-
ตัวอย่าง Hacking Methodologies หรือ Security Testing Frameworks
-
Hacking Methodologie
-
EC-Council Ethical Hacking methodology
- Reconnaissance
- Scanning
- Gaining access
- Maintaining access
- Clearing tracks
-
Foundstone Hacking methodology
- Footprinting
- Scanning
- Enumeration
- Gaining Access
- Escalation Privilege
- Covering Tracks
-
Hacking Exposed Methodology
- Footprint
- Scan
- Enumerate
- Exploit
- Pillage
- Stealth
-
Security Testing Framework
- The Open Source Security Testing Methodology Manual (OSSTMM)
- SP800-115 National Institute of Standards and Technology(NIST) Special Publication
-
The Information Systems Security Assessment Framework (ISSAF)
- PHASE I: PLANNING AND PREPARATION
-
PHASE II: ASSESSMENT
- Information Gathering
- Network Mapping
- Vulnerability Identification
- Penetration
- Gaining Access and Privilege Escalation
- Gaining Access
- Gain Least Privilege
- Compromise
- Final Compromise on Target
- Privilege Escalation
- Enumerating Further
- Compromise Remote Users/Sites
- Maintaining Access
- Covert Channels
- Backdoors
- Root-kits
- Cover the Tracks
- Hide Files
- Clear Logs
- Defeat integrity checking
- Defeat Anti-virus
- Implement Root-kits
- Audit (optional)
- PHASE III: REPORTING, CLEAN UP & DESTROY ARTIFACTS
- Reporting
- Verbal Reporting
- Final Reporting
- Clean Up and Destroy Artifacts
-
Common Steps
-
Reconnaissance
-
Active
-
สืบค้นจาก DNS Server ของเป้าหมายโดยตรง
- ข้อมูลใน DNS มีดังต่อไปนี้
- SOA Records - Indicates the server that has authority for the domain.
- Serial
- Refresh
- Retry
- Expiry
- Minimum
- MX Records - List of a host’s or domain’s mail exchanger server(s).
- NS Records - List of a host’s or domain’s name server(s).
- A Records - An address record that allows a computer name to be translated to an IP address. Each computer has to have this record for its IP address to be located via DNS.
- PTR Records - Lists a host’s domain name, host identified by its IP address.
- SRV Records - Service location record.
- HINFO Records - Host information record with CPU type and operating system.
- TXT Records - Generic text record.
- Version.bind
- CNAME - A host’s canonical name allows additional names/ aliases to be used to locate a computer.
- RP - Responsible person for the domain.
- วิธีการสืบค้น
- DNS Zone Transfer
- Reverse Lookup Zone Query
-
Social Engineering
- Remote
- Phone
- Scenarios
- IT Department.
"Hi, it's Zoe from the helpdesk. I am doing a security audit of the network
and I need to re-synchronise the Active Directory usernames and passwords.
This is so that your logon process in the morning receives no undue delays"
If you are calling from a mobile number, explain that the helpdesk has been
issued a mobile phone for 'on call' personnel.
- Results
- Contact Details
- Name
- Phone number
- Email
- Room number
- Department
- Role
- Email
- Scenarios
- Hi there, I am currently carrying out an Active Directory Health Check
for TARGET COMPANY and require to re-synchronise some outstanding
accounts on behalf of the IT Service Desk. Please reply to me
detailing the username and password you use to logon to your desktop
in the morning. I have checked with MR JOHN DOE, the IT Security
Advisor and he has authorised this request. I will then populate the
database with your account details ready for re-synchronisation with
Active Directory such that replication of your account will be
re-established (this process is transparent to the user and so
requires no further action from yourself). We hope that this exercise
will reduce the time it takes for some users to logon to the network.
Best Regards,
Andrew Marks
- Good Morning,
The IT Department had a critical failure last night regarding remote access to the corporate network, this will only affect users that occasionally work from home.
If you have remote access, please email me with your username and access requirements e.g. what remote access system did you use? VPN and IP address etc, and we will reset the system. We are also using this 'opportunity' to increase the remote access users, so if you believe you need to work from home occasionally, please email me your usernames so I can add them to the correct groups.
If you wish to retain your current credentials, also send your password. We do not require your password to carry out the maintainence, but it will change if you do not inform us of it.
We apologise for any inconvenience this failure has caused and are working to resolve it as soon as possible. We also thank you for your continued patience and help.
Kindest regards,
lee
EMAIL SIGNATURE
- Software
- Results
- Contact Details
- Name
- Phone number
- Email
- Room number
- Department
- Role
- Other
- Local
- Personas
- Name
- Suggest same 1st name.
- Phone
- Give work mobile, but remember they have it!
- Email
- Have a suitable email address
- Business Cards
- Get cards printed
- Contact Details
- Name
- Phone number
- Email
- Room number
- Department
- Role
- Scenarios
- New IT employee
- New IT employee.
"Hi, I'm the new guy in IT and I've been told to do a quick survey of users on the network. They give all the worst jobs to the new guys don't they? Can you help me out on this?"
Get the following information, try to put a "any problems with it we can help with?" slant on it.
Username
Domain
Remote access (Type - Modem/VPN)
Remote email (OWA)
Most used software?
Any comments about the network?
Any additional software you would like?
What do you think about the security on the network? Password complexity etc.
Now give reasons as to why they have complexity for passwords, try and get someone to give you their password and explain how you can make it more secure.
"Thanks very much and you'll see the results on the company boards soon."
- Fire Inspector
- Turning up on the premise of a snap fire inspection, in line with the local government initiatives on fire safety in the workplace.
Ensure you have a suitable appearance - High visibility jacket - Clipboard - ID card (fake).
Check for:
number of fire extinguishers, pressure, type.
Fire exits, accessibility etc.
Look for any information you can get. Try to get on your own, without supervision!
- Results
- Maps
- Satalitte Imagery
- Google Maps
- Building layouts
- Other
-
Active Web Spider
- htttrack
- teleport pro
- Black Widow
-
Passive
-
สืบค้นจากฐานข้อมูล Whois
- Authoratitive Bodies
- IANA - Internet Assigned Numbers Authority
- ICANN - Internet Corporation for Assigned Names and Numbers.
- NRO - Number Resource Organisation
- RIR - Regional Internet Registry
- AFRINIC - African Network Information Centre
- APNIC - Asia Pacific Network Information Centre
- National Internet Registry
- APJII
- CNNIC
- JPNIC
- KRNIC
- TWNIC
- VNNIC
- ARIN - American Registry for Internet Numbers
- LACNIC - Latin America & Caribbean Network Information Centre
- RIPE - Reseaux IP Européens—Network Coordination Centre
-
Internet Search
- General Information
- Web Investigator
- Tracesmart
- Friends Reunited
- Ebay - profiles etc.
- Financial
- EDGAR - Company information, including real-time filings. US
- Google Finance - General Finance Portal
- Hoovers - Business Intelligence, Insight and Results. US and UK
- Companies House UK
- Land Registry UK
- Phone book/ Electoral Role Information
- 411 - Online White Pages and Yellow Pages. US
- Abika - Background Check, Phone Number Lookup, Trace email, Criminal record, Find People, cell phone number search, License Plate Search. US
- Zabasearch - People Search Engine. US
- 192.com - Electoral Role Search. UK
- BT.com. UK
- Residential
- Business
- Google Hacking Database
- Code Search
- Generic Web Searching
- Linked To
- (See also Kartoo)
- Linked From
- (See also Kartoo)
- Forum Entries
- Email Addresses
- Contact Details
- Newsgroups/forums
- Back end files
- .exe / .txt / .doc / .ppt / .pdf / .vbs / .pl /
.sh / .bat / .sql / .xls / .mdb / .conf
- Metagoofil
- metagoofil.py -d [domain] -l [no. of] -f [type] -o results.html
- Social/ Business Networks
- The following sites are some of many social and business realted networking entities that are in use today. This list is not exhaustive and has been limited to those with over 1 million members.
- Africa
- BlackPlanet
- Australia
- Bebo
- Belgium
- Netlog
- Holland
- Hyves
- Hungary
- iWiW
- Iran
- Cloob
- Japan
- Mixi
- Korea
- CyWorld
- Poland
- Grono
- Nasza-klasa
- Russia
- Odnoklassniki
- Vkontakte
- Sweden
- LunarStorm
- UK
- FriendsReunited et al
- Badoo
- FaceParty
- US
- Facebook
- MySpace
- Classmates
- Friendster
- Assorted
- Linkedin
- Care2
- Habbo
- Hi5
- MocoSpace
- Orkut
- Passado
- Tagged
- Windows Live Spaces
- Yahoo! 360°
-
Dumpster Diving
- Rubbish Bins
- Contract Waste Removal
- Ebay ex-stock sales i.e. HDD
- Passive Web Spider
-
เครื่องมือในการสืบค้น
- Websites
- DNS Stuff
- Online DNS one-stop shop, with the ability to perform a great deal of disparate DNS type queries.
- Fixed Orbit
- Autonomous System lookups and other online tools available.
- MyIPNeighbors.com
- Excellent site that gives you details of shared domains on the IP queried/ conversely IP to DNS resolution
- Geektools
- IP2Location
- Allows limited free IP lookups to be performed, displaying geolocation information, ISP details and other pertinent information.
- Kartoo
- Metasearch engine that visually presents its results.
- Netcraft
- Online search tool allowing queries for host information.
- Robtex
- Excellent website allowing DNS and AS lookups to be performed with a graphical display of the results with pointers, A, MX records and AS connectivity displayed.
- Note: - Can be unreliable with old entries (Use CentralOps to verify)
- Traceroute.org
- Website listing a large number links to online traceroute resources.
- Wayback Machine
- Stores older versions of websites, making it a good comparison tool and excellent resource for previously removed data.
- Central Ops
- Domain Dossier
- Email Dossier
- Whois.net
- Applications/Utilities
- Maltego
- It is a great online resource for carrying out initial footprinting of your target network. It can be utilised in searching for the following: People, Groups of people (social networks), Companies, Organizations, Web sites, (including Domain and DNS details, Netblocks and IP addresses), Phrases, Affiliations, Documents and files
- Country whois
- Cheops-ng
- Domain Research Tool
- Firefox Plugins
- AS Number
- Shazou
- Firecat Suite
- Gnetutil
- Goolag Scanner
- Greenwich
- GTWhois
- Sam Spade
- Smart whois
- SpiderFoot
-
Scanning
- Active
- Passive
- Enumeration
- Gaining Access
- Escalation Privilege
- Maintaining Access
- Covering Tracks