Toolkit
  • Password Guesser
    Attempt to log in by trying lots of different passwords from a database
  • Web Scanner
    Scan a public web server for vulnerabilities
  • Device Scanner
    Scan a server, printer or IoT device for vulnerabilities
  • WiFi Scanner
    Look for visible wifi networks
  • Network Mapper
    Scan a network to see what devices are on it

Web Site

You visit donuts.govt.nz on your web browser. Looks pretty boring: annual report blah blah governance structures blah strategic initiative blah blah blah board members yawn... Oh wait. There are some pictures of donuts. They do look good! Mmmmm!

Focus! You remind you self to focus on the job...

Seems like there is not much of interest on the publicly visible part of the web site itself. Time go get out some tools and dig around inside.

A web site is usually made of three parts:

  • The content: the text and pictures you can see as you browse
  • The software: a tool that knows how to get the correct text and pictures for each page from a database and show it to you when you ask
  • The server: a computer somewhere in the internet that runs the software and stores the content until it is needed

Try the Web Scanner to poke at the software

Try the Device Scanner to poke at the web server

Back