Kali Linux for Advanced Pen Testing and Ethical Hacking

Kali Linux for Advanced Pen Testing and Ethical Hacking

2h 24mAdvanced2021-12-15

Authors

Malcolm Shore

Malcolm Shore

Cybersecurity Expert, Former Director of GCSB

Course details

Kali Linux is the penetration-testing professional's main tool, and includes hundreds of modules for scanning, exploitation, payloads, and post exploitation. In this course, Malcolm Shore teaches you advanced pen testing with Kali, including stealthy testing, privilege escalation, and pivoting. Learn how to use the basic toolset and extend Kali, integrating native exploits into the Metasploit environment. Find out how to generate and maintain a variety of shells, including Python and C++, and discover how to collect and use credentials. Get an introduction to the online Hack The Box and Offensive Security labs where you can practice your pen-testing skills. Malcolm details the advanced customization of exploits and achieving root access through a sustainable shell. This course covers many of the key objectives needed to pass the Offensive Security Certified Professional (OSCP) exam, and will appeal to all ethical hackers and pen testers, as well as general IT professionals.

Skills covered

Penetration TestingSecurity TestingLinuxCybersecurityOpen SourceDeep Dive (X:Y)

Concepts

Introduction

  • Using Kali Linux as the basis for advanced penetration testing
  • What you should know
  • Disclaimer

Kali Basics

  • Testing with Kali Linux
  • Understanding Kali deployments
  • Preparing your toolbox
  • Preparing to use exploits for testing
  • Managing the Kali menu
  • Using the LinkedIn Learning penetration testing lab

System Shells

  • Introduction to shells
  • Exploring Kali webshells
  • Weeving a shell
  • Generating shellcode with msfvenom
  • Injecting images with jhead
  • Using shellcode in exploits

Exploiting Targets from Kali

  • Exploiting systems with Kali
  • Exploiting with Python
  • Exploiting with Perl
  • Exploiting with C
  • Exploiting with CPP

Passwords

  • Obtaining Windows passwords
  • Obtaining Linux passwords

Exploiting the Metasploitable Server

  • Targeting Metasploitable
  • Exploiting VSFTPD
  • Exploiting with ProFTPD
  • Exploiting Tomcat
  • Exploiting IRC
  • Exploiting the distributed compile system
  • Exploiting network files
  • Hiding in plain sight
  • Escalating to root

End-to-End Testing

  • Hacking the box
  • Exploiting rejetto
  • Exploiting the Devel
  • Time to exploit Cronos
  • Cronos revisited - Getting to the root
  • Using a nightmare escalator

Conclusion

  • Next steps
80,000 Toman