19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

204<br />

Part IV: Hacking Operating Systems<br />

Figure 11-1:<br />

Port scanning<br />

a<br />

Windows 7<br />

system with<br />

NetScan<br />

Tools Pro.<br />

2. Perform OS enumeration (such as scanning for shares and specific OS<br />

versions) by using an all-in-one assessment tool, such as LanGuard.<br />

Figure 11-2 shows a LanGuard scan that reveals the server version,<br />

vulnerabilities, open ports, and more.<br />

If you need to quickly identify the specific version of Windows that’s<br />

running, you can use Nmap (http://nmap.org/download.html) with<br />

the -O option, as shown in Figure 11-3.<br />

Other OS fingerprinting tools are available, but I’ve found Nmap to be<br />

one of the most accurate.<br />

3. Determine potential security vulnerabilities.<br />

This is subjective and might vary from system to system, but what you<br />

want to look for are interesting services and applications and proceed<br />

from there.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!