Book Image

Learn Penetration Testing

By : Rishalin Pillay
Book Image

Learn Penetration Testing

By: Rishalin Pillay

Overview of this book

Sending information via the internet is not entirely private, as evidenced by the rise in hacking, malware attacks, and security threats. With the help of this book, you'll learn crucial penetration testing techniques to help you evaluate enterprise defenses. You'll start by understanding each stage of pentesting and deploying target virtual machines, including Linux and Windows. Next, the book will guide you through performing intermediate penetration testing in a controlled environment. With the help of practical use cases, you'll also be able to implement your learning in real-world scenarios. By studying everything from setting up your lab, information gathering and password attacks, through to social engineering and post exploitation, you'll be able to successfully overcome security threats. The book will even help you leverage the best tools, such as Kali Linux, Metasploit, Burp Suite, and other open source pentesting tools to perform these techniques. Toward the later chapters, you'll focus on best practices to quickly resolve security threats. By the end of this book, you'll be well versed with various penetration testing techniques so as to be able to tackle security threats effectively
Table of Contents (21 chapters)
Free Chapter
1
Section 1: The Basics
4
Section 2: Exploitation
12
Section 3: Post Exploitation
16
Section 4: Putting It All Together

Preparing your environment

To demonstrate the various post-exploitation attacks in this chapter, I have built a basic Active Directory (AD) lab. You can build the same one that I built by using the following diagram:

Figure 1: Lab diagram

Windows 10 Enterprise Evaluation can be downloaded from the following URL: https://www.microsoft.com/en-us/evalcenter/evaluate-windows-10-enterprise.

Windows Server 2016 Evaluation can be downloaded from the following URL: https://www.microsoft.com/en-us/evalcenter/evaluate-windows-server-2016.

The setup steps for creating a domain on the server operating system is as follows:

  1. Once your server is installed, log in using the local administrator account.
  2. Configure a static IP address on the Ethernet adapter. If you are building a virtual machine, ensure that you set your network adapter to be a private network on the virtualization software.
  3. ...