Index

Note: Page numbers with “f” denote figures’ “t” tables; and “b” boxes.

A

Arduino attack vectors, 138–139
Armitage, 116
command, 117
connection exception, 117–118
Hail Mary function, 117
initial Armitage screen, 118
main Armitage screen, 118
starting Armitage, 117–118
utilization, 117
See also exploitation
Attack machine
dhclient command, 11
DHCP use, 11
DNS server, 10
icon to launch terminal window, 9f
ifconfig command, 10
IP address, 10
Linux distributions, 9–10
lo interface, 10
review steps, 11
for running Kali or Backtrack, 9
for turning network card on, 10
Automated attacks, 125

B

Back Orifice, 185
Backdoor, 17, 48–49, 168
See also Netcat
Backtrack Linux, 4–7, 13
advantage, 9
attack machine to run, 9
boot options, 8f
burning process, 7
GRUB bootloader boot menu, 8
Paros, 6
safe graphical mode, 8
security community, 6
VMware image, 7–8
VMware Player, 7–8
VMware software role, 11
Base64 encoding, 153
Bdcli100.exe client software, 176
Black box penetration testing, 4
Black Hat conference, 196
Brute forcing program, 83
Burp Suite, 165

C

Code injection attacks
bypass client-side authentication, 156
generic framework, 154
interpreted language, 153
or statement, 155
unintended commands, 153–154
web applications, 156
Credential harvester, 136
captured credentials, 136
employee satisfaction survey, 136–137
on fake Gmail website, 137
HTTPS, 136
web attack vectors, 136–137
from website, 137
Cross-site scripting (XSS), 142–144
attacking method, 157
First-Order, 159
penetration tester, 158
reflected and stored, 159
skilled attacker, 157
stored, 159
test code, 158
username and password, 158
Cryptcat, 174
–k switch, 174
tunnel encryption, 174
twofish encryption, 174

D

Dakota State University (DSU), 26, 196
Damn Vulnerable Web App (DVWA), 164
De-ICE Linux CD, 123
DEFCON, 194–195
DerbyCon, 195
Dig, 42–43
Digital reconnaissance, 21
Directory browsing, 30
Domain Name System (DNS), 10, 34
interrogation, 42
servers, 39
Dsniff tools, 113

E

E-mail servers, 44
rejected message, 44
target e-mail server, 44
Exchange server, 136–137
Executive summary, 189
Exploitation, 79–80
Armitage, 116–118
concept of, 79–81
automated attacks, 125
ettercap, 125
buffer overflows, 126
password brute forcing tool hydra, 124
personal password dictionary, 124
RainbowCrack, 124
stack and heap-based buffer overflows, 125
further practice, 124–126
Linux and OS X password cracking, 107–108
local password hacking, 100–106
macof, 112–116
Medusa, 81–85
Metasploit, 85–97
multiple tools, 119–120
password resetting, 108–111
phase, 17
practice, 122–124
remote password hacking, 106–107
sniffing (Wireshark), 111–112

F

Fierce, 43–44
brute-force host names, 43
directory, 43
in Kali, 43
File transfer protocol (FTP), 32, 59, 81
First-Order XSS, 159
FOCA, 50

G

Google directives, 26–31
allintitle, 27
command to, 26
directory browsing, 30
dynamic content, 20, 30
examples of, 26
GHDB, 29f, 30f
filetype directive, 28
intitle, 27
inurl directive, 27
live chat features, 30–31
PC tech example, 31
power of, 29f
public forums, 31
utilization, 26
See also reconnaissance
Google Dorks, 28–29
Google-FU, See Google directives
Graphical user interface (GUI), 59, 86

H

Hacker Defender, 176–180
cmd shell, 178
configuration files, 176
full-fledged Windows Rootkit, 176
headings, 176
hidden processes, 177
Hidden RegKeys, 177–178
hidden services, 177
hsdef100.zip file, 176
.ini configuration file, 178
ports, 178
root processes, 177
startup run, 178
See also Rootkits
Hail Mary function (Armitage), 117, 119
Harvester, 31–32
commands, 33
folder, 33
output, 34f
quickest way to access, 32
run program, 32
subdomains, 33
twisting and manipulating information, 32
Hashes.txt file, 103
Hidden RegKeys, 177–178
Host
command, 39
documentation, 39
host command output, 39, 39f
tool, 39
HTTrack, 23–26
Hxdef100.exe, 176
Hxdef100.ini, 176
Hypertext markup language (HTML), 141–142
Hypertext transfer protocol (HTTP), 149

I

Information extraction
dig, 42–43
DNS servers, 39–40
from e-mail servers, 44
Fierce, 43–44
MetaGooFil, 44–46
nslookup, 41–42
sharing process, 40
zone transfer, 40
See also reconnaissance
Information gathering, See reconnaissance
Internet Control Message Protocol (ICMP), 57
Internet protocol (IP), 21, 53–54, 81

J

Java applet attack, 131
John the Ripper (JtR), 82
directory, 99
encrypted version, 98
four-step process, 99
hashing algorithms, 98–99
local attack, 99–100
performance metrics list, 99
red team exercises, 97–98
remote attack, 99–100
user or guest group, 97

K

Kali Linux, 4–9, 7b
advantage, 9
attack machine to run, 9
burning process, 7
GRUB bootloader boot menu, 8
security community, 6
VMware Player, 7–8
VMware software role, 11

L

Lan Manager (LM), 99, 103–104
Linux password cracking
privilege level, 107
privileged users, 107
SHA, 108
shadow file, 107
system file, 107–108
Local password cracking
brute forcing letter combinations, 105
cracked passwords, 105
extracting and viewing password hashes, 102–103
format_name command, 105
hashes.txt file, 103, 105
invoking samdump2 program, 102
LM password cracking, 103–104
mkdir command, 101
mount command, 101
mounting local drive, 101
NTLM, 104
remote password cracking, 106
SAM file, 100–102
samdump2 command, 101–102
super secret password, 104
utilizing Meterpreter, 106
VNC payload, 106
Windows passwords cracking, 106
See also exploitation

M

Macof, 113
discrete routing property, 112
dsniff, 113
fail closed switches, 112
fail open switches, 112
MAC addresses, 113
network traffic, 113
Wireshark, 111–112
Maintain access, 167–168
Manual proxy configuration, 149
Media access control (MAC), 112
Medusa, 81–85
brute forcing program, 83–84
command, 83–84
online password crackers, 81
parallel login brute force, 82
password dictionary, 82
remote access systems, 81
and SSH, 84
user name list creation, 83
uses, 82
word list, 82
MetaGooFil, 44–46
attacker ability, 45
directory, 45
metadata, 44
output, 45
Python script, 45
Metasploit, 85–97
for accessing msfconsole, 86
bind payload, 95–96
buffer overflows and exploitation, 92–93
cheat sheet, 93–94
command process and requirements, 92–93
critical or high vulnerabilities, 89
exploit framework, 85
exploit of Windows target, 94
framework, 122, 142–144
hashdump command, 97
initial screen, 86–87
Metasploit express, 86
Metasploit pro, 86
Meterpreter and, 95–96
migrate command, 97
msfconsole, 86
Nessus and, 88–89
Nmap and, 88–89
non-GUI, 86
output review, 90
payloads, 85–86, 91–92, 94
ranking methodology, 91
ratings to rank exploitation, 90–91
remote code execution, 87, 89
reverse payloads, 95–96
reviewing Metasploit documentation, 95
“search” command, 89
sending exploits and payloads to target, 93
set option name command, 92
set payload, 91
“show options” use, 92
source exploit framework, 85
use command, 91
VNC software, 92
vulnerability scanner vs., 86, 91
See also exploitation
Meterpreter, 95–96, 181–183
advantages, 96–97
built-in commands, 181
functions, 96
post exploitation activities, 182–183
shell, 173, 182
Mkdir command, 101
MultiPyInjector vectors, 133

N

Ncat tool, 185
Netbus tool, 185
Netcat, 168–174
backdoors, 184
client or server mode, 169
communication, 170
–e switch, 172, 184
force Netcat, 171
further practice, 185
keyboard input, 171
Linux version, 170
listener mode, 169
“ls” command, 171
“man” pages, 184
Meterpreter shell, 173
nc.exe program, 173
practice, 183–184
Rootkits, 184
target machine, 169–170
terminal window, 172
transfer files, 168–170
UDP packets, 172
virus.exe, 171
web server, 172
Windows registry, 173
Windows target, 173
See also Cryptcat
Netcraft, 37–38
information gathering, 38
search option, 37f
site report for syngress.com, 38f
Network interface card (NIC), 10
Nikto
command line, 144
multiple ports, 144
port number, 144
web server, 144
web vulnerability scanner, 145
Nmap
and NULL scan, 68–69
and port scan, 61–62
and SYN scan, 63–64
and TCP scan, 61–62
and UDP scan, 39
and Xmas scan, 67
Nmap scripting engine (NSE), 54, 69
banner script, 70
community, 69
divides scripts by category, 69
invoking, 70
NSE–Vuln scan results, 70f
vuln category, 70
Nonpromiscuous mode, 111
NS Lookup, 41–42
DNS interrogation, 42
error message, 42
and host, combinatin of, 42f
interactive mode, 41
during reconnaissance process, 41

O

Offensive security, 4
Online password crackers, 81
Open Web Application Security Project (OWASP), ZAP, See Zed Attack Proxy (ZAP)
Open-Source Intelligence (OSINT), 21
OpenVAS, 77

P

Password resetting, 108–111
See also exploitation
Paterva’s Maltego tool, 51
Penetration testing, 1, 187
attack machine, See attack machine
black box, 4
chat rooms, 194
concept of, 2–4
detailed report, 189–191
ethical hacker vs. malicious hacker, 3
executive summary, 189
exploitation phase
See explotation
final PT report, 17–18
final report, 187
further practice, 18
good vs. evil, 2
hacking lab, use and creation of, 12–13
inverted triangle model, 14–15
Kali and Backtrack Linux and other tools, 4–9
pen testing lab, 2, 13
phases of, 14–18
pivoting, 16
post exploitation and maintaining access, 17
raw output, 191–194
realistic attack simulation, 3–4
reconnaissance phase, See reconnaissance
rule exception, 14
security auditing distributions, 18
security community, 195
white box penetration testing, 4
vulnerability assessment vs., 1–2
zero entry hacking penetration, 15f, 16f
Penetration Testing Execution Standard (PTES), 197
Penetration Testing Framework (PTF), 197
Penetration testing report, 189
border router, 190
flaws, 190
legal and ethical restrictions, 190
mitigations, 191
proof-of-concept screenshots, 190
raw data, 188
raw tool output, 191
reconnaissance phase, 188
solutions, 191
vulnerabilities, 189–190
Ping sweeps, 57–59
blocking ping packets, 59
cat command, 58–59
FPing, 58
switches, 59
Pings, 57–59
command, 57–58, 57f
ICMP echo request packet, 58
replacing target_ip, 57
Port scanning, 59
command line version, 59–60
fingerprinting operating system, 71
gain access to target system, 60
GUI-driven way, 60
list of open ports, 71
Nmap and, 59
switches, 71
target_ip, 71
timing switch, 71
version scanning, 71
Powershell injection technique, 133, 139
Promiscuous mode, 111
PyInjector vectors, 133
Python script, 45, 126

Q

QRCode, 139

R

RainbowCrack, 124
Raw output, 191–194
direct output tools, 191
document encryption, 192
electronic document, 192
grammar and spelling mistakes, 193
professional-looking report, 193
report-writing phase, 194
well written penetration test, 193
Reconnaissance, 19f, 20, 50
active, 22
attackable targets finding, 49
automated tools, 20–21
dig, 42–43
digital, 21
DNS servers, extracting information from, 39–40
e-mal servers, extracting information from, 44
Fierce, 43–44
further practice, 50–51
Google Directives, 26–31
Harvester, 31–34
host tool, 39
HTTrack, 23–26
MetaGooFil, 44–46
Netcraft, 37–38
NS Lookup, 41–42
passive, 22
practice steps, 50
public information search, 21
social engineering, 48–49
Syngress, 20, 23
Threatagent Drone, 46–47
Whois, 34–37
Remote system, maintaining access to, 167–168
using backdoor, 168
Cryptcat, 174
Hacker Defender, 176–180
Meterpreter, 168
Netcat, 168–174
Rootkits, 168
Request for comments (RFC), 67
Rootkits, 174–176, 181
antivirus, 175
detecting and defending against, 180–181
files hiding, 174
software package, 175
stealthy backdoor access, 176
“su” or “Run As” commands, 180–181
traffic, 181
See also hacker defender

S

Scanning, 54
analogy, 55
concept of, 53–57
final target, 56
further practice, 77–78
Nmap, 61–70
NSE and, 55
null scan, using Nmap, 68–69
perimeter devices, 57
ping sweeps, 57–59
pings, 57–59
port, 54–55
port numbers and service, 56t
port scanning, 59–60, 71
practice, 76–77
scanning method, 55
SYN scan, using Nmap, 63–64
TCP Connect scan, using Nmap, 61–62
three-way handshake process, 60–61
UDP scan, using Nmap, 39
vulnerability scanning, 72–76
Xmas scan, using NMAP, 67
Search engine directives, 50
See also Google directives
SearchDiggity, 50
Secure hash algorithm (SHA), 108
Secure shell (SSH), 81
Security account manager (SAM), 100–101
Sniffing, 111–112
nonpromiscuous mode, 111
promiscuous mode, 111
sniff network traffic, 108, 111
Socat, 185
Social engineering, 48–49
concept of, 127–128
credential harvester, 136–137
example, 48–49
menus, 138
website attack vectors, 131–136
Social-engineer toolkit (SET), 128–131, 138–139
folder structure, 128
interface, 128
menu-driven system, 128
spear phishing attacks, 128–129
universal exploits, 130–131
Windows XP SP3, 129–130
Spidering
certificates, 150
connection settings, 149
full-featured interface mode, 148
Iceweasel, 149–150
panels, 148
proxy program, 149
target’s website, 148, 150
WebScarab, 148
SSH, See secure shell
Stack and heap-based buffer overflows, 125
Startup Run programs, 178
Structured query language (SQL), 142–144
injection, 153–154
statements, 154–155
SubSeven (Sub7), 185
Swiss army knife internet tool, 51
Syngress, 20

T

ThreatAgent Drone, 46–47
attack vector identification, 47f
drone, 46–47
option for reconnaissance, 46
results, 47f
starting search with, 46f
Transmission control protocol (TCP), 59, 169
TrueCrypt, 192
TrustedSec program, 135
Tunnel encryption, 174
Twofish encryption, 174

U

Ubuntu 7.04, 122–123
Uniform resource locator (URL), 21, 134, 142–144
User datagram protocol (UDP), 59, 169

V

Virtual machine (VM), 7, 122, 169b
Virtual network computing (VNC), 81
payload, 106
software, 92
Virtual Private Network (VPN), 32
VMware image, 7
Vulnerability scanning, 16, 55, 70, 72–76
Nessus, 72, 74, 75f
plug-in, 73
result link, 76
safe checks, 75
scan policies, 75
scan targets box, 76
setting up “safe” scan option, 74f

W

Web Application Audit and Attack Framework (w3af), 145–147
flowing command, 145
Kali menu, 145
plug-ins, 145–147
and scanning, 145, 147
Shells pane, 147
Web-based exploitation, 141–142
architect system software, 142
basics, 142–144
cloud computing services, 142
code injection attacks, 153–157
concept of, 141–142
cross-site scripting (XSS), 157–159
further practice, 164
Nikto, 144–145
practice, 163–164
spidering, 148
w3af, 145–147
WebScarab, 148–153
WebGoat, 163–164
WebScarab, 148–153
Base64, 153
Cancel ALL Intercepts, 152
hidden fields, 151
HTTP requests and responses, 152
proxy server, 151
Website attack vectors
antivirus products, 134
applets, 131
IP address, 131, 135
Java applet popup, 134
Metasploit, 133
Meterpreter shells, 134
payload selection, 132–133
Powershell injection technique, 133
and SET, 131
TrustedSec, 135
White box penetration testing, 4
Windows XP, 13
Wireshark, 111–112
Capture Interface window, 113–115
command, 114, 125
“list available capture interfaces” button, 114
Linux target, 115
MAC address, 112
nonpromiscuous mode, 111
promiscuous mode, 111
sniffing, 108, 111, 116
stopping Wireshark capture, 115–116

X

Z

Zed Attack Proxy (ZAP), 160
break points functionality, 161
Iceweasel proxy settings configuration, 160
input variables, 161
interception, 161–162
in Kali menu, 160
scanning, 163
spidering, 162–163
Zone transfer, 40, 42–44