当前位置:网站首页>Analysis of penetration test learning and actual combat stage
Analysis of penetration test learning and actual combat stage
2022-07-06 13:48:00 【One call yyds】
Initial contact stage
Many little partners who have just come into contact with the penetration testing industry when you walk out of the gate of the College , Sometimes I feel very confused , I don't know the plan for the future after learning penetration testing .
According to my analysis for many years , Come up with a set of my own ideas and opinions .
The first step is , Of course, first learn the basic knowledge of penetration testing .
The second step , It belongs to the advanced stage , Constantly summarize what content of penetration testing in the process of the project is the most helpful to us through actual combat .
The third step , Constantly learn from the practical experience of our predecessors , Thus, it can be flexibly applied to actual combat .
Step four , Analyze simply , Technical expertise , Go back to the source .
Step five , Mining and analyzing the most primitive elements , Discover the latest 0day Loophole .
I think the cognitive level should also be constantly improved , The cognitive side represents your height , Knowledge represents the current height .
Learning penetration testing must have their own ideas , Just like setting goals , What to do first, then what to do , Don't mess up the rhythm .
Here is a share of my learning and practical experience .
I am a rookie with dreams ,
The first stage , Of course, it is to understand the market of the network security industry , And development trend 、 The work done .
The second stage , So I began to look for ways to learn , Method , Ask Baidu if you don't understand , Baidu has also given me many methods of predecessors . So we choose the learning method that suits us to start learning .
I just started to learn PHP programing language , Secondly, I revisited MySQL database , Then learn how to collect information , Then learn about loopholes , Basic loopholes .
The third stage , It is to apply knowledge to actual combat , This stage is a small breakthrough stage , At first, I was digging some unprotected sites , Put the knowledge learned on the real website , So I chose src, Digging holes in actual combat is a stage of the formation of self thinking , Every penetration testing engineer should have his own ideas and methods of vulnerability mining , Bring everyone together , What is digested is what belongs to you .
Goals matter , In the actual combat stage, I plan to be on the list at least , So I studied some methods of vulnerability fast mining .
The fourth stage , It is the extension stage , Continue to expand the scope of our possible attacks , Or the way of defense .
Whatever it is , It is helpful for our attack , This will let us know how the target defends , In order to make better use of countermeasures . To achieve our goal of attacking target vulnerabilities .
The fifth stage , Analyze the origin of the vulnerability , Learn reverse thinking , No killing thought , Penetration testing technology , Programming technology , Network knowledge , Development integration and other knowledge , Think about what kind of problems it will produce , Try to explore new bug.
Maybe the idea is like this , After that, I will continue to publish my technical articles , Welcome to Europe !
边栏推荐
- A piece of music composed by buzzer (Chengdu)
- Floating point comparison, CMP, tabulation ideas
- 魏牌:产品叫好声一片,但为何销量还是受挫
- 5.函数递归练习
- 2.C语言初阶练习题(2)
- 透彻理解LRU算法——详解力扣146题及Redis中LRU缓存淘汰
- Caching mechanism of leveldb
- Have you encountered ABA problems? Let's talk about the following in detail, how to avoid ABA problems
- 7-1 输出2到n之间的全部素数(PTA程序设计)
- [the Nine Yang Manual] 2022 Fudan University Applied Statistics real problem + analysis
猜你喜欢
7-7 7003 组合锁(PTA程序设计)
C语言入门指南
[面试时]——我如何讲清楚TCP实现可靠传输的机制
这次,彻底搞清楚MySQL索引
自定义RPC项目——常见问题及详解(注册中心)
Safe driving skills on ice and snow roads
【黑马早报】上海市监局回应钟薛高烧不化;麦趣尔承认两批次纯牛奶不合格;微信内测一个手机可注册俩号;度小满回应存款变理财产品...
Thoroughly understand LRU algorithm - explain 146 questions in detail and eliminate LRU cache in redis
5.函数递归练习
2. First knowledge of C language (2)
随机推荐
仿牛客技术博客项目常见问题及解答(二)
Nuxtjs快速上手(Nuxt2)
魏牌:产品叫好声一片,但为何销量还是受挫
实验九 输入输出流(节选)
The latest tank battle 2022 full development notes-1
Beautified table style
Principles, advantages and disadvantages of two persistence mechanisms RDB and AOF of redis
TypeScript快速入门
【九阳神功】2019复旦大学应用统计真题+解析
canvas基础1 - 画直线(通俗易懂)
甲、乙机之间采用方式 1 双向串行通信,具体要求如下: (1)甲机的 k1 按键可通过串行口控制乙机的 LEDI 点亮、LED2 灭,甲机的 k2 按键控制 乙机的 LED1
C language Getting Started Guide
The difference between cookies and sessions
[hand tearing code] single case mode and producer / consumer mode
A comprehensive summary of MySQL transactions and implementation principles, and no longer have to worry about interviews
A piece of music composed by buzzer (Chengdu)
It's never too late to start. The tramp transformation programmer has an annual salary of more than 700000 yuan
5.函数递归练习
【九阳神功】2020复旦大学应用统计真题+解析
The latest tank battle 2022 - Notes on the whole development -2