Results pentest questionnaire
I am writing my thesis for my EDP auditor education. In my thesis I will compare the used methods and standards used by penetration testers with the method and standards used by the Dutch IT auditor association.
I need to know which methods and standards are used the most by penetration testers and how the final report looks like. To get my answers I have developed a short questionnaire about p (read article) Nmap 5 cheat sheet and howto
Index
Basic Scanning Techniques
Discovery Options
Advanced Scanning Functions
Port Scanning Options
Version Detection
Timing Options
Firewall Evasion Techniques
Output Options
Troubleshooting and Debugging
Nmap Scripting Engine
Ndiff
Basic Scanning Techniques
Goal
command
example
Scan a Single Target
nmap [target]
nmap 192.168.1.1
Scan Multiple Targets
nmap (read article) Changing the ClieOp3 file and the hash totals with the elfproef
Several financial applications can generate batch payment files, which can be used in electronic banking applications. In the Netherlands these files are in the ClieOp3 format and contains the approved payments from the company account to other accounts. The ClieOp3 file will be saved in a folder (which can be a network share). The clieOp3 file will be uploaded to the electronic banking applicatio (read article) TLS & SSLv3 renegotiation vulnerability
This paper describes how to test for the TLS & SSLv3 renegotiation vulnerability:
The toolset provided by Openssl offers the simplest way to test whether a server allows for client-side renegotiation in the established tunnel.
Note: This doesn't necessarily mean that the application beneath is vulnerable to attacks over this channel, but indicates the server allows attacks to happen (read article) A description on how to use the Firewalk network tool
Firewalk is an active reconnaissance network security tool that attempts to determine what layer 4 protocols a given IP forwarding device will pass. Firewalk works by sending out TCP or UDP packets with a TTL one greater than the targeted gateway. If the gateway allows the traffic, it will forward the packets to the next hop where they will expire and elicit an ICMP_TIME_EXCEEDED message. If the g (read article) Installing the tools on Ubuntu
To install the tools on this site on Ubuntu or Kubuntu, you will need to add the following packages:
build-essentiallibgtk2.0-devlibncurses5-devflexbisonlibperl-devtcllib
libreadline5-devrubylibopenssl-rubylibpq-devsqlite
On my test system the following packages are installed:
acpi
acpi-support
acpid
adduser
alacarte
alsa-base
alsa-utils
anacron
apmd
app--data
app--data-commercial
a (read article) | |
