Infrastructure Penetration Testing Checklist
Infrastructure Penetration Testing Checklist
Infrastructure Penetration Testing Checklist
Contact Me!!
LinkedIn : https://www.linkedin.com/in/purabparihar/
Twitter : https://twitter.com/purab_parihar
Recon
External Infrastructure
Extracting email addresss from Employees's Profile for Identifying email formats
Internal Infrastructure
Fingerprinting
Google Dorking
Site: Domain]
filetype:xml inurl:sitemap
Mapping Network
Port Scan
Service Scan
Version Scan
OS Scan
SNMP Enumeration
snmpcheck
snmpwalk
NetBIOS Enumeration
nbtscan
nmblookup
Anonymous Login
FTP Bounce
Null Password
SMTP Relay
User Enumeration
Jenkins
/people
/securityRealm/user/admin/search/index?q=
https://github.com/gquere/pwn_jenkins
IIS
Path Traversal
Downloading DLLs
System.Web.Routing.dll
System.Web.Optimization.dll
System.Web.Mvc.dll
System.Web.Mvc.Ajax.dll
System.Web.Mvc.Html.dll
/admin:$i30$INDEX_ALLOCATION/admin.php
/admin::$INDEX_ALLOCATION/admin.php
Directory BruteForce
krb5-enum-users.nse
NFS 2049
showmount -e IP
Mounting
Extracting Users
Extracting my info
Extracting Administrators:
Anonymous Credentials
Null Sessions
Listing Shares
Null Session
Mount share
Without Credential
With Credential
Banner Grabbing
Authenticated
UnAuthenticated
auxiliary/admin/mssql/mssql_escalate_dbowner
auxiliary/admin/mssql/mssql_escalate_execute_as
Banner Grabbing
Basic Commands
Enumerating Privileges
select user();
Reading file
select load_file('/home/purabparihar/read_file.txt');
Extracting credentials
Banner Grabbing
VNC Password
~/.vnc/passwd
Decrypting Password
Banner Grabbing
Extracting information
client list
Extracting configuration
CONFIG GET *
Dumping Database
KEYS *
GET KEY
https://github.com/RUBNDS/PRET
Extracting Stats
memcstat --servers=127.0.0.1
Extracting Memcdump