EH-Basic Hacking Techniques
EH-Basic Hacking Techniques
EH-Basic Hacking Techniques
Michael Jones
Review
All computer systems are under attack
from inside and outside
Security = countermeasures and
mitigations
White hat hackers are testing security
with permission
Grey hat hackers claim to test security
for the common good
Black hat hackers aim to reach security
for profit or other gain
Michael Jones
Michael Jones
Enumeration
Mapping in detail
Planning
Identifying the where, when, how, how long
Execution
Analysis & evaluation
Layer Selection
Footprinting and enumeration may
occur at more than one level
Selection of layer will depend on:
Nature of targets security
Skills available
Time available
Nature of attack
Michael Jones
Michael Jones
Attack mechanisms
Viruses, trojans
Michael Jones
Attacks on Applications
Examples:
Word macros
VBA in general
JavaScript in PDF etc.
Michael Jones
Social Layer
Social engineering
Short or long term (sleepers)
Blackmail or grooming
Grooming
one sided develop trust between
mark and attackers
two sided also reduce trust between
mark and his/her support network
Michael Jones
10
11
Non-repudiation
Critical in electronic commerce
Sender cannot deny (repudiate)
sending a message
Receiver cannot repudiate having
received a message
NOTE: potential for message to be
sent multiple times
Michael Jones
12
13
14
Issues
Rules of engagement, handling reporting
Michael Jones
15
OSSTMM Categories
Vulnerability
Affects access
Weakness
Affects interactivity controls, e.g.,
authentication
Concern
Affects one or more of PANIC principles
Exposure
Increase of visibility
Anomaly
Other
Michael Jones
16
Diagnostics
Gathering data about the processes
and procedures
What worked and why
What did not work and why
Problems:
Accuracy of documentation
Completeness of documentation
Time involved
Motivation
Michael Jones
17
Summary
Ethical hackers conduct pen(etration)
tests
Black hat hackers simply attack
Issue: handling mitigations
Compare with: fire drills
How realistic can these be if they are
planned?
What if not planned and an irreversible
change has taken place?
Michael Jones
18