Ethical Hacking: Scanning Networks (2016)
2h 3mIntermediate2021-03-19
Authors

Lisa Bock
Security ambassador with a broad range of IT skills and knowledge
Course details
After footprinting and reconnaissance, scanning is the second phase of information gathering that hackers use to size up a network. Network scans are also a key tool in the arsenal of ethical hackers, who work to prevent attacks on an organization's infrastructure and data.
This course investigates the scanning tools and techniques used to obtain information from a target system, including ping sweeps, UDP scans, and TCP flags. Instructor Lisa Bock discusses scanning techniques and their objectives, then goes over vulnerability scanning and how to predict possible attack paths. Lisa introduces scanning tools for port scans, fingerprinting OS, time syncs, and more, then shows you some ways that hackers counter detection via evasion, concealment, and spoofing. She also addresses how to reduce the threat of tunneling, a method hackers use to circumvent network security.
Note: The Ethical Hacking series maps to the 20 parts of the EC-Council Certified Ethical Hacker (CEH) exam (312_50) version 10.
Topics include:
Scanning overview
Port scanning countermeasures
Scanning and querying DNS
Scanning with ICMP
Mapping (or blueprinting) a network
Scanning for vulnerabilities
Using tools such as hping and NetScan
Evading detection
Concealing your network traffic
Preventing tunneling
This course investigates the scanning tools and techniques used to obtain information from a target system, including ping sweeps, UDP scans, and TCP flags. Instructor Lisa Bock discusses scanning techniques and their objectives, then goes over vulnerability scanning and how to predict possible attack paths. Lisa introduces scanning tools for port scans, fingerprinting OS, time syncs, and more, then shows you some ways that hackers counter detection via evasion, concealment, and spoofing. She also addresses how to reduce the threat of tunneling, a method hackers use to circumvent network security.
Note: The Ethical Hacking series maps to the 20 parts of the EC-Council Certified Ethical Hacker (CEH) exam (312_50) version 10.
Topics include:
Scanning overview
Port scanning countermeasures
Scanning and querying DNS
Scanning with ICMP
Mapping (or blueprinting) a network
Scanning for vulnerabilities
Using tools such as hping and NetScan
Evading detection
Concealing your network traffic
Preventing tunneling
Skills covered
LinuxNetwork SecurityCybersecurityCert PrepOpen Source
Concepts
0. Introduction
- 01 - Scan the LAN
- 02 - What you should know
- 03 - Hacking ethically
- 04 - Setting up your virtual network
1. Scanning Overview and Methodology
- 05 - Roadmapping a scan
- 06 - Scanning techniques
- 07 - Scanning vs. penetration testing
- 08 - Scanning IPv6 networks
- 09 - Port scanning countermeasures
- 10 - Challenge - Compare pen test from a vulnerability scan
- 11 - Solution - Compare pen test from a vulnerability scan
2. Identifying Live Systems Using Protocols
- 12 - The three-way handshake
- 13 - TCP flags
- 14 - Idle scans
- 15 - Scan and query DNS
- 16 - Scan using ICMP
- 17 - Banner grabbing
- 18 - Challenge - Using online tools for discovery
- 19 - Solution - Using online tools for discovery
3. Blueprint the Network
- 20 - Map a network with Nmap
- 21 - Passive operating system discovery
- 22 - SSDP for discovery
- 23 - Other network mapping tools
4. Vulnerability Scanning
- 24 - Scanning for vulnerabilities
- 25 - Discovering vulnerabilities with Acunetix
- 26 - Using commercial and free scanners
5. Scanning Tools
- 27 - Use hping
- 28 - Scan with Nikto
- 29 - Exploring NetScan Tools
6. Evading Detection
- 30 - Intrusion detection systems
- 31 - Use IP fragmentation scan
- 32 - Staying anonymous
- 33 - Challenge - Draw a network diagram
- 34 - Solution - Draw a network diagram
7. Concealing and Spoofing
- 35 - Hiding with onion routing
- 36 - Obscuring with Proxifier and SocksChain
- 37 - IP addresses spoofing countermeasures
- 38 - IP spoofing detection techniques
8. Tunneling
- 39 - HTTP
- 40 - SSH
- 41 - Defend against tunneling
Conclusion
- 42 - Next steps