Lesson 6 - Scanning Logical Vulnerabilities Flashcards
Apply knowledge of network topology and scan identified targets using a variety of techniques, such as stealth and TCP full connect scans. Compile data on network traffic by gathering API requests and responses and ARP traffic while using tools such as Wireshark and Nessus. Produce reports on wireless assets by using tools and techniques that include Wireless Geographic Logging Engine (WiGLE) and wardriving.
What is another name for a discovery scan used during reconnaissance to find hosts on a network to reveal potential target also called and what tools is commonly used
Ping Sweep
Nmap
nmap -sn -v 192.168.1.0/24
What flag on nMap for the following:
What Flag that foregoes Host discovery
-Pn
What is a common vulnerability to search for in an API
API Key
What is the testing that is done early in the SDLC
Static Application Security Testing
Testing that is done after code is place into production and is able to find production vulnerabiliteis
Dynamic Application Security Testing
What is the NIST Framework that outlines various accpeted practices for automating vulnerability scanning
Security Content Automation Protocol (SCAP)
During the process of packet sniffing where does the device conducting the packet capture need to sit on the LAN
SPAN Port
Switched Port Analysis - allows for copying ingress/egress communication from all switch ports.
Also called port mirroring
Sniffer interface must be in promiscuous mode
What is a good protocol to examine to find details such as network hosts information. What is the attack based on that protocol
Netbios
NetBIOS Name Service (NBNS) - an attack where an attacker responds to a request for a name service resolution over NetBIOS
In PCI DSS you must have cardholder data segmented. What is the term for that
Cardholder Data Environment (CDE)
Why would ARP traffice be valuable to a hacker and what are its limitations?
They can launch an ARP Poisoning mapping an incorrect MAC addres to a correct one. Common Spoofing techniques.
Name the common tools to search for open WAPs
Aircrak-ng
Kisment
Wifite
What is the site that is dedicated to mapping and indexing access points and what type of tool would it be considered
WiGLE
OSINT Tool
Open AP’s are labeled - Free Love
What is the measurement of a wireless signal level in relation to background noise and how is signal strength measures
Signal to Noise Ratio (SNR)
decibels per isotripic (dBi)