The Five Phases of Hacking

(Keeper of Darkness) #1

We have a lot to discuss, so let’s get started!

Five Phases of Hacking:-

The five phases of Hacking are as follow:

  1. Reconnaissance
  2. Scanning
  3. Gaining Access
  4. Maintaining Access
  5. Covering Tracks


This is the primary phase where the Hacker tries to collect as much information as possible about the target. It includes Identifying the Target, finding out the target’s IP Address Range, Network, DNS records, etc.


It involves taking the information discovered during reconnaissance and using it to examine the network. Tools that a hacker may employ during the scanning phase can include dialers, port scanners, network mappers, sweepers, and vulnerability scanners. Hackers are seeking any information that can help them perpetrate attack such as computer names, IP addresses, and user accounts.

Gaining Access:-

After scanning, the hacker designs the blueprint of the network of the target with the help of data collected during Phase 1 and Phase 2. This is the phase where the real hacking takes place. Vulnerabilities discovered during the reconnaissance and scanning phase are now exploited to gain access. The method of connection the hacker uses for an exploit can be a local area network (LAN, either wired or wireless), local access to a PC, the Internet, or offline. Examples include stack based buffer overflows, denial of service (DoS), and session hijacking.Gaining access is known in the hacker world as owning the system.

Maintaining Access:-

Once a hacker has gained access, they want to keep that access for future exploitation and attacks. Sometimes, hackers harden the system from other hackers or security personnel by securing their exclusive access with backdoors, rootkits, and Trojans. Once the hacker owns the system, they can use it as a base to launch additional attacks. In this case, the owned system is sometimes referred to as a zombie system.

Covering Tracks:-

Once hackers have been able to gain and maintain access, they cover their tracks to avoid detection by security personnel, to continue to use the owned system, to remove evidence of hacking, or to avoid legal action. Hackers try to remove all traces of the attack, such as log files or intrusion detection system (IDS) alarms. Examples of activities during this phase of the attack include steganography, the use of tunneling protocols, and altering log files.

Retrieved from &

1 Like


So did you directly copy this from another website or have I found your little facebook page? :smirk:

1 Like


This also looks similar to me…



(Leader & Offsec Engineer & Forum Daddy) #5

I’ve sent an official plagurism notice to Shadow. He has 24 hours to quote a source or remove it. Otherwise I will remove it.



Null Byte - The Five Phases of Hacking

Notice how the other Facebook posts were also taken from other sources as well. Not that I’m saying ShadowLost didn’t plagiarize, you guys just need more evidence to support your arguments instead of clicking the first link on Google and jumping to conclusions.


(Leader & Offsec Engineer & Forum Daddy) #7

They were all posted around January 2016. So I can’t be sure at all.



I’m not claiming he plagiarized either. I’m just saying that what he wrote looks similar.