Posts: 22
Threads: 3
Joined: Aug 2023
Hi guys, I've done some ctf and challenge but now I want to test it on real target so what do you advice me to find some vulnerable websites to train myself and maybe make a bit of money ?
Posts: 159
Threads: 20
Joined: Oct 2023
it's not that easy, CTF and real world are two different things as i said in the SB.
But, if u wanna start looking around, i suggest u to strat from Shodan...
Posts: 22
Threads: 3
Joined: Aug 2023
(11-03-2023, 01:29 PM)XTN Wrote: it's not that easy, CTF and real world are two different things as i said in the SB.
But, if u wanna start looking around, i suggest u to strat from Shodan...
Ah yes thanks that's a good place to start, and have you any advice to compromise a system like in real world is phishing that works in most case or is there also a lot of exploitation needed?
Posts: 159
Threads: 20
Joined: Oct 2023
(11-03-2023, 01:33 PM)TeaPot Wrote: (11-03-2023, 01:29 PM)XTN Wrote: it's not that easy, CTF and real world are two different things as i said in the SB.
But, if u wanna start looking around, i suggest u to strat from Shodan...
Ah yes thanks that's a good place to start, and have you any advice to compromise a system like in real world is phishing that works in most case or is there also a lot of exploitation needed?
if u are going tho sart phishsing depends on who are u phishing, what kind of company and lot of other consideration.
The most common technique to comprise company is to find an SQLi and get all the data from them.
Posts: 22
Threads: 3
Joined: Aug 2023
Posts: 76
Threads: 18
Joined: Jun 2023
(11-03-2023, 01:33 PM)TeaPot Wrote: (11-03-2023, 01:29 PM)XTN Wrote: it's not that easy, CTF and real world are two different things as i said in the SB.
But, if u wanna start looking around, i suggest u to strat from Shodan...
Ah yes thanks that's a good place to start, and have you any advice to compromise a system like in real world is phishing that works in most case or is there also a lot of exploitation needed?
If you want to start by phishing you should first focus on doing a full reconnaissance of your target company and its workers, emails, campaigns you could use to your advantage, vulnerable workers and what kind of sites they frequent, etc. You could use signalhire or snov.io which collect information about a company's employees, emails, occupations, etc, as it pulls the info from the internet.
Ban reason: Beep boop you're a bot. (Permanent)
Posts: 22
Threads: 3
Joined: Aug 2023
(11-03-2023, 01:29 PM)XTN Wrote: If you want to start by phishing you should first focus on doing a full reconnaissance of your target company and its workers, emails, campaigns you could use to your advantage, vulnerable workers and what kind of sites they frequent, etc. You could use signalhire or snov.io which collect information about a company's employees, emails, occupations, etc, as it pulls the info from the internet.
ok thanks for the ref i'll try
Posts: 293
Threads: 0
Joined: Aug 2023
Posts: 129
Threads: 11
Joined: Apr 2024
|