Tutorials of How to Use Metasploit, Nessus and Nmap

Total Page:16

File Type:pdf, Size:1020Kb

Tutorials of How to Use Metasploit, Nessus and Nmap Tutorials of how to use Metasploit, Nessus and Nmap Obed A. Adames Méndez Computer Engineering Jeffrey L. Duffany, Ph.D. Computer Engineering Polytechnic University of Puerto Rico Abstract This paper is in support of three newly Confidentiality is also known as secrecy or privacy; created tutorials, focused on different Security and breaches of confidentiality range from the Penetration testing tools. The tutorials have been embarrassing to the disastrous. Integrity means that selected to cover three different areas in the information is protected against unauthorized security and penetration field. These tutorials are changes that are not detectable to authorized users; will provide basic understanding on the many incidents of hacking compromise the functionalities and capabilities of each particular integrity of databases and other resources. tool. Authentication means that users are who they claim Currently there are many different ways to to be. Availability means that resources are protect our systems. However none of them are accessible by authorized parties; "denial of service" 100% secure. We may have severe vulnerabilities attacks, which are sometimes the topic of national in our system and may not be aware of it. Testing news, are attacks against availability. Other our systems for vulnerabilities is something that we important concerns of computer security should not overlook. professionals are access control and The purposed of these tutorials is to give an nonrepudiation. Maintaining access control means overview of the free security tools that are not only that users can access only those resources available and that we can use to verify the integrity and services to which they are entitled, but also that and the security of a network. We will also they are not denied resources that they legitimately demonstrate how vulnerabilities can be exploited can expect to access. Nonrepudiation implies that a using this tools. person who sends a message cannot deny that he Key Terms Computer Security, Network sent it and, conversely, that a person who has Scan, Penetration Testing, Vulnerability. received a message cannot deny that he received it. In addition to these technical aspects, the INTRODUCTION conceptual reach of computer security is broad and multifaceted. Computer security touches draws The term computer security is used frequently, from disciplines as ethics and risk analysis, and is but the content of a computer is vulnerable to few concerned with topics such as computer crime; the risks unless the computer is connected to other prevention, detection, and remediation of attacks; computers on a network. As the use of computer and identity and anonymity in cyberspace. networks, especially the Internet, has become What is penetration testing? Penetration pervasive, the concept of computer security has testing, often called “pentesting”, “pen testing”, or expanded to denote issues pertaining to the “security testing”, is the practice of attacking your networked use of computers and their resources. own or your clients’ IT systems in the same way a The major technical areas of computer security hacker would to identify security holes. Of course, are usually represented by the initials CIA: you do this without actually harming the network. confidentiality, integrity, and authentication or The person carrying out a penetration test is called availability. Confidentiality means that information a penetration tester or pentester.[1] cannot be access by unauthorized parties. The purpose of the newly created tutorials is to interference with the scan) during the run. Also, provide a basic understanding to new computer owing to the large and active user community security tools users on how computer security providing feedback and contributing to its features, works. The tutorials will provide users with the Nmap has been able to extend its discovery description of the graphical user interface, console capabilities beyond simply figuring out whether a applications, examples of how to employ the tool, host is up or down and which ports are open and and practical exercises. closed; it can determine the operating system of the The tutorials are designed around three security target, names and versions of the listening services, tools which are described as follows: estimated uptime, type of device, and presence of a Nmap: (Network Mapper) is a security scanner firewall. used to discover hosts and services on a Nmap features include: computer network, thus creating a "map" of the Host Discovery - Identifying hosts on a network. network. For example, listing the hosts which Nessus: is a proprietary comprehensive respond to pings or have a particular port open. vulnerability scanning program. It is free of Port Scanning - Enumerating the open ports on charge for personal use in a non-enterprise one or more target hosts. environment. Its goal is to detect potential Version Detection - Interrogating listening vulnerabilities on the tested systems. network services listening on remote devices to Metasploit: is an open-source, computer determine the application name and version security project which provides information number. about security vulnerabilities and aids in OS Detection - Remotely determining the penetration testing and IDS signature operating system and some hardware development. Its most well-known sub-project characteristics of network devices. is the Metasploit Framework, a tool for Scriptable interaction with the target - using developing and executing exploit code against Nmap Scripting Engine (NSE) and Lua a remote target machine. Other important sub- programming language, customized queries projects include the Opcode Database, can be made. shellcode archive, and security research. In addition to these, Nmap can provide further The Metasploit Project is also well known information on targets, including reverse DNS for anti-forensic and evasion tools, some of names, device types, and MAC addresses. which are built into the Metasploit Framework. Typical uses of Nmap: Auditing the security of a device by identifying NMAP the network connections which can be made to Nmap (Network Mapper) is a security scanner it. originally written by Gordon Lyon (also known by Identifying open ports on a target host in his pseudonym Fyodor Vaskovich)[2] used to preparation for auditing. discover hosts and services on a computer network, Network inventory, Network mapping, thus creating a "map" of the network. To maintenance, and asset management. accomplish its goal, Nmap sends specially crafted Auditing the security of a network by packets to the target host and then analyzes the identifying unexpected new servers. responses. Unlike many simple port scanners that just send packets at some predefined constant rate, Nmap is used to discover computers and Nmap accounts for the network conditions (latency services on a computer network, thus creating a fluctuations, network congestion, the target "map" of the network. Just like many simple port scanners, Nmap is capable of discovering passive NESSUS services on a network, despite the fact that such Nessus is the world’s most widely-deployed services aren't advertising themselves with a service vulnerability and configuration assessment product discovery protocol. In addition, Nmap may be able with more than five million downloads to date. to determine various details about the remote Nessus 5[5] features high-speed discovery, computers. configuration auditing, asset profiling, sensitive Like most tools used in computer security, data discovery, patch management integration, and Nmap can be used for black hat hacking, or vulnerability analysis of your security posture with attempting to gain unauthorized access to computer features that enhance usability, effectiveness, systems. It would typically be used to discover efficiency, and communication with all parts of open ports which are likely to be running your organization. vulnerable services, in preparation for attacking The Nessus tool works a little differently than those services with another program.[3] System other scanners. Rather than purporting to offer a administrators often use Nmap to search for single, all-encompassing vulnerability database that unauthorized servers on their network, or for gets updated regularly, Nessus supports the Nessus computers which don't meet the organization's Attack Scripting Language (NASL), which allows minimum level of security.[4] Nmap is often security professionals to use a simple language to confused with host vulnerability assessment tools describe individual attacks. Nessus administrators such as Nessus, which go further in their then simply include the NASL descriptions of all exploration of a target by testing for common desired vulnerabilities to develop their own vulnerabilities in the open ports found. In some customized scans. jurisdictions unauthorized port scanning may be Nessus is an open-source network vulnerability illegal. scanner that uses the Common Vulnerabilities and To use Nmap you must open the command Exposures architecture for easy cross-linking prompt windows with administrator privilege see between compliant security tools. Nessus employs Figure 1. the Nessus Attack Scripting Language (NASL), a simple language that describes individual threats and potential attacks. Nessus has a modular architecture consisting of centralized servers that conduct scanning, and remote clients that allow for administrator interaction. Administrators can include
Recommended publications
  • Oracle with Metasploit
    Oracle Penetration Testing Using the Metasploit Framework Chris Gates & Mario Ceballos Metasploit Project Abstract Over the years there have been tons of Oracle exploits, SQL Injection vulnerabilities, and post exploitation tricks and tools that had no order, methodology, or standardization, mainly just random .sql files. Additionally, none of the publicly available Pentest Frameworks have the ability to leverage built- in package SQL Injection vulnerabilities for privilege escalation, data extraction, or getting operating system access. In this whitepaper we will present an Oracle Pentesting Methodology and give you all the tools to break the "unbreakable" Oracle as Metasploit auxiliary modules. We've created your version and SID enumeration modules, account bruteforcing modules, ported all the public (and not so public) Oracle SQL Injection vulnerabilities into SQLI modules (with IDS evasion examples for 10g/11g), modules for OS interaction, and modules for automating some of our post exploitation tasks. The modules are currently only supported under Linux and OSX. Oracle Penetration Testing Methodology Locate a system running Oracle. Determine Oracle Version. Determine Oracle SID. Guess/Bruteforce USERNAME/PASS. Privilege Escalation via SQL Injection. Manipulate Data/Post Exploitation. Cover Tracks. Locating an Oracle System You will typically find most Oracle installations by performing port scanning in the target netblock. The Oracle listener default port is 1521 but can listen on an port generally in the 1521-1540 range. You can also discover oracle instances by scanning other common Oracle ports. Review http://www.red- database-security.com/whitepaper/oracle_default_ports.html for common Oracle ports. Generally running a service scan will NOT give you the Oracle TNS Listener version but updated fingerprints for new versions of Nmap may yield versions in some situations.
    [Show full text]
  • Final Project Report
    FINAL REPORT The OS Security Showdown Ciara Dunleavy C00217731 Supervisor Paul J. Barry 30th April 2021 Contents Introduction ............................................................................................................................................ 2 Description of Submitted Project............................................................................................................ 3 Description of Conformance to Specification and Design ...................................................................... 5 Description of Learning ........................................................................................................................... 5 Technical ............................................................................................................................................. 5 Python ............................................................................................................................................. 5 Nmap ............................................................................................................................................... 5 Personal .............................................................................................................................................. 5 Review of Project .................................................................................................................................... 6 Acknowledgements ................................................................................................................................
    [Show full text]
  • Lab 4: Generating, Capturing and Analyzing Network Scanner Traffic
    The Cyber Center for Security and Analytics ZEEK INSTRUSION DETECTION SERIES Lab 4: Generating, Capturing and Analyzing Network Scanner Traffic Document Version: 02-01-2020 Award 1829698 “CyberTraining CIP: Cyberinfrastructure Expertise on High-throughput Networks for Big Science Data Transfers” Lab 4: Generating, Capturing and Analyzing Network Scanner Traffic Contents Overview ............................................................................................................................. 3 Objective ............................................................................................................................. 3 Lab topology........................................................................................................................ 3 Lab settings ......................................................................................................................... 3 Lab roadmap ................................................................................................................... 4 1 Introduction to Internet scanning and probing .......................................................... 4 2 Generating real time network scans ........................................................................... 5 2.1 Starting a new instance of Zeek ........................................................................... 5 2.2 Setting up the Bro2 machine for live network capture ....................................... 6 2.3 Using the Bro1 machine for network scanning activities ...................................
    [Show full text]
  • PDF with Notes
    Wireless Tools Training materials for wireless trainers This talk covers tools that will show you a great deal of information about wireless networks, including network discovery, data logging, security auditing, and spectrum analysis. Version 1.4 by Rob, @2009-11-23 Version 1.5 by Rob, @2010-02-28 Version 1.6 by Rob, @2010-03-12 Goals ‣ The goal of this talk is to provide an introduction to a few software tools that will help you to: ‣ monitor your WiFi network to identify problems ‣ perform security audits and prevent attacks ‣ observe the ongoing performance of your network and plan for future needs ‣ detect interference 2 Types of wireless tools ‣ Network ESSID scanners ‣ Wireless protocol analyzers ‣ Encryption cracking tools ‣ Wireless device auditing and management ‣ “War driving” tools: network mapping ‣ Spectrum analysis 3 Built-in wireless clients 4 If a computer has a wireless card, it has a basic network scanner. NetStumbler http://www.stumbler.net/ 5 NetStumbler was one of the first and most widely used WiFi detection tools. It runs only in Windows XP or Windows 2000, and works with many (but not all) wireless cards. NetStumbler can be used for mapping the coverage of your WiFi network, War Driving, rogue AP detection, aligning antennas on a long distance link, and more. NetStumbler is not open source, and was last updated in 2004. http://www.vistumbler.net/ 6 Vistumbler is an updated open source network detection tool for Windows Vista and Windows 7. It supports many of the same features as NetStumbler, including network detection and GPS integration. It also works with Google Earth to allow realtime WiFi mapping on a live map.
    [Show full text]
  • Software Assurance
    Information Assurance State-of-the-Art Report Technology Analysis Center (IATAC) SOAR (SOAR) July 31, 2007 Data and Analysis Center for Software (DACS) Joint endeavor by IATAC with DACS Software Security Assurance Distribution Statement A E X C E E C L I L V E R N E Approved for public release; C S E I N N I IO DoD Data & Analysis Center for Software NF OR MAT distribution is unlimited. Information Assurance Technology Analysis Center (IATAC) Data and Analysis Center for Software (DACS) Joint endeavor by IATAC with DACS Software Security Assurance State-of-the-Art Report (SOAR) July 31, 2007 IATAC Authors: Karen Mercedes Goertzel Theodore Winograd Holly Lynne McKinley Lyndon Oh Michael Colon DACS Authors: Thomas McGibbon Elaine Fedchak Robert Vienneau Coordinating Editor: Karen Mercedes Goertzel Copy Editors: Margo Goldman Linda Billard Carolyn Quinn Creative Directors: Christina P. McNemar K. Ahnie Jenkins Art Director, Cover, and Book Design: Don Rowe Production: Brad Whitford Illustrations: Dustin Hurt Brad Whitford About the Authors Karen Mercedes Goertzel Information Assurance Technology Analysis Center (IATAC) Karen Mercedes Goertzel is a subject matter expert in software security assurance and information assurance, particularly multilevel secure systems and cross-domain information sharing. She supports the Department of Homeland Security Software Assurance Program and the National Security Agency’s Center for Assured Software, and was lead technologist for 3 years on the Defense Information Systems Agency (DISA) Application Security Program. Ms. Goertzel is currently lead author of a report on the state-of-the-art in software security assurance, and has also led in the creation of state-of-the-art reports for the Department of Defense (DoD) on information assurance and computer network defense technologies and research.
    [Show full text]
  • Metasploit Framework «Back|Track-[IT]
    Metasploit Framework www.backtrack.it «Back|Track-[IT] www.backtrack.it (c) 2009 brigante - fiocinino [email protected] [email protected] Metasploit Framework Metasploit Framework www.backtrack.it Metasploit Framework www.backtrack.it Questo documento è rivolto a tutti coloro che vogliono conoscere cos'é, come viene utilizzato e cosa comporta l' uso del “Metasploit Framework”, parte del Metasploit Project. Metasploit è più di un semplice progetto per la sicurezza informatica, è un vero è proprio insieme di strumenti, (appunto denominato Framework), che ha praticamente rivoluzionato l' intero mondo della sicurezza informatica. Come per la stragrande maggioranza della nostra documentazione verrà, anche in questo documento, dato spazio sia alla parte teorica che alla parte pratica e descrittiva, con svariati esempi e con la descrizione dettagliata alcuni nostri video, reperibili naturalmente dall' apposita sezione del nostro portale. “Che cos'é Metasploit” Metasploit Project nasce con l' intento di fornire informazioni su vulnerabilità, sviluppo di sistemi di rilevamento di intrusioni e semplificare le operazioni di penetration testing. Il sub-project più conosciuto è il Metasploit Framework, un' insieme di strumenti per lo sviluppo e l'esecuzione di exploits, di shellcodes, auxiliary, opcode noto per lo sviluppo di strumenti di elusione ed anti- rilevamento. Uno dei principali Goals del “Metasploit Project” è quello di mirare principalmente a fornire informazioni utili allo sviluppo di nuove tecniche di pentesting e di firme per
    [Show full text]
  • Lab 3: Scanning and Reconnaissance
    CSC 5991 Cyber Security Practice Lab 3: Scanning and Reconnaissance Introduction The key to successfully exploit or intrude a remote system is about the information you have. The first step for penetration is the scanning and reconnaissance. In this lab, you will learn how to use tools to scan and retrieve information from a targeting system. You will be using nmap and OpenVAS to scan a vulnerable machine and identify exploits that can be used to attack it. We will use two Linux virtual machines: One is a Kali Linux with nmap and OpenVAS installed; and the other one is intentionally vulnerable Linux. We will use the nmap and OpenVAS on Kali Linux to scan the vulnerable Linux machine. Software Requirements - The VMWare Software http://apps.eng.wayne.edu/MPStudents/Dreamspark.aspx - The Kali Linux, Penetration Testing Distribution https://www.kali.org/downloads/ - Metasploitable2: Vulnerable Linux Platform http://sourceforge.net/projects/metasploitable/files/Metasploitable2/ - nmap: the Network Mapper - Free Security Scanner https://nmap.org/ - OpenVAS: Open Vulnerability Assessment System http://www.openvas.org/index.html Fengwei Zhang - CSC 5991 Cyber Security Practice 1 Starting the Lab 3 Virtual Machines We need to use two VMs for this lab: the Kali Linux and the Metasploitable2-Linux. First, select the Kali Linux and press Start up Login the Kali Linux with username root, and password [TBA in the class]. Below is the screen snapshot after login. Fengwei Zhang - CSC 5991 Cyber Security Practice 2 Then, you select Metasploitble2-Linux, and press Start up. This is an intentionally vulnerable Linux VM that you will attack against.
    [Show full text]
  • Metasploit Pro User Guide
    4.11 USER GUIDE Getting Started First things first. If you haven't installed Metasploit yet, check out this these instructions if you're a commercial user. Otherwise, if you already have Metasploit installed, congratulations! You've come to the right place to get started. What's Metasploit? Metasploit is a penetration testing platform that enables you to find, exploit, and validate vulnerabilities. The platform includes the Metasploit Framework and its commercial counterparts: Metasploit Pro, Express, Community, and Nexpose Ultimate. Metasploit Framework The Metasploit Framework is the foundation on which the commercial products are built. It is an open source project that provides the infrastructure, content, and tools to perform penetration tests and extensive security auditing. Thanks to the open source community and Rapid7's own hard working content team, new modules are added on a regular basis, which means that the latest exploit is available to you as soon as it's published. There are quite a few resources available online to help you learn how to use the Metasploit Framework; however, we highly recommend that you take a look at the Metasploit Framework Wiki, which is maintained by Rapid7's content team, to ensure that you have the most up to date information available. You can also use the sidebar navigation on the left to view the documentation that is available on this site; just click on the Metasploit Framework topic or search for the topic you want. Either way, if you are unable to find what you need, let us know, and we will add it to the documentation back log.
    [Show full text]
  • List of NMAP Scripts Use with the Nmap –Script Option
    List of NMAP Scripts Use with the nmap –script option Retrieves information from a listening acarsd daemon. Acarsd decodes ACARS (Aircraft Communication Addressing and Reporting System) data in real time. The information retrieved acarsd-info by this script includes the daemon version, API version, administrator e-mail address and listening frequency. Shows extra information about IPv6 addresses, such as address-info embedded MAC or IPv4 addresses when available. Performs password guessing against Apple Filing Protocol afp-brute (AFP). Attempts to get useful information about files from AFP afp-ls volumes. The output is intended to resemble the output of ls. Detects the Mac OS X AFP directory traversal vulnerability, afp-path-vuln CVE-2010-0533. Shows AFP server information. This information includes the server's hostname, IPv4 and IPv6 addresses, and hardware type afp-serverinfo (for example Macmini or MacBookPro). Shows AFP shares and ACLs. afp-showmount Retrieves the authentication scheme and realm of an AJP service ajp-auth (Apache JServ Protocol) that requires authentication. Performs brute force passwords auditing against the Apache JServ protocol. The Apache JServ Protocol is commonly used by ajp-brute web servers to communicate with back-end Java application server containers. Performs a HEAD or GET request against either the root directory or any optional directory of an Apache JServ Protocol ajp-headers server and returns the server response headers. Discovers which options are supported by the AJP (Apache JServ Protocol) server by sending an OPTIONS request and lists ajp-methods potentially risky methods. ajp-request Requests a URI over the Apache JServ Protocol and displays the result (or stores it in a file).
    [Show full text]
  • Hacking Techniques & Intrusion Detection
    Hacking Techniques & Intrusion Detection Ali Al-Shemery arabnix [at] gmail All materials is licensed under a Creative Commons “Share Alike” license. • http://creativecommons.org/licenses/by-sa/3.0/ 2 # whoami • Ali Al-Shemery • Ph.D., MS.c., and BS.c., Jordan • More than 14 years of Technical Background (mainly Linux/Unix and Infosec) • Technical Instructor for more than 10 years (Infosec, and Linux Courses) • Hold more than 15 well known Technical Certificates • Infosec & Linux are my main Interests 3 Scanning and Fingerprinting Outline • Diving into Important Network Protocols (TCP, UDP, ICMP, ARP, etc) • Nmap – Intro. • Host Discovery • Tracing the Route • Port Scanning • OS and Service Fingerprinting • Learning Python in 4 Slides • Packet Crafting 5 Diving into Important Network Protocols • Diving into Important Network Protocols: – TCP – UDP – ICMP – ARP – HTTP – etc 6 Nmap • "Network Mapper” is a free and open source utility for network discovery and security auditing. - Fyodor • IMO: #1 tool in your security arsenal! Important Note: A huge difference between running Nmap as a privileged/unprivileged user! 7 Host Discovery • Identifying Live Systems • Also called “Network Sweep” • Nmap ping sweeps: – Ping Only (-sP) – ARP Ping (-PR) – ICMP Echo Request Ping (-PE) – TCP SYN Ping (-PS) – TCP ACK Ping (-PA) – UDP Ping (-PU) DEMO 8 Assignment #1 • Why do host discovery or network sweeping if we already have the target list of IP(s)? 9 Tracing the Route • Nmap --traceroute option • DEMO DEMO 10 Port Scanning • The act of testing a remote
    [Show full text]
  • Project 3: Networking Due: Parts 1–3: May 18 11:59 PM PT Part 4: May 25 11:59 PM PT
    CS155: Computer Security Spring 2021 Project 3: Networking Due: Parts 1{3: May 18 11:59 PM PT Part 4: May 25 11:59 PM PT Introduction This project is all about network security. You will both use existing software to examine remote machines and local traffic as well as play the part of a powerful network attacker. Parts one and two show you how a simple port scan can reveal a large amount of information about a remote server, as well as teach you how to use Wireshark to closely monitor and understand network traffic observable by your machine. Part three will focus on a dump of network traffic in a local network, and will teach you how to identify different types of anomalies. Finally, in part four, you will get to implement a DNS spoofer that hijacks a HTTP connection. This project will solidify your understanding of the mechanics and shortfalls of the DNS and HTTP protocols. Go Language. This project will be implemented in Go, a programming language most of you have not used before. As such, part of this project will be spent learning how to use Go. Why? As you saw in Project 1, C and C++ are riddled with memory safety pitfalls, especially when it comes to writing network code. It's practically impossible to write perfectly secure C/C++ code|even experienced programmers make errors. For example, just this week, Qualys uncovered 21 exploits in Exim, a popular open source mail server. The security community has largely agreed that future systems need to be built in safe languages.
    [Show full text]
  • Penetration Testing Using Metasploit Framework: an Ethical Approach
    International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056 Volume: 06 Issue: 08 | Aug 2019 www.irjet.net p-ISSN: 2395-0072 PENETRATION TESTING USING METASPLOIT FRAMEWORK: AN ETHICAL APPROACH Seema Rani1, Ritu Nagpal2 1M.Tech Scholar, Computer Science & Engineering, GJUS&T, Hisar, India 2Associate Professor, Computer Science & Engineering, GJUS&T, Hisar, India ---------------------------------------------------------------------***---------------------------------------------------------------------- Abstract-Security is an essential concern for the internet describe the installation and lists of tools provided by since nowadays almost all communication occurs via the Kali Linux 2017.3 and uses preconfigured and internet. The motive of performing penetration testing is preinstalled tools for laboratory project using VMware to ensure that system and network have no security hole (virtual machine framework). Matthew Denis et al [2] that allows an unauthorized access to system and in this paper titled "Penetration testing: Concepts, attack network. One possible and appropriate way to avoid methods, and defense strategies" examines the distinct hacking of system and network is penetration testing. This penetration testing tools of Kali Linux: Metasploit, paper summarily describe some basics of penetration Wireshark, JohnThe Ripper, BeEF, Nmap, Nessus and testing, evaluation of existing exploits and tools and use Dradisare to study attack methodologies and defense Metasploit framework for penetration testing and to run strategies. Himanshu Gupta and Rohit Kumar [4] In exploits in this framework. We describe penetration this paper titled “Protection against penetration attacks testing techniques: information gathering, vulnerability using Metasploit” discusses the script based attacks, analysis, vulnerability exploitation, post exploitation and using Metasploit built-in module to exploit the target report generation using Metasploit framework’s existing system, implements Metasploit attacks and analyze modules, exploits and tools.
    [Show full text]