Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 56 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow Scanning Amazon EC2 Servers
EH-Net
May 21, 2013, 10:48:19 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Scanning Amazon EC2 Servers  (Read 3170 times)
0 Members and 1 Guest are viewing this topic.
Seen
Full Member
***
Offline Offline

Posts: 134


View Profile
« on: July 26, 2012, 12:57:38 AM »

I'm testing a friend's website running on Amazon's EC2 servers.  He put in a request to allow me to test it next week.  The terms are pretty standard, don't DoS the servers.  I'm planning on running Nessus (regular server scan and web app scan), Nikto and BurpSuite Scanner on the site.  Is there anything I should know, settings I should change in the scans before I start?

Thanks.
Logged

Sec+, eCPPT
3xban
Hero Member
*****
Offline Offline

Posts: 607


View Profile WWW
« Reply #1 on: July 26, 2012, 07:34:38 PM »

Go through the Nessus plugins and make sure you are running safe scans.  Maybe disable some of the plugins that won't be needed (don't run Oracle plugins if no Oracle service is running).  Will you be running an authenticated scan?
Logged

Certs: GCWN
(@)Dewser
Seen
Full Member
***
Offline Offline

Posts: 134


View Profile
« Reply #2 on: July 27, 2012, 12:49:01 PM »

Thanks, I was planning on doing both.  Running a server scan without credentials (External IP Scan), and then a web app scan with credentials.  I will have safe scans enabled.  If I have all the plugins enabled, safe scan will ensure that the non-safe ones aren't run right?  The server is run through a PaaS provider, so my friend isn't sure about all the services running so I want to be thorough.

I've never run a scan on a live, external server before, so I'm just trying to be cautious.  I kind of wish I had an external server to test the scans on first, but oh well.

Thanks
Logged

Sec+, eCPPT
3xban
Hero Member
*****
Offline Offline

Posts: 607


View Profile WWW
« Reply #3 on: July 29, 2012, 07:00:43 AM »

Although the safe scans are supposed to be "safe" there are some plugins that can cause undesired results.  A good example is when you scan a network with all plugins enabled and you hit a bunch of network printers.  The scan requests caused them to print reams of garbage.  Not that I ever did that.  But I heard about it from a friend Cheesy  Now Nessus has a checkbox in the policy to skip "sensitive" devices. 

To find the web app vulns you may want to utilize something like Nikto or Burp suite.
Logged

Certs: GCWN
(@)Dewser
Seen
Full Member
***
Offline Offline

Posts: 134


View Profile
« Reply #4 on: July 29, 2012, 05:29:48 PM »

I have checked skip sensitive devices Smiley  And I have Nikto integrated into Nessus.  I also set the max TCP connections very low, so I don't think I'll have a problem.

We'll see though...

And I just ordered Burp Pro.
Logged

Sec+, eCPPT
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.068 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.