Index
Note: Page numbers with “f” denote figures’ “t” tables; and “b” boxes.
A
Advanced Package Tool (APT),
5b–6b
initial Armitage screen,
118
main Armitage screen,
118
Attack machine
icon to launch terminal window,
9f
Linux distributions,
9–10
for running Kali or Backtrack,
9
for turning network card on,
10
B
GRUB bootloader boot menu,
8
Bdcli100.exe client software,
176
Black box penetration testing,
4
Black Hat conference,
196
Brute forcing program,
83
C
Code injection attacks
bypass client-side authentication,
156
interpreted language,
153
Credential harvester,
136
captured credentials,
136
employee satisfaction survey,
136–137
on fake Gmail website,
137
Cross-site scripting (XSS),
142–144
reflected and stored,
159
username and password,
158
D
Dakota State University (DSU),
26,
196
Damn Vulnerable Web App (DVWA),
164
Digital reconnaissance,
21
Domain Name System (DNS),
10,
34
E
password brute forcing tool hydra,
124
personal password dictionary,
124
stack and heap-based buffer overflows,
125
Linux and OS X password cracking,
107–108
F
brute-force host names,
43
File transfer protocol (FTP),
32,
59,
81
G
live chat features,
30–31
Graphical user interface (GUI),
59,
86
H
full-fledged Windows Rootkit,
176
.ini configuration file,
178
Hail Mary function (Armitage),
117,
119
quickest way to access,
32
twisting and manipulating information,
32
Host
host command output,
39,
39f
Hypertext markup language (HTML),
141–142
Hypertext transfer protocol (HTTP),
149
I
Information extraction
Internet Control Message Protocol (ICMP),
57
J
John the Ripper (JtR),
82
hashing algorithms,
98–99
performance metrics list,
99
red team exercises,
97–98
K
GRUB bootloader boot menu,
8
L
Linux password cracking
Local password cracking
brute forcing letter combinations,
105
extracting and viewing password hashes,
102–103
invoking samdump2 program,
102
mounting local drive,
101
remote password cracking,
106
super secret password,
104
utilizing Meterpreter,
106
M
discrete routing property,
112
fail closed switches,
112
Manual proxy configuration,
149
Media access control (MAC),
112
brute forcing program,
83–84
online password crackers,
81
parallel login brute force,
82
remote access systems,
81
user name list creation,
83
for accessing msfconsole,
86
buffer overflows and exploitation,
92–93
command process and requirements,
92–93
critical or high vulnerabilities,
89
exploit of Windows target,
94
ratings to rank exploitation,
90–91
remote code execution,
87,
89
reviewing Metasploit documentation,
95
sending exploits and payloads to target,
93
set option name command,
92
source exploit framework,
85
post exploitation activities,
182–183
MultiPyInjector vectors,
133
N
client or server mode,
169
information gathering,
38
site report for syngress.com,
38f
Network interface card (NIC),
10
Nikto
web vulnerability scanner,
145
Nmap
Nmap scripting engine (NSE),
54,
69
divides scripts by category,
69
NSE–Vuln scan results,
70f
and host, combinatin of,
42f
during reconnaissance process,
41
O
Online password crackers,
81
Open-Source Intelligence (OSINT),
21
P
Paterva’s Maltego tool,
51
Penetration testing,
1,
187
ethical hacker
vs. malicious hacker,
3
exploitation phase
See explotation
hacking lab, use and creation of,
12–13
inverted triangle model,
14–15
Kali and Backtrack Linux and other tools,
4–9
post exploitation and maintaining access,
17
realistic attack simulation,
3–4
security auditing distributions,
18
white box penetration testing,
4
vulnerability assessment
vs.,
1–2
zero entry hacking penetration,
15f,
16f
Penetration Testing Execution Standard (PTES),
197
Penetration Testing Framework (PTF),
197
Penetration testing report,
189
legal and ethical restrictions,
190
proof-of-concept screenshots,
190
reconnaissance phase,
188
blocking ping packets,
59
ICMP echo request packet,
58
command line version,
59–60
fingerprinting operating system,
71
gain access to target system,
60
Powershell injection technique,
133,
139
Q
R
grammar and spelling mistakes,
193
professional-looking report,
193
report-writing phase,
194
well written penetration test,
193
attackable targets finding,
49
DNS servers, extracting information from,
39–40
e-mal servers, extracting information from,
44
public information search,
21
social engineering,
48–49
Remote system, maintaining access to,
167–168
Request for comments (RFC),
67
detecting and defending against,
180–181
stealthy backdoor access,
176
S
null scan, using Nmap,
68–69
port numbers and service,
56t
SYN scan, using Nmap,
63–64
TCP Connect scan, using Nmap,
61–62
three-way handshake process,
60–61
vulnerability scanning,
72–76
Xmas scan, using NMAP,
67
Secure hash algorithm (SHA),
108
Security account manager (SAM),
100–101
sniff network traffic,
108,
111
Social engineering,
48–49
Spidering
full-featured interface mode,
148
Stack and heap-based buffer overflows,
125
Startup Run programs,
178
Structured query language (SQL),
142–144
Swiss army knife internet tool,
51
T
attack vector identification,
47f
option for reconnaissance,
46
starting search with,
46f
Transmission control protocol (TCP),
59,
169
U
User datagram protocol (UDP),
59,
169
V
Virtual network computing (VNC),
81
Virtual Private Network (VPN),
32
setting up “safe” scan option,
74f
W
Web Application Audit and Attack Framework (w3af),
145–147
architect system software,
142
cloud computing services,
142
cross-site scripting (XSS),
157–159
Cancel ALL Intercepts,
152
HTTP requests and responses,
152
Website attack vectors
Powershell injection technique,
133
White box penetration testing,
4
“list available capture interfaces” button,
114
stopping Wireshark capture,
115–116
X
Z
Zed Attack Proxy (ZAP),
160
break points functionality,
161
Iceweasel proxy settings configuration,
160