room ~ Guided Pentest: Web
Guided Pentest: Web
IDOR, password reset, upload bypass, RCE, attack chains, and remediation
1/6
lessons
Reconnaissance & Enumeration
Types of Recon
| Type | What | Examples |
|---|---|---|
| Passive | Public sources, no direct contact | Google, WHOIS, LinkedIn |
| Active | Direct interaction with target | Nmap, Gobuster, curl |
Web Enumeration Flow
1. Nmap -> Open ports (80, 443?)
- 2.Visit site -> Technology fingerprint
- 3.Gobuster -> Hidden directories
- 4.API inspection -> Endpoints, data
- 5.robots.txt, sitemap.xml
Key Principle
> Enumeration is NOT exploitation. Finding a path is recon. Finding sensitive data is a vulnerability.