Ethical Hacking: Scanning Networks

Ethical Hacking: Scanning Networks

2h 16mIntermediate2023-12-15

Authors

Lisa Bock

Lisa Bock

Security ambassador with a broad range of IT skills and knowledge

Course details

After footprinting and reconnaissance, scanning is the second phase of information gathering that hackers use to size up a network. Network scans are a key tool in the arsenal of ethical hackers, who work to prevent attacks on an organizations infrastructure and data. This course investigates the scanning tools and techniques used to obtain information from a target system. Instructor Lisa Bock discusses the importance of scanning the network during an Ethical Hacking exercise. She covers host discovery methods and explains ways to identify open services and determine the OS on a host. In addition, Lisa outlines evasion techniques to use when scanning and presents anti-spoofing and scanning methods Note: The Ethical Hacking series maps to the 20 parts of the EC-Council Certified Ethical Hacker (CEH) exam (312_50) version 12.

Skills covered

Security TestingIncident ResponseCert PrepCybersecurity

Concepts

Introduction

  • Scanning the LAN
  • Discovering resources
  • Hacking ethically
  • Setting up your virtual network

Scanning Purpose and Methodology

  • Roadmapping a scan
  • Outlining the TCP flags
  • Leveraging the TCP three-way handshake
  • Summarizing scanning tools
  • Discovering Nmap
  • Using hping3

Discovering Hosts

  • Locating network hosts
  • Comparing ping scans
  • Sending SYN and ACK scans
  • Challenge - Identify a scanning signature
  • Solution - Identify a scanning signature

Identifying Open Services

  • Evaluating port scanning methods
  • Scanning IPv6 networks
  • Identifying listening hosts using SCTP
  • Using SSDP for discovery
  • Optimizing scans with Nmap Script Engine

Determining Operating Systems

  • Fingerprinting the OS
  • Using Wireshark for OS discovery
  • Employing IPv6 fingerprinting
  • Harnessing the TTL value
  • Mapping the network using Nmap

Moving through the Network

  • Generating less noise
  • Understanding the idle scan
  • Firewalking the network
  • Implementing stealth scans

Avoiding Detection

  • Manipulating packets
  • Spoofing and cloaking
  • Employing proxies
  • Leveraging anonymizers

Counteracting Scanning

  • Preventing scanning
  • Detecting spoofing
  • Challenge - Draw a network diagram
  • Solution - Draw a network diagram
  • Next steps
80,000 Toman