Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 30 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
please shed some light
EH-Net
May 20, 2013, 03:21:33 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
please shed some light
Pages: [
1
]
2
3
4
Go Down
« previous
next »
Print
Author
Topic: please shed some light (Read 12412 times)
0 Members and 1 Guest are viewing this topic.
LT72884
Jr. Member
Offline
Posts: 95
please shed some light
«
on:
July 21, 2012, 10:55:57 PM »
I have been reading thomas wilhelms book pro pen testing and i have been reading some other resoirces from his site as well. Here is a question i have. I have noticed that every lab scenero from countless tutorials have you always preform a nmap scan to see what hosts are on the network that could be potentual placers for hackers. Such as open ports i assume. Thats fine but i noticed its all private side scanning. What if a hacker is from a remote location and has to go through public ip. He or they would have to gain inside private access first then do scans. So it seems pointless to me to do pen testing from private side cuz that assumes the hacker has gotten in apready. Can you scan a public ip for open ports? Thanks guys
Logged
shadowzero
Full Member
Offline
Posts: 120
It's a UNIX system, I know this!
Re: please shed some light
«
Reply #1 on:
July 21, 2012, 11:15:23 PM »
Of course you can scan public IPs for open ports. If a site allows you to SSH in, or serves web pages, or web applications, then there's a port open somewhere. If you want to play around with scanning a public IP, scanme.nmap.org is designed for testing nmap.
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: please shed some light
«
Reply #2 on:
July 22, 2012, 02:14:29 AM »
If you want an authorized target to test against, try nmap's own scanme.nmap.org.
Provides a good opportunity to get used to nmap's options different results you can get from different parameters and scripts.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
LT72884
Jr. Member
Offline
Posts: 95
Re: please shed some light
«
Reply #3 on:
July 23, 2012, 12:12:27 AM »
Thats cool about the scanme.nmap.org site. thanks for sharing that.
Ok, so why are all the tutorials out there about hacking from the private side? I dont understand that. IE, the de ice challange lvl 1, you scan and enumerate from the private side as if you had already gained access. But i thought the whole point of pen test training is to show how to gain access, but if you are attacking from the private side, then that assumes you already have gained access. Are you supposed to sorta"pretend" that the web server on de ice or any other challenge has a "public" ip and your just using a private ip as your fake/unreal public?
thanks. I hope this is not confusing. Im just trying to make sense of it all. I am totally new to this whole hacking thing. I mean i need someone to hold my hand for levle one because i have no idea where to start or why. Even watching movies does not help because it does not explain why they chose to do that.
thanks guys.
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: please shed some light
«
Reply #4 on:
July 23, 2012, 03:03:40 AM »
When working in a lab, try to ignore that your machines (and the publicly provided targets like De-ICE) are using
rfc1918
address space. This is merely for convenience, if you needed public hosting and IP space for a test environment the costs would skyrocket. And it's obviously not sensible to host vulnerable systems on public facing networks.
Using De-ICE as an example, the server is built as a (poorly protected) public facing system. It's not uncommon for public systems to have the same ports and services exposed to the wider world, rather than locking down administrative ports for example.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
shadowzero
Full Member
Offline
Posts: 120
It's a UNIX system, I know this!
Re: please shed some light
«
Reply #5 on:
July 23, 2012, 06:56:34 AM »
There's nothing stopping you from setting up De-ICE or any other vulnerable machine as a publicly facing external server. The issue is that you'll be facing attacks and scans from other people who happen to come across your server.
Logged
3xban
Hero Member
Offline
Posts: 605
Re: please shed some light
«
Reply #6 on:
July 23, 2012, 01:21:13 PM »
think of the book as a proof of concept. It gives you the ability to learn some of the tools to perform a pen test as well as the reporting process involved.
Logged
Certs: GCWN
(@)Dewser
SephStorm
Hero Member
Offline
Posts: 530
Re: please shed some light
«
Reply #7 on:
July 24, 2012, 11:10:23 AM »
This is a good question and one that I struggled with in my early stages. The best way to think of it is to believe that you have established a foothold on the local LAN, and now you are scanning for additional targets. If you want a more realistic setup, you could build a backdoor, send it to yourself in a email (using SET), compromise your internal LAN, then scan and hack from a public location.
The truth is, most hacking these days isnt external, its occurring on the LAN, or against a web front-end.
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
3xban
Hero Member
Offline
Posts: 605
Re: please shed some light
«
Reply #8 on:
July 24, 2012, 11:30:07 AM »
Seph makes a valid point. Even when it comes to advanced attacks, most of them have been done using a phishing email that gets them access to the victim's machine. From there they attept lateral movement through the network until they can gain access to an elevated account which can be used to lay in some backdoors for future use. Now if the victim network has proper controls in place (egress filtering, network ACLs, a monitored SIEM etc...) then this may make internal movement/compromise more difficult. Its tough to create an outbound reverse TCP shell if all ports are being filtered/blocked. Unfortunately not all orgs do this and even filtered ports can be used if you can compromise the external host they are going to.
If you wanted to setup a lab to simulate attacking from outside, you can always aquire a low end firewall and put that in front of the victim hosts. Attempt to attack directly or create some SET or metasploit payloads you can apply to the internals.
Logged
Certs: GCWN
(@)Dewser
LT72884
Jr. Member
Offline
Posts: 95
Re: please shed some light
«
Reply #9 on:
July 24, 2012, 04:56:25 PM »
AWESOME. ok. so i was somewhat right about just pretend they are public facing ip's. I was just making sure. It was really confusing me.
Im still trying to remember everything i learned from 5 years ago in my ccna and ccnp classes. i never used the info so its kind of dusty. haha.
as for my lab, my ultimate would be to have an online lab that is virtual(vmware) and have some virtual cisco and firewall products in it. But that will be after i know what i am doing. haha. As of right now, i would love to have a vpn set up and run rdc over it to run my labs or some sort of online lab for this.
My next question i need some light on is ssh. I know its a secure shell. I think of it like a type of vpn. it logs me into the system/network from a remote location. so sorta like the early stages of rdc. My question is this. once i have ssh'd from my ubuntu 11.10 laptop into a remote machine running backtrack5, i can issue backtrack commands that would be unfamiliar to ubuntu 11.10 if i were not in a ssh session right? IE, i can type metasploit and it will run the program because i have ssh'd into the BT5 machine right?
Here is what my ultimate virtual lab would be. basically the hacking dojo has somehow read my mind and created it. haha.
http://hackingdojo.com/lab/
But for now, i need to learn how to set up a basic vpn that is easy to use and understand. i have no firewall. just a basic centry link router. I think hamachi or open vpn might be best.
thnaks for the help so far. Im not sure where to post my other questions. I have no idea what i am doing when it comes to security. i have tried the last couple of years but i end up just stopping because i have no help or idea. I would love to find a full tutorial that explains how to complete de-ice lvl1 and why they chose that path and why it is important. I really do need my hand held. haha cuz i have no idea what im doing. haha
thanks guys
Logged
rance
Full Member
Offline
Posts: 212
<censored>
Re: please shed some light
«
Reply #10 on:
July 25, 2012, 03:24:21 AM »
I'm surprised nobody has actually mentioned this. Not to be snide, but if you're having those kinds of questions about IP address classes and you're on step number nmap in your learning, I'd say you need to stop now, and go read a good networking fundamentals book. You are going to be totally lost as you work through the technical details of pen testing, if you don't know the fundies, you'll never be good at it.
Logged
Poking at security since 1986. +++ATH
3xban
Hero Member
Offline
Posts: 605
Re: please shed some light
«
Reply #11 on:
July 25, 2012, 07:59:53 AM »
Good point Rance. LT, what is your current base of experience? Have you been working in IT? Do you have a programming or systems background? The way to succeed in this industry is to build up the base. Many of us have worked in IT for years doing one thing or another. Knowing some network and system fundamentals helps a good deal. I did notice you mentioned some Cisco books, did you get either of the certs or just picked up the books to get an idea of the material?
Logged
Certs: GCWN
(@)Dewser
LT72884
Jr. Member
Offline
Posts: 95
Re: please shed some light
«
Reply #12 on:
July 25, 2012, 12:03:45 PM »
Quote from: 3xban on July 25, 2012, 07:59:53 AM
Good point Rance. LT, what is your current base of experience? Have you been working in IT? Do you have a programming or systems background? The way to succeed in this industry is to build up the base. Many of us have worked in IT for years doing one thing or another. Knowing some network and system fundamentals helps a good deal. I did notice you mentioned some Cisco books, did you get either of the certs or just picked up the books to get an idea of the material?
I have a degree in net engineering along with a CCNA and the routing part of my CCNP. I also have my RHCT. BUT that was 5 years ago and i have never had a job that uses it. I have had IT jobs and was department head BUT our network was sourced out before i got there. Prez said no touchy so i handled the lower end stuff. But i did work for IBM and i installed the back bone for the EBAY HQ in my area. But after that i switched to Mechanical Engineering because that had the career options i wanted. Hard to explain. haha.
The IP addressing is not hard for me to do. I can supernet and subnet address space for route propagation and ACLS in cisco routers just fine. Supernetting is my favorite especially when you used wild card masks for the Control lists haha What was confusing me was why all the attacks were private side. I was getting the impression from the material that access had already been gained and know you were just trying to enumerate more info. It was confusing me because i thought the material was supposed to teach how to gain access in order to know how to protect. I was not under the impression that such a unsecure server could exist, but then again, this is levle one material and they have to present it somehow for the basics. haha.
lol. BUT it has been 4 or 5 years since i have used my CCNP knowledge. My friend is Todd Lammle and his ghost writer and editor was my professor(the book was not the professor, haha. It was a real person:)). It was kind of cool.
Now, i will say this. Just because i was excellent at supernetting and configuring routers, does not mean i am good at security. I know how ICMP,TCP and other protocols work pretty well, but that does not mean i know how to manipulate them. I could never figure that part out. haha. Understanding things how they worked normally was easy for me, but to understand how to manipulate them or troubleshoot because they are not working so well, that was the hard part.
This is why i am wanting to complete the heorot courses. I feel that as an mechanical engineer, this can and will help my problem solving skills and a sense of accomplishment. haha. I never know if in the future, i will be called to the office because the IT team needs some help. So i do like to review concepts every so often. BUT security is something i have never done. I mean its easy to follow a firewall tutorial to protect your house or company, but if you dont know why its doing what it is doing, well then. haha and thats why i am here. to learn security. haha.
That was a LONG winded reply but i wanted to make sure i expressed my unawareness of security but also let you know that i have some excellent exp in networking.
you guys are awesome and i trust you all. thanks much.
«
Last Edit: July 25, 2012, 12:11:01 PM by LT72884
»
Logged
3xban
Hero Member
Offline
Posts: 605
Re: please shed some light
«
Reply #13 on:
July 25, 2012, 07:23:59 PM »
ok so you can get the "fundies" as Rance put it. Just wanted to check. Yes the security mindset is definitely a different thought process. You need to take yourself out of the shoes of an engineer who builds something to work and reverse that to look at how it shouldn't work or where you can break it. As we said, the private IP range is just easier to setup in a simple lab. But by all means, build this out more complex, not only will you exercise your old skills but you will make a more realistic lab. You can still do this with private IP addressing, just use a different private range for your "WAN" side. Get a router or low end firewall and put that in front of the lab machine. If you can get a hold of a box to run ESXi on and toss a bunch of VMs on it. Including the De-ICE systems.
As for the De-ICE systems remember you are doing more than scanning for ports. Here's a hint (though you probably found it), there is a webpage available on the first one. This gives you a taste of doing recon and building some intel on the victim. That is the first part. The next part involves using that information.
In pen testing, the more time you spend on building a portfolio of the client/victim, the more information you will have to use during the test. This is especially important if you need to use social engineering to obtain more information that may not be publicly available.
Another item to note, if you really want to get in the mindset, try to hook up with the local community. One of the best things I ever did was attend a BSides event. They are great for meeting some cool people who don't mind sharing what they know.
Logged
Certs: GCWN
(@)Dewser
LT72884
Jr. Member
Offline
Posts: 95
Re: please shed some light
«
Reply #14 on:
July 26, 2012, 01:40:31 AM »
Thanks for the awesome reply my friend. I didnt meant ot make the post soooo long winded, but i had to defend my honor of having a bachelors in network engineering that i NEVER use. I can totally see why you guys asked though.
Ok first things frist, you all are gonna laugh at me. So about 2 or 3 years ago i purchased thomas willhelms book " professional penetration testing" didnt read much and didnt check out the dvd. It was during a rough time in school and life so things got put on back burner. So last night i finally got a chance to watch the Heorot Penetration Testing Fundimentals course videos. The dvd comes with the full course for the issaf including lecture notes, videos and live cd's. except hackerdemia must be out of date because all the lessons on it go to a page under construction... so the tutorial on hydra is not there. oh well.
Here where i need to look at things backwards and i may need some help. I watched the video on the dvd where he scans using differnt techniques. He shows that port 80 is open and then goes to the webpage. What is so important about port scanning besides the fact that it shows what types of services are running?
To tell you the truth, sarcastically i thought to my self" yeah so whats the big deal that port 80 is open or 21. So they have a web server up. who doesnt" ok thats what i need some correction on. the importance of open ports. You cant do much if you do not have a password.. which i assume is part of the challange BUT the tutorial on the live cd of hackerdemia does not exist so im stuck at the moment. haha. maybe the vids show me what to do in a sense.
Ok, i also noticed on the webpage that it says pictures comming soon of the picnic and to send flowers and cards to a specific place. are finding the pictures and finding where the cards are going any part of the challange?
ok thanks guys. i know i have alot to say but im practicing to document everything so i can get a cert and also use the technical report for my engineering writing class.
you guys are fantastic
Logged
Pages: [
1
]
2
3
4
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(91) by
r0ckm4n
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.