Mastering Ethical Hacking with Kali Linux 2019

Introduction to the Book

Learning Kali Linux 2019 is a comprehensive resource packed with practical exercises, designed with a student-centric approach that makes it easy to follow each chapter. The book begins by introducing ethical hacking concepts and threat actors, then transitions into penetration testing methodologies. Each chapter flows logically into the next, supported by detailed theory on penetration testing phases and hands-on labs using Kali Linux, one of the most popular penetration testing platforms.

Readers will learn to build a personal penetration testing lab environment, execute passive and active reconnaissance against target organizations, perform vulnerability scanning with multiple tools, and conduct wireless penetration, network penetration testing, web application penetration testing, and client-side attacks.

Additionally, readers will gain the skills needed to perform privilege escalation and lateral movement using the Metasploit Framework. Learning Kali Linux 2019 takes readers from beginner to expert level while keeping engagement high.

This book also serves as a training guide for courses related to penetration testing, ethical hacking, and cybersecurity.

Target Audience

This book is designed for students, network and security engineers, cybersecurity/ information security professionals, enthusiasts, and anyone interested in ethical hacking and penetration testing. It is suitable for both self-study and classroom training in penetration testing and cybersecurity courses.

Whether you are new to the IT field or an experienced professional, Learning Kali Linux 2019 is accessible to everyone. While prior knowledge of networking and IT security is helpful, it is not mandatory as the book caters to all skill levels.

Book Content Overview

  • Chapter 1, Getting Started with Hacking: Introduces various threat actors and penetration testing methodologies and approaches.
  • Chapter 2, Setting Up Kali - Part 1: Covers virtualization concepts, building a penetration testing lab, and installing Kali Linux and vulnerable target machines.
  • Chapter 3, Setting Up Kali - Part 2: Focuses on installing and configuring Windows and Ubuntu operating systems, plus troubleshooting Kali Linux.
  • Chapter 4, Familiarizing with Kali Linux 2019: Teaches about Kali Linux, its features, and commands to perform various tasks.
  • Chapter 5, Passive Information Gathering: Explores passive methods of collecting target information from Open Source Intelligence (OSINT) via public resources.
  • Chapter 6, Active Information Gathering: Explains active information collection using DNS queries, scanning, and enumeration techniques.
  • Chapter 7, Using Vulnerability Scanners: Covers various network and web vulnerability scanners including Nessus, Nikto, WPScan, and Burp Suite.
  • Chapter 8, Understanding Network Penetration Testing: Introduces basic concepts of wireless penetration testing.
  • Chapter 9, Network Penetration Testing - Pre-Connection Attacks: Explores wireless hacking tools like aircrack-ng, basic deauthentication attacks, and creating fake access points.
  • Chapter 10, Network Penetration Testing - Gaining Access: Introduces basics of gaining access and cracking WEP/WPA encryption using dictionaries and brute force attacks.
  • Chapter 11, Network Penetration Testing - Post-Connection Attacks: Covers information gathering, Man-in-the-Middle attacks, sniffing with Wireshark, privilege escalation, and lateral movement on networks.
  • Chapter 12, Network Penetration Testing - Detection and Security: Explains detecting ARP poisoning attacks and suspicious activity using Wireshark and packet analysis.
  • Chapter 13, Client-Side Attacks - Social Engineering: Explains various social engineering attacks, defense strategies, creating a phishing Facebook page, and mitigation techniques.
  • Chapter 14, Conducting Web Application Penetration Testing: Introduces web application penetration testing basics, covering common vulnerabilities like SQL Injection, Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF).
  • Chapter 15, Web Penetration Testing - Gaining Access: Explains bypassing logins via SQL injection, reflective and stored XSS attacks, and using BeEF for client-side attacks.
  • Chapter 16, Best Practices: Provides guidance for penetration testers and web application security blueprints to adopt industry-standard practices.

Prerequisites for the Book

To get the most out of this book, readers should have a basic understanding of networking, including various network/application protocols, network devices, and routing/switching concepts. Prior IT security knowledge is helpful but not required to grasp the concepts and exercises presented.

The only required hardware is a personal computer (laptop or desktop) capable of running Oracle VM VirtualBox or VMware Workstation 15 Pro. Recommended specifications:

  • Processor: Intel i5, i7, or better
  • Hard Drive: 200 GB HDD
  • Memory: 4 GB RAM (8 GB preferred)
  • Internet connection
  • Alfa Network AWUS036NHA wireless adapter

Text Conventions Used

The following text conventions are used throughout the book:

  • CodeInText: Indicates code words, database table names, folder names, filenames, file extensions, pathnames, virtual URLs, user input, and Twitter handles. Example: "Use the ifconfig command to verify the adapter status."
  • Command-line input/output is formatted as: ``` airodump-ng --bissid -c wlan0mon
  • Bold: Indicates new terms, important words, or on-screen text like menu or dialog box items. Example: "If using VMware, the New Virtual Machine Wizard will prompt you to proceed in 'Typical (recommended)' or 'Custom (advanced)' mode."

Part 1: Kali Linux Fundamentals

This section covers hacking basics, discusses penetration testing concepts and their value in combating cyber threats. Readers will learn to build a penetration testing lab with various operating systems to practice and improve their skills.

Chapters in this section:

  • Chapter 1, *Getting Started with Hacking*
  • Chapter 2, *Setting Up Kali - Part 1*
  • Chapter 3, *Setting Up Kali - Part 2*
  • Chapter 4, *Familiarizing with Kali Linux 2019*

Chapter 1: Getting Started with Hacking

Cybersecurity is one of the fastest-growing IT fields. Daily attacks target entities from individuals to large enterprises and governments. These threats have created new career paths for professionals who can protect assets. This book provides the knowledge and techniques required to become a penetration tester in the cybersecurity field.

Penetration testers are skilled professionals with hacking abilities; they are hired by organizations to simulate real attacks on their network infrastructure to identify security vulnerabilities before actual attacks occur. This is done with written legal permission from the target organization. To become a skilled hacker, a deep understanding of computers, networking, and programming is essential, but creativity is the most important trait. Creative thinking allows hackers to go beyond conventional uses of technology and find unexpected implementation methods.

We will use Kali Linux, one of the most popular penetration testing operating systems. Kali Linux includes hundreds of tools for vulnerability assessment, penetration testing, and digital forensics. The book follows a student-centric approach with hands-on exercises ranging from beginner to advanced topics.

In this chapter, you will learn:

  • Who hackers are
  • Key terminology
  • Penetration testing phases
  • Penetration testing methodologies
  • Penetration testing approaches
  • Types of penetration testing
  • Hacking phases

Who Are Hackers?

The term "hacker" has become ubiquitous in the 21st century. Computer hacking is the art of using computer technology in unexpected ways to make systems perform unintended operations. Hacking has taken many forms over the years, from phreaking (exploiting analog phone systems) to modern digital attacks. Data breaches at organizations like Equifax, NHS, and Home Depot are daily news items. If you are reading this book, you have taken the first step to understanding this field.

Types of Hackers

Hackers are classified into several categories based on their motives and actions:

  • Black Hat
  • White Hat
  • Gray Hat
  • Suicidal
  • State-Sponsored
  • Script Kiddies
  • Cyber Terrorists

Black Hat Hackers

Black hat hackers have deep knowledge of systems, networks, and application programming, which they use for malicious or criminal purposes. They understand evasion tactics to avoid imprisonment and are familiar with common tools used by ethical hackers. If caught, they are often blacklisted from ethical hacking employment.

White Hat Hackers

White hat hackers (ethical hackers) have similar technical knowledge to black hats but use their skills to test systems, applications, and networks for security vulnerabilities with permission from the target. Their motivation is to protect systems and entities while adhering to legal and ethical standards. They must think like black hats to identify vulnerabilities, making white hat hacking the focus of this book.

Gray Hat Hackers

Gray hat hackers perform vulnerability research independently and disclose findings to force vendors to release patches. Their skills focus on fuzzing, debugging, and reverse engineering. They occupy a middle ground between ethical and non-ethical hacking and provide valuable security information to the community.

Suicidal Hackers

Suicidal hackers have lower technical skills and care little about being detected or imprisoned. Their motivation is often revenge or political ideology, and they aim to disrupt systems regardless of consequences.

State-Sponsored Hackers

State-sponsored hackers are employed by governments to conduct espionage and cyberattacks against other nations. They have access to extensive resources and legal protection to perform their duties.

Script Kiddies

Script kiddies lack in-depth technical knowledge and use pre-written scripts and tools created by other hackers to perform attacks. Most hackers start as script kiddies and progress to more advanced skill levels as they develop their knowledge.

Cyber Terrorists

Cyber terrorists are individuals or groups aiming to cause chaos, often motivated by political or ideological goals. They may disrupt cybersecurity, breach confidential databases, or compromise physical security via digital means.

Key Terminology

  • Threat: A person or thing with the potential to cause harm to systems, networks, or individuals.
  • Asset: Systems, people, or data that need protection. Assets are categorized as tangible (physical devices), intangible (intellectual property, data), or personnel.
  • Vulnerability: A weakness in technical, physical, or human systems that can be exploited to gain access or control. Common vulnerabilities include human error, web application injection flaws, and buffer overflows.
  • Exploit: The method of leveraging a vulnerability to attack a system. For example, the vulnerability is the softness of wood, and the exploit is driving a nail into it.
  • Risk: The potential impact of a vulnerability, threat, or asset on an organization, calculated against other factors. Risk assessment helps determine the likelihood of data breaches causing financial or reputational damage.
  • Zero-Day: A vulnerability unknown to the vendor, with no available patch. These are often used in state-level attacks or by large criminal organizations. Ethical hackers can earn bug bounties for discovering zero-day vulnerabilities.
  • Hacker Value: The motivation or reason for infiltrating a system or network.

Penetration Testing Phases

Penetration testing follows a structured process to ensure all objectives are met:

  1. Pre-Engagement: Select key personnel, define scope, and sign legal agreements including Non-Disclosure Agreements (NDAs) and Consulting Services Agreements (CSAs).
  2. Information Gathering: Collect critical details about the target, including application platforms, APIs, web application firewalls, authentication methods, and network exposure.
  3. Threat Modeling: Identify the most likely threats to the organization, network, or application to guide testing.
  4. Vulnerability Analysis: Run vulnerability scans and perform manual testing to identify security flaws in systems and applicasions.
  5. Exploitation: Leverage identified vulnerabilities to demonstrate potential impact and gain access to systems.
  6. Post-Exploitation: Use gained access to retrieve sensitive data or move laterally through the network.
  7. Reporting: Document findings, risks, business impact, and remediation steps for the client.

Penetration Testing Methodologies

  • OWASP: Open Web Application Security Project provides methodologies and the top 10 web application security risks, the standard framework for web app penetration testing.
  • NIST: National Institute of Standards and Technology publishes best practices and standards for organizational security, helping map vulnerabilities to compliance requirements.
  • OSSTMM: Open Source Security Testing Methodology Manual is a community-driven, peer-reviewed set of security testing standards covering a wide range of testing topics.
  • SANS 25: A list of 25 top security issues defined by the SANS Institute to help assessors understand and categorize discovered vulnerabilities.

Penetration Testing Approaches

  • White Box: Testers receive full information about the target, including technology details and credentials with varying access levels for thorough vulnerability identification.
  • Black Box: Testers have little to no prior information about the target, simulating real-world external attacks. Common for network and social engineering tests.
  • Gray Box: A mix of white and black box testing, providing enough information to reduce reconnaissance time while simulating realistic attack scenarios. Ideal for network penetration testing.

Types of Penetration Testing

  • Web Application Penetration Testing (WAPT): Manual testing of web applications to find vulnerabilities that automated scanners miss. The most common form of penetration testing.
  • Mobile Application Penetration Testing: Testing mobile apps for unique attack vectors and threats, a growing field as mobile usage increases.
  • Social Engineering Penetration Testing: Manipulating human psychology via phishing emails, vishing calls, or physical access attempts to test organizational security awareness.
  • Network Penetration Testing: Identifying vulnerabilities in network systems, devices (switches, routers), and infrastructure. Tasks include bypassing IDS/IPS, firewall evasion, password cracking, and exploiting misconfigurations.
  • Cloud Penetration Testing: Assessing cloud platform security to find vulnerabilities exposing confidential data. Requires legal permission from the cloud vendor (e.g., Microsoft for Azure testing).
  • Physical Penetration Testing: Testing physical access controls like security cameras, biometric systems, locks, and security personnel to protect organizational data.

Hacking Phases

  1. Reconnaissance: Gather meaningful information about the target using search engines, social media, Google hacking, DNS queries, and social engineering.
  2. Scanning: Use direct methods to probe the target for active systems, open ports, running services, firewall rules, and network topology.
  3. Gaining Acces: Exploit vulnerabilities to gain remote access, perform privilege escalation, and execute malicious code on compromised systems.
  4. Maintaining Access: Create backdoors and persistent connections to ensure continued access for lateral movement, data exfiltration, or further attacks.
  5. Covering Tracks: Remove traces of activity to avoid detection, simulating stealthy real-world attacks.

Chapter 2: Setting Up Kali - Part 1

Ethical hackers must practice skills without harming others' networks. Building a personal lab environment allows testing tools and techniques without legal or security risks to organizational networks. This chapter covers designing a virtual penetration testing lab.

Technical Requirements

  • Oracle VM VirtualBox
  • VMware Workstation Pro
  • Kali Linux 2019.2
  • Nessus Vulnerability Scanner
  • Android OS (x86 version 4.4-r4)
  • Metasploitable 2

Lab Overview

Virtualization eliminates the need for physical servers and network devices, saving space, power, and costs. A hypervisor creates a simulated environment for guest operating systems to run. There are two types of hypervisors:

  • Type 1 (Bare Metal): Installed directly on hardware, allowing guest OS to access hardware resources directly. Examples: VMware ESXi, Microsoft Hyper-V Server, XCP-ng.
  • Type 2: Installed on a host OS (Windows, Linux, macOS). Guest OS access hardware indirectly via the host. Examples: Oracle VM VirtualBox, VMware Workstation Pro, VMware Fusion.

Building the Lab

For a single laptop/desktop, use a Type 2 hypervisor like Oracle VM VirtualBox or VMware Workstation Pro. Steps to install VirtualBox:

  1. Download the installer from www.virtualbox.org and follow the default installation wizard.
  2. Open VirtualBox to verify successful installation.

For VMware Workstation Pro, download from www.vmware.com and follow default installation steps.

Creating a Virtual Network

Create a host-only virtual network to isolate lab VMs from the internet:

  • VirtualBox: Go to Tools > Network > Create, set IPv4 address to 10.10.10.1, subnet mask 255.255.255.0, and optionally enable DHCP with range 10.10.10.2-10.10.10.254.
  • VMware Workstation: Go to Edit > Virtual Network Editor, select VMnet1 (host-only), set IPv4 address to 10.10.10.1, subnet mask 255.255.255.0.

Setting Up Kali Linux

Kali Linux is a Debian-based OS with over 300 penetration testing tools. Import the pre-built virtual image from Offensive Security:

  1. Download the appropriate image for your hypervisor and extract the files.
  2. Right-click the .ova file and open with VirtualBox or VMware Workstation.
  3. Follow the import wizard; the VM will appear in your library once complete.
  4. Set the VM's network adapter to Custom (VMnet1) to connect to the lab network.
  5. Start the VM with default credentials: username root, password toor.

Installing Nessus

Nessus is a popular vulnerability scanner detecting over 47,000 CVEs. Install on Kali Linux:

  1. Update packages: apt-get update && apt-get upgrade
  2. Register for a Nessus Home activation code at www.tenable.com
  3. Download the Nessus .deb package from www.tenable.com
  4. Install: dpkg -i Nessus-8.3.1-debian6_amd64.deb
  5. Start the service: /etc/init.d/nessusd start
  6. Enable auto-start: update-rc.d nessusd enable
  7. Access the web interface at https://localhost:8834, create an admin account, and activate with your code.

Setting Up Android Emulator

Download Android-x86 4.4-r4 from www.osboxes.org, extract the files, and import the .ova file into your hypervisor. Set the network adapter to VMnet1. Start the VM to access a fully functional Android 4.4 environment.

Installing Metasploitable 2

Metasploitable 2 is a vulnerable Linux VM for practice. Download from SourceForge, extract files, import the .ova into your hypervisor, set network to VMnet1. Default credentials: msfadmin/msfadmin. Verify network connectivity with ifconfig.

Chapter 3: Setting Up Kali - Part 2

This chapter extends the lab with Windows and Ubuntu VMs, plus Kali Linux troubleshooting.

Technical Requirements

  • Oracle VM VirtualBox or VMware Workstation Pro
  • Windows 10, Windows Server 2016
  • Ubuntu Desktop/Server
  • Kali Linux

Installing Windows as a VM

Download Windows 10 and Server 2016 ISOs from the Microsoft Evaluation Center. Create a new VM in your hypervisor:

  1. Select "Install from ISO" and browse to the downloaded ISO.
  2. Enter product keys (from evaluation center) and create admin accounts.
  3. Allocate 100 GB virtual HDD, adjust hardware resources as needed.
  4. Follow the installation wizard, accept the EULA, select custom install, and choose the virtual disk.
  5. After installation, create additional user accounts via Control Panel > User Accounts.
  6. Disable automatic updates: Open Command Prompt, run sconfig, select option 5, set updates to Manual.
  7. Set static IP: Go to Server Manager > Local Server > Ethernet0 > Properties > IPv4, set IP in 10.10.10.2-254 range, subnet 255.255.255.0, gateway 10.10.10.1.
  8. Add extra NICs via VM settings > Add > Network Adapter.

Installing Ubuntu 8.10

Download Ubuntu 8.10 ISO from old-releases.ubuntu.com. Create a VM with 1 CPU core, 1-2 GB RAM, 60 GB HDD, NIC set to VMnet1. Follow the installation wizard:

  1. Select "Install Ubuntu Server", choose language and region.
  2. Select "Guided - use entire disk", confirm disk (sda).
  3. Create user account and password, skip encrypted home directory.
  4. Disable automatic updates, finish installation.

Create snapshots before major changes to restore VM state easily via VirtualBox or VMware snapshot menus.

Kali Linux Troubleshooting

  • Network/USB Incompatibility: In VirtualBox, go to VM Settings > Network/USB, select the correct adapter/controller (USB 2.0/3.0 requires VirtualBox Extension Pack).
  • Memory Issues: Go to VM Settings > System, adjust base memory to the green zone. Enable virtualization in BIOS/UEFI if needed.

Chapter 4: Familiarizing with Kali Linux 2019

Kali Linux replaced BackTrack in 2013, based on Debian with over 300 pre-installed tools. Key benefits: open-source tools, low resource usage, supports live USB/CD, mobile device installation.

What's New in Kali Linux 2019

Upgraded to kernel 4.19.13, Metasploit Framework updated to 5.0 with new evasion techniques, automated API, and updated tools including theHarvester, dbeaver, exe2hex, msfpc, and SecLists.

Kali Linux Basics

  • Terminal Commands: passwd (change password), pwd (current directory), ls -la (list files including hidden), cd (change directory), cat (view file content), echo "text" >> file.txt (append text to file).
  • Navigation: Applications menu organizes tools by category (Information Gathering, Vulnerability Analysis, etc.). Access settings via the power button > wrench icon. Terminal is accessible via Applications > Favorites > Terminal.
  • Updating/Installing Software: Update repo: apt-get update. Upgrade packages: apt-get upgrade. Distro upgrade: apt-get dist-upgrade. Clean old packages: apt autoremove. Install new tools: apt-get install openvas (example for OpenVAS).
  • File Search Commands: updatedb (build file database), locate filename (find file via database), which executable (find executable path), find / -name "keyword*" (aggressive file search), man tool (view tool manual).
  • Service Management: Start service: service apache2 start. Verify running: netstat –antp | grep apache2. Enable auto-start: update-rc.d apache2 enable. Change root password: passwd.

Part 2: Reconnaissance

This section teaches extensive reconnaissance before launching attacks. Readers will learn information gathering techniques and OSINT tools to retrieve target details. Chapters:

  • Chapter 5, *Passive Information Gathering*
  • Chapter 6, *Active Information Gathering*

Chapter 5: Passive Information Gathering

Passive information gathering uses indirect methods to collect target data from public sources without interacting with the target. This phase is critical for tailoring attacks to the target's attack surface.

Technical Requirements

  • Kali Linux
  • Maltego
  • Recon-ng
  • theHarvester
  • OSRFramework
  • HTTrack
  • Sublist3r
  • S3Scanner

Understanding OSINT

Open Source Intelligence (OSINT) uses publicly available internet resources to build target profiles. Job postings often reveal an organization's tech stack (e.g., Cisco networking, Windows Server, VoIP systems), helping penetration testers narrow attack scope.

Top OSINT Tools

  • Maltego: Graphical data mining tool from Paterva. Create a free account, open Maltego CE in Kali, create a new graph, add domain entities, and use transforms to resolve IP addresses, find subdomains, extract whois emails, and identify name servers.
  • Recon-ng: Python-based OSINT framework with modules, database, and workspace support. Install from GitHub: ``` git clone https://github.com/lanmaster53/recon-ng.git cd recon-ng pip install -r REQUIREMENTS ./recon-ng
    
    Create workspaces: `workspaces create pentest`, load modules: `modules load recon/domains-contacts/whois_pocs`, set source: `options set SOURCE microsoft.com`, run: `run`. Generate HTML reports via `modules load reporting/html`.
    
  • theHarvester: Collects emails, domains, and host data from public sources. Usage: theharvester –d checkpoint.com –b google.
  • Shodan: IoT device search engine indexing internet-connected devices. Search for devices like Cisco RV325 routers, view open ports, services, and known vulnerabilities. Access at www.shodan.io.
  • OSRFramework: Toolset for username, DNS, and deep web searches. Components: domainfy (check domain availability), mailfy (find email accounts), searchfy (multi-platform queries), usufy (find username registrations).

Identifying Target Technologies

  • Shodan: Search by organization to view open ports, running services, and known vulnerabilities.
  • Netcraft: Visit www.netcraft.com, enter a domain to view hosting history, OS, web server platform, and site technology.
  • WhatWeb: Kali tool to identify web technologies. Usage: whatweb 192.168.1.100 (detailed output: whatweb -v 192.168.1.100).

Discovering Cloud Data Leaks

Cloud providers (AWS S3, Azure Files, GCP Storage) may have misconfigured storage buckets exposing sensitive data. Use S3Scanner to find open AWS S3 buckets:

git clone https://github.com/sa7mon/S3Scanner.git
cd S3Scanner
pip install -r requirements.txt
python ./s3scanner.py flaws.cloud

Scan multiple domains via a text file, use host and nslookup -ptr to resolve bucket names.

Google Hacking

Use advanced Google search operators (Google Dorks) to find vulnerable systems and sensitive information. Examples: penetration testing tools -kali (exclude results with "kali"), "login page" site:example.com (find login pages on a domain). Access the Google Hacking Database at www.exploit-db.com.

Whois and HTTrack

  • whois: Query domain registration info. Usage: whois example.com (or use online tools like whois.net).
  • HTTrack: Clone websites for offline analysis. Run httrack in terminal, follow the interactive wizard to set project name, storage path, and target URL.

Finding Subdomains with Sublist3r

Sublist3r enumerates subdomains using search engines and OSINT. Install from GitHub:

git clone https://github.com/aboul3la/Sublist3r.git
cd Sublist3r
python sublist3r.py –d example.com

Tags: Kali Linux Penetration Testing Ethical Hacking OSINT Metasploit

Posted on Sun, 11 Oct 2026 16:50:40 +0000 by nawhaley2265