Temporary Advertisements:
Ad
Ad
Ad
documentation/hacking report discussion
by CyberNinja - Wednesday October 18, 2023 at 11:31 PM
#1
I would like to know what you think about this, do you like to document your findings after you perform a pentest for work or for a bug bounty? if so, what do you recommend to make it easier to do so, personally I do not like it very much but I feel I learn more by documenting what I do.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Beep boop you're a bot.
Reply
#2
yes, i think that's the right way to go about it

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#3
If you are hired to do a pentest then you probably SHOULD document everything. Not only for the customer but it protects you. Set your AP up to log everything and it does half the work for you. There was a time when a out of scope host went down during our operation window and the customer tried to blame us. Our logs are what proved we weren't at fault.
Here are two suggestions:
1) Add this line to your ~/.bashrc file to timestamp your terminal inputs: export PROMPT_COMMAND="echo -n \[\$(date +%H:%M:%S)\]\ "
2) use the script command to log your input and output for your terminal. In its simplest form you can start it with 'script output.log' and stop it with 'exit'.
Reply
#4
Document action that were not successful in a simlpe way, and extensive documentation with screen dumps for working exploits.
Reply
#5
(Nov 01, 2023, 02:34 PM)s1ic3r Wrote: If you are hired to do a pentest then you probably SHOULD document everything. Not only for the customer but it protects you. Set your AP up to log everything and it does half the work for you. There was a time when a out of scope host went down during our operation window and the customer tried to blame us. Our logs are what proved we weren't at fault.
Here are two suggestions:
1) Add this line to your ~/.bashrc file to timestamp your terminal inputs: export PROMPT_COMMAND="echo -n \[\$(date +%H:%M:%S)\]\ "
2) use the script command to log your input and output for your terminal. In its simplest form you can start it with 'script output.log' and stop it with 'exit'.

SOLID INFO  Cool
Reply
#6
Well there are plenty of good note taking softwares out there that can make note taking or documentation easier. Kali Linux comes with one pre-installed, it's called Cherry Tree. There are other alternative options like Obsidian where you can utilize a template to create a report or to document your pentest, some people recommend Notion for it's ease of access, there's the good old Notepad++ or VS Code even for that matter, it's all about which software you feel more comfortable using and that works with your flow of work,
Reply
#7
I just have a process text file spat out after any action I perform, so i can see where exactly things break exactly.
"Universal appeal is poison masquerading as medicine. Horror is not meant to be universal. It's meant to be personal, private, animal"
Reply
#8
Any recommendations as to how we can automate the screen capture part and produce it into a report ??
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Google AI & Drive Deletion Forensic Chain Bitu79 0 506 Sep 28, 2026, 11:48 PM
Last Post: Bitu79
  grapheneos, in all phones? dai5 3 2,989 Sep 27, 2026, 09:51 AM
Last Post: B2BMatrix
  Google AI Studio chats reappear after deletion Bitu79 1 748 Sep 27, 2026, 09:44 AM
Last Post: B2BMatrix
  Google AI Studio ‘Delete’ is a scam: Your prompts are not deleted Bitu79 1 926 Sep 26, 2026, 11:42 AM
Last Post: Bitu79
  How do "paid" jobs work in this space? floater 1 2,837 Sep 18, 2026, 07:24 PM
Last Post: ProspectKing

Forum Jump:


 Users browsing this forum: