0% found this document useful (0 votes)
20 views2 pages

Offensive Hacking Course

The document is a guide on Offensive Cyber Security, covering key topics such as reconnaissance, scanning, web application vulnerabilities, exploitation, post-exploitation, wireless security, and defensive practices. It aims to educate readers on ethical hacking and responsible security research. Each section provides detailed techniques and concepts essential for understanding offensive hacking methodologies.

Uploaded by

markosmados
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
20 views2 pages

Offensive Hacking Course

The document is a guide on Offensive Cyber Security, covering key topics such as reconnaissance, scanning, web application vulnerabilities, exploitation, post-exploitation, wireless security, and defensive practices. It aims to educate readers on ethical hacking and responsible security research. Each section provides detailed techniques and concepts essential for understanding offensive hacking methodologies.

Uploaded by

markosmados
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Offensive Hacking Fundamentals Guide

This document provides a structured overview of key topics in Offensive Cyber Security. The
purpose of this guide is educational awareness, ethical hacking knowledge, and responsible
security research.

1. Reconnaissance Phase

• Passive Recon – Collecting information without directly interacting with the target.

• Active Recon – Direct interaction with the target system to gather data.

• Subdomain Enumeration – Discovering hidden or additional subdomains.

• WHOIS & DNS Enumeration – Gathering domain registration and DNS records.

• OSINT Basics – Using publicly available information sources.

2. Scanning & Enumeration

• Port Scanning – Identifying open ports on a target system.

• Service Detection – Determining services running on open ports.

• Vulnerability Scanning – Automated detection of known weaknesses.

• Banner Grabbing – Extracting service/version information.

• SMB / FTP / SSH Enumeration – Extracting detailed service information.

3. Web Application Vulnerabilities

• SQL Injection – Manipulating database queries.

• Cross-Site Scripting (XSS) – Injecting malicious scripts into web pages.

• Cross-Site Request Forgery (CSRF) – Forcing users to execute unwanted actions.

• Insecure Direct Object Reference (IDOR) – Unauthorized access to resources.

• Authentication Bypass – Circumventing login mechanisms.

• File Upload Vulnerability – Exploiting insecure file upload features.

• Local File Inclusion (LFI) / Remote File Inclusion (RFI).

• Command Injection – Executing system commands through vulnerable input.

4. Exploitation Concepts
• Exploit Basics – Understanding what an exploit is.

• Reverse Shell Concept – Gaining remote command-line access.

• Payload Concept – Code delivered to execute malicious actions.

5. Post-Exploitation Concepts

• Privilege Escalation – Gaining higher-level permissions.

• Buffer Overflow Theory – Memory exploitation concept.

• Persistence – Maintaining long-term access.

• Lateral Movement – Moving across systems within a network.

• Log Analysis – Understanding and analyzing system logs.

6. Wireless & Human Factors

• WiFi Security Basics – Wireless network fundamentals.

• WPA/WPA2 Concepts – Wireless encryption standards.

• Bluetooth Security Basics.

• Phishing Awareness – Identifying social engineering attacks.

• Human Psychology in Security – Understanding manipulation tactics.

7. Defensive & Professional Practices

• Defensive Awareness – Understanding how defenders mitigate attacks.

• Writing Vulnerability Reports – Professional security reporting.

• CVSS Basics – Vulnerability severity scoring system.

• Responsible Disclosure – Ethical vulnerability disclosure process.

• Bug Bounty Workflow – Steps in responsible bug bounty research.

You might also like