|
|||||||||||
|
Re: A little Help with Pen Testing My systems!
From: <miguel.dilaj(at)pharma.novartis.com>
Date: Wed Mar 12 2003 - 04:10:14 EST
To: pen-test@securityfocus.com
cc:
Subject: A little Help with Pen Testing My systems!
Hi Mike >I have set up a little network at home, for "my own Penetration Testing
Cool. Good for practice ;-)
First: the right order is vulnerabilities, then xploits (if they're
available).
>installed SYGATE with default settings on Windows XP machine, Went over
Just a comment. Never used SYGATE myself. >Linux and ran a NMAP scan:
That seems to be good. >So then tryed NESSUS against this machine and got back:
USUALLY 123 is NTP (Network Time Protocol), dunno if XP has this open for different purposes (you can never trust Micro$oft ;-) >But if it is behind a firewall can it still be exploited???and would
Let me explain. In the nmap scan above you did a SYN scan, that's TCP.
Nessus detected 123/udp open, not TCP.
>Than i installed zonealarm and searched for exploits on it and found this
>nmap exploit and ran an NMAP scan like this:
Sorry, this is not a xploit. This is just a way to use nmap (source port scanning). Has NOTHING to do with a xploit. >nmap -g67 -P0 -sS 111.11.111.111
>and run that against the Firewalled machine too see what happens.
No, just try to use nmap's 'UDP scan'. >I also remember Windows XP installs MSN Messenger by default. Soo i
Sorry again, this is Windows Messenger, and has nothing to do with MSN Messenger... Didn't know this link, thanks! >And i ran the test with SYGATE firewall enabled, and a POP-WINDOW POPPED
Could be that you'r firewall isn't protecting you in the right way? Or
perhaps is "stealthing" your ports, but they still answer a proper
request.
>Soo can anyone tell me i DONT mean step by step "but(SUGGESTIONS, IDEAS)"
Get as much information as possible about the target, that include proper port scans, service identification, banner grabbing, etc. Do some search about the services available, to detect those with vulnerabilities (Nesuss can help, but beware of false positives). Check if those with vulnerabilities have xploits available. Got information about the xploits, and the xploits themselves if they're programs. Create a situation similar to your target in your lab. TEST all the xploits and techniques in your lab, until both you're confident, and you what works and what won't work. USE the working xploits on the target. >ENOUGH.. I want to test HPING against it too but there are just soo many
I think that you're trying to get all the information at once, and are
getting confused. Go slowly, step by step. I'm here right now, but I
started with computerized systems in 1982, and with IT security around
1997.
>would some of you approach something like this: im really trying to get
>found this code also for bypassing firewalls but dont understand it, i
I'll try to visit this link later. >Thanks Mike
I'll suggest that you put your hands on the excellent book "Hacking
Exposed, 4th edition".
Nekromancer
Are your vulnerability scans producing just another report?
Manage the entire remediation process with StillSecure VAM's
Vulnerability Repair Workflow.
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:34 EDT |
||||||||||
|
|||||||||||