其實冇話用開邊種,跟本係睇你搵到咩番黎,一開始咪nmap先,之後有web services咪gobuster, 想睇下request係點咪burp, 通想係remote command execution用burp放便好多
password cracking 咪John the ripper/Hydra, 佢唔俾用auto tools, 所以我都少用
就算啲人有script做enumeration都少用,太易miss左啲野
我試過做做下揾到個db file要特登download tools黎開
揾現實既vulnerability真心覺得自己未到家
不過ctf, boot2root個啲就冇問題既
但係份份都話要cissp呢