Showing posts with label Information Gathering. Show all posts

Saturday, February 2, 2013

Netdiscover

backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting



"Netdiscover" is an active/passive address reconnaissance tool, mainly developed for those wireless networks without dhcp server, when you are wardriving. It can be also used on hub/switched networks.

Built on top of libnet and libpcap, it can passively detect online hosts, or search for them, by actively sending arp requests, it can also be used to inspect your network arp traffic, or find network addresses using auto scan mode, which will scan for common local networks." source: netdiscover

Here are the different available options of this tool:




backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting




In this example, i am going to use "netdiscover" to search for available hosts on my wireless interface:



backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting





You can input the interface of your choice, if you are cable connected for example, your internet interface should be eth0. To see what available network interfaces you have, opĂȘn a terminal and type: ifconfig




backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting

Read more

Saturday, January 26, 2013

An introduction to Information Gathering

backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting


Information Gathering is the first step in penetration testing, and is also the most crucial part in the whole process itself, and every successful operation will heavily depend on it. This phase consistes of collecting all possible type of information about a given target. Any information whatever irrelevant it may seem, can be of the utmost importance. This includes network address range, live hosts, open ports and the services running on these ports, operating systems,and you can also collect emails or phone numbers that can be used later on for social engineering purposes.


A big arsenal of tools is available for the reconnaissance phase and they are pre- installed  in Backtrack. We cannot talk about Information gathering without mentioning nmap (Network Mapper). It is in fact a flexible and powerful utility for network discovery and security auditing.




backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting


figure 1: nmap in action



backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting

                                                                                 figure 2: nmap in action

Other alternatives for nmap are zenmap, dnmap, netifera, netcat and a dozen of other useful tools like dmitry. (i already posted a tutorial about Dmitry, if you are intersted, here is the link: http://backtrack-wifu.blogspot.com/2013/01/dmitry-footprinting-tool.html).


 We can also start with a dns lookup.




backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting



figure3: performing a whois lookup on facebook




backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting


figure 4: more whois data about facebook

I f you are that lazy, you can rely on online tools. A useful site for this purpose is: http://www.all-nettools.com/ which is of great help for beginners. It provides a lot of services like: whois lookup, tracerouting, nslookup etc...



backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting


figure 5: list services in all-net-tools



backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting


figure6: smart whois on cnn.com


You may also try http://www.dnsstuff.com/


backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting

figure 7: available service in dnsstuff.com


backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting

figure 8: performing an ip traceroute


To the surprise of many people, one of the first information gathering sources for a pentester is GOOGLE !! It can reveal a lot of valuable information that people may not want us to discover. This is possible with what is referred to as google hacks.

Let's look for a private directory for example:



backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting


figure 9: google hacks




backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting


figure 10: google hacks


You can also use other tools to trace email senders or for IDS or IPS identification. The only thing that you have to bear in mind, is that information gathering is an art, and if you master this art, everything else would be much easier. Another important thing here worth mentioning, which is documentation. This step consists of having a good and organized documentation for your findings. A lot of tools are also available for this task like: casefile,magictree and basket. I am going to post some tutorials about information gathering tools, and documentation tools as soon as possible. Hope you enjoyed.

                                                                                                                                        TO BE CONTINUED
Read more

Friday, January 25, 2013

Collecting emails with Metasploit

backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting

In this tutorial, we are going to lean how to collect emails from a given domain name with a Metasploit 
First step, open the metasploit console:

root@bt:~#msfconsole



backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting


Next, issue the following command:


msf > use auxiliary/gather/search_email_collector


backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting



Let's have a look at the available options:

 > show options


backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting



Now we are going to set up our domain name, you can choose here whatever you like, then you type 

 > run



backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting




backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting




backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting



backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting

Read more

Dmitry: footprinting tool

backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting




Dmitry is a wonderful linux tool used for footprinting purposes. As its name suggests : Deep Magic Information gathering Tool, Dmitry has a wonderful ability to gather as much possible information about a given target as possible.
You can access the tool in different ways. First you can hit: ALT+F2, and a small window will pop up at the top of your screen in which you type "dmitry" then click on the displayed icon:




backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting



Or, you can follow this path:

Applications ->Backtrack ->Information gathering ->Network analysis ->route analysis ->dmitry




backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting



-You can use Dmitry to perform a whois lookup by using this command:

dmitry -w target


example:





backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting



-You can also use it to perform the same above task with an IP address, example:





backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting




-You can use to retrieve Netcraft.com information on a host:





backtrack, backtrack 5, linux, hacking, tutorial, hacking tutorial, ethical hacking, pentest, penetration testing, pc, wpa, wpa2, metasploit, nmap, browser exploit, information gathering, footprinting




You can also use this tool for many purposes, like performing a tcp port scan on a host,  searching possible email addresses, search for possible subdomains etc...
Read more

Wednesday, January 23, 2013



download James Messner's Secrets of Network Cartography PDF file)

Secrets of Network Cartography: A comprehensive Guide to nmap
Secrets DOWNLOAD it HERE : http://adf.ly/G6yXw (NOTE: skip AD then you can download James Messner's Secrets of Network Cartography PDF file)
Read more