1
00:00:06,688 --> 00:00:08,790
- In this lesson 27.3,

2
00:00:08,790 --> 00:00:11,520
we're gonna continue talking
about penetration testing

3
00:00:11,520 --> 00:00:14,910
with a focus on tools and techniques.

4
00:00:14,910 --> 00:00:17,370
Now, penetration test
is designed to exploit

5
00:00:17,370 --> 00:00:20,400
either actual or proof
of concept weaknesses

6
00:00:20,400 --> 00:00:22,620
in a target environment.

7
00:00:22,620 --> 00:00:25,200
Then not to be confused
with a vulnerability scan

8
00:00:25,200 --> 00:00:26,790
which looks for known vulnerabilities

9
00:00:26,790 --> 00:00:27,960
in the target environment

10
00:00:27,960 --> 00:00:30,333
and reports on potential exposures.

11
00:00:31,620 --> 00:00:34,830
So let's look at the phases
of a penetration test.

12
00:00:34,830 --> 00:00:37,920
It's gonna start with
passive reconnaissance,

13
00:00:37,920 --> 00:00:40,530
followed by active reconnaissance,

14
00:00:40,530 --> 00:00:42,093
then the exploitation.

15
00:00:43,260 --> 00:00:46,293
Additional research might
come from the exploitation,

16
00:00:47,370 --> 00:00:51,600
continued exploitation, and
then finally, reporting out.

17
00:00:51,600 --> 00:00:54,270
Now we're gonna look at
these penetration test phases

18
00:00:54,270 --> 00:00:57,900
individually from the
perspective of an ethical hacker,

19
00:00:57,900 --> 00:01:00,510
but really everything we're
talking about here until

20
00:01:00,510 --> 00:01:03,450
we get to reporting with the same thing

21
00:01:03,450 --> 00:01:06,480
that our adversaries or
our attackers would do

22
00:01:06,480 --> 00:01:09,360
when they're trying to find ways to get

23
00:01:09,360 --> 00:01:12,930
into our environment or
exploit our environment.

24
00:01:12,930 --> 00:01:17,635
So passive, active exploitation,
additional research,

25
00:01:17,635 --> 00:01:20,280
continued exploitation and reporting.

26
00:01:20,280 --> 00:01:22,380
So let's start with the very first step,

27
00:01:22,380 --> 00:01:25,170
reconnaissance, which is
also known as footprinting.

28
00:01:25,170 --> 00:01:26,730
There are two types of reconnaissance,

29
00:01:26,730 --> 00:01:30,630
we have passive reconnaissance
and active reconnaissance.

30
00:01:30,630 --> 00:01:33,360
Passive reconnaissance
is information gathering

31
00:01:33,360 --> 00:01:35,880
using publicly available resources,

32
00:01:35,880 --> 00:01:39,360
the target of the
reconnaissance has no knowledge

33
00:01:39,360 --> 00:01:41,700
of the activity 'cause
there's no interaction

34
00:01:41,700 --> 00:01:43,740
with any of the target systems.

35
00:01:43,740 --> 00:01:47,370
So an example might be going
to who is for IP addresses

36
00:01:47,370 --> 00:01:51,000
or looking at LinkedIn or
Facebook for external relationship

37
00:01:51,000 --> 00:01:54,990
or people or personal information
or content of interest.

38
00:01:54,990 --> 00:01:56,100
Do they have a website?

39
00:01:56,100 --> 00:01:57,240
Do they have email?

40
00:01:57,240 --> 00:01:59,790
Does it look like they have
a remote access portal?

41
00:02:00,840 --> 00:02:03,600
Active reconnaissance
is using technical tools

42
00:02:03,600 --> 00:02:05,790
could be automated and or manual

43
00:02:05,790 --> 00:02:09,150
to really probe and discover information.

44
00:02:09,150 --> 00:02:12,420
Now, active recon can be intrusive

45
00:02:12,420 --> 00:02:15,240
and may very well be discovered.

46
00:02:15,240 --> 00:02:18,480
So examples are looking for
things like network connections,

47
00:02:18,480 --> 00:02:22,140
open ports, enumeration
of users and groups

48
00:02:22,140 --> 00:02:25,230
and services and maybe
what type of browser

49
00:02:25,230 --> 00:02:26,793
you have and applications.

50
00:02:28,070 --> 00:02:29,580
And then trying to identify
the vulnerabilities

51
00:02:29,580 --> 00:02:31,920
that are associated with those.

52
00:02:31,920 --> 00:02:34,240
Let me give you some examples of passive

53
00:02:35,127 --> 00:02:35,970
reconnaissance sources,

54
00:02:35,970 --> 00:02:39,360
search engines, social
media, domain registration

55
00:02:39,360 --> 00:02:43,290
DNS reconnaissance, public
databases, web scraping,

56
00:02:43,290 --> 00:02:46,860
OSINT, and AI Chatbots.

57
00:02:46,860 --> 00:02:48,900
So we can use search
engines such as Google

58
00:02:48,900 --> 00:02:51,210
and Bing and Showdown.

59
00:02:51,210 --> 00:02:52,773
We can use social media, right?

60
00:02:54,504 --> 00:02:55,920
Monitoring and analyzing
social media platforms.

61
00:02:55,920 --> 00:02:58,830
We can use a who is database
or the who is lookup tables

62
00:02:58,830 --> 00:03:03,180
for IP addresses and domain registrations.

63
00:03:03,180 --> 00:03:04,500
We can use a number of tools

64
00:03:04,500 --> 00:03:08,850
for DNS reconnaissance,
like DNS recon or Fierce,

65
00:03:08,850 --> 00:03:12,393
and which can perform passive
DNS information gathering.

66
00:03:13,650 --> 00:03:17,190
We can use public databases
such as databases of breaches,

67
00:03:17,190 --> 00:03:20,670
previous breaches or
vulnerability databases.

68
00:03:20,670 --> 00:03:22,990
And do web scraping tools like Netcraft

69
00:03:24,840 --> 00:03:27,360
can be used to identify a
website server and client side

70
00:03:27,360 --> 00:03:29,550
operating systems and software.

71
00:03:29,550 --> 00:03:31,350
If you haven't used Netcraft before,

72
00:03:31,350 --> 00:03:34,170
go try it out, it's really a lot of fun.

73
00:03:34,170 --> 00:03:37,950
You can use OSINT tools, open
source intelligence tools

74
00:03:37,950 --> 00:03:41,730
like Recon NG, which can
automate the collection

75
00:03:41,730 --> 00:03:45,510
and analysis of various
publicly available data sources.

76
00:03:45,510 --> 00:03:48,900
And an emerging source is
using our AI chat boxes.

77
00:03:48,900 --> 00:03:51,690
Again, this is all
gathering information right

78
00:03:51,690 --> 00:03:54,390
about the organization, right?

79
00:03:54,390 --> 00:03:56,237
Without actually interacting.

80
00:03:56,237 --> 00:03:58,560
Why is passive reconnaissance?

81
00:03:58,560 --> 00:03:59,820
And then, and we're gonna talk about

82
00:03:59,820 --> 00:04:01,814
active as well in just
a moment so important,

83
00:04:01,814 --> 00:04:04,530
because gathering all that information

84
00:04:04,530 --> 00:04:07,770
is what the pen testers
will do to design and craft

85
00:04:07,770 --> 00:04:09,960
their exploits, and you know,

86
00:04:09,960 --> 00:04:12,660
in an attack scenario,
it's all the information

87
00:04:12,660 --> 00:04:16,473
our attackers would use
to craft their attack.

88
00:04:18,180 --> 00:04:20,940
So let's look at some active recon tools,

89
00:04:20,940 --> 00:04:25,260
NMap and Nessus,
Megagoofil and Burp Suite.

90
00:04:25,260 --> 00:04:27,374
And if you have a home lab,

91
00:04:27,374 --> 00:04:28,800
you should be trying all of these out.

92
00:04:28,800 --> 00:04:31,980
Nmap we use for port scanning
and network discovery,

93
00:04:31,980 --> 00:04:35,340
Nessus for vulnerability
scanning and enumeration,

94
00:04:35,340 --> 00:04:37,500
Metgoofil for extracting metadata,

95
00:04:37,500 --> 00:04:40,710
remember that's data about
data of public documents,

96
00:04:40,710 --> 00:04:43,983
and Burp Suite for website
vulnerability scanning.

97
00:04:45,870 --> 00:04:48,600
Now exploitation is the
stage where the testers

98
00:04:48,600 --> 00:04:51,483
exploit target systems to compromise them.

99
00:04:52,650 --> 00:04:56,580
Now there are two approaches,
one is compromise exploitation

100
00:04:56,580 --> 00:04:59,100
and the other is proof
of concept exploitation.

101
00:04:59,100 --> 00:05:02,790
You wanna be very clear in your
ROE, which one you're doing.

102
00:05:02,790 --> 00:05:05,070
So compromise exploitation is the process

103
00:05:05,070 --> 00:05:07,020
of fully exploiting the vulnerability

104
00:05:07,020 --> 00:05:08,880
without regard to potential damage.

105
00:05:08,880 --> 00:05:09,870
Now, what could happen?

106
00:05:09,870 --> 00:05:13,170
Well, we could have a system
crash denial of service,

107
00:05:13,170 --> 00:05:15,324
we could end up with corruption

108
00:05:15,324 --> 00:05:16,770
or we could end up with exfiltration

109
00:05:16,770 --> 00:05:21,600
of sensitive, confidential
or regulatory protected data.

110
00:05:21,600 --> 00:05:23,400
Now, proof of concept exploitation

111
00:05:23,400 --> 00:05:26,430
is the process of providing
just enough evidence

112
00:05:26,430 --> 00:05:28,470
that the vulnerability is exploitable.

113
00:05:28,470 --> 00:05:31,770
Could be a screenshot or
a snippet out of a log

114
00:05:31,770 --> 00:05:33,600
or a piece of code.

115
00:05:33,600 --> 00:05:36,150
Once again, those
exploitation expectations

116
00:05:36,150 --> 00:05:39,480
should be agreed upon and documented

117
00:05:39,480 --> 00:05:41,583
in your rules of engagement document.

118
00:05:43,560 --> 00:05:45,810
Let's look at some common
exploitation techniques.

119
00:05:45,810 --> 00:05:47,250
These are common techniques that are used

120
00:05:47,250 --> 00:05:50,508
by both our testers
and by our adversaries.

121
00:05:50,508 --> 00:05:53,040
Pivoting is the act of using a weakness

122
00:05:53,040 --> 00:05:56,880
on one system to access a
better protected system.

123
00:05:56,880 --> 00:05:58,560
It's usually really
difficult to be able to

124
00:05:58,560 --> 00:06:01,380
get right into a better
protected system, right?

125
00:06:01,380 --> 00:06:03,450
Because well, you've got
lots of controls, right?

126
00:06:03,450 --> 00:06:05,850
Defense and depth, you're
better protecting it.

127
00:06:05,850 --> 00:06:07,410
But there are gonna be lots of systems

128
00:06:07,410 --> 00:06:09,510
in an environment that people
don't really care about.

129
00:06:09,510 --> 00:06:10,910
Maybe it's a training server

130
00:06:12,467 --> 00:06:13,300
maybe it's an old archive server,

131
00:06:13,300 --> 00:06:14,580
maybe it's an old server still running

132
00:06:14,580 --> 00:06:16,530
like Windows seven,

133
00:06:16,530 --> 00:06:19,260
we haven't used for a long time
but once in a while, right?

134
00:06:19,260 --> 00:06:20,730
Someone might need to access it.

135
00:06:20,730 --> 00:06:23,400
So it's sit in a corner
somewhere and we, you know

136
00:06:23,400 --> 00:06:25,020
get to it when we need it.

137
00:06:25,020 --> 00:06:28,080
So pivoting being the act
of finding those weaknesses

138
00:06:28,080 --> 00:06:31,110
on systems and using that weak systems

139
00:06:31,110 --> 00:06:34,260
to pivot to access a
better protected system.

140
00:06:34,260 --> 00:06:35,910
Escalation of privilege is the act

141
00:06:35,910 --> 00:06:37,500
of exploiting a vulnerability

142
00:06:37,500 --> 00:06:39,840
to gain elevated access to a resource.

143
00:06:39,840 --> 00:06:41,280
And that's really elevated,

144
00:06:41,280 --> 00:06:43,153
we mean that, you know

145
00:06:43,153 --> 00:06:45,180
it's not just what a
user could normally do,

146
00:06:45,180 --> 00:06:47,776
it's more access than the
user or even an application

147
00:06:47,776 --> 00:06:50,373
would have more access to that resource.

148
00:06:51,420 --> 00:06:55,590
Persistence is the active
installing or modifying services

149
00:06:55,590 --> 00:06:58,300
or installing malware
or creating back doors

150
00:06:59,699 --> 00:07:01,500
or creating accounts that
will survive reboots,

151
00:07:01,500 --> 00:07:03,649
that's why it's called persistence,

152
00:07:03,649 --> 00:07:04,840
you could reboot your system

153
00:07:04,840 --> 00:07:06,360
and reboot your system and
it's still gonna be there.

154
00:07:06,360 --> 00:07:09,873
Very popular Exploitation
tool is Metasploit,

155
00:07:10,772 --> 00:07:12,193
so again, if you have a home lab

156
00:07:12,193 --> 00:07:13,793
you may wanna play around with Metasploit.

157
00:07:14,722 --> 00:07:17,300
Now exploitation can be
manual or it can be automated

158
00:07:17,300 --> 00:07:20,110
and it can be just kind of off the shelf

159
00:07:21,188 --> 00:07:22,021
or it can be customized.

160
00:07:22,021 --> 00:07:24,300
And certainly our best
penetration testers,

161
00:07:24,300 --> 00:07:26,250
you know, are going to use a whole array

162
00:07:26,250 --> 00:07:28,170
of automated techniques.

163
00:07:28,170 --> 00:07:31,530
But they're also gonna
craft some really, really

164
00:07:31,530 --> 00:07:35,013
strategically targeted exploits.

165
00:07:37,560 --> 00:07:38,940
And then we get to reporting,

166
00:07:38,940 --> 00:07:40,650
penetration test reports should include

167
00:07:40,650 --> 00:07:41,700
vulnerability findings,

168
00:07:41,700 --> 00:07:45,450
exploit activities, and
recommendations for mitigation.

169
00:07:45,450 --> 00:07:47,610
Vulnerability findings
should be categorized

170
00:07:47,610 --> 00:07:51,900
and referenced appropriately
with the CBE notation.

171
00:07:51,900 --> 00:07:54,510
The exploit activities,
including proof of concept,

172
00:07:54,510 --> 00:07:57,060
should be documented with enough details

173
00:07:57,060 --> 00:07:58,740
so they're reproducible.

174
00:07:58,740 --> 00:08:01,203
So after we re remediate, we can say,

175
00:08:02,223 --> 00:08:03,270
okay, is that problem that issue

176
00:08:03,270 --> 00:08:05,430
with that vulnerability still there?

177
00:08:05,430 --> 00:08:08,550
Now mitigation recommendations
should be prioritized

178
00:08:08,550 --> 00:08:11,910
and as applicable should
include risk reduction

179
00:08:11,910 --> 00:08:14,703
and security enhancement recommendations.

180
00:08:15,630 --> 00:08:19,410
And that my friends, brings us
to a three second challenge.

181
00:08:19,410 --> 00:08:21,420
Five challenge questions,
three seconds each.

182
00:08:21,420 --> 00:08:22,420
You know what to do.

183
00:08:23,430 --> 00:08:27,270
Information gathering using
publicly available resources.

184
00:08:27,270 --> 00:08:32,013
1, 2, 3, it's gonna be
passive reconnaissance.

185
00:08:33,150 --> 00:08:36,450
Number two, active using
a weakness on one system

186
00:08:36,450 --> 00:08:38,970
to access a better protected system.

187
00:08:38,970 --> 00:08:40,410
What's that called?

188
00:08:40,410 --> 00:08:41,823
1, 2, 3.

189
00:08:42,840 --> 00:08:43,990
It's gonna be pivoting.

190
00:08:44,970 --> 00:08:47,640
Number three, the act of
explaining of vulnerability

191
00:08:47,640 --> 00:08:50,463
to gain elevated access to a resource.

192
00:08:51,900 --> 00:08:54,000
1, 2, 3.

193
00:08:54,000 --> 00:08:56,000
That's gonna be escalation of privilege.

194
00:08:57,120 --> 00:09:00,077
Number four document that

195
00:09:00,077 --> 00:09:02,370
authorizes your exploitation approach.

196
00:09:02,370 --> 00:09:03,633
1, 2, 3.

197
00:09:04,868 --> 00:09:07,770
That is your ROE or your
rules of engagement.

198
00:09:07,770 --> 00:09:09,735
And lastly, number five,

199
00:09:09,735 --> 00:09:13,323
providing evidence that a
vulnerability is exploitable.

200
00:09:14,400 --> 00:09:16,320
1, 2, 3.

201
00:09:16,320 --> 00:09:19,473
And that's gonna be POC
or proof of concept.

202
00:09:20,759 --> 00:09:21,990
All right, let's do a security in action.

203
00:09:21,990 --> 00:09:24,423
This is about a regulatory recommendation.

204
00:09:25,380 --> 00:09:27,960
Your organization's regulatory agency

205
00:09:27,960 --> 00:09:31,140
has recommended that the
next penetration test

206
00:09:31,140 --> 00:09:34,110
allow for compromise exploitation.

207
00:09:34,110 --> 00:09:38,071
Management's really puzzled
by this and you've been tasked

208
00:09:38,071 --> 00:09:41,190
with explaining what it
is and the pros and cons.

209
00:09:41,190 --> 00:09:43,350
So what are you gonna tell them?

210
00:09:43,350 --> 00:09:45,510
Kind of an odd request
from a regulatory agency

211
00:09:45,510 --> 00:09:47,320
but we have a regulatory agency

212
00:09:48,500 --> 00:09:49,333
who said this is what we want you to do.

213
00:09:49,333 --> 00:09:52,260
So more than likely, it's what
you're going to do, right?

214
00:09:52,260 --> 00:09:54,987
They're saying that it should
be a compromise exploitation

215
00:09:54,987 --> 00:09:58,440
and management's pretty
puzzled and said what is this?

216
00:09:58,440 --> 00:10:00,000
And they turn to you and say

217
00:10:00,000 --> 00:10:02,040
can you tell us the pros and cons?

218
00:10:02,040 --> 00:10:03,960
So go ahead and put me
on pause for a second.

219
00:10:03,960 --> 00:10:05,670
Jot down what you think the pros

220
00:10:05,670 --> 00:10:08,553
and cons are of compromise exploitation.

221
00:10:11,310 --> 00:10:14,160
Well, compromise
exploitation is an aggressive

222
00:10:14,160 --> 00:10:16,860
form of testing that involves exploiting

223
00:10:16,860 --> 00:10:20,060
discovered vulnerabilities to gain

224
00:10:20,060 --> 00:10:21,843
unauthorized access or control.

225
00:10:23,610 --> 00:10:25,110
So what are the pros?

226
00:10:25,110 --> 00:10:27,870
Well, it provides a really
detailed understanding

227
00:10:27,870 --> 00:10:30,000
of potential damage,

228
00:10:30,000 --> 00:10:33,000
and it does simulate a real world attack.

229
00:10:33,000 --> 00:10:35,895
Because we know that our
attackers aren't gonna just say,

230
00:10:35,895 --> 00:10:37,140
hey I'm gonna give you
proof of concept, right?

231
00:10:37,140 --> 00:10:38,973
They're gonna go for the jugular.

232
00:10:40,590 --> 00:10:41,520
But what are the cons?

233
00:10:41,520 --> 00:10:44,040
Which may outweigh the pros.

234
00:10:44,040 --> 00:10:47,880
It's much riskier as it involves
exploiting vulnerabilities

235
00:10:47,880 --> 00:10:50,040
to its full extent.

236
00:10:50,040 --> 00:10:52,710
And it could potentially cause disruption,

237
00:10:52,710 --> 00:10:55,560
damage, and exfiltration of sensitive

238
00:10:55,560 --> 00:10:58,620
or maybe regulatory protected data.

239
00:10:58,620 --> 00:11:00,240
So before I went off and said,

240
00:11:00,240 --> 00:11:02,550
okay, let's just do this
compromise exploitation

241
00:11:02,550 --> 00:11:05,190
penetration test I'd probably
wanna have another chat

242
00:11:05,190 --> 00:11:06,900
with my regulatory agency.

243
00:11:06,900 --> 00:11:08,580
Make sure that's really what they want

244
00:11:08,580 --> 00:11:10,260
and get a better understanding

245
00:11:10,260 --> 00:11:12,209
of why they want it doing all that.

246
00:11:12,209 --> 00:11:14,516
That my friend is security in action.

247
00:11:14,516 --> 00:11:17,040
There's your word cloud.

248
00:11:17,040 --> 00:11:18,500
I know you know what to do with it.

249
00:11:18,500 --> 00:11:20,430
Soon as you're ready, come on over,

250
00:11:20,430 --> 00:11:21,880
I got a quiz waiting for you.
