Web Hacking & Penetration testing.pdf

(9481 KB) Pobierz
Web Hacking
KSAJ Inc.
www.PENETRATIONTEST.com
HaX0rz Toolkit
Complicated ‘sploits that need a
Bachelor’s degree to understand and
use
Scripts in various languages and
syntaxes like C, PERL, gtk and bash
Automated scanning tools like nmap
and nessus
A web browser
A Web Browser?
Web surfing:
• Is easy to do,
• Is Operating System independent,
• Doesn’t require intimate knowledge of
“the system”,
• Provides access to vast amounts of data
and information,
• and topped off with all kinds of data
mining tools
Web Features
Reverse phone number searches
Detailed address topological maps
Satellite photography of target area
Resumes
Phone and Email lists
Likely targets described in detail
Exploit information easy to obtain
Data aggregation makes it more serious
What We’ll Learn
Methods of Reconnaissance
The level of sensitive detail
companies and organizations leave
exposed to the Internet
The level of detail about specific
people on the Internet
The effect of data aggregation on
privacy
Zgłoś jeśli naruszono regulamin