What is a stepping stone?
Attackers can collect and organize a complete analysis of the information security status of an organization by planning and step-by-step actions on the Organization. Combined with various tools and techniques, coupled with some useful patience and thinking organizations, attackers can completely change from being unknown to an organization (such as XYZ, they can identify the domain names, network address blocks, IP addresses of related systems directly connected to the Internet, and other details about the security status of information from public channels. There are many technologies that can be used to step on, but their main goal is to discover and collect information related to the following network environments:
The list is as follows:
Information to be confirmed in the Network Environment
Internet Domain
Network address block and Subnet
Details of various systems that can be accessed directly from the Internet
IP address
TCP and UDP services run on the detected Systems
System Architecture (for example, or X86)
Access control mechanism and ACL
IDS
System details (such as user name and user group name,
SNMP)
DNS host name
Intranet organization protocols (IP, IPX, DecNET, etc)
Internal Domain Name
Network Address Block
Details of various systems that can issue questions directly from the Intranet
IP address
TCP and UDP services run on the detected Systems
The architectures of discovered systems (for example
Or X86)
Access control mechanism and ACL
IDS
System details (user name and user group)
SNMP information)
Remote Access simulation/digital phone number
Remote System Type
Authentication Mechanism
VPN and related protocols (IPSec and PPTP)
Source Address and target address of the Internet connection
Connection Type
Access Control Mechanism
Why is it necessary to step on the page?
Hackers are very good at understanding your thoughts without your knowledge. They systematically and systematically collect information about the technologies used in your environment. Without a complete set of methods to collect such intelligence, you are likely to lose your hands on key information related to the technical organization. But believe me, no hackers will.
Despite warnings in advance, it is still one of the hardest tasks to try to determine the security defense system of a certain ancestor. Meanwhile, for beginners who try to drive hacker attempts, it is also the most boring, but it is also one of the most important tasks. The step must be accurate and under control.
STEP 1 determine the range of the stepping Activity
The center I extracted is to look at the target when receiving tickets, and try to find out the weakest link in the security defense system.
STEP 2 obtain necessary authorization
Er... This has nothing to do with me, because we are all "passing by friendship". What you know is that the author mentioned in the book: if you have asked penetration testing experts about "free gold medal", I am sure you will see their uncertain smile.
STEP 3 information that can be obtained from public channels
1. company WEB Page
Many companies list security configuration details and detailed asset lists on their Internet WEB servers.
In addition, the Comment statement in the HTML source code is also a good place to collect intelligence. Reading offline is faster than online reading. You can download the webpage using wget (linux) or Teleport Pro (windows.
In addition to "http: // www" and "https: // www", you can also tap the host names of www1, www2, web, web1, test, and test1. There are still many such choices.
Many organizations have dedicated sites to process requests to access internal resources of the Organization through web browsers. Outlook Web Access of Micosoft is a very common example. It serves as a proxy server that allows users to Access Microsoft Exchange within an organization from the Internet. The URLs of such resources are most common in http://owa.company.com or http: // outlook.company.com. Similarly, organizations with large hosts, System/3b, or AS/400 often provide users with a method to remotely access the Organization through WEB browsers through services such AS OpenConnect WebConnect; the function is equivalent to a JAVA-based 3270 or 5250 simulation device, which allows remote users to remotely access large hosts or medium-sized servers within an organization using a WEB browser on the client, for example, AS/400.
In addition, many organizations have VPN, try to visit "http://vpn.company.com", "https: // vpn.company.com", "http://www.company.com/vpn”site. On such websites, you can usually find the suppliers and versions of VPN software and the specific steps for downloading and configuring VPN Client software. This type of website may even provide a phone number. Hackers-sorry, I mean employee-can call this phone number for help in connection to the VPN network.
2. Related Organizations
References or connections to other organizations in the target are also worth noting. For example, many target WEB development and design services are outsourced. It is common to find comments from the author in a file on the WEB homepage.
3. Geographical location and details
This social worker makes a lot of use, and the book mentions spam, stalking, social engineering, or other non-technical attacks. Or illegally intrude into office buildings and access wired or wireless networks.
WEB services that probe in this regard: http://earth.google.com/http://terrserver.microsoft.com/
4. Recent Major Events
If the company's revenue is not high recently, employees are all thinking about their own wages rather than the possibility of Information Security leakage. The various reports of large companies are not difficult to find.
5. Employees: phone number, contact list, email address, and detailed personal data
It is also the use of social engineering.
6. Indicate the privacy/security policies and technical details of the existing Information Security Mechanism
For a very obvious reason, any information and technical details that helps to gain an in-depth understanding of the privacy/security policies of the target organization and help it to protect its hardware and software, they are invaluable to hackers. For an experienced hacker, As long as enough information is collected, it is not difficult to find opportunities to intrude into the target organization.
7. dissatisfied employees
The roles of dissatisfied employees are obvious to all. The Google search engine's advanced search function "link: www.company.com" can be used to search for websites with links to the target organization within the scope of its knowledge. Among those websites, we often find some malicious websites that intentionally leak the secrets of the target organization or target the target organization.
In addition, if you want to find a dissatisfied employee, you can go to the dedicated BBS to search for comments.
8. Search Engine, Usenet, resume
Search engine: google hacking, a well-known tool: Athena, SiteDigger, Wikto
Resume: the online recruitment notice and resume are also a good resource for collecting information. For example, if you see in a company's recruitment notice that it is looking for a security professional who has more than five years of experience in CheckPoint firewall and Snort IDS, what do you mean by the firewall and IDS used by this organization? They may want to invite experts in intrusion detection to form and lead their IR teams. If so, what is their current intrusion detection and response capabilities? Is there a problem? Do they currently have a leader in this field? If the recruitment notice fails to provide such details, you may gain some benefits by making a phone call. If you are interested in your resume, you can follow a similar approach-simply pretend to be a headhunting company and ask questions.
STEP 4 WHOIS and DNS Lookup
Mechanism resource application platform
Web interface http://whois.inana.org
Http://www.arin.net
Http://www.allwhois.com
Install a WEB Client Program
Any Platform
The whois client provides the whois query tool UNIX in most UNIX versions.
Fwhois html "> http://linux.maruhn.com/sec/fwhois.html UNIX
WS_Ping ProPack http://www.ipswitch.com/Windows95/NT/2000/XP
Sam Spade http://www.samspade.org/ssw Windows95/NT/2000/XP
Web Interface
Sam Spade tool http://www.samspade.org installed with WEB Client Program
Any Platform
Net Scan tool http://www.netscantools.com/nspromain.html Windows95/NT/2000/XP
Xwhois nr/xwhois/"> http://c64.org/<126> nr/xwhois/installed with X and GTK + GUI
Development Kit UNIX System
Jwhois http://www.gnu.org/software/jwhois/jwhois.html UNIX
STEP 5 DNS query
Under the windows book introduced nslookup, sam spade "UNIX well that much, nslookup, host, dig, axfr (http://packetstormsecurity.nl/groups/ADM/axfr-0.5.2.tar.gz)
STEP 6 network detection
This step book only describes a tool tracetoute (ftp://ftp.ee.lbl.gov/traceroute.tar.gz), in fact there are many similar tools, BackTrack 4 R2 under the Information Gathering directory can be found in all.