Etical Hacking
Etical Hacking
Etical Hacking
**************************************
***********************************************************************************
**************************************
-----------------------------------------------------------------------------------
--------------------------------------
iptool.com (Pagina para buscar informacion sobre una ip) otras
(123people, cuwhois, netcraft)
-----------------------------------------------------------------------------------
--------------------------------------
serversniff ()
-----------------------------------------------------------------------------------
--------------------------------------
Restclient-tool (herramienta que permite obtener un listado de metodos
http)
-----------------------------------------------------------------------------------
----------------------------------------------
DNSrecon (Revisar el cache de un servidor DNS, muestra listado
de dominio) dnsrecon.py -t snoop -c nose -D Escritorio/dominios
-----------------------------------------------------------------------------------
---------------------------------------------
evigrade framework (atacar)
-----------------------------------------------------------------------------------
---------------------------------------------
haveibeenpwned (pagina proporciona la posibilidad si un correo ha sido
dumpeado en alguna bd publicada en internet)
-----------------------------------------------------------------------------------
---------------------------------------------
googlepythonmail.py () comando python googlepythonmail.py dominio.com
-----------------------------------------------------------------------------------
------------------------------------------------------
whatweb (es como nmap pero para web) whatweb -v
-----------------------------------------------------------------------------------
----------------------------------------------------------
blindElephant {Permite disponer de un listado de plugins de Drupal y
wordpress} nikto[se integra con metasploit] plecost y WPScan o joomacan
-----------------------------------------------------------------------------------
----------------------------------------------------------
Pagiga 28:
-----------------------------------------------------------------------------------
--------------------------------------
AccCheck (usa diccionario) y nbtscan (explotan el protocolo SMB, se
encuentra por defecto en kaliy nbtstat es windows) busca sevidore netbios abiertos
en la red. nbtsacan -r 172.16.1.2
-----------------------------------------------------------------------------------
----------------------------------------------------------
SMTP-user-enum y ncat (permiten conseguir usuarios de correo) ncat [--
SSL] [email protected] 25 https://nmap.org/ncat/guide/ncat-ssl.html
https://fwhibbit.es/auditando-un-servidor-smtp
-----------------------------------------------------------------------------------
----------------------------------------------------------
netcan (enviar correo) netcan -vv smtp:[email protected] 25
-----------------------------------------------------------------------------------
----------------------------------------------------------
snmpcheck (budc informacion)
-----------------------------------------------------------------------------------
----------------------------------------------------------
Fuzzer y crawler y wmap (analisis de vulnerabilidades)
-----------------------------------------------------------------------------------
----------------------------------------------------------
https://www.securityfocus.com (pagina para buscar exploit y vunerabilidades)
-----------------------------------------------------------------------------------
----------------------------------------------------------
Nessus y nexpose (escaneres de primer nivel)
-----------------------------------------------------------------------------------
----------------------------------------------------------
dirbuster (obtener por fuerza bruta los nombres de directorios
y archivos en servidores Web/de aplicaci�n)
-----------------------------------------------------------------------------------
----------------------------------------------------------
WFuzz (es una herramienta poderosa para probar la seguridad
en la web en el que se realizan pruebas en las aplicaciones de la web)
-----------------------------------------------------------------------------------
----------------------------------------------------------
http://dominio.com/robots.txt o http://dominio.com/sitemap.xml
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-----------------------------------------------------------------------------------
------------------------------------------------------------------------------
-
***********************************************************************************
**************************************