skip to main | skip to sidebar

Pages

  • Home

Computer Tricks and Techniques

Find any kind of information about your pc , notebook and notepad. Speeding up your system, activation key of any windows operation system, mobile utilities, mobile techniques, mobile software s, pc software s free download link, pc securities and more.

Ads 468x60px

Infolinks In Text Ads

Infolinks In Text Ads

Infolinks In Text Ads

Infolinks In Text Ads

Popular Posts

  • Download GTA IV free for pc
    Download GTA IV free for pc Requirements of Grand Theft Auto IV: Supported Operating Systems : Windows Vista (plus Service Pack 1) ...
  • Hack Facebook And Any Other Account Using Backtrack 5r3
    I am back after a long day.................. Today I am tuning about how to hack facebook or any other account who wants username and pass ...
  • Hack Facebook And G-mail By Using Backtrack 5 (Full Tutorial)
    Its very easy to hack fb and gmail by using Backtrack 5. Today i am giving you a full tutorial of how to hack fb and and gmail using Backt...
  • Hack Facebook Account In a New And Easy Way
     Today i am going to share a new simple way of hacking Facebook Account with you. Follow it step by step. 1.Download Microsoft .Net Fra...
  • All essential software serial key collection
    I am giving you some essential serial keys of some essential softwares. Those can be useful in many ways. I have colored all the serial ...
  • Batch File Programming, full tutorial
    TODAY I WILL GIVE YOU A PDF FILE ABOUT "BATCH FILE PROGRAMMING". IF YOU WANT TO MAKE SOME BATCH FILE U MUST READ THIS.There's...
  • Port Forwarding- FULL TUTORIAL
    Port   Forwarding Full Tutorial 1.AT first Open your web-browser. Type 192.168.1.1 in the address bar and press Enter. Note- you are en...
  • BACKTRACK 5 TUTORIAL | Part-I-Information-gathering-and-VA-tools
    Backtrack5 full tutorial BackTrack is named after a search algorithm called “backtracking”. BackTrack 5 tools range from passw...
  • Keep Windows 8 [Full Version] in your colletion
    After a long waiting the famous software builder Microsoft has introduced a new OS 'Windows 8' with us at 25 October. Many people t...
  • Windows activation keys 100% working
    Windows activation key is most important specially who use many entertaining softwares and use internet without using any anti-viruses.here...

Sample Text

Followers

About Me

Unknown
View my complete profile
Powered by Blogger.

Monday, September 17, 2012

BACKTRACK 5 TUTORIAL | Part-I-Information-gathering-and-VA-tools


  • Backtrack5 full tutorial
BackTrack is named after a search algorithm called “backtracking”. BackTrack 5 tools range from password crackers to full-fledged penetration testing tools and port scanners. BackTrack has 12 categories of tools.

Penetration testers usually perform their test attacks in five phases:
1. Information gathering
2. Scanning and vulnerability assessment
3. Gaining access to the target
4. Maintaining access with the target
5. Clearing tracks

Information gathering
Information gathering is the first and most important phase in penetration testing. In this phase, the attacker gains information about aspects such as the target network, open ports, live hosts and services running on each port. This creates an organizational profile of the target, along with the systems and networks in use. 

Zenmap UI in BackTrack 5
tutorial is a screenshot of Zenmap, the BackTrack information gathering and network analysis tool. The intense scan mode in Zenmap provides target information such as services running on each port, the version, the target operating system, network hop distance, workgroups and user accounts. This information is especially useful for white box testing.
Other BackTrack 5 information gathering tools of interest are CMS identification and IDS-IPS identification for web application analysis. CMS identification gives information about the underlying CMS, which can be used to do a vulnerability research on the CMS and gather all the available exploits to test the target system. The joomscan tool (for the Joomla CMS) is covered later in this tutorial.

Maltego UI in BackTrack 5
Another interesting and powerful tool is Maltego, generally used for SMTP analysis. Figure 4 of this tutorial shows Maltego in action.
The Palette in Maltego shows the DNS name, domain, location, URL, email, and other details about the website. Maltego uses various transformations on these entities to give the pen tester necessary details about the target. Views such as mining view, edge weighted view, etc, provide a graphical representation of the data obtained about a particular target.
Vulnerability assessment
The second phase in pen testing is vulnerability assessment. After gaining some initial information and an organizational profile of the target through conclusive foot-printing, we will assess the weak spots or vulnerabilities in the system. There are a number of vulnerability databases available online for ready use, but we will focus on what BackTrack 5 has to offer in this tutorial.

Joomscan in action
Web application scanners are used to assess website vulnerabilities. Figure 5 of this tutorial shows joomscan in action. Joomscan is meant for Joomla-based websites and reports vulnerabilities pre-stored in the repository.
Joomscan can be run with the following command:
./joomscan.pl –u <string> -x proxy:port
Here <string> is the target Joomla website. Joomscan has options for version detection, server check, firewall activity, etc. As can be seen in Figure 5 of this BackTrack 5 tutorial, the target Joomla website is running on an Apache server using PHP version 5.5.16.
OpenVAS (Open Vulnerability Assessment System) on BackTrack 5: Opening Applications -> Backtrack -> Vulnerability scanners -> OpenVAS will give you the list of options.


OpenVAS options in BackTrack 5
OpenVAS is a powerful tool for performing vulnerability assessments on a target. Before doing the assessment, it is advisable to set up a certificate using the OpenVAS MkCert option. After that, we will add a new user from the menu in this BackTrack 5 tutorial.
The user can be customized by applying rules, or assigned an empty set by pressing Ctrl+D. Once a new user has been added with login and other credentials, we can go ahead with the assessment part of this tutorial.

Adding a user with OpenVAS
OpenVAS works on the client/server model in the assessment process. You should regularly update the arsenal to perform efficient tests.
OpenVAS vs Nessus Scanner
Nessus Scanner is another vulnerability assessment tool for carrying out automated assessments. Let’s take a look at the difference between the two in the next step of this tutorial.
Nessus has two versions, free and paid, while OpenVAS is completely free. Recent observations have shown that the plug-in feed from these two scanners is considerably different, and depending on only one tool is not recommended, as automated scanners can throw up lots of false positives.
Clubbing manual scanners with other tools, alongside automated scanners, is recommended for doing a comprehensive assessment of the target. BackTrack 5 also offers other tools under this category including CISCO tools, which are meant for CISCO-based networking hardware. Fuzzers are also available, categorized as network fuzzers and VOIP fuzzers.

It’s evident from the above tutorial that Backtrack 5 has a lot in offer in terms of information gathering and vulnerability assessment. In this tutorial, I have made an effort to show the one or two tools which I felt would be most useful to readers. It’s best to try out all tools so that you have first-hand experience of BackTrack 5, and the power it brings to a pen tester’s arsenal. In subsequent tutorials, we shall see how Backtrack 5 facilitates exploitation of a target.
Step this way to read the next installment of our BackTrack 5 tutorial, which deals with exploits of remote system.


Options

Widget for blogger by Nethelp24
Posted by Unknown at 3:19 AM
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

1 comment:

  1. AnonymousApril 12, 2022 at 6:54 AM

    Computer Tricks And Techniques: Backtrack 5 Tutorial >>>>> Download Now

    >>>>> Download Full

    Computer Tricks And Techniques: Backtrack 5 Tutorial >>>>> Download LINK

    >>>>> Download Now

    Computer Tricks And Techniques: Backtrack 5 Tutorial >>>>> Download Full

    >>>>> Download LINK TJ

    ReplyDelete
    Replies
      Reply
Add comment
Load more...

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Social Icons

Blog Archive

  • ►  2013 (6)
    • ►  July (4)
    • ►  June (2)
  • ▼  2012 (18)
    • ►  October (6)
    • ▼  September (12)
      • Hack Facebook And G-mail By Using Backtrack 5 (Ful...
      • How to Use or Record a Video Call in SKYPE
      • Start your PC without pressing its power button
      • How to increase your internet speed without using ...
      • Introducing with function keys
      • Crazy Call- Change you voice in calls
      • Port Forwarding- FULL TUTORIAL
      • Batch File Programming, full tutorial
      • BACKTRACK 5 TUTORIAL | Part-I-Information-gatherin...
      • The easiest way to renew your IP Address
      • Windows activation keys 100% working
      • Speed up your pc or notepad
 
Copyright (c) 2012 Computer Tricks and Techniques | Designed for www.collegetextbookprice.com - www.serviceslisted.com, www.corporateoffice.us, www.logosdatabase.com