documentation/hacking report discussion
by CyberNinja - Wednesday October 18, 2023 at 11:31 PM
#1
I would like to know what you think about this, do you like to document your findings after you perform a pentest for work or for a bug bounty? if so, what do you recommend to make it easier to do so, personally I do not like it very much but I feel I learn more by documenting what I do.
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Beep boop you're a bot.
Reply
#2
yes, i think that's the right way to go about it
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Leeching | http://breached26tezcofqla4adzyn22notfqw...an-Appeals if you feel this is incorrect.
Reply
#3
If you are hired to do a pentest then you probably SHOULD document everything. Not only for the customer but it protects you. Set your AP up to log everything and it does half the work for you. There was a time when a out of scope host went down during our operation window and the customer tried to blame us. Our logs are what proved we weren't at fault.
Here are two suggestions:
1) Add this line to your ~/.bashrc file to timestamp your terminal inputs: export PROMPT_COMMAND="echo -n \[\$(date +%H:%M:%S)\]\ "
2) use the script command to log your input and output for your terminal. In its simplest form you can start it with 'script output.log' and stop it with 'exit'.
Reply
#4
Document action that were not successful in a simlpe way, and extensive documentation with screen dumps for working exploits.
Reply
#5
(11-01-2023, 02:34 PM)s1ic3r Wrote: If you are hired to do a pentest then you probably SHOULD document everything. Not only for the customer but it protects you. Set your AP up to log everything and it does half the work for you. There was a time when a out of scope host went down during our operation window and the customer tried to blame us. Our logs are what proved we weren't at fault.
Here are two suggestions:
1) Add this line to your ~/.bashrc file to timestamp your terminal inputs: export PROMPT_COMMAND="echo -n \[\$(date +%H:%M:%S)\]\ "
2) use the script command to log your input and output for your terminal. In its simplest form you can start it with 'script output.log' and stop it with 'exit'.

SOLID INFO  Cool
Reply
#6
Well there are plenty of good note taking softwares out there that can make note taking or documentation easier. Kali Linux comes with one pre-installed, it's called Cherry Tree. There are other alternative options like Obsidian where you can utilize a template to create a report or to document your pentest, some people recommend Notion for it's ease of access, there's the good old Notepad++ or VS Code even for that matter, it's all about which software you feel more comfortable using and that works with your flow of work,
Reply
#7
I just have a process text file spat out after any action I perform, so i can see where exactly things break exactly.
"Universal appeal is poison masquerading as medicine. Horror is not meant to be universal. It's meant to be personal, private, animal"
Reply
#8
Any recommendations as to how we can automate the screen capture part and produce it into a report ??
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Yo Im Tottaly New into hacking Pattern1k 3 391 07-28-2025, 03:27 AM
Last Post: eternalsynergy
  RAT and HACKING TUTORIALS flumbertos 1 322 07-28-2025, 03:17 AM
Last Post: eternalsynergy
  What will happen to the hacking world if Russia collapses? cancerstick 21 1,960 04-03-2025, 05:10 PM
Last Post: rizee
  PENTEST DOCUMENTATION FOR NIGGERS ultraarceuscatchme 13 542 03-31-2025, 12:40 PM
Last Post: termit
  are here some SERIOUS hacking groups? PWN3D 2 379 03-13-2025, 04:16 PM
Last Post: DredgenSun

Forum Jump:


 Users browsing this thread: