CS338 Computer Security Monday, 11 November 2024 + Lab: a little more pen-testing - Host detection - Port scanning - Website brute-forcing + Pen-testing rough overview - Contract between client and pen-tester - Scope of work (what's allowed, what's not,...) - what's allowed - what's explicitly off-limits - external? ("here's a starter IP address range") - internal? ("here's login credentials for machine A") - physical? ("our warehouse facility in south Northfield") - Get-out-of-jail-free card - Time limits - ... - For the rest of this, assume "external", and that we're given an IP range - Host detection (nmap is good for this) - ICMP pings (sometimes disabled on the servers) - TCP connections to very common ports (80/443, 22, SMP,...) - ... - Getting a foothold - Port scanning (nmap again) - Vulnerability scanning - Roughly, port scans + database of vulnerabilities - nessus - metasploit - ... - Web scanning - brute-forcing (gobuster, feroxbuster, etc.) to find files and folders - autoindexing? maybe you can just see lots of files - file uploads? - command injection? - SQL injection? - .git/ folder? - download .git/, and you can get all the source code, config files, etc. and their history - XSS opportunities? build a demo of an attack on the company's customers - firewall dashboard? other admin management tools exposed? - login forms? password spraying & cred stuffing - Various kinds of fuzzing - Publicly available exploits - ... - Privilege escalation starting logged in as alice - you might have alice's password, but you might not - does alice have unusual permissions? sudo -l getcap groups - do critical system files have bad permissions? ls -l /etc/passwd ls -l /etc/shadow ... - Publicly available exploits