Hacking for Dummies 3rd edition - Sample Chapter 4.pdf

(954 KB) Pobierz
Hacking For Dummies
rd
3 Edition
Chapter 4
Hacking Methodology
ISBN: 978-0-470-55093-9
Copyright of Wiley Publishing, Inc.
Indianapolis, Indiana
Posted with Permission
Chapter 4
Hacking Methodology
In This Chapter
Examining steps for successful ethical hacking
Gleaning information about your organization from the Internet
Scanning your network
Looking for vulnerabilities
efore you dive in head first with your ethical hacking, it’s critical
to have at least a basic methodology to work from. Ethical hacking
involves more than just penetrating and patching a system or network.
Proven techniques can help guide you along the hacking highway and ensure
that you end up at the right destination. Using a methodology that supports
your ethical hacking goals separates the professionals from the amateurs and
helps ensure that you make the most of your time and effort.
B
Setting the Stage for Testing
In the past a lot of ethical hacking involved manual processes. Now, tools can
automate various tasks. These tools allow you to focus on performing the tests
and less on the specific steps involved. However, following a general methodol-
ogy and understanding what’s going on behind the scenes will help you.
Ethical hacking is similar to beta testing software. Think logically — like a
programmer, a radiologist, or a home inspector — to dissect and interact
with all the system components to see how they work. You gather informa-
tion, often in many small pieces, and assemble the pieces of the puzzle. You
start at point A with several goals in mind, run your tests (repeating many
steps along the way), and move closer until you discover security vulnerabili-
ties at point B.
46
Part I: Building the Foundation for Ethical Hacking
The process used for ethical hacking is basically the same as the one a mali-
cious attacker would use — the primary differences lie in the goals and how
you achieve them. Another key difference is that you, as an ethical hacker,
will eventually attempt to assess
all
your information systems for vulnerabili-
ties and properly address them, rather than run a single exploit or attack a
small number of systems. Today’s attacks can come from any angle against
any system, not just from the perimeter of your network and the Internet
as you might have been taught in the past. Test every possible entry point,
including partner, vendor, and client networks, as well as home users, wire-
less LANs, and laptop computers. Any human being, computer system, or
physical component that protects your computer systems — both inside and
outside your buildings — is fair game.
When you start rolling with your ethical hacking, keep a log of the tests you
perform, the tools you use, the systems you test, and your results. This infor-
mation can help you do the following:
Track what worked in previous tests and why.
Help prove that you didn’t maliciously hack the systems.
Correlate your testing with intrusion detection systems and other log
files if trouble or questions arise.
Document your final report.
In addition to taking general notes, taking screen captures of your results
whenever possible is also helpful. These shots come in handy later should
you need to show proof of what occurred, and they also will be useful as
you generate your final report. Also, depending on the tools you use, these
screen captures might be your only evidence of vulnerabilities or exploits
when it comes time to write your final report. Chapter 3 lists the general steps
involved in creating and documenting an ethical hacking plan.
Your main task is to simulate the information gathering and system com-
promises carried out by someone with malicious intent. This task can be a
partial attack on one computer or it can constitute a comprehensive attack
against the entire network. Generally, you look for weaknesses that mali-
cious users and external attackers might exploit. You want to assess inter-
nal systems (processes and procedures that involve computers, networks,
people, and physical infrastructures). Look for vulnerabilities; check how all
your systems interconnect and how private systems and information are (or
aren’t) protected from untrusted elements.
These steps don’t include specific information on the low-tech hacking meth-
ods that you use for social engineering and assessing physical security, but
the techniques are basically the same. I cover these methods in more detail
in Chapters 5 and 6.
Chapter 4: Hacking Methodology
If you’re performing ethical hacking for a client, you may go the blind assessment
route and start with just the company name and no other information. This blind
assessment approach allows you to start from the ground up and gives you a
better sense of the information and systems that malicious attackers can access
publicly. However, keep in mind that this way of testing can take longer, and you
may have an increased chance of missing some security vulnerabilities.
As an ethical hacker, you might not have to worry about covering your tracks
or evading intrusion detection systems because everything you do is legiti-
mate. But you might want to test systems stealthily. I discuss techniques that
hackers use to conceal their actions in this book and outline some counter-
measures for them, as well.
47
Seeing What Others See
Getting an outside look can turn up a ton of information about your organiza-
tion and systems that others can see, through a process often called
footprint-
ing.
Here’s how to gather the information:
Use a Web browser to search for information about your organization.
Search engines, such as Google and Bing, are great places to start.
Run network scans, probe open ports, and assess vulnerabilities to
determine specific information about your systems. As an insider, you
can use port scanners and Windows share-finder tools, such as GFI
LANguard, to see what’s accessible.
Whether you search generally or probe more technically, limit the amount of
information you gather based on what’s reasonable for you. You might spend
an hour, a day, or a week gathering this information — how much time you
spend depends on the size of the organization and the complexity of its infor-
mation systems.
Gathering public information
The amount of information you can gather about an organization’s business
and information systems is staggering and widely available on the Internet.
Your job is to find out what’s out there. This information allows malicious
attackers and employees to target specific areas of the organization, includ-
ing departments and key individuals.
The following techniques can be used to gather information about your
organization.
Zgłoś jeśli naruszono regulamin