Syllabus Hacker 01
Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.
The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.
00-Readings are due before class.
Day 1 PPT #9
Day 2 SPT #2 & PPT #10
Two other source documents are here:
OSSTMM (16MB) SP800-115 (.6MB)
01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.
02-Tool review
Our first week of class is different from this process- Start off with small artifacts submitted via email.
You must have the VBox structure in place to start the labs. Every week and every class you will be assigned one or two base tools. We will discuss that tool in the Lab part of class. Your assignment is to work the tool, collect artifacts and send via email or post them. Artifacts are ALWAYS packet captures and sometimes a screenshot. Do not send large raw packet captures- you must cut the capture down to the attack/response data. You should be able to discuss this tool’s function, place in the process, and comparison to other tools.
The list of tools discussed this week:
2. Footprinting:
- Whois, Nslookup, ARIN, Traceroute
- NeoTrace (Now McAfee Visual Trace)
- VisualRoute Trace
- SmartWhois
- VisualLookout
- VisualRoute Mail Tracker
- eMailTrackerPro
- Sam Spade
3. Scanning:
- NMap
- NetScanTools Pro 2003
- SuperScan
- War Dialer
- THC Scan
- Pinger
- Cheops
- SocksChain
- Httptunnel
- HTTPort
- ipEye or IPSecScan
- ToneLoc
- TBA
03-Reports
As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future. Use OSSTMM.
04-Recording Links are listed for your review of presentations. These are updated one week after the new class.
Please pick up your files for the next class at the end of the previous class or before. You can find these links and the class schedule here:http://www.expandingsecurity.com/about/events/
All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.
Links:
02 Footprinting
-
02 Reading
- Footprinting, scoping and recon with DNS, Google Hacking and Metadata (Hacking Illustrated Series InfoSec Tutorial Videos)
- DOMAIN NAMES – CONCEPTS AND FACILITIES [RFC-Ref]
- Regional Internet registry – Wikipedia, the free encyclopedia
- http://www.packetwatch.net/documents/papers/osdetection.pdf
- Information Gathering Tools
- http://simson.net/clips/academic/2009.BL.InternetFootprint.pdf
- http://www.ecqurity.com/wp/footprinting-encored.pdf
- http://www.ietf.org/rfc/rfc1034.txt
- http://web.textfiles.com/hacking/footprinting.txt
- NEOHAPSIS – Peace of Mind Through Integrity and Insight
- SecuriTeam – Analysis of Remote Active Operating System Fingerprinting Tools
- Remote OS Detection via TCP/IP Fingerprinting
- Remote OS detection via TCP
- Chapter 8. Remote OS Detection
- Fingerprinting Merit Badge
- http://freeworld.thc.org/thc-ffp/
- CJ625 Student Paper
- Footprinting: The Basics of Hacking :: Hack In The Box :: Keeping Knowledge Free
- Readings the hacker’s choice – THC
- What is competitive intelligence?
- Know Your Enemy: Passive Fingerprinting | The Honeynet Project
- IMS General Web Services glossary
-
02 IP and telephone networks
- American Registry for Internet Numbers (ARIN)
- IP Trace, IP Tracing tools – by TialSoft software
- APNIC – About network abuse and spamming
- Sandstorm PhoneSweep 4.4 War Dialer Telephone Line Scanner
- Port monitor – CallerIP – IP connection monitor, port monitoring, spyware monitoring, adware monitoring, whois and network reports
-
02 DNS
- DNS-Digger – Trying to digg deeper into the information behind the net
- Dig web interface
- Domain Recon
- host – Linux man page
- DNS tools
- DNS Tools | Ajax DNS
- DNS RIPE.NET
- DNS APNIC
- DNS LACNIC
-
02 Whois
- The Prefix WhoIs Project – Greetings
- Free online network tools – traceroute, nslookup, dig, whois lookup, ping – IPv6
- DomainTools | Whois Lookup, DNS Lookup, Reverse Whois Lookup
- Whois 2010 PRO
- Freeware Programs: NetInspector
- Whois By IP Address
- Better Whois: The WHOIS domain search that works with all registrars.
- Whois
- Domain Research Tool – Typein domains, Pagerank domain, Link Popularity domains, Bulk whois
- Domain Name Management Software – Internet Business Asset Management : DomainPunch.Com
-
02 Tracerout
- 3d Traceroute
- Path Analyzer Pro – Graphical Traceroute, WhoIs, Charts, Maps, Performance Testing, ip location, tracert, trace route
- Traceroute – VisualRoute Live Demo – Diagnosing your connection problems.
- Visual IP Trace – IP, website and doamin location trace tool
- Roadkil.Net – Roadkil’s Trace Route Program Download
- vTrace
- Ping Plotter Download
- Ping-Probe (Essential Network Toolkit Suite)
- Traceroute Tool
- Traceroute, Ping, Domain Name Server (DNS) Lookup, WHOIS
-
02 SNMP
-
02 Email Tracking
- eMailTrackerPro – Email tracing and analysis to in depth forensic email analysis including email header analysis.
- Certified email with delivery receipts, silent tracking, proof-of-opening history, security and timestamps.
- 404 – File or directory not found.
- How To Track Your Sent Email
- Bulk Email Marketing & SEO Solutions from G-Lock Software
-
02 Website offline cache
- PageNest Free Offline Browser
- HTTrack Website Copier – Offline Browser
- website monitoring KeepNI
- BlackWidow will download part or complete website.
- Website Ripper Copier, Download Website Downloader, Extract Web site, Webspider – high-speed tool for saving website data!
- WebSite-Watcher – Software to check websites for updates and changes (web page monitoring)
-
02 Site Recon
- gmapcatcher – An offline map viewer – Google Project Hosting
- googlehacks – A compact utility for several google hacks. – Google Project Hosting
- PHENOELIT
- Maltego 3
- Trellian Competitive Intelligence – Business Intelligence Tool
- Compete Search Analytics Search | Compete
- Graph Visualization and Social Network Analysis Software | Navigator – TouchGraph.com
- SpyFu
- Web Investigator
- Web Data Extractor – Extract URL, Meta Tag, Email, Phone, Fax from Web
- Internet Archive: Digital Library of Free Books, Movies, Music & Wayback Machine
-
02 Companies
- Carratu Ltd – Risk Mitigation and Corporate Investigation consultants
- Market Intelligence – Global Intelligence Alliance
- Fuld & Company – The Global Leader in Competitive Intelligence – Home Page
- Datamonitor | the home of Business Information
- ProQuest – Central To Research Around The World
- Factiva – business news, business information, financial news, company profiles, executive information
- Press Release Distribution, Financial Disclosure, Online Newsrooms, PR, Public Relations, Investor Relations, EDGAR filing, XBRL, Breaking News, Business News, Financial News | Business Wire
- MarketWatch – Stock Market Quotes, Business News, Financial News
- The Wall Street Transcript Online: TWST.COM
- Global Market Research and Analysis for Industries, Countries, and Consumers
- SEC Info – the best EDGAR online database of Securities and Exchange Commission filings & IPOs
- C-SPAN | Capitol Hill, The White House and National Politics
- Information for the World’s Business Leaders – Forbes.com
- White Pages | Phone Number Lookup & People Search – AnyWho
- Google Finance: Stock market quotes, news, currency conversions & more
- Yahoo! Finance – Business Finance, Stock Market, Quotes, News
- Google Earth
-
02 People
- Pipl – People Search
- People Search
- Instant People Search
- Yahoo! Search – People Search
- 123people.com
- Free People Search
- Find Public Records at PeopleFinders
- Address Finder and Addresses Lookup
- People Search by ZabaSearch
- Public People Finder
- PeopleLookup Public Records, Background Checks
- Welcome to Facebook
- orkut – login
-
02 Defense
03 Scanning
-
03 Readings
- Internet Anonymizers
- TCP/IP Fingerprinting Methods Supported by Nmap
- Nmap – Scan Modes | Openxtra
- Classnotes: UNIX03/Introduction To Nmap
- OS Fingerprinting with ICMP
- Nmap: The Art of Port Scanning
- Port Scanning / Internet Security Lectures by Prabhaker Mateti
- http://www.in-f-or.it/informatica/docs/portscan.pdf
- http://www.lancemueller.com/blog/Create%20Reverse%20SSH%20to%20reach%20servlet%20inside%20firewall.pdf
- http://cobweb.ecn.purdue.edu/%7Ekak/compsec/NewLectures/Lecture23.pdf
- http://www.nordu.net/development/2nd-cnnw/tcp-analysis-based-on-flags.pdf
- hping security tool – man page
- http://www.systemexperts.com/assets/tutors/wardial0299.pdf
- IMS General Web Services Security Profile
- Network Security Library / Misc
- Thc- Ed video
- news at Netcraft
-
03 Multi layer
- Nmap
- Free Application Monitoring
- AutoScan-Network : Free Network Scanner
- Network Scanner – Port Scanner – Host Monitor – Network Utilities
- HP Network Node Manager (NNM) Advanced Edition software – HP – BTO Software
-
03 Tool Suite
- Netscantools
- Must-Have Network Troubleshooting Tools from SolarWinds
- Home of NetScanTools® Network Engineering Tools and the Managed Switch Port Mapping Tool
- Network Inventory Software: Audit and Track Network Computer Inventory (Hardware & Software) for Windows
- Atelier network tools security tools
- Network Security Audit Software
- IP-Tools – 19 network utilities
-
03 IP
- Hping – Active Network Security Tool
- Ping Tester – Visual Ping Test Tool
- Home – Ultra Ping
- Lumeta – IPsonar
- PingInfoView – Ping to multiple host names/IP addresses
- NetworkMiner Network Forensic Analysis Tool (NFAT) and Packet Sniffer
- Network Map Generation Software from SolarWinds
- Network Mapper and Monitor
- Switch Center: Network Discovery and Mapping Monitoring Software
- 1234XXX.COM | 1234xxx
-
03 Port
-
03 Vulnerability scanner
- OpenVAS – OpenVAS – Open Vulnerability Assessment System Community Site
- Network vulnerability scanner, security scanner and port scanner
- SAINT Scanner
- Core Security Technologies | Core Impact Pro Penetration Testing Software
- Network Security Scanner & Database Security Scanner & Online Security Scanner
- Insightix BSA Visibility
- Network Diagram | Network Mapping
-
03 Proxy
- DRB- great simple proxy site with privacy laws
- TOR: The Onion Router (in Society > Privacy > Remailers @ iusmentis.com)
- Proxifier – Bypass firewall and proxy, tunnel connections through an HTTPS and SOCKS proxy
- SOCKS chain proxy
- ProxyCommander – DLAO Software
- GProxy | Global Pass
- Protoport Proxy Chain software
- Proxy+ | Main page
- FastProxySwitch Overview – Affinity-Tools.com
- Proxy List – Free Proxy Servers Search — HTTP Socks Proxies Finder
- Fast 10000+ Fresh Http Proxy Lists Search Leech from Internet
- JAP — ANONYMITY & PRIVACY
- Proxy Switcher – change proxy settings on the fly
- Handcrafted Software Portal
- Professional bidirectional http tunnel software,include client and server, bypass any proxy or firewall
- neophob.com » are you still afraid?
- HTTPTunnel – Tunnel Connections Through Restrictive Proxies
-
03 Anonymous Internet Surfing
- Free open source winsock and LSP – tools and guides
- ksoft – G-Zapper – Block Google Cookie, Software for Automatic Cookie Cleaning
- just ping – Online ping – Online web-based ping: Free online ping from 50 locations worldwide
- Website monitoring by WatchMouse
- Mowser – Mobilizing the web
- Surf Anonymously, Hide IP Address, Change IP Address | Anonymous Web Surfing
- Hide Your IP Address – Free download of hide my ip software
- Hide IP and Anonymous Web Browsing Software | Anonymizer
- the-cloak home
- IDzap & IDseal — Secure anonymous web surfing and secure email services
- Guardster – Welcome to Guardster – Your Privacy Headquarters
-
03 Telephone