Hiển thị các bài đăng có nhãn CEH v8 Labs Module 02 Footprinting and Reconnaissance. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn CEH v8 Labs Module 02 Footprinting and Reconnaissance. Hiển thị tất cả bài đăng

Thứ Ba, 22 tháng 4, 2014

Footprirvting a Target Network .p19

Lab 11


Identifying Vulnerabilities and Information Disclosures in Search Engines using Search Diggity

Search Diggity is the primary attack tool of the Google Hacking Diggity Project It is an MS Win dons GUI application that serves as a front-end to the latest versions of Diggity tools: GoogleDiggity, BingDiggity, Bing L/nkFromDomainDiggity, CodeSearchDiggity, Dl^PDiggity, FlashDiggity, Main areDiggity, Po/tS can Diggity, SHOD.4NDiggity, BingBina/yMalnareSearch, andNotlnMyBackYardDiggity.

Lab Scenario

An easy way to find vulnerabilities 111 websites and applications is to Google them, which is a simple method adopted bv attackers. Using a Google code search, hackers can identify crucial vulnerabilities 111 application code stnngs, providing the entry point they need to break through application security. As an expert ethical hacker, you should use the same method to identity all the vulnerabilities and patch them before an attacker identities them to exploit vulnerabilities.

Lab Objectives

The objective of tins lab is to demonstrate how to identity vulnerabilities and information disclosures 111 search engines using Search Diggity. Students will learn how to:

■ Extract Meta Tag, Email, Phone/Fax from the web pages

Lab Environment

To carry out the lab, you need:
■ Search Diggitvis located at D:\CEH-Tools\CEHv8 Module 02
Footprinting and Reconnaissance\Google Hacking
Tools\SearchDiggity

■ You can also download die latest version of Search Diggity from the link http: / /www.stachliu.com/resources / tools / google-hacking-diggitvproject/ attack-tools

■ If you decide to download the latest version, then sc re ensh ots shown 111 the lab might differ

■ Tins lab will work 111 the CEH lab environment - 011 Windows Server 2012, Windows 8, Windows Server 2008, and Windows 7

Lab Duration

Time: 10 Minutes

Overview of Search Diggity

Search Diggity has a predefined query database diat nuis against the website to scan die related queries.

Lab Tasks
1. To launch the Start menu, hover the mouse cursor 111 the lower-lelt
corner of the desktop

FIGURE 11.1: Windows Server 2012—Desktop view
2. 111 the Start menu, to launch Search Diggity click the Search Diggity icon

FIGURE 11.2: Windows Server 2012 — Start menu
3. The Search Diggity main window appears with Google Diggity as the default

FIGURE 11.3: Search Dimity—Main window

4. Select Sites/Domains/IP Ranges and type the domain name 111 the domain lield. Click Add

FIGURE 11.4: Search Dimity - Selecting Sites/Domains/IP Ranges
5. The added domain name will be listed in the box below the Domain held

FIGURE 11.5: Search Diggity — Domain added
6. Now, select a Query trom left pane you wish to run against the website that you have added 111 the list and click Scan
Note: 111 this lab, we have selected the query SWF Finding Generic. Similarly, you can select other queries to run against the added website

FIGURE 11.6: Seaich Diggity — Selecting query and Scanning
7. The following screenshot shows the scanning process

FIGURE 11.7: Search Diggity— Scanning ill progress
8. All the URLs that contain the SWF extensions will be listed and the output will show the query results

FIGURE 11.8: Search Diggity-Output window

Lab Analysis

Collect die different error messages to determine die vulnerabilities and note die information disclosed about the website.



Questions

Is it possible to export the output result for Google Diggity? If yes,
how?


Footprirvting a Target Network .p18

Lab 10

Extracting a Company’s Data Using Web Data Extractor

Web Data Extractor'is used to extract targeted companj(s) contact details or data such as emails; fax, phone through web for responsible b '2b communication.

Lab Scenario

Attackers continuously look tor the easiest method to collect information. There are many tools available with which attackers can extract a company’s database. Once they have access to the database, they can gather employees’ email addresses and phone numbers, the company’s internal URLs, etc. With the information gathered, they can send spam emails to the employees to till
their mailboxes, hack into the company’s website, and modify the internal URLs. They may also install malicious viruses to make the database inoperable. As an expert penetration tester, you should be able to dunk from an attacker’s perspective and try all possible ways to gather information 011 organizations. You should be able to collect all the confidential information of an organization and implement security features to prevent company data leakage. 111 tins lab, you will learn to use Web Data Extractor to extract a company’s data.

Lab Objectives

The objective ot tins lab is to demonstrate how to extract a company’s data using Web Data Extractor. Smdents will learn how to:

■ Extract Meta Tag, Email, Phone/Fax from the web pages

Lab Environment

To earn’ out the lab you need:

■ Web Data Extractor located at D:\CEH-Tools\CEHv8 Module 02 Footprinting and Reconnaissance\Additional Footprinting Tools\Web Data Extractor

■ You can also download the latest version ol Web Data Extractor from the link http://www.webextractor.com/download.htm

■ If you decide to download the latest version, then screenshots shown 111 the lab might differ

■ This lab will work in the CEH lab environment - 011 Windows Server
2012, Windows 8 י Windows Server 2008, and Windows 7

Lab Duration

Time: 10 Minutes

Overview of Web Data Extracting Web data extraction is a type of information retrieval diat can extract automatically unstructured or semi-stmctured web data sources 111 a structured manner.

Lab Tasks

1. To launch the Start menu, hover the mouse cursor in the lower-left corner of the desktop


FIGURE 10.1: Windows 8 — Desktop view

2. 111 the Start menu, click Web Data Extractor to launch the application Web Data Extractor

FIGURE 10.2: Windows 8—Apps

3. Web Data Extractor’s main window appears. Click New to start a new session

FIGURE 10.3: The Web Data Extractor main window

4. Clicking New opens the Session settings window.

5.Type a URL rwww.cert1hedhacker.com) 111 die Starting URL held. Select die check boxes for all the options as shown 111 die screenshot and click OK

FIGURE 10.4: Web Data Extractor die Session setting window

6. Click Start to initiate the data extraction

FIGURE 10.5: Web Data Extractor initiating the data extraction windows

7. Web Data Extractor will start collecting the information (emails, phones, faxes, etc.). Once the data extraction process is completed, an Information dialog box appears. Click OK

FIGURE 10.6: Web Data Extractor Data Extraction windows
8. The extracted information can be viewed by clicking the tabs

FIGURE 10.7: Web Data Extractor Data Extraction windows
9. Select the Meta tags tab to view the URL, Tide, Keywords, Description, Host, Domain, and Page size information

FIGURE 10.8: Web Data Extractor Extracted emails windows
10. Select Emails tab to view the Email, Name, URL, Title, Host, Keywords density, etc. information related to emails

FIGURE 10.9: Web Data Extractor Extracted Phone details window
11. Select the Phones tab to view the information related to phone like Phone number, Source, Tag, etc.
FIGURE 10.10: Web Data Extractor Extracted Phone details window
12. Similarly, check for the information under Faxes, Merged list, Urls (638), Inactive sites tabs

13. To save the session, go to File and click Save se ssion

FIGURE 10.11: Web Data Extractor Extracted Phone details window
14. Specify the session name in the Save se ssion dialog box and click OK

FIGURE 10.12: Web Data Extractor Extracted Phone details window

15. By default, the session will be saved at
                   D:\Users\admin\Documents\WebExtractor\Data

Lab Analysis

Document all die Meta Tags, Emails, and Phone/Fax.


Questions

1. What does Web Data Extractor do?

2. How would you resume an interrupted session 111 Web Data Extractor?

3. Can you collect all the contact details of an organization?






Footprirvting a Target Network .p17

Lab 9

Mirroring Websites Using the HTTrack Web Site Copier Tool

HTTrnck Web S ite Copier is an Offline hr on ser utility that allon ׳sjo// to don \nload
a World Wide Web site through the Internet to jour local directory.

Lab Scenario

Website servers set cookies to help authenticate the user it the user logs 111 to a secure area of the website. Login information is stored 111 a cookie so the user can enter and leave the website without having to re-enter the same authentication information over and over.

You have learned 111 the previous lab to extract information from a web application using Firebug. As cookies are transmitted back and forth between a browser and website, if an attacker or unauthorized person gets 111 between the data transmission, the sensitive cookie information can be intercepted. A11 attacker can also use Firebug to see what JavaScript was downloaded and evaluated. Attackers can modify a request before it’s sent to the server using Tamper data. It they discover any SQL or cookie vulnerabilities, attackers can perform a SQL injection attack and can tamper with cookie details of a request before it’s sent to the server. Attackers can use such vulnerabilities to trick browsers into sending sensitive information over insecure channels. The attackers then siphon off the sensitive data for unauthorized access purposes. Therefore, as a penetration tester, you should have an updated antivirus protection program to attain Internet security. 111 tins lab, you will learn to mirror a website using the HTTrack W eb Site Copier Tool and as a penetration tester y o u can prevent D-DoS attack.

Lab Objectives

The objective of tins lab is to help students learn how to mirror websites.

Lab Environment

To carry out the lab, you need:

■ Web Data Extractor located at D:\CEH-Tools\CEHv8 Module 02 Footprinting and Reconnaissance\Website Mirroring Tools\HTTrack Website Copier

■ You can also download the latest version of HTTrack Web Site Copier from the link http://www.httrack.com/page/2/ en/ 111dex.html

■ If you decide to download the latest version, then sc re ensh ots shown 111 the lab might differ

■ Follow the Wizard driven installation process

■ Tins lab will work 111 the CEH lab environment - on Windows Server 2012. Windows 8, Window Server 2008 י and Windows 7

■ To run tliis tool Administrative privileges are required

Lab Duration

Time: 10 Minutes

Overview of Web Site Mirroring

Web mirroring allows you to download a website to a local director}7, building recursively all directories. HTML, images, flash, videos, and other tiles from die server to your computer.

Lab Tasks

1. To launch the Start menu, hover the mouse cursor in the lower-left corner of the desktop

FIGURE 9.1: Windows Server 2012—Desktop view
2. 111 the Start metro apps, click WinHTTrack to launch the applicadon WinHTTrack

FIGURE 9.2: Windows Server 2012—Apps3. 111 the WinHTTrack main window, click Next to
FIGURE 9.3: HTTrack Website Copier Main Window
4. Enter the project name 111 the Project name held. Select the Base path to store the copied files. Click Next

FIGURE 9.4: HTTrack Website Copier selecting a New Project
5. Enter www.certifiedhacker.com under Web Addresses: (URL) and then click the Set options button

FIGURE 9.5: HTTrack Website Copier Select a project a name to organize your download

6. Clicking the Set options button will launch the WinHTTrack window

7. Click the Scan Rules tab and select the check boxes for the tile types as shown in the following screenshot and click OK

FIGURE 9.6: HTTrack Website Copier Select a project a name to organize your download

8. Then, click Next

FIGURE 9.7: HTTrack Website Copier Select a project a name to organize your download

9. By default, the radio button will be selected for Please adjust connection parameters if necessary, then press FINISH to launch the mirroring operation

10. Click Finish to start mirroring the website

FIGURE 9.8: HTTrack Website Copier Type or drop and drag one or several Web addresses

11. Site mirroring progress will be displayed as 111 the following screenshot

FIGURE 9.9: HTTrack Website Copier displaying site mirroring progress
12. WinHTTrack shows the message Mirroring operation complete once the site mirroring is completed. Click Browse Mirrored Website

FIGURE 9.10: HTTrack Website Copier displaying site mirroring progress
13. Clicking the Browse Mirrored Website button will launch the mirrored website for www.cert1fiedhacker.com. The URL indicates that the site is located at the local machine

Note: If the web page does not open for some reasons, navigate to the director}־ where you have mirrored the website and open index.html with any web browser

FIGURE 9.11: HTTrack Website Copier Mirrored Website Image
14. A few websites are very large and will take a long time to mirror the complete site

15. If you wish to stop the mirroring process prematurely, click Cancel in the Site mirroring progress window

16. The site will work like a live hosted website.

Lab Analysis

Document the mirrored website directories, getting HTML, images, and other tiles


Questions

5. How do you retrieve the files that are outside the domain while mirroring a website?

6. How do you download ftp tiles/sites?

7. Can HTTrack perform form-based authentication?

8. Can HTTrack execute HP-UX or ISO 9660 compatible files?

9. How do you grab an email address 111 web pages?


Footprirvting a Target Network .p16

16. Expand a request in the Net panel to get detailed information on Params, Headers, Response, Cached, and Cookies. The screenshot that follows shows die Cache information

FIGURE 8.12: Windows Server 2012—Apps
17. Expand a request in the Cookies panel to get information 011 a cookie Value, Raw data, ]SON, etc.

FIGURE 8.13: Windows Server 2012 —Apps
Note: You can find information related to the CSS, Script, and DOM panel 011
the respective tabs.

Lab Analysis

Collect information such as internal URLs, cookie details, directory structure,
session IDs. etc. for different websites using Firebug.


Questions
1. Determine the Firebug error message that indicates a problem.

2. After editing pages within Firebug, how can you output all the changes that you have made to a site's CSS?

3. 111 the Firebug DOM panel, what do the different colors of the variables mean?

4. What does the different color line indicate 111 the Timeline request 111 the Net panel?


Footprirvting a Target Network .p15





Lab 8


Collecting Information about a Target Website Using Firebug

Firebug integrates nith F1'refox, providing a lot of development tools all on 'ingjon to
edit, debug, and monitor CSS, HTML, and JavaScript live in any n ׳eb page.

Lab Scenario

As you all know, email is one of the important tools that has been created. Unfortunately, attackers have misused emails to send spam to communicate 111 secret and lude themselves behind the spam emails, while attempting to undermine business dealings. 111 such instances, it becomes necessary for penetration testers to trace an email to find the source of email especially where a crime has been committed using email. You have already learned in the previous lab how to find the location by tracing an email using eMailTr acker Pro to provide such information as city, state, country, etc. from where the email was acftiallv sent.

The majoritv of penetration testers use the Mozilla Firefox as a web browser tor their pen test activities. In tins lab, you will learn to use Firebug for a web application penetration test and gather complete information. Firebug can prove to be a useful debugging tool that can help you track rogue JavaScript code on servers.

Lab Objectives

The objective of dus lab is to help sftidents learn editing, debugging, and monitoring CSS, HTML, and JavaScript 111 any websites.

Lab Environment

111 the lab, you need:

■ A web browser with an Internet connection
■ Administrative privileges to run tools
■ Tins lab will work 111 the CEH lab environment - on Windows Server 2012, Windows 8, Windows Server 2008, and Windows 7

Lab Duration

Tune: 10 Minutes

Overview of Firebug

Firebug is an add-on tool for Mozilla Firefox. Running Firebug displays information such as directory structure, internal URLs, cookies, session IDs, etc.

Lab Tasks

1. To launch the Start menu, hover the mouse cursor in the lower-left corner of the desktop

FIGURE 8.1: Windows Server 2012 — Desktop view

2. Oil the Start menu, click Mozilla Firefox to launch the browser

FIGURE 8.2: Windows Server 2012—Apps
3. Type the URL https://getfirebug.com 111 the Firefox browser and click Install Firebug

FIGURE 8.3: Windows Server 2012 - Apps

4. Clicking Install Firebug will redirect to the Download Firebug page Click the Download link to install Firebug

FIGURE 8.4: Windows Server 2012—Apps
5. On the Add-Ons page, click the button Add to Firefox to initiate the Add-On installation

FIGURE 8.5: Windows Server 2012 — Apps
6. Click the Install Now button 111 the Software Installation window

FIGURE 8.6: Windows Server 2012—Apps
7. Once the Firebug Add-On is installed, it will appear as a grey colored bug 011 the Navigation Toolbar as highlighted in the following screenshot

FIGURE 8.7: Windows Server 2012—Apps

8. Click the Firebug icon to view the Firebug pane.

9. Click the Enable link to view the detailed information for Console panel. Perform the same for the Script, Net, and Cookies panels


10. Enabling the Console panel displays all die requests by the page. The one highlighted 111 the screenshot is the Headers tab

11. 111 this lab, we have demonstrated http://www.microsoft.com

12. The Headers tab displays the Response Headers and Request Headers by die website

FIGURE 8.9: Windows Server 2012 — Apps
13. Similarly, the rest of the tabs 111 the Console panel like Params. Response. HTML, and Cookies hold important information about the website

14. The HTML panel displays information such as source code, internal URLs of the website, etc.

FIGURE 8.10: Windows Server 2012—Apps
15. The Net panel shows the Request start and Request phases start and elapsed time relative to the Request start by hovering the mouse cursor on the Timeline graph for a request

FIGURE 8.11: Windows Server 2012 — Apps