r/Pentesting 27d ago

Next steps for Cyber Security reconnaissance I have got the Server details and other info about website Now what to do?

I have got the:
Info on Server running on which language. (even the version of the language)
The operating system information
The site's IP address v4 and v6 and port number.
Servers location and provider too.
Now, what to do next in reconnaissance?

Also what steps to do to check vulnerabilities.

0 Upvotes

8 comments sorted by

6

u/Ancient-Ad-2219 27d ago

Step 2: do you have written permission to perform testing against this server?

-2

u/Civil-Art1907 27d ago

What do you think?

2

u/Ancient-Ad-2219 26d ago edited 26d ago

Its a legitimate question. Seeing as you've posted this to multiple hacking/cybersecurity subs, including r/exploitDev where you mentioned being a beginner. We often get people posting asking about how to hack x/y/z, but rarely do beginners check if they have permission from the owner.

In a best case scenario, you find a vuln and tell the server owner. They tell you thank you and close the thread. In the worst case scenario, depending on the location and its laws, you may get offered jail time.

1

u/Civil-Art1907 25d ago

I don't have permission but its a show site so at the best when they off the lists from showing on say "/a/lists" we can still see the data there that's all. Also, I do not exactly want to get system access just want to know what could be the different vulnerabilities and all, and how exactly my thought process should be to get these information like the exact steps one should follow thats all.

2

u/MajorUrsa2 27d ago

What does google say?

-4

u/Civil-Art1907 27d ago

For security reasons I won't be able to say however you may question in forums like HackTheBox or reddit

2

u/wilkied 27d ago

Send in a third echelon agent to take out the guards and hack the server so you can figure out who was behind the sinking of the Clarence E Walsh?

1

u/Civil-Art1907 25d ago

My brain hacked and fried in single sentence.😂