Penetration Testing against vulnerable apps on Oracle VirtualBox
• Reconnaissance and Fingerprinting using OSINT tools; Shodan, Google Dorks, Burp & ZAP passive scanning.
• Network Ports mapping and scanning using Nmap, Masscan. Network data packets sniffing using Wireshark.
• Passive and Active scanning; manual & automated, spidering, directory brute-force, etc. (Burp Suite, OWASP-ZAP, Nessus)
• Injection techniques to exploit Web apps: XSS, CSRF, SSRF, SQL, brute-force passwords and users, HTML Headers, etc. (Burp)
• Analyzed system for potential vulnerabilities from improper system and network configuration – Automated and Manual
• Exploitation, and Post exploitation using Metasploit
GitHub