Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 39 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
First steps to learning Hacking
EH-Net
May 26, 2013, 02:46:26 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
First steps to learning Hacking
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: First steps to learning Hacking (Read 8895 times)
0 Members and 1 Guest are viewing this topic.
Kev
Guest
First steps to learning Hacking
«
on:
February 14, 2007, 08:51:41 AM »
I get asked a lot about where you should first start if you want to learn hacking. Rather than just give the more vague and generic answer like “learn all about networking and learn the ins and outs of operating systems” I thought I would recommend something a little more hands on and practical. Something that could get a budding hacker’s feet wet quickly.
The very first place to start is scanning. Yes scanning! Its not hard and it’s a fundamental technique that you must know and know well to be a hacker. Don’t just open up your super scan and plug an IP range in a couple of times and think “ok I am done”! Make it a point over the next 2 weeks to know all there is about scanning. Make it a goal to become a master scanner.
Nmap is really the tool to focus on. The majority of Hackers use it and gives you a good idea of what they can see. Learn all the switches and variations. Don’t just use sS or sT but try all kinds of combinations and more importantly, try and understand them. Try making decoys, etc… The goal is to get to the point that you feel like you would be comfortable sitting at a table with a group of high level hackers and you could hold your own when discussing nmap.
The ideal place to scan is your own network or test lab. Yes you can scan blindly over the internet, but there is a little risk involved. While scanning is not illegal (remember hackers consider illegal as nothing more than a sick bird-ok no more bad jokes) some ISPs look down on it and consider it a violation of your service agreement. If they catch you, they might suspend your internet connection. For instance Cox cable has 3 strikes and your out policy. If they catch you the first time, they will suspend your connection until you explain what’s going on. That just happened to someone I know. No it’s not me, lol! The 3rd time they catch you, you will be permanently cut off by them and must look for a new provider. If you do get caught and suspended, you will need to give them some reason for the activity coming off your modem. They assume you have been trojaned and expect you to run your anti-virus and fix the problem. In the case of the person I know, that’s exactly what he told them he had done. He played dumb and said he forgot to update his anti-virus. He then claimed to update it and scan his computer and found all kinds of bad things ( probably that was true because the bad things were the stuff he placed on there himself, lol!) and now they were all gone and his box was clean. They quickly gave his access back but that was strike 1 on his record. I am only telling that story in case someone reading this decides to go crazy scanning NORAD or something from their home network! If you do, remember you have been warned. Just use common sense (like scan from your neighbor’s house just kidding!) and you will be fine. On a side note, I have never had a problem scanning even from home. The key is not to keep scanning the same target over and over and especially not the server of the ISP, jeeze! Also, don’t try and telnet to anything, even just as an innocent banner grab. That’s will be seen as an unauthorized attempt to connect. However, if you attempt that to a remote server that is not part of your ISP’s network, more than likely you will be ok. Most ISPs dont give a dang if you are scanning boxes in say, Nigeria!
I still say the best place to scan is your own lab. You can have the benefit of seeing how your snort logs respond to it, etc… Commit at least a half hour a day for the next 2 weeks and you will have a good understanding of nmap and have a solid grasp on a crucial fundamental.
«
Last Edit: February 14, 2007, 09:04:37 AM by Kev
»
Logged
funkybunch78
Newbie
Offline
Posts: 12
Re: First steps to learning Hacking
«
Reply #1 on:
February 14, 2007, 06:56:07 PM »
Great Post Kev! I have worked with nmap but only in limited fashion to perform os finger print scans and active port scans of systems on the network I support. I will try just what you suggested and report back in two weeks. Thanks for posting such a great topic.
Logged
Kev
Guest
Re: First steps to learning Hacking
«
Reply #2 on:
February 14, 2007, 08:33:37 PM »
Hey thanks and I look forward to seeing your findings that you post in 2 weeks.
Logged
brian12988
Newbie
Offline
Posts: 2
Re: First steps to learning Hacking
«
Reply #3 on:
February 14, 2007, 09:47:36 PM »
ok..........now dat the forst part is done..wats next?? Good post..
Logged
slimjim100
EH-Net Columnist
Sr. Member
Offline
Posts: 385
Re: First steps to learning Hacking
«
Reply #4 on:
February 15, 2007, 06:46:27 AM »
Please keep the scanning to your own network till you feel you fully understand what you are doing. You can use VMWare to build a nice lab and do all kinds of fun stuff. Most ISP's are getting a lot tighter on what there customers do on and off of there network. It would relay suck to lose service and be black listed by all the Broadband providers in your area. I say before you decide to take on the internet and remote hosts off your subnet you should try to hack and crack your own lab. Get some windows and Linux tools (NMap, Snort, Cain, Ethereal/Wireshark, & many more). Once you understand how a local LAN works you can more to the next level. I say follow the OSI model and begin with Layer 1 (physical) then work your way up to layer 7 (Application). I feel once you understand how networks work by OSI layer your understanding of networking will be so much better. Anyway this is just my opinion and I come from a routing background.
Brian
(aka Slimjim100)
Logged
CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
Bane
Guest
Re: First steps to learning Hacking
«
Reply #5 on:
February 15, 2007, 01:13:36 PM »
One of the best next steps as SlimJim stated is to build a lab. When you build your lab, one of the most useful things you can do is to install operating systems and applications in known vulnerable states, such as Windows 2000 sp1 with IIS. Doing this will allow you to complete the entire cycle, from recon all the way to actually using an exploit to own a box. I would suggest that at the same time you are performing scans and using exploits, that you run a packet sniffer such as wireshark so that you can observe and learn how to pick out suspicious traffic without the aid of an IDS/IPS as this skill is invaluable when dealing with new exploits that have yet to be identified by the major vendors or major open source projects.
Logged
Kev
Guest
Re: First steps to learning Hacking
«
Reply #6 on:
February 15, 2007, 11:39:12 PM »
I guess I was hoping to stay on the topic of scanning. Most people when they are starting to focus on hacking freak out and want to know all! They want to know all in 2 weeks, lol! Hey, I understand and I wish it was that easy. You want to be good? Take baby steps. Don’t jump ahead until you really know each step. That was the point I was trying to make. If any hacker here says that’s not true, well please post!. Learn scanning and learn it well. Once you know nmap then play with other scanners. Research each one. Try and put a little pressure on yourself. Don’t feel like you can go to a hacker meeting and say you have never tried scanline , superscan, or angry scanner. The natural progression is to move to other scanners like hping2, etc... You might even try and write your own scanner. The first program I wrote when I was learning C was to write a very basic program that would ping all the hosts on a network. That is a very easy program to write and its a great place to start if you want to learn C and also understand the very basics of a scanner. Again, the idea is to be a master of scanning. Are you? Please don’t post asking whats the next step! If you have really learned scanning you should know the next step. Its obvious! Learn this first one and I PROMISE it will pay off big time as a hacker-security pro! Those here that have experience will agree!
«
Last Edit: February 16, 2007, 07:13:53 AM by Kev
»
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(95) by
zeebee
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.