19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

202<br />

Part IV: Hacking Operating Systems<br />

All-in-one assessment tools<br />

All-in-one tools perform a wide variety of security tests, including the following:<br />

✓ Port scanning<br />

✓ OS fingerprinting<br />

✓ Basic password cracking<br />

✓ Detailed vulnerability mappings of the various security weaknesses<br />

that the tools find on your Windows systems<br />

I use these tools in my work with very good results:<br />

✓ GFI LanGuard (www.gfi.com/network-security-vulnerabilityscanner)<br />

✓ QualysGuard (www.qualys.com)<br />

Qualys’s cloud application service provider/software as a service (whatever<br />

term you want to use these days) is very easy to use. Simply log in to the interface,<br />

give it the IP addresses to scan, and tell it to go. The service has very<br />

detailed and accurate vulnerability testing — it’s my all-time favorite for network/OS<br />

vulnerability testing. Another scanner I’ve heard good things about is<br />

Rapid7’s Nexpose (www.rapid7.com/vulnerability-scanner.jsp).<br />

Task-specific tools<br />

The following tools perform one or two specific tasks. These tools provide<br />

detailed security assessments of your Windows systems and insight that you<br />

might not otherwise get from all-in-one assessment tools:<br />

✓ Metasploit (www.metasploit.com) for exploiting vulnerabilities that<br />

such tools as QualysGuard and Nexpose discover to obtain remote<br />

command prompts, add users, and much more<br />

✓ NetScanTools Pro (www.netscantools.com) for TCP port scanning,<br />

ping sweeps, and share enumeration<br />

✓ ShareEnum (http://technet.microsoft.com/en-us/sys<br />

internals/bb897442.aspx) for share enumeration<br />

✓ TCPView (http://technet.microsoft.com/en-us/sysinternals/<br />

bb897437.aspx) to view TCP and UDP session information<br />

✓ Winfo (www.ntsecurity.nu/toolbox/winfo) for null session enumeration<br />

to gather such configuration information as security policies,<br />

local user accounts, and shares

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!