Syllabus Hacker 01

Certified Ethical Hacker on June 19th, 2010 No Comments

Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.

The steps below, the files, and links within, are numbered  in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.

00-Readings are due before class.

Day 1 PPT #9

Day 2 SPT #2 & PPT #10

Two other source documents are here:

OSSTMM (16MB) SP800-115 (.6MB)

01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.

02-Tool review

Our first week of class is different from this process- Start off with small artifacts submitted via email.

You must have the VBox structure in place to start the labs. Every week and every class you will be assigned one or two base tools. We will discuss that tool in the Lab part of class.  Your assignment is to work the tool, collect artifacts and send via email or post them. Artifacts are ALWAYS packet captures and sometimes a screenshot. Do not send large raw packet captures- you must cut the capture down to the attack/response data. You should be able to discuss this tool’s function, place in the process, and comparison to other tools.

The list of tools discussed this week:

2. Footprinting:

  1. Whois, Nslookup, ARIN, Traceroute
  2. NeoTrace (Now McAfee Visual Trace)
  3. VisualRoute Trace
  4. SmartWhois
  5. VisualLookout
  6. VisualRoute Mail Tracker
  7. eMailTrackerPro
  8. Sam Spade

3. Scanning:

  1. NMap
  2. NetScanTools Pro 2003
  3. SuperScan
  4. War Dialer
  5. THC Scan
  6. Pinger
  7. Cheops
  8. SocksChain
  9. Httptunnel
  10. HTTPort
  11. ipEye or IPSecScan
  12. ToneLoc
  13. TBA

03-Reports

As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future. Use OSSTMM.

04-Recording Links are listed for your review of presentations. These are updated one week after the new class.

Recording 02

LabRecording02

Recording 03

LabRecording 03

Please pick up your files for the next class at the end of the previous class or before. You can find these links and the class schedule here:http://www.expandingsecurity.com/about/events/

All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.

Links:

02 Footprinting

02 Reading

Footprinting, scoping and recon with DNS, Google Hacking and Metadata (Hacking Illustrated Series InfoSec Tutorial Videos)
DOMAIN NAMES – CONCEPTS AND FACILITIES [RFC-Ref]
Regional Internet registry – Wikipedia, the free encyclopedia
http://www.packetwatch.net/documents/papers/osdetection.pdf
Information Gathering Tools
http://simson.net/clips/academic/2009.BL.InternetFootprint.pdf
http://www.ecqurity.com/wp/footprinting-encored.pdf
http://www.ietf.org/rfc/rfc1034.txt
http://web.textfiles.com/hacking/footprinting.txt
NEOHAPSIS – Peace of Mind Through Integrity and Insight
SecuriTeam – Analysis of Remote Active Operating System Fingerprinting Tools
Remote OS Detection via TCP/IP Fingerprinting
Remote OS detection via TCP
Chapter 8. Remote OS Detection
Fingerprinting Merit Badge
http://freeworld.thc.org/thc-ffp/
CJ625 Student Paper
Footprinting: The Basics of Hacking :: Hack In The Box :: Keeping Knowledge Free
Readings the hacker’s choice – THC
What is competitive intelligence?
Know Your Enemy: Passive Fingerprinting | The Honeynet Project
IMS General Web Services glossary

02 IP and telephone networks

American Registry for Internet Numbers (ARIN)
IP Trace, IP Tracing tools – by TialSoft software
APNIC – About network abuse and spamming
Sandstorm PhoneSweep 4.4 War Dialer Telephone Line Scanner
Port monitor – CallerIP – IP connection monitor, port monitoring, spyware monitoring, adware monitoring, whois and network reports

02 DNS

DNS-Digger – Trying to digg deeper into the information behind the net
Dig web interface
Domain Recon
host – Linux man page
DNS tools
DNS Tools | Ajax DNS
DNS RIPE.NET
DNS APNIC
DNS LACNIC

02 Whois

The Prefix WhoIs Project – Greetings
Free online network tools – traceroute, nslookup, dig, whois lookup, ping – IPv6
DomainTools | Whois Lookup, DNS Lookup, Reverse Whois Lookup
Whois 2010 PRO
Freeware Programs: NetInspector
Whois By IP Address
Better Whois: The WHOIS domain search that works with all registrars.
Whois
Domain Research Tool – Typein domains, Pagerank domain, Link Popularity domains, Bulk whois
Domain Name Management Software – Internet Business Asset Management : DomainPunch.Com

02 Tracerout

3d Traceroute
Path Analyzer Pro – Graphical Traceroute, WhoIs, Charts, Maps, Performance Testing, ip location, tracert, trace route
Traceroute – VisualRoute Live Demo – Diagnosing your connection problems.
Visual IP Trace – IP, website and doamin location trace tool
Roadkil.Net – Roadkil’s Trace Route Program Download
vTrace
Ping Plotter Download
Ping-Probe (Essential Network Toolkit Suite)
Traceroute Tool
Traceroute, Ping, Domain Name Server (DNS) Lookup, WHOIS

02 SNMP

3DSNMP – Network Engineer’s Toolkits
snmp monitoring – monitoring software – network management

02 Email Tracking

eMailTrackerPro – Email tracing and analysis to in depth forensic email analysis including email header analysis.
Certified email with delivery receipts, silent tracking, proof-of-opening history, security and timestamps.
404 – File or directory not found.
How To Track Your Sent Email
Bulk Email Marketing & SEO Solutions from G-Lock Software

02 Website offline cache

PageNest Free Offline Browser
HTTrack Website Copier – Offline Browser
website monitoring KeepNI
BlackWidow will download part or complete website.
Website Ripper Copier, Download Website Downloader, Extract Web site, Webspider – high-speed tool for saving website data!
WebSite-Watcher – Software to check websites for updates and changes (web page monitoring)

02 Site Recon

gmapcatcher – An offline map viewer – Google Project Hosting
googlehacks – A compact utility for several google hacks. – Google Project Hosting
PHENOELIT
Maltego 3
Trellian Competitive Intelligence – Business Intelligence Tool
Compete Search Analytics Search | Compete
Graph Visualization and Social Network Analysis Software | Navigator – TouchGraph.com
SpyFu
Web Investigator
Web Data Extractor – Extract URL, Meta Tag, Email, Phone, Fax from Web
Internet Archive: Digital Library of Free Books, Movies, Music & Wayback Machine

02 Companies

Carratu Ltd – Risk Mitigation and Corporate Investigation consultants
Market Intelligence – Global Intelligence Alliance
Fuld & Company – The Global Leader in Competitive Intelligence – Home Page
Datamonitor | the home of Business Information
ProQuest – Central To Research Around The World
Factiva – business news, business information, financial news, company profiles, executive information
Press Release Distribution, Financial Disclosure, Online Newsrooms, PR, Public Relations, Investor Relations, EDGAR filing, XBRL, Breaking News, Business News, Financial News | Business Wire
MarketWatch – Stock Market Quotes, Business News, Financial News
The Wall Street Transcript Online: TWST.COM
Global Market Research and Analysis for Industries, Countries, and Consumers
SEC Info – the best EDGAR online database of Securities and Exchange Commission filings & IPOs
C-SPAN | Capitol Hill, The White House and National Politics
Information for the World’s Business Leaders – Forbes.com
White Pages | Phone Number Lookup & People Search – AnyWho
Google Finance: Stock market quotes, news, currency conversions & more
Yahoo! Finance – Business Finance, Stock Market, Quotes, News
Google Earth

02 People

Pipl – People Search
People Search
Instant People Search
Yahoo! Search – People Search
123people.com
Free People Search
Find Public Records at PeopleFinders
Address Finder and Addresses Lookup
People Search by ZabaSearch
Public People Finder
PeopleLookup Public Records, Background Checks
Welcome to Facebook
Twitter
orkut – login

02 Defense

GHH – The “Google Hack” Honeypot

03 Scanning

03 Readings

Internet Anonymizers
TCP/IP Fingerprinting Methods Supported by Nmap
Nmap – Scan Modes | Openxtra
Classnotes: UNIX03/Introduction To Nmap
OS Fingerprinting with ICMP
Nmap: The Art of Port Scanning
Port Scanning / Internet Security Lectures by Prabhaker Mateti
http://www.in-f-or.it/informatica/docs/portscan.pdf
http://www.lancemueller.com/blog/Create%20Reverse%20SSH%20to%20reach%20servlet%20inside%20firewall.pdf
http://cobweb.ecn.purdue.edu/%7Ekak/compsec/NewLectures/Lecture23.pdf
http://www.nordu.net/development/2nd-cnnw/tcp-analysis-based-on-flags.pdf
hping security tool – man page
http://www.systemexperts.com/assets/tutors/wardial0299.pdf
IMS General Web Services Security Profile
Network Security Library / Misc
Thc- Ed video
news at Netcraft

03 Multi layer

Nmap
Free Application Monitoring
AutoScan-Network : Free Network Scanner
Network Scanner – Port Scanner – Host Monitor – Network Utilities
HP Network Node Manager (NNM) Advanced Edition software – HP – BTO Software

03 Tool Suite

Netscantools
Must-Have Network Troubleshooting Tools from SolarWinds
Home of NetScanTools® Network Engineering Tools and the Managed Switch Port Mapping Tool
Network Inventory Software: Audit and Track Network Computer Inventory (Hardware & Software) for Windows
Atelier network tools security tools
Network Security Audit Software
IP-Tools – 19 network utilities

03 IP

Hping – Active Network Security Tool
Ping Tester – Visual Ping Test Tool
Home – Ultra Ping
Lumeta – IPsonar
PingInfoView – Ping to multiple host names/IP addresses
NetworkMiner Network Forensic Analysis Tool (NFAT) and Packet Sniffer
Network Map Generation Software from SolarWinds
Network Mapper and Monitor
Switch Center: Network Discovery and Mapping Monitoring Software
1234XXX.COM | 1234xxx

03 Port

AWPTA – Atelier Web Ports Traffic Analyzer
Welcome to Phatlinks.com

03 Vulnerability scanner

OpenVAS – OpenVAS – Open Vulnerability Assessment System Community Site
Network vulnerability scanner, security scanner and port scanner
SAINT Scanner
Core Security Technologies | Core Impact Pro Penetration Testing Software
Network Security Scanner & Database Security Scanner & Online Security Scanner
Insightix BSA Visibility
Network Diagram | Network Mapping

03 Proxy

DRB- great simple proxy site with privacy laws
TOR: The Onion Router (in Society > Privacy > Remailers @ iusmentis.com)
Proxifier – Bypass firewall and proxy, tunnel connections through an HTTPS and SOCKS proxy
SOCKS chain proxy
ProxyCommander – DLAO Software
GProxy | Global Pass
Protoport Proxy Chain software
Proxy+ | Main page
FastProxySwitch Overview – Affinity-Tools.com
Proxy List – Free Proxy Servers Search — HTTP Socks Proxies Finder
Fast 10000+ Fresh Http Proxy Lists Search Leech from Internet
JAP — ANONYMITY & PRIVACY
Proxy Switcher – change proxy settings on the fly
Handcrafted Software Portal
Professional bidirectional http tunnel software,include client and server, bypass any proxy or firewall
neophob.com » are you still afraid?
HTTPTunnel – Tunnel Connections Through Restrictive Proxies

03 Anonymous Internet Surfing

Free open source winsock and LSP – tools and guides
ksoft – G-Zapper – Block Google Cookie, Software for Automatic Cookie Cleaning
just ping – Online ping – Online web-based ping: Free online ping from 50 locations worldwide
Website monitoring by WatchMouse
Mowser – Mobilizing the web
Surf Anonymously, Hide IP Address, Change IP Address | Anonymous Web Surfing
Hide Your IP Address – Free download of hide my ip software
Hide IP and Anonymous Web Browsing Software | Anonymizer
the-cloak home
IDzap & IDseal — Secure anonymous web surfing and secure email services
Guardster – Welcome to Guardster – Your Privacy Headquarters

03 Telephone

THC-SCAN – the worlds most used opensource wardialer!
Scanning the hacker’s choice – THC all tools
SecureLogix® Home Page
No Responses to “Syllabus Hacker 01”

Leave a Reply

You must be logged in to post a comment.