36.6 Defence Checklist for These Tools
Aata tools shikle – pan tumhi trainer/defender pan aahaat. Raja ani Rani chya Pune chya fictional shop chya website sathi short checklist:
| Threat from this chapter | Defence |
|---|---|
| FFUF / directory fuzz | Rate-limit, WAF, no backup files public, auth on admin paths |
| Amass / subdomain enum | CT monitoring, kill dead subdomains, inventory |
| WhatWeb fingerprint | Strip version headers, harden banners, patch stack |
| Netcat shells | Egress filter, host firewall, watch ss/netstat, EDR |
| Bettercap MITM | HTTPS+HSTS, segmentation, static ARP/DAI, user awareness |
Rozcha habit: lab madhe attack try kara, mag tyachya against control implement kara – techi real learning. Aata pudhe jaauya.
Ravindra Bagale's Tip
Memorising tool names helps a little in exams, but on the job they ask: "How would you detect FFUF?" Write the checklist table in your own words – then you'll be able to say it the same way in the interview. Learn attack and defence together, not separately.
Ravindra Bagale's Tip – मराठी
Tools ची नावे पाठ करणे exam साठी थोडी मदत करते, पण job मध्ये विचारतात: "FFUF detect कसा करशील?" Checklist table स्वतःच्या शब्दांत लिहा – interview मध्ये तसेच बोलता येईल. Attack आणि defence जोडून शिका, वेगवेगळे नाही.
Ravindra Bagale's Tip – हिंदी
Tools के नाम रटना exam में थोड़ी मदद करता है, पर job में पूछते हैं: "FFUF detect कैसे करोगे?" Checklist table अपने शब्दों में लिखो – interview में वैसे ही बोल पाओगे. Attack और defence साथ-साथ सीखो, अलग-अलग नहीं.
Practice task
Varcha table copy karun aaplya notes madhe expand kara: pratyek row sathi ek concrete command kiwa config step liha (example: fail2ban / nginx limit_req for fuzzing; ss -tulnp cron for shells). Shraddha Bagale la (fictional junior) samjavnyasarkha ek paragraph liha: "Why HTTPS alone is not enough against lab MITM."