Skip to content
View mango00y's full-sized avatar

Block or report mango00y

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mango00y/README.md

Header

[root@haider]─[~]$ whoami
> Certified Ethical Hacker | Offensive Security Focus
> Breaking things in isolated labs so I can explain exactly how — and how to fix it

~/about

role:          Penetration Tester / Red Team 
certification: CEH (Certified Ethical Hacker) — Corvit, NAVTTC — Completed
also_studying: CCNP, Huawei (GNS3 / eNSP)
focus:         Recon → Enumeration → Vulnerability Analysis → Exploitation → Post-Exploitation
philosophy:    Labs > theory. Evidence > claims. Every exploit gets a remediation.

~/lab-infrastructure

Everything below runs in an isolated, host-only virtualized lab — Kali as the attack box, Windows/Metasploitable2 as intentionally vulnerable targets, never against anything I don't own or have authorization for.

Layer Stack
Virtualization VMware Workstation, EVE-NG, GNS3, Cisco Packet Tracer
Attack box Kali Linux
Targets Metasploitable 2, Windows 7/10/11 VMs (XAMPP-simulated services), Cisco 3640 (GNS3)
Networking gear (virtual) Cisco routers/switches (IOS), HSRP/VRRP/GLBP labs

~/skills

Networking OS Offensive WebSec Net

Tools:

Nmap Wireshark Metasploit Burp Kali Ettercap

Nmap · Gobuster · Shodan · SearchSploit · Metasploit/Meterpreter · John the Ripper · Hydra · Nessus · OpenVAS/Greenbone · OWASP ZAP · Burp Suite · Wireshark · Ettercap · Lynis · Aircrack-ng


~/evidence-portfolio

Documented, reproducible offensive work — not just "I installed the tool."

[+] Metasploitable 2 — Nessus Vulnerability Assessment
    436 findings | 28 Critical · 99 High · 148 Medium · 20 Low · 141 Info
    Critical: Apache PHP-CGI RCE, Shellshock, bind-shell backdoor,
              phpMyAdmin SQLi exposure, UnrealIRCd backdoor, weak VNC creds

[+] Metasploitable 2 — Controlled Exploitation & Pentest Report
    - Bind shell backdoor (ingreslock/1524)  → root shell, validated via Nmap + netcat
    - UnrealIRCd 3.2.8.1 backdoor            → Meterpreter session, root access
    - VNC weak credential ("password")       → validated via Metasploit aux scanner
    - Apache PHP-CGI argument injection      → vuln confirmed, alt. exploit path documented
    Each finding paired with remediation guidance.

[+] OWASP ZAP — Web Application Assessment (v2.17.0)
    Target: Metasploitable2 (DVWA, Mutillidae II, TWiki, phpMyAdmin, WebDAV)
    23 findings | Highest: High (MD5-crypt hash disclosure)
    Medium: missing CSP, directory browsing, vulnerable JS library, no anti-clickjacking

[+] ARP Poisoning / MITM Lab — Ettercap + Wireshark
    Topology: Kali (attacker) · Windows 7 (victim 1) · Windows 10 (victim 2) — isolated host-only network

    Baseline:
    - Recorded IPv4 + MAC for both Windows hosts (ipconfig /all) and Kali's eth0 (ifconfig)
    - Verified clean ARP state on both victims (arp -a) — each held the other's true MAC, no Kali entry
    - Confirmed baseline reachability with ICMP between victims (no poisoning yet)

    Attack:
    - Launched Ettercap (GUI mode) on Kali, sniffing on eth0
    - Performed a host scan, identified both Windows machines from the host list
    - Assigned Win7 → Target 1, Win10 → Target 2
    - Enabled IP forwarding on Kali (net.ipv4.ip_forward = 1) so poisoned traffic would route
      through the attacker instead of black-holing
    - Launched MITM → ARP Poisoning attack

    Validation:
    - Re-checked arp -a on both victims — each host's ARP table now resolved the other's IP
      to Kali's MAC address, confirming successful cache poisoning
    - Started a live Wireshark capture on Kali's eth0
    - Generated ICMP traffic between the two Windows hosts and observed it transiting through
      the attacker, visible directly in the Wireshark capture

    Takeaway: demonstrates the core weakness ARP exploits — no authentication on ARP replies —
    and the practical mechanics of a Layer 2 MITM: poison → verify cache corruption → enable
    forwarding to stay transparent → intercept with a packet analyzer.

[+] Network Forensics — Malware Delivery + C2 Investigation (PCAP)
    Victim requested /update.exe x4 over HTTP:8000 → outbound TCP:4444 to C2 host
    ~566KB transferred in <1s post-handshake, ~67s sustained bidirectional session
    Pattern consistent with staged Meterpreter payload + interactive C2

[+] Nessus / Wireshark — Windows Network Scan Analysis
    15,621 packets / ~16 min capture | ~623 TCP ports probed via SYN scan
    SMB/RPC enumeration (LSA, SAMR, share enum) + default SNMP "public" string found
    Correctly distinguished recon/enum activity from actual exploitation

[+] Cisco 3640 — Nessus Vulnerability Assessment (GNS3)
    Network-device-focused scan with full severity breakdown

[+] Lynis — Linux Security Audit (Kali)
    269 tests | Hardening index: 60/100 | 1 warning, 49 suggestions
    Findings: inactive firewall/IDS, fail2ban gap, GRUB & PAM hardening opportunities

[+] OSINT & Recon Tooling
    Aliens Eye     — username OSINT scanner across 840+ platforms
    MailAccess     — email investigation/harvesting workflow (venv-based CLI tool)
    OSINT Recon    — subdomain/DNS enumeration (dnsenum, dnsrecon, dig, Subfinder) on a
                     real target, uncovered internal subdomains (sonarqube/vpn/UAT) behind
                     real origin IPs missed by standard footprinting

[+] AI-Assisted Offensive Tooling
    HexStrike AI & pentest-ai (ptai) — MCP-driven offensive tool orchestration (150+ modules,
    17 specialist agents), self-verifying scan/exploit findings, natural-language-driven
    recon and exploitation workflows — used strictly in authorized lab environments

~/cisco-networking

Hands-on Cisco IOS labs, not just theory:

IPv4/binary/subnetting · NAT (static + dynamic) · Standard & Extended ACLs · VLANs + inter-VLAN routing · RIP/OSPF/EIGRP/BGP concepts · HSRP/VRRP/GLBP failover labs · STP/BPDU & switching loops · DHCP · Wireless/WLC concepts


~/currently

+ CEH (Certified Ethical Hacker) — Completed, Corvit
+ Learning CCNP + Huawei configuration (GNS3 / eNSP)
+ Sharpening exploitation and post-exploitation workflows on new lab targets
+ Preparing for Penetration Tester / Red Team entry-level roles

Everything above was performed in isolated, authorized lab environments — Metasploitable2, self-hosted VMs, and virtual network topologies. No unauthorized targets.

Footer

Pinned Loading

  1. mango00y mango00y Public

  2. vulnerability-assessment-metasploitable2 vulnerability-assessment-metasploitable2 Public

    Nessus vulnerability scan of Metasploitable2 with manual Metasploit validation of critical findings

  3. network-forensics-pcap-investigation network-forensics-pcap-investigation Public

    Forensic investigation of a PCAP capture — port scanning, C2 beaconing, and DNS tunneling detection

  4. hexstrike-groq-client hexstrike-groq-client Public

    Python MCP client bridging HexStrike AI's pentesting tools to Groq/Llama 3.3 for natural-language tool orchestration

    Python

  5. icmp-flood-attack-defense-lab icmp-flood-attack-defense-lab Public

    ICMP flood attack (hping3, nping, pentmenu) and defense (Windows Firewall, Wazuh active response, rate-limiting) lab — Kali → Windows VM, CEH coursework (Corvit).

  6. njrat-analysis-lab njrat-analysis-lab Public

    Blue-team analysis of njRAT 0.7D delivery, execution & C2 behavior in an isolated VM lab — CEH coursework, SOC detection-engineering focus (Wazuh/Sysmon)