Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 30 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Is my methodology correct or am I going about Penetration Testing all wrong?
EH-Net
May 23, 2013, 08:46:05 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Is my methodology correct or am I going about Penetration Testing all wrong?
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Is my methodology correct or am I going about Penetration Testing all wrong? (Read 8445 times)
0 Members and 1 Guest are viewing this topic.
mjones
Newbie
Offline
Posts: 3
Is my methodology correct or am I going about Penetration Testing all wrong?
«
on:
March 24, 2011, 03:46:45 PM »
You can ignore the following backstory, but I added it for dramatic effect.
I'm currently wrapping up Computer Forensics course here at school. Sadly we got stuck with a first year professor who doesnt know half of what she is talking about. She claims to have worked for a Fortune 50 company doing their network security, but her knowledge level is laughable for the job she used to have held. Students will commonly correct her on the basic facts about subjects, its almost offensive to my education. There are very few intelligent people in this class, its considered an easy minor, no wonder with professors like this, and a lot of Criminal Justice students latch onto it as well.
All of this being said,I've learned next to nothing from these Computer Forensics courses with her after a full year. So to cap off my year she decides to announce a live "computer hacking" competition of sorts. The major problem with this competition is the fact that there has
never
been any sort of lesson on network penetration or computer hacking in the general sense. The closest we got was a card trick that somehow simulated password cracking. All we know about the competition is the class will be split in 2 groups, one on defense and the other on offense. I have no doubt there are only two people on the opposing team who could be potential threats but I am pretty confident I know more in this area.
This type of work is what I'd like to do for a career so I'm making this assignment into a test of sorts for myself. ONCE AGAIN KEEP IN MIND WE HAVE BEEN TAUGHT ABSOLUTELY NOTHING INVOLVING NETWORK SECURITY OR PENETRATION TESTING. Everything here is stuff that I've either been taught, picked up over the years or have convinced myself to believe is true. Pick it apart, whats good, whats bad, whats flat out wrong.
The Setting:
PC's that barely boot.
Windows XP Service Pack 3
Every machine was built using the same image, they all have very little added aside from some shithead forensic tools we've never used
We're on our own network of about 15 machines
The following are the software I plan on putting to use and my strategy for both defending and attacking.
Defense:
Software:
Firewall - Really have no idea here, havent used anything that was a specific "firewall" since ZoneAlarm back in 2006, would really be interested to hear some recommendations for a firewall.
Anti-Virus - Microsoft Security Essentials, these PC's are pieces of shit and need all the resources they can hold on to and I've always liked this software.
Miscelaneous:
Get all machines patched up to date, uninstall all unnecessary programs, shit like Adobe Reader/Flash, MSOffice, etc. Remove all Administrator accounts, basically try to leave as few things they could attack as possible. Generate a strong Windows password, wont do much for physical security but I assume it'd help network-wise. Lame as it is, BIOS passwords on all our machines, theyre padlocked so the jumpers cant be pulled.
Offense:
I cannot stress enough how little I formally know about this type of stuff, so please help me better myself. I think of it as a simple 4-part attack attempt
1. Port Scan, identify the targets and recognize their open ports
2. Vulnerability Scan, scan the target IP's and discover known vulnerabilities the machines currently have.
3. Attack, use Metasploit to exploit the vulnerability and gain access to the users system.
4. Keep control, installing a backdoor to keep control of the system
Software:
nmap - Read a few books on the tool so I know a decent amount of what I'm doing with it, couldnt think of a better portscanner
Nessus - vulnerability scanner, again the most revered in its category I figured I couldnt go wrong, know little about the software though
Metasploit - I've been looking for a decent introduction to Metasploit for a long time but havent had much luck. I've messed with it a little bit but would definitely like a thorough introduction from the start. I know Metasploit is even considered to be script kiddy-esque but I'm not sure of a better starting point.
BACKUP PLAN:
I will have unmonitored access to this lab for hours at a time, and I highly doubt the other students would consider physical security of their machines or take advantage of us in the same way. I had considered placing trojans on the PC's and adding them to the "Ignored" section of the Anti-Virus, along with simply adding another Administrator account and giving it remote desktop access. I'd rather have this as a back up plan because of how lame it is, but if times get tough this I will resort to 10th grade tactics.
I'm basically wondering if this is an accurate strategy to be going into this type of thing with? Having you offer constructive criticism are things I'm looking for so please do. Have another place you visit where I could post this story and get some knowledgeable feedback, send that my way too.
Logged
WCNA
Full Member
Offline
Posts: 187
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #1 on:
March 24, 2011, 03:59:57 PM »
If they allow it, I'd boot up a Live CD of BT w/ Armitage. There's some good videos on youtube and elsewhere that someone with little experience should be able to follow to point-click-root(!). Hope that helps.
Logged
ISC2 Associate, WCNA, CWNA, OSCP, Network+
AndyB
Full Member
Offline
Posts: 100
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #2 on:
March 24, 2011, 04:24:14 PM »
Will you be able to bring in a laptop/netboot in and plug it into the network? If so you could pre-build it with backtrack and get everything updated to give you the best chance.
Ref the av software, the microsoft security essentials is poor to say the least. How long is the lab to run for as you could get one of the better Internet Security packages and run it on a trial version for about 10-20 days. Would give you better AV and firewall? Try steer clear of McAfee, Nortons and BitDefender as they can all be a bit resource hungry.
Re the metasploit, check some of the videos on security tube and see if you can get hold of any of the hacking books that get a good review on here.
«
Last Edit: March 24, 2011, 04:27:05 PM by AndyB
»
Logged
Net+ Sec+ More to come
kriscamaro68
Jr. Member
Offline
Posts: 61
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #3 on:
March 24, 2011, 05:46:55 PM »
You can try this for av/firewall:
http://personalfirewall.comodo.com/free-download.html
As for the computers themselves I would use secpol.msc and gpedit.msc to lock down the services on the computer. If there are no rules you can pretty much shut everything usable down with those. If you dont know what those are type them in a run bar and hit enter and go through each one.
As for attacking... If you have physical access to them during the contest then this would be a 3 minute win on your part by booting any sam cracking tool. You can even use Microsoft Dart to reset admin passwords.
If no physical access to it then like others have said bring a laptop with backtrack on it. Or bring a backtrack live dvd and boot from it then attack from there.
If possible check the bios for boot password setups. If there is one and physical access is allowed tot he computers this will atleast require them to know the boot password to boot to a live cd or usb stick. Also set the boot order to only allow the local drive and nothing else.
If you want to get crazy you can always encrypt the entire drive with truecrypt as well. If I remember correctly you need to know the password to even boot up the drive which means unless they know the password for the drive then they cant crack the password too any accounts.
I know there are ways around some of these recommendations but they dont sound to bright from what you have said so they should work.
Hope that helps.
Logged
A+, Net+, Server+, Security+, MCP/XP
chrisj
Hero Member
Offline
Posts: 1163
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #4 on:
March 24, 2011, 10:16:09 PM »
Maybe I missed it, but what books were you using in your class?
Logged
OSWP, Sec+
mjones
Newbie
Offline
Posts: 3
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #5 on:
March 24, 2011, 10:50:00 PM »
I'd like to say thanks for all the information, I've spent a long time on the Internet trying to find a decent forum on this subject and I think I just found a great one.
Quote from: chrisj on March 24, 2011, 10:16:09 PM
Maybe I missed it, but what books were you using in your class?
http://www.amazon.com/Guide-Computer-Forensics-Investigations-Nelson/dp/1435498836/ref=sr_1_1?ie=UTF8&qid=1301024720&sr=8-1
We have yet to crack this book yet, with 4 weeks left in the semester.
http://www.amazon.com/Guide-Network-Defense-Countermeasures-Weaver/dp/1418836796/ref=pd_sim_b_24
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #6 on:
March 25, 2011, 10:25:07 AM »
Quote from: kriscamaro68 on March 24, 2011, 05:46:55 PM
I know there are ways around some of these recommendations but they dont sound to bright from what you have said so they should work.
Not the feeling I'm left with. First year teacher. She's still learning how to teach.
I had more than one class in college, where I was the guy that showed up to class, sat in the back of the class and slept during lecture, get up during break get coffee and then surf the web during lab time. Some of the easiest A's I ever got.
So don't underestimate your opponents. Some of them may be "sleepers" there for the easy A.
Quote from: mjones on March 24, 2011, 10:50:00 PM
We have yet to crack this book yet, with 4 weeks left in the semester.
http://www.amazon.com/Guide-Network-Defense-Countermeasures-Weaver/dp/1418836796/ref=pd_sim_b_24
I think you might want to open that one up and scan through it. See if there is anything in it you can use.
Logged
OSWP, Sec+
sil
Hero Member
Offline
Posts: 549
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #7 on:
March 25, 2011, 01:54:27 PM »
Quote from: chrisj on March 25, 2011, 10:25:07 AM
I had more than one class in college, where I was the guy that showed up to class, sat in the back of the class and slept during lecture, get up during break get coffee and then surf the web during lab time. Some of the easiest A's I ever got.
Reminds me of a pentesting class I took in the Beltway... Man was I so tired from studying other stuff during class off hours (was a 10 week course). I would stroll into the class often off of two-three hours of sleep, doing my own security exploitaition research, not giving an iota of thought to what was going on... 3 days into the class, I started answering the questions students were asking, explaining to the class and often correcting the proctor, I ended up teaching like 4 days of the class, sleeping through the rest of it.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
tturner
Sr. Member
Offline
Posts: 432
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #8 on:
March 25, 2011, 02:14:35 PM »
I may be teaching a 2000 level ethical hacking course at a community college this fall and my biggest fear is that I get a Sil.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
chrisj
Hero Member
Offline
Posts: 1163
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #9 on:
March 25, 2011, 02:46:39 PM »
Quote from: tturner on March 25, 2011, 02:14:35 PM
I may be teaching a 2000 level ethical hacking course at a community college this fall and my biggest fear is that I get a Sil.
If you do, leverage them. Pick their brain, and have them help with the labs. Kind of like a TA.
Logged
OSWP, Sec+
hayabusa
Hero Member
Offline
Posts: 1633
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #10 on:
March 25, 2011, 02:49:38 PM »
Quote from: tturner on March 25, 2011, 02:14:35 PM
I may be teaching a 2000 level ethical hacking course at a community college this fall and my biggest fear is that I get a Sil.
bwahahahahaha! <evil grin>
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
sil
Hero Member
Offline
Posts: 549
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #11 on:
March 25, 2011, 03:10:27 PM »
Quote from: tturner on March 25, 2011, 02:14:35 PM
I may be teaching a 2000 level ethical hacking course at a community college this fall and my biggest fear is that I get a Sil.
Nah no way, I try to be as humble as all hell. Everyone can know something another can't and I enjoy learning as well as sharing. The comment though reminded me of one my wife made: "damnit he's just like you" (will explain now)...
One of my sons just turned 10 years old (other is a Marine
). I have XBox family settings enabled and an allocated amount of time set for him on school days of 1.5 hours play time... So my ten year old calls me up and this is what transpired in the convo:
Son: "Hi... How is your day?"
Me: "Fine, almost over ready to go home"
Son: "Mom is cooking I told her to make your favorite food"
Me: "Really... Cool" (mind you the password reset for XBox question is: What is your favorite food)
Son: "What is your favorite food anyway?"
Me: "Chicken" (threw it out there not the answer...)
Son: "ok well I'll see you when you come home, love you"
Me: "love you too bye"
2 minutes later, phone rings...
Son: "you lied, chicken is not your favorite food!"
Me: "Of course it is how would you know its not"
Son: "well its not working!!"
Me: "what's not working?"
Son: "forget it bye!"
Same happened with the remote, I have ratings enabled to watch shows...
Son: "I love you so much... What's your favorite number?" (programming for cable is a 4 digit number, you have no idea how many times the TV is pseudo-mysteriously locked out)
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
chrisj
Hero Member
Offline
Posts: 1163
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #12 on:
March 25, 2011, 03:17:42 PM »
Sil, some how I expect your social engineering attempts to work better than his.
Logged
OSWP, Sec+
sil
Hero Member
Offline
Posts: 549
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #13 on:
March 25, 2011, 03:54:30 PM »
Quote from: chrisj on March 25, 2011, 03:17:42 PM
Sil, some how I expect your social engineering attempts to work better than his.
I think in this game (security) perception, intuition go a long way. Another example... While I was in a pissy mood I threw my wedding ring at my wife (I like to pretend I'm the boss)... For days I didn't have it on... In fact, I hadn't stopped to look for it because I knew she would... Anyhow, days passed by, I was no longer in a pissy mood lying down and my wife walks away from her night stand asking... "Did you find your ring..." to which I responded... "Nope haven't even looked." Next morning before I went to work, I went straight to the drawer she had closed the night before. I didn't need to search, knew it was there. Her response: "how did you find it" to which I responded: "I didn't have to bother looking you told me where it was at the moment you walked away from the drawer...
Social engineering though, I think I do well, but I tend to hybrid this (social engineering + technology)... Caller ID goes a long way.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
hayabusa
Hero Member
Offline
Posts: 1633
Re: Is my methodology correct or am I going about Penetration Testing all wrong?
«
Reply #14 on:
March 28, 2011, 03:38:51 PM »
<grin> Funny, I did ALMOST the same thing, a few years ago, ring and all. But in my case, wife didn't try to hide it.
BTW, if sil's wife is anything like mine, he got eyes rolled at him, as soon as he tipped his hand to her, though. It's amazing how our wives put up with so much from us, but more amazing how much they're willing to dish out, in return, sometimes... I can only imagine the following day or two...
And I agree with the kids thing, too. While mine hasn't, yet, been the Xbox live password, they try, hard, to get other passwords from me, all the time, through careful 'manipulation.' Fortunately, they just never figure out how mom and dad KNOW what they're up to.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Greetings
: Hi from the UK
(3) by
UKSecurityGuy
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(2) by
n37sh@rk
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.