
Watch a live web application hack demonstrated in action, following along to learn what a penetration tester does. Welcome beginners to a practical, hands-on introduction focusing on training.
Outline the penetration testing mission from the kickoff meeting through the engagement plan to the attack plan, including the client proposal stage and consultancy selection.
Kick off the mission to find and report security vulnerabilities on the server hosting web application and gain root access within a black-box scope, with rules, time frame, and prerequisites.
Begin with port scanning to discover services, then enumeration and fingerprinting to map applications and build the attack path, exploit weak points, escalate to root, and deliver the final report.
Discover how to perform port scanning with nmap to enumerate services on a web server, identifying open ports like http on 80, ssh, and smtp.
Learn to fingerprint services with nmap -sV, capture banners and versions, explore exploits, run service scripts, and uncover data such as ssh keys and robots.txt.
Interact with a web app to perform application mapping and enumeration. Explore url parameters, hidden paths, and source code to identify directories like admin and a db.sql file.
Learn practical SSH interaction in a white hat hacking workflow, handle errors through research, enumerate servers, accept the fingerprint, and proceed even without a password.
Identify cross-site scripting vulnerabilities by observing how injected input is returned and executes JavaScript in a penetration testing context.
To learn more about the course
Head over to the course's page at https://academy.thehackerish.com/p/from-zero-to-signing-your-first-ethical-hacker-job
Learn how to obtain a remote shell by leveraging an open SSH service and reused passwords, gaining an initial foothold and beginning system enumeration.
Perform post-exploitation enumeration by listing running processes, inspecting root-owned services like sendmail, and examining web files under var/www for config data and credentials, including internal mail access.
The lecture explains privilege escalation in a white-hat hacking context, demonstrating how misconfigured sudo privileges can yield a root shell and full server access.
Welcome to this course that will demystify the exciting job of a white hat hacker, and help you decide if it's worth pursuing! If you're curious about penetration testing, cybersecurity, but now little to nothing about it, you're in the right place.
I will take you through a practical use case approach. Rather than inundating you with theoretical jargon, I will immerse you in a practical use case where you'll have a peek behind the curtain. You will discover different tools, vulnerabilities, and how to use them to hack a web application.
Starting from the very first kickoff meeting and progressing through the various stages that define a pentest mission, this course will offer you valuable insights into the fundamental building blocks of a pentest job. We will take you on a journey through the mission, immersing you in the real-world experiences of a white hat hacker's job.
Upon completing this course, you will possess the knowledge and experience necessary to make an informed decision about whether a career in penetration testing aligns with your aspirations. This course will help you evaluate whether a job in this field resonates with your interests and goals.
The sole purpose of this course is to introduce penetration testing, it is NOT intended for those who want to build their technical skills.