Skip to main content

Penetration Testing

===============================

Kali Linux

===============================

Install Kali Linux in the virtual box in the windows operation system.
Below is the link of the video which will demonstrate how to install kali linux in the virtual machine.
https://www.youtube.com/watch?v=wCEPusruqQM

SCANNING
NMAP CHEAT SHEET (FULL + STEP-BY-STEP + EASY)

For Kali Linux – Penetration Testing

===============================

1. BASIC DISCOVERY SCANS

===============================

1.1 Ping Scan (Find live hosts)

nmap -sn <target/subnet>

Purpose: Checks which hosts are online (no port scanning).
Example:
nmap -sn 192.168.1.0/24

1.2 Disable Ping (When host blocks ping)

nmap -Pn <target>

Purpose: Treats all hosts as online and scans even if ICMP is blocked.

1.3 Quick Scan of Top Ports

nmap <target>

Purpose: Scans top 1000 common TCP ports.

===============================

2. PORT SCANNING

===============================

2.1 Full TCP Port Scan (all 1–65535 ports)

nmap -p- -sS <target>

Purpose: Finds ALL open TCP ports.
-sS: Stealthy SYN scan.

2.2 Scan Specific Ports

nmap -p 22,80,443 <target>

2.3 Scan Port Range

nmap -p 1-1000 <target>

0R
nmap -Pn 192.168.1.1-50

2.4 UDP Scan

nmap -sU <target>

Purpose: Finds open UDP ports (slower).

2.5 TCP & UDP Together

nmap -sS -sU <target>

2.6 Fast Scan (Top 100 ports only)

nmap -F <target>

2.7 Multiple Targets from a File Create a file named targets.txt with a list of IPs (one per line):

targets.txt

192.168.1.10 192.168.1.15 example.com

Then run:

nmap -Pn -iL targets.txt

===============================

3. SERVICE & VERSION DETECTION

===============================

3.1 Detect Service Versions

nmap -sV <target>

Purpose: Show exact versions (e.g., Apache 2.4.49).

3.2 Aggressive Version Detection

nmap -sV --version-intensity 9 <target>

3.3 OS Detection

nmap -O <target>

Purpose: Attempts to identify OS (Linux/Windows/etc.).

===============================

4. AGGRESSIVE & COMBINED SCANS

===============================

4.1 Aggressive Scan

nmap -A <target>

Includes:
✔ OS detection
✔ Version detection
✔ Scripts
✔ Traceroute

⚠️ Noisy – use carefully!

4.2 Everything in One Scan

nmap -p- -A -T4 <target>

===============================

5. NMAP SCRIPTING ENGINE (NSE)

===============================

5.1 Run Default Scripts

nmap -sC <target>

Equivalent to:

nmap --script=default <target>

5.2 Run Vulnerability Scripts

nmap --script vuln <target>

Purpose: Automatically checks common CVEs.

5.3 Run Specific Scripts

nmap --script smb-vuln* <target>

Examples for SMB:

  • smb-vuln-ms17-010

  • smb-vuln-regsvc-dos

5.4 Safe Script Scan

  • nmap --script safe <target>

5.5 Malware Detection

  • nmap --script malware <target>

===============================

6. SCAN TIMING & PERFORMANCE

===============================

6.1 Speed Up Scans

nmap -T4 <target>

T0 = slowest | T5 = fastest

6.2 Max Speed Scan

nmap -T5 <target>

⚠️ Very noisy.

6.3 Slow, Stealthy Scan

nmap -T1 <target>

===============================

7. EVASION & BYPASSING FIREWALLS

===============================

7.1 Fragment Packets

nmap -f <target>

7.2 Decoy Scan

nmap -D RND:10 <target> Purpose: Makes scan appear as if coming from random IPs.

7.3 Randomize Scan Order

nmap --randomize-hosts <targets>

7.4 Change Source Port

nmap --source-port 53 <target> Useful when firewalls allow DNS.

===============================

8. OUTPUT & REPORTING

===============================

8.1 Save Output to Text File

nmap <target> -oN scan.txt

8.2 Save Output in XML

nmap <target> -oX scan.xml

8.3 Save All Formats

nmap <target> -oA result

Creates:

  • result.nmap

  • result.xml

  • result.gnmap

===============================

9. ADVANCED & SPECIAL SCANS

===============================

9.1 DNS Brute Force

nmap --script dns-brute <domain>

9.2 HTTP Enumeration

nmap --script http-enum <target>

9.3 SSL/TLS Vulnerabilities

nmap --script ssl-enum-ciphers <target>

9.4 FTP Anonymous Login Check

nmap --script ftp-anon <target>

9.5 SMB Enumeration

nmap --script smb-enum-shares,smb-enum-users <target>

===============================

10. REAL-WORLD NMAP WORKFLOW

===============================

STEP 1: Find live hosts

nmap -sn 192.168.1.0/24

STEP 2: Scan top ports

nmap <target>

STEP 3: Full port scan

nmap -p- -sS <target>

STEP 4: Detect services

nmap -sV <target>

STEP 5: OS detection

nmap -O <target>

STEP 6: Vulnerability scan

nmap --script vuln <target>

STEP 7: Save report

nmap -oN final_report.txt <target>

Comments

Popular posts from this blog

Install MariaDB Latest Version 11.4 in Red Hat Version 9

 This this post i will show you step by step the installation process of mariaDB in red hat version 9. Step1 Run the command to pull the latest updated packages on applications installed in your system. -dnf update If you get Kernal update than reboot the system -reboot Step2 Go to official mariaDB site Make mariadb repository in /etc/yum.repos.d Place the configuration in this file # MariaDB 11.4 RedHatEnterpriseLinux repository list - created 2024-09-24 11:12 UTC # https://mariadb.org/download/ [mariadb] name = MariaDB # rpm.mariadb.org is a dynamic mirror if your preferred mirror goes offline. See https://mariadb.org/mirrorbits/ for details. # baseurl = https://rpm.mariadb.org/11.4/rhel/$releasever/$basearch baseurl = https://mirrors.aliyun.com/mariadb/yum/11.4/rhel/$releasever/$basearch # gpgkey = https://rpm.mariadb.org/RPM-GPG-KEY-MariaDB gpgkey = https://mirrors.aliyun.com/mariadb/yum/RPM-GPG-KEY-MariaDB gpgcheck = 1 Now install the mariaDB with its dependencies package...

How to find out if a package is installed in Linux?

1) How to find out if a package is installed or not in Linux There are multiple ways to check find locate package is installed in linux machine or not 1.a) Using which command The  ‘which’  command returns an executable path that can be executed when the command is entered in the terminal. # which vi /usr/bin/vi 1.b) Using whereis command The  ‘whereis’  command is used to search the binary, source, and man page files for a given command. # whereis vi vi: /usr/bin/vi /usr/share/man/man1/vi.1p.gz /usr/share/man/man1/vi.1.gz 1.c) Using locate command The  ‘locate’  command performs faster than the find command because it uses an updatedb database, whereas the find command searches in real time. # locate --basename '\nano' /usr/bin/nano /usr/share/nano /usr/share/doc/nano 2) How to find out whether a package is installed or not in Linux, using package manager 2.a) On CentOS / Red Hat (RHEL) 6/7 Use  yum command  or  rpm command  to deter...

Default login form code in laravel

  <div class="container">     <div class="row justify-content-center">         <div class="col-md-8">             <div class="card">                 <div class="card-header">{{ __('Login') }}</div>                 <div class="card-body">                     <form method="POST" action="{{ route('login') }}">                         @csrf                         <div class="form-group row">                             <label for="email" class="col-md-4 col-form-label text-md-right">{{ __('E-Mail Address') }}</label>         ...