This is the fifth unit of my course for teachers, which brings together a lot of material I generated while working as Project Manager for the Hacker Highschool v2 Rewrite Project, 2012-2016.

Pen Testing :: Step by Step: Burp Suite

Burp Suite Start with the basics: https://www.cybrary.it/s3ss10n/s3ss10n-wednesday-burp-suite-basics/ Use Burp to Test for Path Traversal Vulnerabilities https://support.portswigger.net/customer/en/portal/articles/2590663-using-burp-to-test-for-path-traversal-vulnerabilities

Pen Testing :: Step by Step: Metasploit and Armitage


Metasploit and Armitage Starting Metasploit Generic Metasploit installation instructions for any OS: https://metasploit.help.rapid7.com/docs/installing-the-metasploit-framework Instructions for starting Metasploit in Kali: https://docs.kali.org/general-use/starting-metasploit-framework-in-kali The default install of Metasploit that comes with Kali needs to be initialized. service postgresql start msfdb init # only if necessary

Pen Testing :: Step by Step: Enumeration

Enumeration Okay, by now you've spent hours, days or weeks stealthily footprinting your scope. Since this is pen testing, you've been mighty careful not to exceed your scope, right? So let's talk tools and techniques. See https://security.stackexchange.com/questions/168247/reduce-noise-when-penetration-testing for an extensive list of

Pen Testing :: Step by Step: Prepping a Fresh Kali Install for Action

Initial Tasks for a New Kali Install # Run these commands to make sure your Kali box is # truly up-to-date: apt-get update apt-get upgrade apt-get upgrade –fix-missing apt-get distupgrade # You WILL need git: apt-get install git # Edit /root/.bash_aliases, for