📚
Notes
  • Welcome
    • Intro
    • My OSCP Exam Adventure
  • Security Blogs
    • Initial Access 101
      • Spring Cloud Function CVE-2022-22963
    • Bug Hunting
      • XSS
        • Blog site search field
  • Active Directory
    • Tools
    • Common built-in AD groups
    • Identifying Users
    • LLMNR/NBT-NS Poisoning
    • Password Spraying
      • Enumerating & Retrieving Password Policies
      • Making a Target User list
      • Internal Password Spraying - from Linux
      • Internal Password Spraying - from Windows
    • Credentialed Enumeration
      • Linux
      • Windows
      • Living Off the Land
    • Kerberoasting
      • Linux
      • Windows
    • ACL
      • Enumeration
      • Abusing ACLs
      • DCSync
    • Privileged Access
    • AS-REP Roasting
    • Attacking Trusts
      • Enumerating Trust Relationships
      • Child -> Parent Trusts
      • Cross-Forest Trust Abuse
  • Enumeration
    • SMB, RPC - 137,138,139,445,111
    • MYSQL - 3306
    • MSSQl - 1433
    • FTP - 21
    • RPC - 111
    • DNS - 53
    • NFS - 2049
    • SMTP - 25
    • IMAP, POP3 - 110,143,993,995
    • SNMP - 161
    • SVN - 3690
    • IRC - 8067
    • Oracle TNS - 1521
    • LDAP
    • Linux Remote Management Protocols
    • Windows Remote Management Protocols
    • Fuzzing
    • IPMI - 623(UDP)
  • Common Applications
    • Application Enumeration
    • CMS (Content Management System)
      • Wordpress
      • Joomla
      • Drupal
    • Servlet Containers/Software Development
      • Tomcat
      • Jenkins
    • Customer Service Mgmt & Configuration Management
      • Gitlab
  • Shells
    • Reverse Shells
    • Bind Shells
    • Spawning a TTY Shell
    • Web Shells
  • Privilege Escalation
    • Other Resources
    • Linux PrivEsc
    • Windows PrivEsc
      • Windows Users Privileges
      • Information Gatthering & Enumeration
      • Privilege Escalation Techniques
  • File Transfers
    • Quick Cheatsheet
    • Windows File Transfer
    • Linux File Transfer
  • Password Attacks
    • Linux Local Password Attacks
      • Credential Hunting in Linux
      • Passwd, Shadow & Opasswd
    • Windows Local Password Attacks
      • Attacking SAM
      • Attacking LSASS
      • Attacking Active Directory & NTDS.dit
      • Credential Hunting in Windows
    • Pass-the-Hash (PtH)
    • Cracking Files
    • Remote Password Attacks
  • SIde Notes
    • Pivoting, Tunneling, and Port Forwarding
    • File Encryption
  • Programming
    • Downloading Files
Powered by GitBook
On this page
  1. Welcome

Intro

NextMy OSCP Exam Adventure

Last updated 10 months ago

This is a Cheatsheet that i have prepared while learning Penetration Testing and preparing for OSCP. So it contains Information more than required for oscp. Will Keep updating it as i learn more daily and Please correct me if any information is wrong.

UPDATE - I have passed oscp and shared my journey on different platforms and in this space too. You can check it on next page.

Enjoy Learning...

Below are some resources and cheatsheets that i used to make this and will add more in future.

  • AD Attacks -

Useful CVE sites:

  • CVE lookup -

  • CVE information -[CVE]

  • CVE information -[CVE]

  • CVE information -[CVE]

  • [CVE]

  • CVE sources -

https://book.hacktricks.xyz/welcome/readme
https://github.com/Kitsun3Sec/Pentest-Cheat-Sheets
https://github.com/swisskyrepo/PayloadsAllTheThings
https://github.com/danielmiessler/SecLists
https://liodeus.github.io/2020/09/18/OSCP-personal-cheatsheet.html
https://github.com/tagnullde/OSCP/blob/master/oscp-cheatsheet.md
https://reconshell.com/oscp-preparation-cheat-sheets/
https://www.netwrix.com/attack.html
https://www.cvedetails.com/vendor.php
https://www.cvedetails.com/cve/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=
https://web.nvd.nist.gov/view/vuln/detail?vulnId=
https://security-tracker.debian.org/tracker/
https://cve.mitre.org/data/refs/index.html