room ~ Guided Pentest: Infrastructure
Guided Pentest: Infrastructure
Metasploit, CVE research, privilege escalation, and pentest reporting
1/6
lessons
Pentest Methodology — 5 Steps
The Framework
1. Enumeration → 2. Vulnerability Analysis → 3. Initial Access → 4. Privilege Escalation → 5. Reporting
Step by Step
| # | Phase | Question | Tools |
|---|---|---|---|
| 1 | Enumeration | What's there? | nmap, gobuster, dig |
| 2 | Vulnerability Analysis | What's weak? | searchsploit, CVE databases |
| 3 | Initial Access | How to get in? | Metasploit, manual exploits |
| 4 | Privilege Escalation | How to get root? | LinPEAS, WinPEAS, manual |
| 5 | Reporting | What did we find? | Documentation, evidence |
Mindset
- Not just "run tools" — think like an attacker
- Programmer: "where could code fail?"
- Sysadmin: "where's the misconfiguration?"
- Attacker: "what was missed?"
Infrastructure vs Web Pentest
| Aspect | Web | Infrastructure |
|---|---|---|
| Target | Web apps, APIs | Servers, network devices |
| Entry | Browser-based vulns | Network services (SSH, SMB, IRC) |
| Tools | Burp Suite, browser | Nmap, Metasploit, SSH |
| Priv Esc | Admin panel access | Root/SYSTEM access |
| Common vulns | IDOR, XSS, SQLi | Outdated software, misconfig |
Prerequisites
- Nmap scanning skills
- Basic Linux commands
- Understanding of services (SSH, FTP, IRC, SMB)
- Metasploit basics