.

[Article]-Video: The 15-Minute Network Pen Test Part 1

<<

don

User avatar

Administrator
Administrator

Posts: 4226

Joined: Sun Aug 28, 2005 10:47 pm

Location: Chicago

Post Wed Jan 21, 2009 4:09 am

[Article]-Video: The 15-Minute Network Pen Test Part 1

Ryan Linn has been contributing to EH-Net for quite some time. With his willingness to help with many projects and writing assignments, the quality of his work, and the expanse of his knowledge, it only made sense for him to be our next columnist. This first contribution will give you a great indication of his talents.

We also came up with a new format for EH-Net vids that we hope will become the standard template. Please let us know what you think.

In the near future, look for additional book reviews from Ryan in addition to Part 2 of this video series, other vids and a review of SANS updated 6-day course, Web App Penetration Testing and Ethical Hacking, by InGuardians Kevin Johnson. Should be a great year with this fantastic addition to our family.

Welcome into the fray!!

Permanent link: [Article]-Video: The 15-Minute Network Pen Test Part1


Image


There are numerous tools used in the Penetration Testing (pen testing) process, and there are plenty of books that go into how to use the individual tools. There are very few resources that discuss how the tools are used and how to approach the process.  When Henry Qin at the Duke University ACM Chapter approached EthicalHacker.net on doing a presentation for his organization on the tools and process of pen testing, I jumped at the opportunity.  The following videos encompass the basic outline of what was presented at Duke with some minor changes.

The first video takes the viewer through the initial network recon stage of pen testing and then follows up with actual exploitation using Metasploit.  Initially the network is scanned through Nmap, and after some basic discovery and information gathering, the scan continues to Nessus.  Nessus is a vulnerability scanning tool that allows the user to analyze a host for vulnerabilities, but also has the ability to export reports.  The video then walks the viewer through importing the Nessus vulnerabilities directly into Metasploit in order to determine which Metasploit modules correspond to the Nessus vulnerabilities for the specific host.  The module data is then used to compromise a remote Microsoft Windows XP box.



Stay tuned for Part 2 coming very soon.

Don
Last edited by don on Wed Jan 21, 2009 4:23 am, edited 1 time in total.
CISSP, MCSE, CSTA, Security+ SME
<<

RoleReversal

User avatar

Hero Member
Hero Member

Posts: 928

Joined: Fri Jan 04, 2008 8:54 am

Location: UK

Post Wed Jan 21, 2009 8:43 am

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

Nice video and walkthrough Ryan :D

I'm looking forward to part 2
<<

morpheus063

User avatar

Sr. Member
Sr. Member

Posts: 393

Joined: Sun Jun 25, 2006 10:08 am

Location: Cochin - India

Post Wed Jan 21, 2009 9:23 am

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

Really Nice video. Thank you so much for this video and looking forward for the next release.

All the best.
Manu Zacharia
MVP (Enterprise Security), ISLA-2010 (ISC)², C|EH, C|HFI, CCNA, MCP,
Certified ISO 27001:2005 Lead Auditor

[b]There are 3 roads to spoil; women, gambling & hacking. The most pleasant with women, the quickest with gambling, but the surest is hacking - c0c0n
<<

dynamik

Recruiters
Recruiters

Posts: 1119

Joined: Sun Nov 09, 2008 11:00 am

Location: Mile High City

Post Wed Jan 21, 2009 10:06 pm

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

Great job! My only (very) minor suggestion would be to do a little editing and cut out that awkward silence while waiting for metasploit to load. I'm definitely looking forward to part two :D
The day you stop learning is the day you start becoming obsolete.
<<

alan

User avatar

Newbie
Newbie

Posts: 48

Joined: Sat Dec 27, 2008 11:55 pm

Post Wed Jan 21, 2009 11:51 pm

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

enjoyed it! waiting for the i've got shell access, now what!? part 2 :)
<<

stimmerman

Newbie
Newbie

Posts: 2

Joined: Tue Jan 13, 2009 4:55 am

Post Thu Jan 22, 2009 2:52 am

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

Thanks  for the video! The metasploit database/import thing was nice to learn :)
Can't wait for part two with ophtcrack?
<<

MadmanTM

User avatar

Newbie
Newbie

Posts: 27

Joined: Sat Nov 22, 2008 7:57 pm

Post Thu Jan 22, 2009 2:28 pm

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

yup, ophcrack with some little hash would be exquisite.

thanks for the first part and impatiently waiting for the second one.
Network+, Security+
CEH Soon.
<<

punkrokk

Newbie
Newbie

Posts: 21

Joined: Thu Aug 07, 2008 8:35 pm

Location: Rochester, NY

Post Mon Jan 26, 2009 2:16 pm

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

nice video Ryan, I liked the demo of the metasploit db also!
-=punkrokk=-
<<

blackazarro

User avatar

Sr. Member
Sr. Member

Posts: 368

Joined: Sun Aug 13, 2006 5:31 pm

Post Mon Jan 26, 2009 5:57 pm

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

Nice, especially the part of importing Nessus results to Metasploit. Can't wait for part 2.
Security+, OSCP, CEH
<<

apollo

Full Member
Full Member

Posts: 146

Joined: Fri Apr 04, 2008 7:44 pm

Post Tue Jan 27, 2009 12:08 pm

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

Thanks for the positive feedback :) I'm hoping to do more of these in the future, so if you have some suggestions for things you would like to see, feel free to drop me a PM.  Hopefully everyone will find part 2 as interesting as part 1.
CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
<<

Humper

Newbie
Newbie

Posts: 1

Joined: Thu Jan 15, 2009 12:32 pm

Post Wed Jan 28, 2009 9:18 am

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

Very nice work!!

Whens part two going to be up?  You got me hooked now.. I wanna know more
<<

snortymcsnort

Newbie
Newbie

Posts: 17

Joined: Fri May 30, 2008 12:00 pm

Post Wed Jan 28, 2009 2:13 pm

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

Great job on the video!

I am working on some tools for an upcoming penetration test of my network. I have been running nessus scans on some XP boxes and they are currently showing as vulnerable to the MS08-067 vulnerability. I am exporting the scans as .nbe files and importing them into Metasploit framework3 using a sqlite3 database. When I run db_autopwn -t -x, some older exploits will show up but not the MS08-067 one that is in Metaploit. I looked in the nbe file and the reference to MS08-067 does show up. I have also ran fasttrack and that exploit from Metasploit does work. How does Metasploit reference the vulnerabilities found in the nessus scan?
<<

apollo

Full Member
Full Member

Posts: 146

Joined: Fri Apr 04, 2008 7:44 pm

Post Wed Jan 28, 2009 3:54 pm

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

If you want the latest and greatest, then you need to make sure you have both of your feeds updated.  You will want to make sure you have the latest plugins from nessus.  The latest metasploit modules may not be in the metasploit release that is on the backtrack3 cd or the likes, so you may need to make sure that you update metasploit via subversion in order to have the latest exploits. 

There are references in each metasploit module to CVE and other vulnerability tracking numbers, and metasploit walks through those to match up with the vulnerabilities that nessus provides.  If you don't have the latest from Metasploit, or don't have the latest from nessus, either one of those could lead to false negatives.

If you have updated both and still don't see it listed, let me know and I can try to help you figure out what is going on.


Let me know if you have any more questions :)
CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
<<

snortymcsnort

Newbie
Newbie

Posts: 17

Joined: Fri May 30, 2008 12:00 pm

Post Thu Jan 29, 2009 8:46 am

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

Thanks for the reply Apollo.  I believe I have updated Nessus and Metasploit to the latest feeds.  What I am seeing in my NBE file is a reference to ms08-067,  CVE-2008-4250, nBID 31874, and at the beginning of the line the number 34477.  Do you know the name of the file in Metasploit that reference these numbers?

Thanks
<<

apollo

Full Member
Full Member

Posts: 146

Joined: Fri Apr 04, 2008 7:44 pm

Post Thu Jan 29, 2009 11:38 am

Re: [Article]-Video: The 15-Minute Network Pen Test Part 1

modules/exploits/windows/smb/ms08_067_netapi.rb is the metasploit module.  To find out what external vulnerability references a module has, if you open the file in a text viewer and search for the word "References" it should be easy to find.  This one has two: A CVE of 2008-4250 and a MS reference of MS08-067. 

Hope this helps
CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
Next

Return to Linn

Who is online

Users browsing this forum: No registered users and 2 guests

.
Powered by phpBB® Forum Software © phpBB Group.
Designed by ST Software