Chapter 2 / Vulnerabilities and Exploits
An English reading edition of Toni Angelchovski’s “The Hacker’s Path”.
A weakness creates an opening; an exploit makes use of it. Understanding the relationship helps you see how systems fail and how they can be protected.
Where weaknesses hide
- Unfinished code and software bugs.
- Misconfigured servers and exposed services.
- Weak passwords and missing encryption.
- People persuaded to hand over access.
What an exploit is
An exploit can be a script, command or program designed to use a particular vulnerability. Some are publicly known; others involve vulnerabilities not yet known to those responsible for fixing them.
Understanding the process
Security testing identifies a weakness, examines whether it can be used, documents the impact and helps repair the system. An attacker may instead try to persist or conceal activity. Recognising that distinction is part of understanding the process.
Tools and protection
The original guide introduces Nmap, Nikto, Metasploit, Burp Suite and Wireshark. Their purpose depends on the person using them and the scope of permission.
Keep systems updated, control exposed services, use strong authentication, train people and test your own defences. The goal is to recognise a weakness before someone exploits it.