Summary
Keywords
Full Transcript
To get the Course Notes & Practice Questions, Join Hackaholics Anonymous as an Agent or Above: https://youtube.com/@HankHacksHackers/join By joining the Hackaholics Anonymous community, you'll get direct access to me, a community of supportive likeminded individuals, and exclusive perks like: - Exclusive Downloads (Like the PenTest+ course notes & practice questions) - Bug Bounties - Python Automations for CySec, PenTesting, SysAdmin - Exclusive Content - Live Chats / Q&A's / AMA's - And much, much more! https://youtube.com/@HankHacksHackers/join ************************** Module 3 Time Stamps: 00:00 SECTION 3.1 INTRO - VULNERABILITY DISCOVERY TECHNIQUES 03:32 How to Get the Notes & Practice Questions 05:01 Container Scans 11:59 Dynamic Application Security Testing 19:34 Interactive Application Security Testing 22:46 Static Application Security Testing 29:34 Software Composition Analysis 34:22 TCP/UDP Scanning 41:58 Stealth Scans 47:02 Authenticated Scans 51:40 Unauthenticated Scans 53:33 Secrets Scanning 58:47 Wireless Vulnerability Assessments 01:05:47 ICS Vulnerability Assessment 01:09:35 SECTION 3.1 PRACTICE QUESTIONS 01:22:30 HOW TO GET THE NOTES & PRACTICE QUESTIONS ———— 01:23:56 SECTION 3.2 INTRO - ANALYZING RECON, SCANNING & ENUMERATION RESULTS 01:27:22 HOW TO GET THE NOTES & PRACTICE QUESTIONS 01:28:51 Why Validate Scan Results? 01:32:40 Identifying False Positives 01:40:31 Identifying False Negatives 01:47:18 Ensuring Scan Completeness 01:54:02 Where to Find Public Exploits 02:00:23 Matching Exploits to Vulnerabilities 02:04:51 Identifying Reliable Exploits 02:09:36 Why Use Scripts to Validate Results 02:10:57 Python Script: Check For Apache Vulnerability 02:17:07 Bash Script: Automate Nmap Validation 02:20:46 SECTION 3.2 PRACTICE QUESTIONS 02:33:19 HOW TO GET THE NOTES & PRACTICE QUESTIONS ———— 02:34:45 SECTION 3.3 INTRO - PHYSICAL SECURITY CONCEPTS 02:37:46 HOW TO GET THE NOTES & PRACTICE QUESTIONS 02:39:16 Tailgaiting (Piggybacking) 02:48:56 Badge Cloning & RFID Hacking 02:55:00 Lock Picking & Physical Bypass 03:00:37 What Is a Site Survey? 03:04:08 Performing a Physical Security Assessment 03:09:16 USB Drops (Baiting Attacks) 03:13:53 Social Engineering & Human Exploitation 03:18:25 SECTION 3.3 PRACTICE QUESTIONS 03:29:10 HOW TO GET THE NOTES & PRACTICE QUESTIONS ———— 03:31:33 SECTION 3.4 INTRO - TOOLS FOR VULNERABILITY DISCOVERY 03:35:25 HOW TO GET THE NOTES & PRACTICE QUESTIONS 03:36:54 Nikto 03:41:14 OpenVAS 03:46:35 Nessus 03:52:37 TruffleHog 03:59:31 PowerSploit 04:07:11 BloodHound 04:14:28 Grype 04:19:10 Trivy 04:23:28 Kube-Hunter 04:25:33 SECTION 3.4 PRACTICE QUESTIONS 04:38:25 HOW TO GET THE NOTES & PRACTICE QUESTIONS
