HTTP(S) (80 / 443)
Remember to update /etc/hosts if experiencing any redirect issues to target site
Example:

Interesting Files
Directory Enum
GoBuster
HTTP (Port 80)
HTTPS (Port 443)
View scan results:
Alternative: Dirbuster
Alternative: Fuzz Faster U Fool (FFUF)
Vulnerability Scanning
1. nmap
2. nikto
3. wpscan (For Wordpress sites)
To do while scans run...
Attempt Weak Credentials on any login features found, refer to Default/Common Credentials
Look for user input fields
Look for file upload fields
Run through source code of webpages
Refer to: https://kashz.gitbook.io/kashz-jewels for targets hosting CMS (Joomla, Wordpress, Tomcat, etc)
Last updated