Pentesting Notes
search
Ctrlk
Pentesting Notes
  • house-chimney-userHome
  • 🌐Web pentesting
    • magnifying-glassContent Discovery
    • globe-pointerSubdomain Enumeration
    • unlock-keyholeAuthentication bypass
    • 3IDOR (Insecure Direct Object Reference)
    • code-pull-requestGit repository
    • jsXSS
    • arrow-turn-upSSRF
    • right-leftCSRF
    • syringeInjection
    • copyFI (File Inclusion)
    • image-landscapeFile upload
    • atOAuth
    • cookieJWT
    • reflect-horizontalCORS
    • atom-simplePrototype pollution
    • bring-forwardRequest Smuggling
  • windowsWindows Pentesting
    • userEnumerating users (No credentials)
    • escalatorPrivilege Escalation
    • arrow-down-from-linePost-Exploitation
    • arrow-progressCross-domain enumeration
    • memo-circle-infoLDAP port (389, 636, 3268, 3269)
    • up-to-bracketSMB port (139,445)
    • databaseMSSQL port (1433)
    • file-certificateCertificate Authority (CA)
    • fingerprintDelegation attacks
    • ticketAttacking Kerberos
    • shuffleRelay attacks
    • lock-openBypassing Security
    • arrow-down-left-and-arrow-up-right-to-centerFile Transfer
    • building-shieldGPO (Group Policy Object)
    • screwdriver-wrenchTools
  • 🐧Linux Pentesting
    • stairsLinux Privilege Esclation
    • boxEscape docker
    • webhookAnsible
  • 🕊️Cross platform pivoting
    • arrows-crossPivoting
  • ☁️Cloud
    • dharmachakraKubernetes
    • windowsAzure
      • sitemapArchitecture
      • bullseye-arrowService Discovery, Recon, Enumeration and Initial Access Attacks
        • glasses-roundUnauthenticated Recon
        • spray-canPassword Spraying
        • globeAzure App Service
        • box-archiveAzure Blob Storage
        • face-angry-hornsPhishing with Evilginx
        • scale-balancedConditional Access
      • magnifying-glassAuthenticated Enumeration
      • stairsPrivilege Escalation
      • sign-postLateral Movement
  • 🔁Reversing
    • windowsWindows executables and DLL's
    • pageLinux binaries
    • javaJava applications
    • mobile-signalAndroid APK
  • 🛜Wireless networks
    • wifiWPA/WPA2
    • campfireWPS
    • wifi-slashWEP
    • unlock-keyholeCapative portal bypass
    • routerSetting up a Rogue Access Point
    • file-certificateWPA Enterpise (WPA-MGT)
  • ⭐Tips and tricks
    • starTips and tricks
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. ☁️Cloudchevron-right
  2. windowsAzure

bullseye-arrowService Discovery, Recon, Enumeration and Initial Access Attacks

glasses-roundUnauthenticated Reconchevron-rightspray-canPassword Sprayingchevron-rightglobeAzure App Servicechevron-rightbox-archiveAzure Blob Storagechevron-rightface-angry-hornsPhishing with Evilginxchevron-rightscale-balancedConditional Accesschevron-right
PreviousConsent and Permissionschevron-leftNextUnauthenticated Reconchevron-right