Presentation is loading. Please wait.

Presentation is loading. Please wait.

Network Mapping  Identify Live Hosts  Determine running Services TCP Port Scanning UDP Port Scanning Banner Grabbing ARP Discovery  Identify Perimeter.

Similar presentations


Presentation on theme: "Network Mapping  Identify Live Hosts  Determine running Services TCP Port Scanning UDP Port Scanning Banner Grabbing ARP Discovery  Identify Perimeter."— Presentation transcript:

1 Network Mapping  Identify Live Hosts  Determine running Services TCP Port Scanning UDP Port Scanning Banner Grabbing ARP Discovery  Identify Perimeter Network (Router / Firewalls)‏ Tracerouting Scan Default Firewall/Router Ports Perform FIN/ACK Scan Map Router / Firewall Rule-Base  Passive OS Guessing  Active OS Guessing TCP/IP Stack Fingerprinting HTTP Packet Analysis ICMP Packet Analysis Telnet Handshake Analysis  Host Enumeration Systems Enumeration Heorot.net

2 Identify Live Hosts  Project Scope will restrict scan spectrum  Tools: ping nmap hping traceroute tpctraceroute Heorot.net

3 Identify Live Hosts ping Demonstration

4 Identify Live Hosts nmap Demonstration

5 Identify Live Hosts hping Demonstration

6 Identify Live Hosts traceroute Demonstration

7 Identify Live Hosts tcptraceroute Demonstration

8 Hands-On Exercise Identify Live Hosts  Tools: ping nmap hping traceroute tpctraceroute  Man pages # man ping # man nmap # man traceroute # man tcptraceroute  Difference between: TCP UDP  What is an “ICMP echo request”? #man icmp Heorot.net

9 Determine Running Services  TCP Port Scanning  UDP Port Scanning  Banner Grabbing  ARP Discovery Heorot.net

10 Determine Running Services TCP Port Scanning  Tools: nmap netcat hping Heorot.net

11 Determine Running Services nmap Demonstration

12 Determine Running Services netcat Demonstration

13 Determine Running Services hping Demonstration

14 Determine Running Services UDP Port Scanning  Tools: nmap netcat hping Heorot.net

15 Determine Running Services nmap Demonstration

16 Determine Running Services netcat Demonstration

17 Determine Running Services hping Demonstration

18 Determine Running Services Banner Grabbing  Tools: nmap amap netcat telnet Heorot.net

19 Determine Running Services nmap Demonstration

20 Determine Running Services amap Demonstration

21 Determine Running Services netcat Demonstration

22 Determine Running Services telnet Demonstration

23 Determine Running Services ARP Discovery  Tools: arping arp + protocol analyzer Heorot.net

24 Hands-On Exercise Determining Running Services  Tools: nmap netcat hping amap netcat telnet  TCP Services 5 “open” services  UDP Services 1 “closed” service (or is it???)  Banners How many banners can you grab? Version Information Application Name  TCP 3-way Handshake Heorot.net

25 Operating System Guessing Operating System Query  Tools: httprint netcat nmap Heorot.net

26 Operating System Guessing httprint Demonstration

27 Operating System Guessing netcat Demonstration

28 Operating System Guessing ICMP Packet Analysis  Tools: xprobe Heorot.net

29 Operating System Guessing xprobe Demonstration

30 Operating System Guessing Telnet Handshake Analysis  Tools: nmap telnetfp Heorot.net

31 Operating System Guessing nmap Demonstration

32 Host Enumeration What did you miss? Unknown application? Unusual OS?  Time to read up: RFC (Request for Comments)‏ White Papers Manuals Heorot.net

33 Hands-On Exercise Operating System Guessing / Host Enumeration  Tools: xprobe nmap  RFCs What they are Who produces them RFC 793, 768, 792 ○ Bonus: 854, 4251 ○ Super-Geek Bonus: 3766  White Papers Linux Slackware  Documentation Slackware Heorot.net

34 Module 4 – Conclusion  Phase II  Controls Assessment  Scheduling ○ Information Gathering ○ Network Mapping Identify Live Hosts Determine running Services Identify Perimeter Network (Router / Firewalls)‏ Passive OS Guessing Active OS Guessing Host Enumeration Heorot.net


Download ppt "Network Mapping  Identify Live Hosts  Determine running Services TCP Port Scanning UDP Port Scanning Banner Grabbing ARP Discovery  Identify Perimeter."

Similar presentations


Ads by Google