Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Now, in the previous lecture we had a quick look on Zenmap 2
2
and how it can be used to gather information. 3
3
So in this lecture we'll build up on that, 4
4
and the main scan that I wanna show you right now 5
5
is the quick scan plus. 6
6
This scan takes the quick scan one step further. 7
7
So first of all it'll be slower, 8
8
but it's going to show us even more information. 9
9
So first we're gonna be able to see the operating system 10
10
running on the discovered devices. 11
11
We will also be able to see the device type, 12
12
whether it's a phone or a laptop or a router, 13
13
and we'll be able to discover the program, 14
14
and the program version running on the discovered ports. 15
15
So before for example, 16
16
we were able to discover port 80 is open, 17
17
but we didn't know what program is running on this port 18
18
or what version of this program. 19
19
Getting the exact program version is really helpful 20
20
when we get to the gaining access section, 21
21
and you'll see then how we can use that 22
22
to exploit vulnerable services 23
23
and gain full control over the computers 24
24
that have these services installed. 25
25
Now straight away when you look at the results, 26
26
you'll se that we got much more information 27
27
than all of the scans we ran so far. 28
28
So the first thing you'll notice is the icons 29
29
beside the IPs of the discovered devices. 30
30
These icons represent the operating system 31
31
running on these devices. 32
32
So right now we have the operating system 33
33
for all of the connected devices, 34
34
and now it's shown us the programs running 35
35
on each of the discovered ports 36
36
and the versions of these programs. 37
37
So for example if we look at the 191.168.1.12, 38
38
the Apple device, 39
39
on the last scan we knew that port 22 open 40
40
and we knew that SSH is running on it, 41
41
but we didn't know what version of SSH was running. 42
42
Right now we can see that it's running open SSH version 6.1, 43
43
so we can go on Google and look for exploits 44
44
and vulnerabilities in this specific version, 45
45
and we might actually find something. 46
46
We'll actually talk more about that 47
47
in the "gaining access" section. 48
48
Now if you look at the device type, 49
49
you can see that it's a media device; it's a phone. 50
50
So before we knew this is an Apple device 51
51
but we didn't know whether it's a tablet, 52
52
a phone, or a MacBook. 53
53
Right now we know that it is a phone. 54
54
It's also discovering that it's running 55
55
Apple iOS four, five or six. 56
56
Now it's actually running a newer version of iOS, 57
57
I'm not entirely sure, I think nine or 10, 58
58
but still, it's close enough it's getting me. 59
59
It's telling me it's an Apple. 60
60
It's telling me that it's a phone, it's running iOS. 61
61
So this is really really good. 62
62
Now if we go to the next device here, the 192.168.1.20. 63
63
This is a Linux device and when we run the quick scan 64
64
we are able to identify port 80 and port 49152 open, 65
65
but again, we didn't know the program running 66
66
or the service version running on this port. 67
67
So right now we know it's a Apache httpd 2.2.22, 68
68
it's running on Ubuntu so again 69
69
now we have the operating system, 70
70
the exact version of the service running 71
71
so we can go and look for weaknesses and exploits 72
72
in this specific version. 73
73
And this port, we didn't even know 74
74
what service was running on it. 75
75
Right now we know it's a UPnP service 76
76
and the server is MediaTomb UPnP. 77
77
We have the exact version again 78
78
so again we can go ahead and look for exploits 79
79
in these specific versions, 80
80
and if we discover any we'll be able 81
81
to gain full control on this computer. 82
82
Again if we go down to the 192.168.1.22 machine we can see 83
83
that it's running a Microsoft HTTPAPI, on port 5357. 84
84
You can also browse by the services. 85
85
So from here on the left if you click on services 86
86
you'll be able to categorize the discovered clients 87
87
based on the services. 88
88
So if we click on http we'll see all the clients 89
89
that have a http service running. 90
90
If you click on ssh we can see the Apple device here. 91
91
It's the only device that has a ssh service running. 92
92
So let me actually show you a quick and fun example. 93
93
If we go back here to the hosts 94
94
and go back to the apple device, the 192.168.1.12. 95
95
As we see and as I said we know it's a phone, 96
96
we know it's an Apple phone, 97
97
we know that it has an ssh service installed on it 98
98
running on port 22, and we know that ssh is a service 99
99
that allows you to remotely execute system commands 100
100
on the computer that has the ssh service installed. 101
101
Now obviously before you can use this service 102
102
you have to use a username and a password. 103
103
Once you authenticate it will allow you to execute 104
104
system commands remotely on that computer or on that phone. 105
105
Now by default iOS devices do not have an ssh server. 106
106
Usually when you jailbreak the phone or the device 107
107
it will automatically install an ssh server 108
108
and the password for that server 109
109
is set to "alpine", by default. 110
110
That's A-L-P-I-N-E. 111
111
Now since we know that this is an iPhone 112
112
and it has port 22 open with open ssh server, 113
113
we know that that this phone has been jailbroken. 114
114
Now since the phone is jailbroken, 115
115
we know the password to log into ssh is "alpine" 116
116
unless the user changed it. 117
117
Now most users do not even know about this, 118
118
and even the ones that know about this, 119
119
like myself, are too lazy to change it. 120
120
So it's always worth a try if you discover 121
121
a phone like this in the same network. 122
122
It's always worth a try to go and try 123
123
to connect to it with the default password. 124
124
So I'm just gonna go to my terminal 125
125
and I'm gonna try to connect to this phone using ssh. 126
126
So I'm gonna type "ssh root", 127
127
which is the username for the admin in Linux, 128
128
"@192.168.1.12". This is the IP of the phone. 129
129
I'm gonna hit enter. 130
130
It's asking me if I should trust this connection, 131
131
I'm gonna say yes, and now it's asking me for the password. 132
132
And like I said, when the phone is jailbroken 133
133
the password is set to "alpine". 134
134
So I'm gonna type A-L-P-I-N-E. 135
135
I'm gonna hit enter. 136
136
And as you can see, I logged in as root. 137
137
So right now I have the highest privileges on the phone 138
138
and I can do whatever I want on the system. 139
139
And now we can use system commands 140
140
to completely control the phone. 141
141
Now this is a little bit ahead of time, 142
142
we are still in the "network hacking" section, 143
143
so don't worry too much about this, 144
144
we'll talk more about it in the "gaining access" section, 145
145
but it's just a quick example that I wanted to show you 146
146
of how powerful information gathering is, 147
147
because we literally did not exploit anything right here, 148
148
we just relied on the information we gathered 149
149
and we were able to hack an iPhone 150
150
that is connected to the same network as us. 151
151
Now like I said Nmap is a huge tool. 152
152
I highly recommend you go ahead 153
153
and try the other profiles in here, 154
154
and like I said, once done with the course, 155
155
I think the Nmap book would be a really really good read. 156
156
We'll also use Nmap much more in the 157
157
"gaining access" section and we'll see how we can use 158
158
this information to gain full control over the computers 159
159
using code execution vulnerabilities and so on. 160
160
But in this lecture I just wanted to give you 161
161
a quick overview and we'll build up on this 162
162
as we go through the course.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.