pentesting

Durum
Üzgünüz bu konu cevaplar için kapatılmıştır...
Süper Üye
Katılım
15 Nis 2020
Mesajlar
653
Çözümler
2
Tepki puanı
37
Ödüller
5
Sosyal
6 HİZMET YILI
Is there any pentesters here?
If yes could someone answer my questions?
Im trying to learn it but i have some questions that i cant find in google.

main question: How do you attack the target?
Do you have to get their wifi or something?
Like in CTF you use vpn to connect to network.
but how do you do it in real life?
 
Son düzenleme:
Süper Üye
Katılım
15 Nis 2020
Mesajlar
653
Çözümler
2
Tepki puanı
37
Ödüller
5
Sosyal
6 HİZMET YILI
already tried youtube, but not reddit thanks for suggestion
 
Moderatörün son düzenlenenleri:
Üye
Katılım
9 Mar 2022
Mesajlar
30
Tepki puanı
1
Yaş
32
4 HİZMET YILI
What's your question. Currently working in a offensive cyber sec role

my main question how do you even start?
like with ctfs you use vpn to connect to network
but how do you in irl?
i know its stupid question but i cannot find the answer
 
Moderatörün son düzenlenenleri:
Süper Üye
Katılım
15 Nis 2020
Mesajlar
653
Çözümler
2
Tepki puanı
37
Ödüller
5
Sosyal
6 HİZMET YILI
Seçkin Üye
Katılım
2 Ara 2018
Mesajlar
576
Tepki puanı
19
Ödüller
5
Yaş
29
7 HİZMET YILI
i do not know sir YouTube is your best friends
 
Moderatörün son düzenlenenleri:
Banlı Üye
Katılım
8 Şub 2022
Mesajlar
559
Tepki puanı
21
Yaş
28
4 HİZMET YILI
What is your question? If you have a lot of questions, add me on Discord and we will talk and answer all your questions
ODI#4044
 
Süper Üye
Katılım
6 Şub 2019
Mesajlar
600
Tepki puanı
23
Ödüller
5
Yaş
36
7 HİZMET YILI
are you still looking for it or did you find it? and also i dont understand your purpose
 
Just another eGirl
Seçkin Üye
Katılım
21 May 2020
Mesajlar
378
Tepki puanı
60
Ödüller
2
Yaş
31
6 HİZMET YILI
Something you can do at first is learn programing so you can understand the basics of everything, after that you can learn about the most well known methods of the market nowadays. I'm aware of these three:
  • Bağlantıları görmek için lütfen Giriş Yap
    - Open Source Security Testing Methodology Manual;
  • Bağlantıları görmek için lütfen Giriş Yap
    - Penetration Testing Execution Standard;
  • Bağlantıları görmek için lütfen Giriş Yap
    - Open Web Application Security Project;
Knowing how things works and now that you are a bit more settled you have to try learning about vulnerabilities by practicing it. A good way to start the practical part is playing
Bağlantıları görmek için lütfen Giriş Yap
on GitHub or participating in bug bounty programs of companies like Twitch, Facebook, Google and other huge companies.
Now that you are more aware and decided that you really wanna be a Pentester there are some certifications to look for. Here is the ones I believe are the main ones to have your resumé:
  • CompTIA Pentest +;
  • Certified Ethical Hacker (CEH);
  • Offensive Security Certified Professional (OSCP)
  • GIAC Penetration Tester (GPEN);
Keep in mind that no matter how many certifications you have this is something you have to study constantly. New technologies come up and with them new stuff to study comes as well.
Never use this knowledge you'll learn to do bad things, if you want to work with security keep in mind to maintain your reputation as good as possible
 
Süper Üye
Katılım
15 Nis 2020
Mesajlar
653
Çözümler
2
Tepki puanı
37
Ödüller
5
Sosyal
6 HİZMET YILI
Something you can do at first is learn programing so you can understand the basics of everything, after that you can learn about the most well known methods of the market nowadays. I'm aware of these three:
  • Bağlantıları görmek için lütfen Giriş Yap
    - Open Source Security Testing Methodology Manual;
  • Bağlantıları görmek için lütfen Giriş Yap
    - Penetration Testing Execution Standard;
  • Bağlantıları görmek için lütfen Giriş Yap
    - Open Web Application Security Project;
Knowing how things works and now that you are a bit more settled you have to try learning about vulnerabilities by practicing it. A good way to start the practical part is playing
Bağlantıları görmek için lütfen Giriş Yap
on GitHub or participating in bug bounty programs of companies like Twitch, Facebook, Google and other huge companies.
Now that you are more aware and decided that you really wanna be a Pentester there are some certifications to look for. Here is the ones I believe are the main ones to have your resumé:
  • CompTIA Pentest +;
  • Certified Ethical Hacker (CEH);
  • Offensive Security Certified Professional (OSCP)
  • GIAC Penetration Tester (GPEN);
Keep in mind that no matter how many certifications you have this is something you have to study constantly. New technologies come up and with them new stuff to study comes as well.
Never use this knowledge you'll learn to do bad things, if you want to work with security keep in mind to maintain your reputation as good as possible
that literally answered nothing. I already know the basics
 
Banlı Üye
Katılım
11 Nis 2019
Mesajlar
251
Tepki puanı
14
Ödüller
3
Yaş
26
7 HİZMET YILI
why do you all have bad english and cant form a sentence tho
 
Just another eGirl
Seçkin Üye
Katılım
21 May 2020
Mesajlar
378
Tepki puanı
60
Ödüller
2
Yaş
31
6 HİZMET YILI
that literally answered nothing. I already know the basics
Good, if you already know the basics how about you use your basic knowledge to work?
Judging by your answer you expecting someone to give you a step-by-step guide. And honestly if you really know the basics you know that there are no step-by-step guide to things like this.
There is no YouTube tutorials for that, there is only knowing what you wanna do and using the basics to try to that and learn more things as you get the results from what you have tried.

For example, a friend of mine called Gabriel found out a security breach on Facebook streams studying how the process of raiding streams works, how did he learned about it? Studying each and every variable that the event uses when that happened and so he found out he could redirect viewers from a stream to another without being admin in any of the pages.

As for how do you attack the target, there are many ways to attack someone. Just don't expect people to share these kind of information to the public like it is nothing.
CTFs are the basic, but if you want something easier than that what about
Bağlantıları görmek için lütfen Giriş Yap
or
Bağlantıları görmek için lütfen Giriş Yap
? These site have challenges for you to learn the basics of hacking with challenges to give you an idea on how to start. To test what you learned in the sites I recommended try to use the
Bağlantıları görmek için lütfen Giriş Yap
that is a web application with lots of vulnerabilities on purpose for you to test your skills
 
Durum
Üzgünüz bu konu cevaplar için kapatılmıştır...
Üst