Got an interesting challenge online while scrolling LinkedIn - a cybersecurity challenge this is my experience hacking my way through it!
With no prior experience in cybersecurity - this is just me and claude - trying to learn and complete the challenge - let's see how I do - sharing the learnings below :
- nmap - trying out this tool for the fist time, based on what I've read about this - this will help me discover devices on a network, services they expose, scanning ports to see what they're running, reading os fingerprints. Great! Have installed nmap on my mac system - simple :
brew install nmap
-
Gobuster - another tool i guess - chatgpt tells me it's : Gobuster is primarily used during web application reconnaissance. Interesting - this lets me search for any number of commonly used routes - for examaple I search for akshatgirdhar.com - a user won't know the available routes on the website, but Gobuster helps you find the most used routes on a website - it helps us discover hidden web directories, files, subdomains, and virtual hosts.
-
SecLists - a collection of security related wordlists and test data used by penetration testers, security researchers etc. Instead of creating our own list of common usernames, passwords, routes, directories etc, SecLists provides these - very cool - now will combine Gobuster and SecLists together to see what we get. Solving a challenge using let's say website xyz.com :
... things didn't work and I had office the next day so that's it, rest I'll do later and update here!
