All language subtitles for 4. Gathering More Sensitive Info (Running Services, Operating System....etc)

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic Download
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranî)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1 1

Now, in the previous lecture we had a quick look on Zenmap 2

2

and how it can be used to gather information. 3

3

So in this lecture we'll build up on that, 4

4

and the main scan that I wanna show you right now 5

5

is the quick scan plus. 6

6

This scan takes the quick scan one step further. 7

7

So first of all it'll be slower, 8

8

but it's going to show us even more information. 9

9

So first we're gonna be able to see the operating system 10

10

running on the discovered devices. 11

11

We will also be able to see the device type, 12

12

whether it's a phone or a laptop or a router, 13

13

and we'll be able to discover the program, 14

14

and the program version running on the discovered ports. 15

15

So before for example, 16

16

we were able to discover port 80 is open, 17

17

but we didn't know what program is running on this port 18

18

or what version of this program. 19

19

Getting the exact program version is really helpful 20

20

when we get to the gaining access section, 21

21

and you'll see then how we can use that 22

22

to exploit vulnerable services 23

23

and gain full control over the computers 24

24

that have these services installed. 25

25

Now straight away when you look at the results, 26

26

you'll se that we got much more information 27

27

than all of the scans we ran so far. 28

28

So the first thing you'll notice is the icons 29

29

beside the IPs of the discovered devices. 30

30

These icons represent the operating system 31

31

running on these devices. 32

32

So right now we have the operating system 33

33

for all of the connected devices, 34

34

and now it's shown us the programs running 35

35

on each of the discovered ports 36

36

and the versions of these programs. 37

37

So for example if we look at the 191.168.1.12, 38

38

the Apple device, 39

39

on the last scan we knew that port 22 open 40

40

and we knew that SSH is running on it, 41

41

but we didn't know what version of SSH was running. 42

42

Right now we can see that it's running open SSH version 6.1, 43

43

so we can go on Google and look for exploits 44

44

and vulnerabilities in this specific version, 45

45

and we might actually find something. 46

46

We'll actually talk more about that 47

47

in the "gaining access" section. 48

48

Now if you look at the device type, 49

49

you can see that it's a media device; it's a phone. 50

50

So before we knew this is an Apple device 51

51

but we didn't know whether it's a tablet, 52

52

a phone, or a MacBook. 53

53

Right now we know that it is a phone. 54

54

It's also discovering that it's running 55

55

Apple iOS four, five or six. 56

56

Now it's actually running a newer version of iOS, 57

57

I'm not entirely sure, I think nine or 10, 58

58

but still, it's close enough it's getting me. 59

59

It's telling me it's an Apple. 60

60

It's telling me that it's a phone, it's running iOS. 61

61

So this is really really good. 62

62

Now if we go to the next device here, the 192.168.1.20. 63

63

This is a Linux device and when we run the quick scan 64

64

we are able to identify port 80 and port 49152 open, 65

65

but again, we didn't know the program running 66

66

or the service version running on this port. 67

67

So right now we know it's a Apache httpd 2.2.22, 68

68

it's running on Ubuntu so again 69

69

now we have the operating system, 70

70

the exact version of the service running 71

71

so we can go and look for weaknesses and exploits 72

72

in this specific version. 73

73

And this port, we didn't even know 74

74

what service was running on it. 75

75

Right now we know it's a UPnP service 76

76

and the server is MediaTomb UPnP. 77

77

We have the exact version again 78

78

so again we can go ahead and look for exploits 79

79

in these specific versions, 80

80

and if we discover any we'll be able 81

81

to gain full control on this computer. 82

82

Again if we go down to the 192.168.1.22 machine we can see 83

83

that it's running a Microsoft HTTPAPI, on port 5357. 84

84

You can also browse by the services. 85

85

So from here on the left if you click on services 86

86

you'll be able to categorize the discovered clients 87

87

based on the services. 88

88

So if we click on http we'll see all the clients 89

89

that have a http service running. 90

90

If you click on ssh we can see the Apple device here. 91

91

It's the only device that has a ssh service running. 92

92

So let me actually show you a quick and fun example. 93

93

If we go back here to the hosts 94

94

and go back to the apple device, the 192.168.1.12. 95

95

As we see and as I said we know it's a phone, 96

96

we know it's an Apple phone, 97

97

we know that it has an ssh service installed on it 98

98

running on port 22, and we know that ssh is a service 99

99

that allows you to remotely execute system commands 100

100

on the computer that has the ssh service installed. 101

101

Now obviously before you can use this service 102

102

you have to use a username and a password. 103

103

Once you authenticate it will allow you to execute 104

104

system commands remotely on that computer or on that phone. 105

105

Now by default iOS devices do not have an ssh server. 106

106

Usually when you jailbreak the phone or the device 107

107

it will automatically install an ssh server 108

108

and the password for that server 109

109

is set to "alpine", by default. 110

110

That's A-L-P-I-N-E. 111

111

Now since we know that this is an iPhone 112

112

and it has port 22 open with open ssh server, 113

113

we know that that this phone has been jailbroken. 114

114

Now since the phone is jailbroken, 115

115

we know the password to log into ssh is "alpine" 116

116

unless the user changed it. 117

117

Now most users do not even know about this, 118

118

and even the ones that know about this, 119

119

like myself, are too lazy to change it. 120

120

So it's always worth a try if you discover 121

121

a phone like this in the same network. 122

122

It's always worth a try to go and try 123

123

to connect to it with the default password. 124

124

So I'm just gonna go to my terminal 125

125

and I'm gonna try to connect to this phone using ssh. 126

126

So I'm gonna type "ssh root", 127

127

which is the username for the admin in Linux, 128

128

"@192.168.1.12". This is the IP of the phone. 129

129

I'm gonna hit enter. 130

130

It's asking me if I should trust this connection, 131

131

I'm gonna say yes, and now it's asking me for the password. 132

132

And like I said, when the phone is jailbroken 133

133

the password is set to "alpine". 134

134

So I'm gonna type A-L-P-I-N-E. 135

135

I'm gonna hit enter. 136

136

And as you can see, I logged in as root. 137

137

So right now I have the highest privileges on the phone 138

138

and I can do whatever I want on the system. 139

139

And now we can use system commands 140

140

to completely control the phone. 141

141

Now this is a little bit ahead of time, 142

142

we are still in the "network hacking" section, 143

143

so don't worry too much about this, 144

144

we'll talk more about it in the "gaining access" section, 145

145

but it's just a quick example that I wanted to show you 146

146

of how powerful information gathering is, 147

147

because we literally did not exploit anything right here, 148

148

we just relied on the information we gathered 149

149

and we were able to hack an iPhone 150

150

that is connected to the same network as us. 151

151

Now like I said Nmap is a huge tool. 152

152

I highly recommend you go ahead 153

153

and try the other profiles in here, 154

154

and like I said, once done with the course, 155

155

I think the Nmap book would be a really really good read. 156

156

We'll also use Nmap much more in the 157

157

"gaining access" section and we'll see how we can use 158

158

this information to gain full control over the computers 159

159

using code execution vulnerabilities and so on. 160

160

But in this lecture I just wanted to give you 161

161

a quick overview and we'll build up on this 162

162

as we go through the course.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.