Module 5 - Active Data Gathering and Network Scans I Flashcards
Wireless Network Vulnerabilities
Service Set ID (SSID) (broadcast or not)
can intercept regardless
WEP - easily defeated
WPA - can be defeated
once in - inside LAN
Tools for wireless network
Kismet
NetStumbler
Pineapple Router (trick people connect to rogue)
Vulnerability Scanners
GFI LanGuard
Microsoft Security Baseline Analyzer
Nessus
NeXpose
Web App Tester
Burp Suite
(free version - limited)
Profession - $299 per user per year
Sniffers
capture network traffic
info transmitted in clear
hardware (hub, port mirroring, port spanning)
Wireshark
can sniff Fiber Optics (~$1000)
Nessus
Tenable ~$1200 per year HomeFeed is free 46,000 plugins Server Manager and Client
Nessus Tabs
Users
Policies
Scans
Reports
Nessus Default Policies
External Network Scan
Internal Network Scan
Prepare for PCI DNS audits
Web App Tests
Nessus Port Scanners
TCP UDP SYN SNMP Netstat SSH Scan Netstat WMI Scan Ping
Nessus Policy Options
General
Credentials
Plugins
Preferences
Avoid Sequential Scans
Nessus Severity levels
High
Medium
Low
Nessus download options
.nessus
HTML
RTF
Vulnerability Scans
establish connection between an open port and a vulnerable application or configuration setting behind it.
NeXpose
Rapid7 Windows 2003 Server integrates with Metasploit Community Edition (free) Express ($3000 per user per year) Professional ($6999 per user per year)
Nexpose Port
3780