474
    @noorzaman474 3 роки тому

    So pen tests also have vulnerability scans already on them?

  • @mrhappysmiley2968
    @mrhappysmiley2968 3 роки тому

    I like to use linPEAS or winPEAS for to find anything we can use for privilege escalation

  • @k.eshwanth7752
    @k.eshwanth7752 3 роки тому

    Hi bro. I am using kali in vmware in my laptop with contains Intel chip in it . When I try to run apache2 server in kali, it's not working. I have tried to restart it by uninstalling & installing it again. Can you help ee with this bro.

  • @backinyourcommentsectionag3191
    @backinyourcommentsectionag3191 3 роки тому +130

    I think the quality of content has gone down tbh, there was way too many times he blinked. it's just unnecessary

    • @sum_andres31
      @sum_andres31 3 роки тому +8

      U got me lol

    • @NullByteWHT
      @NullByteWHT  3 роки тому +49

      I too hate wasted blinks

    • @Z8BLK
      @Z8BLK 3 роки тому +12

      Its Morse code...

    • @PB-eg2je
      @PB-eg2je 3 роки тому +5

      I think its his (unsuccessful) way to convince us he’s human.

    • @olamijiakeemodeyemi9320
      @olamijiakeemodeyemi9320 2 роки тому +2

      @@PB-eg2je People complaint he hardly blink and now he blinks and they complain again. Human being can never be satisfied

  • @MidnightPixies
    @MidnightPixies 3 роки тому +1

    My Man

  • @birdperson180
    @birdperson180 3 роки тому +6

    i love it when my like makes something even
    i was the 500th like

  • @Nino-xe3oj
    @Nino-xe3oj Рік тому

    How do I download the correct Nessus? My wont work for some reason

  • @Blackdiamond.001
    @Blackdiamond.001 3 роки тому +4

    Great

  • @donaldlove4039
    @donaldlove4039 3 роки тому +31

    Allow me to remind you of the first and most important step, legal documentation. This includes a Business Impact Analysis (BIA), Rules of Engagement (ROE), and so on.

    • @JakeTheMDog
      @JakeTheMDog 3 роки тому +9

      Exactly. As a pentester myself, I do not start without any of these documents. Good addition.

    • @JakeTheMDog
      @JakeTheMDog 3 роки тому

      @Da Boss There are a lot of companies looking for pentesters and technical security people. However most companies tend to hire people who studied. OSCP is nice to have, but you must have luck to find a company willing to give them a chance.
      Best thing to do is to do an IT bachelor (or master, even better) and then get the OSCP certificate.

    • @forestriver437
      @forestriver437 3 роки тому

      Yeah I'm sure a blackhat would get all of this first. Thanks for giving out that advice.

    • @JakeTheMDog
      @JakeTheMDog 3 роки тому +3

      Forest River Yeah I’m sure you should be a black hat hacker and parade it around. Luckily there are real specialized people who are taking care of their work, instead of internet heroes.

    • @tinagray9605
      @tinagray9605 Рік тому

      @@JakeTheMDog Please im new on this, how dp i set up my lab?

  • @spamlite
    @spamlite 3 роки тому +37

    Heh video time is 13:37 guess that makes you leet :D

  • @dEExm702
    @dEExm702 3 роки тому +4

    Bro im currently in the process of making a program out of cmd (cuz thats currently my only coding tool i know how to use). Currently with it you can track ips, ping ips, and manually shutdown computers on the same router as you. What do you suggest i add to it next?

    • @m1lkweed
      @m1lkweed 3 роки тому

      SƎNTIИƎL 髪 traceroute is handy, and don't worry if you can only write command scripts, a lot of simple tools are written like that.

    • @dEExm702
      @dEExm702 3 роки тому

      @@m1lkweed hmm ok thx :)

    • @nero2k619
      @nero2k619 3 роки тому

      What you mean manually shutdown computers on the same network ? Do you just send command to the router and it shutdowns another pc or what ?

    • @inxnite4071
      @inxnite4071 Рік тому

      Hey if you’re still interested, search up how to get kali Linux in a virtual machine I suggest virtual box and it gives you many tools to hack and such but you can use some of them for creating a program

  • @minibit0103
    @minibit0103 3 роки тому +1

    Like a Boss

  • @Phaser1980
    @Phaser1980 3 роки тому +46

    Video on hacking is 13:37 long... I see what you did there. 🧐

  • @fahid3342
    @fahid3342 2 роки тому

    And what about enumeration and establish foothold

  • @Marcothemillionaire
    @Marcothemillionaire 2 роки тому

    where can I get Nessus from I don't t have 3k???

  • @MathaGoram
    @MathaGoram 3 роки тому

    Thx. Not your cup of tea but need Nessus on ARM hardware too.

  • @sahilbasia4571
    @sahilbasia4571 3 роки тому +2

    Bro please can you make a video on installing gvm (openvas) vulnerability scanner fir Kali Linux 2020.3

  • @pcislocked
    @pcislocked 3 роки тому

    yeah i know how to do this except step 6

  • @martin_oconnor
    @martin_oconnor 3 роки тому +2

    How do you find out if someone is using these methods or similar against you? Thanks in advance!

    • @pianochannel100
      @pianochannel100 3 роки тому

      In theory, you don't.

    • @ala_b2017
      @ala_b2017 3 роки тому

      By monitoring you network To detect scans and weird trafic coming from someone. Also check your website and server logs every time.

    • @blender_wiki
      @blender_wiki 2 роки тому

      You have monitor tools that detect some kind of behavior that can be associated to different hack technique.
      You can monitor your .log server file or directly the network traffic inside a network especially if you search for inside attack.

  • @bernardphlaxisk6454
    @bernardphlaxisk6454 3 роки тому +1

    I'm here just because EC-Council says it is a 5 step process, the same way they say C|EH is practical n all.

  • @LofilabLofiHipHop
    @LofilabLofiHipHop 3 роки тому

    Thank you for this amazing video. Please bring more content about hacking using android divese =)

  • @laragonzalezcastilla2771
    @laragonzalezcastilla2771 Рік тому

    2 years passed damn

  • @zellers5423
    @zellers5423 3 роки тому +1

    You can do this on any version of Ubuntu, right?

    • @NullByteWHT
      @NullByteWHT  3 роки тому +1

      Yes, but you may have to install some required programs.

  • @RaffaeleSellittoNiInF
    @RaffaeleSellittoNiInF 3 роки тому +9

    I don't understand why you say that SSH is usually associated with port 80. The SSH default port is 22, while 80 is Http default port. Anyhow, I enjoyed your video, really interesting.

  • @nicroxio681
    @nicroxio681 3 роки тому +9

    SUP BOIS

  • @riley530
    @riley530 3 роки тому

    These comments are golden.

  • @MrGFYne1337357
    @MrGFYne1337357 3 роки тому +3

    dig, host, rdns, nmap, metasploit

  • @mauliddifirmansyah252
    @mauliddifirmansyah252 3 роки тому

    hi null byte can you help me to learn me from indonesia

  • @timetraveller4336
    @timetraveller4336 3 роки тому +1

    It's really strange to watch a null byte video with someone who blinks

  • @andrewa7952
    @andrewa7952 3 роки тому

    Step 6?

  • @alimonbanda6983
    @alimonbanda6983 Рік тому

    Link is down

  • @quintinwaterhouse5804
    @quintinwaterhouse5804 Рік тому

    Anyone notice the video length is 13:37

  • @gautamhacks5098
    @gautamhacks5098 3 роки тому

    where is orginal null byte??!

  • @naturalsoundlab4307
    @naturalsoundlab4307 3 роки тому

    Hey!! Where is cody?

  • @tienatnguyen3412
    @tienatnguyen3412 Рік тому

    Can you crack the online ID ransomware pls ?

  • @uaman11
    @uaman11 Рік тому

    this is brilliant and i aint even a brit

  • @hnachtv6555
    @hnachtv6555 3 роки тому

    how did kody k evolve into this !!??

  • @youtubepro5932
    @youtubepro5932 5 місяців тому

    Dude been follow me since bros wanted to b in college

  • @digitalvillage2333
    @digitalvillage2333 2 роки тому

    Ffs can’t get the damn nessus scanner cause I need to pay for a friggin business email 🤦‍♂️

  • @rectify2003
    @rectify2003 3 роки тому

    Where has Codi gone?
    The other Guy?

  • @area-XZLyn
    @area-XZLyn 3 роки тому

    it could be psyarriasis

  • @omegapsiphi1911
    @omegapsiphi1911 3 роки тому

    Wait a minute Where is Cody? What did you guys do with Cody!?!?!?!?!? lol

  • @Ghost-by5zt
    @Ghost-by5zt 3 роки тому +3

    I want to click there website for full tutorial but then again they are hackers

    • @farhanazamchohan6924
      @farhanazamchohan6924 3 роки тому

      I read their 8 courses details and they are convincing. but, buying and giving bank details to hacker mentor is not convincing.

  • @lesiostasio2542
    @lesiostasio2542 3 роки тому +2

    Mmm, yes. I do feel like using this information for educational purposes ONLY. And I'm gonna do the sixth part for sure.

  • @xAlbanianHackerx
    @xAlbanianHackerx 3 роки тому +2

    You skipped reporting!

    • @xAlbanianHackerx
      @xAlbanianHackerx 3 роки тому

      Hah, being in the field I was looking forward to that section 😬

  • @justrickacoustic
    @justrickacoustic 2 роки тому

    can we appreciate that the time of this video is 13:37? 1337

  • @redsol3629
    @redsol3629 3 роки тому

    Get those daemons uploaded.

  • @moonmaan
    @moonmaan 3 роки тому +1

    Just casually using software that has a license that costs several thousand dollars, okay.

  • @GuNoZidE
    @GuNoZidE 2 роки тому

    Damn the video is exactly 1337 long 🤣

  • @cybercat1531
    @cybercat1531 3 роки тому +1

    Step 6. No matter how 1337 a hacker you are takes the longest ;)

    • @cybercat1531
      @cybercat1531 3 роки тому

      At least it always feels that way

  • @kabobz
    @kabobz 3 роки тому +9

    Hi, 2 things to help your skin, eat beats (sometimes skin problems mean something is wrong inside body) and mix yogurt with honey for outside on skin. Nice video, too advanced for me.

  • @josephjefferson2617
    @josephjefferson2617 2 роки тому

    P.S.: SSL is usually associated with port 443.

  • @narcisakaparapet
    @narcisakaparapet 3 роки тому +2

    Blinking was never an option

  • @private_guapo
    @private_guapo 3 роки тому

    nice timeframe xddd

  • @enos5192
    @enos5192 3 роки тому +1

    Where is Cody the Soul Ripper 😌

    • @NullByteWHT
      @NullByteWHT  3 роки тому +1

      That's a badass nickname

    • @enos5192
      @enos5192 3 роки тому

      @@NullByteWHT He really is

  • @realhomy
    @realhomy 3 роки тому +2

    Ahh yes I remember 2 years ago when he used to stare straight into your soul without blinking

    • @MarcoMazziniYT
      @MarcoMazziniYT 3 роки тому

      Not the same guy.

    • @realhomy
      @realhomy 3 роки тому

      @@MarcoMazziniYT no im talking about the guy that was here 2 years ago

    • @realhomy
      @realhomy 3 роки тому

      hope u understand

    • @MarcoMazziniYT
      @MarcoMazziniYT 3 роки тому

      @@realhomy I misinterpreted your "he used to stare".
      You have to admit that it's a bit confusing.

    • @realhomy
      @realhomy 3 роки тому

      oh ok

  • @adamodonoghue4812
    @adamodonoghue4812 3 роки тому

    what happened to the guy that doesnt blink

  • @RETRO-DEV
    @RETRO-DEV 3 роки тому +15

    I'm watching you...

    • @user-es2pd6he7l
      @user-es2pd6he7l 3 роки тому +2

      I’m watching you to...

    • @RETRO-DEV
      @RETRO-DEV 3 роки тому +2

      @@user-es2pd6he7l too* and no... No you're not...

    • @RETRO-DEV
      @RETRO-DEV 3 роки тому +1

      @@user-es2pd6he7l also wtf is your username supposed to be

    • @harambe2185
      @harambe2185 3 роки тому +1

      @@RETRO-DEV longest name in Africa

    • @RETRO-DEV
      @RETRO-DEV 3 роки тому

      @@harambe2185 fair enough I suppose

  • @mattnsac
    @mattnsac Рік тому

    The video is 13:37 long. Im sure it was a coincidence lol

  • @0xSN1PE
    @0xSN1PE 3 роки тому +3

    print("Quality Content")

    • @lavishjaat
      @lavishjaat 3 роки тому +2

      cout

    • @BloodmansCrypt
      @BloodmansCrypt 3 роки тому

      java
      System.out.println("Quality Content");
      C
      printf("Quality Content");
      C#
      Console.WriteLine("Quality Content");

    • @nero2k619
      @nero2k619 3 роки тому

      Assembly:
      section .text
      global _start
      _start:
      mov edx, len
      mov ecx, msg
      mov ebx, 1
      mov eax, 4
      int 0x80
      mov eax, 1
      int 0x80
      section .data
      msg db 'Quality Content',0xa
      len equ $ - msg
      BrainFuck:
      ++++++++++[>+>+++>+++++++>+++++++++++++++++++++++++++.---------.---.+++++++++++.+++++.----------.-.++++++.---------------.+++++++++.++++++.

  • @user-nw4gv9pf8x
    @user-nw4gv9pf8x 2 місяці тому

    WANTED. Alive or Dead :)
    Amazing

  • @forestriver437
    @forestriver437 3 роки тому

    well if it aint nick...haha ha haha

  • @rafaelnacha1788
    @rafaelnacha1788 2 роки тому

    4:20

  • @dydarjadmin
    @dydarjadmin 3 роки тому

    Круто, довай жги пакрышки🤣🤣🤣

  • @tayyabrasul3807
    @tayyabrasul3807 2 роки тому

    Vid is exactly 13:37 long

  • @basudhasworld5539
    @basudhasworld5539 2 роки тому

    Evil or maybe a good copy of micheal reeves

  • @abhikdutta2848
    @abhikdutta2848 3 роки тому

    Bro r u ok????

  • @xanthusxiaobo6307
    @xanthusxiaobo6307 3 роки тому

    Can you make a video on how to hack pubg

  • @0xkucingHacking
    @0xkucingHacking 2 роки тому

    Pls add indonesian sub

  • @edward7935
    @edward7935 3 роки тому +4

    :)

  • @dEExm702
    @dEExm702 3 роки тому

    OoOoooOOOOOOOoooOoooh 0 dislikes. ;)

  • @romangrace2507
    @romangrace2507 3 роки тому

    i love not having a life and doing shit like this lol

    • @boristodorov779
      @boristodorov779 3 роки тому

      Well u can have a life and still do it

    • @romangrace2507
      @romangrace2507 3 роки тому

      @@boristodorov779 true true, but i write so many scripts that i do not have time for anything else....

  • @user-ly4cm3dc3r
    @user-ly4cm3dc3r 9 місяців тому

    =没有来自中国的评论=

  • @OzoneX4
    @OzoneX4 3 роки тому

    way too basic, can we get something more advanced?

  • @renganathanofficial
    @renganathanofficial 3 роки тому

    please don't talk about his face :(

  • @wickedwolf8438
    @wickedwolf8438 3 роки тому +1

    bro nice skin.. haha just kidding.. nice vid

    • @NullByteWHT
      @NullByteWHT  3 роки тому

      I didn't come on the internet to take shit from people who believe in Q-anon.

    • @wickedwolf8438
      @wickedwolf8438 3 роки тому

      @@NullByteWHT oh my god, no need to be toxic, it was a joke :) ...also no need to critize other people beliefs since i dont critize yours :)

    • @aaroojali2085
      @aaroojali2085 3 роки тому

      @@NullByteWHT bann this fucker

    • @NullByteWHT
      @NullByteWHT  3 роки тому +2

      @@wickedwolf8438 Toxic? I don't make asshole comments about the physical appearance of college students bringing you content in their free time during a pandemic and then act like a victim when I get called out for it. When I started this channel, it was people making comments like yours that made me doubt if creating content was worth it. Keep this shit on Reddit.

    • @BloodmansCrypt
      @BloodmansCrypt 3 роки тому

      @@wickedwolf8438 oh god just stfu

  • @tubeDude48
    @tubeDude48 3 роки тому +1

    *LOOSE* *THE* *CRAPPY* *MUSIC!!!!!!!!!!!!!!!!!!!!!!!!!!!*

  • @IFASTBRAKE
    @IFASTBRAKE Рік тому

    To be sincerely speaking in my humble opinion without being sentimental and judgmental and of course without offending anyone who thinks differently from my opinion, but the name above recovered it all for me in no time! I've vowed to always preach about ifastbrake! 👈🏼