create account

My Second day of Ethical hacking by verhp11

View this thread on: hive.blogpeakd.comecency.com
· @verhp11 ·
$6.28
My Second day of Ethical hacking
![g7v1deby6w.png](https://img.esteem.ws/g7v1deby6w.png)

Yesterday I was exhausted so I didn’t  had the energy to write my experiences of the second day of my course Ethical hacking. I will try to do that now :)

The second day was all about using the right tools for the job. And to accomplish that we had to follow a case. The case was about a company whose crown jewels is a recipe of their cola ;) .

All that we got was the IP address of the server where the web-environment was running, the rest was up to you. Like I mentioned in my [previous post](https://steemit.com/life/@verhp11/my-first-day-of-ethical-hacking) you have to think like a hacker to try and find some vulnerabilities. 

<h1>Step one: Scanning</h1>

![3gcn85dou3.png](https://img.esteem.ws/3gcn85dou3.png)
[Source](https://www.kalilinux.in/2018/12/dirb.html)
When you have a IP address you firs can scan it to see which Information you can gather of the server. You can do this by hand or with tools.

For instance Dirbuster. Dirbuster is a tool which can discover content on a server or computer by testing folders and filenames and gives them back in a file or on screen. With that information you can try if you can enter the directories Dirbuster found. 

With Dirbuster I discovered a directory “Intranet” and a directory “Intranet/Uploads”. So they had an intranet, how cool :)…. 


<h1>Step two: Vulnerabillity inventory</h1>

![lvqfvnfix2.png](https://img.esteem.ws/lvqfvnfix2.png)
[Source](https://resources.infosecinstitute.com/introduction-nikto-web-application-vulnerability-scanner/#gref)

The next step was to look if the intranet was up and running, and it was….
So I connected to the intranet, using the url, and saw that it was an apache webserver. 
With tools like Nikto and Vega you can check vulnerabilities on a webserver. Vega gives a graphical view of the findings in terms of High, Medium and Low. 

When you see high’s you know that that will be your point of interest to investigate further. :)
The webserver seemed to be vulnerable for SQL injection. 

<h1>Step three: SQL Injection</h1>

![84zammfhvi.png](https://img.esteem.ws/84zammfhvi.png)
[Source](http://sqlmap.org/)

SQL, Structured Query Language, is used to communicate with databases, and a lot of websites use databases to store or present data. With SQL injection you can manipulate the data towards the database and get some surprising results, for example:
- Revealing data that is not supposed to be seen by us
- Manipulation of data
- Removal of data
- Server takeover
- Find (login) details from clients or employees.


You can check if a parameter change works by trying it in the address bar of the browser.

<b>Example:</b>
Assume the address is http://webstore.com/index.php?p=content&pageid=1

You can try change the pageid to another number. is http://webstore.com/index.php?p=content&pageid=2

When you then hit enter maybe you will receive an error, from within that error you can investigate the system behind it…

So when you know that SQL injection is possible you can use a tool called SQLmap. This tool tries different kinds of injection on the server to reveal information and vulnerabilities.

For example:
- Enumerate all databases which are present on the server
- Get the passwords from the server and will ask you if the tool should try to crack them
- Will show all tables which are present in the database
- Dump all data from the databases in a file
- Gain access to the entire system from data which is in the database
- Testing to see if there are writable directories on the server and start operating system shell



<h1>Step four: Password cracking</h1>

![ofrm50m372.png](https://img.esteem.ws/ofrm50m372.png)
[Source](https://hsploit.com/password-cracking-john-ripper-cracking-rar-zip-linux-passwords/)

When you get the passwords from out of the table you also can do a separate password crack attempt. With that you have multiple options but two common methods are:
- Dictionary based cracking: Based in a provided list of words. This is limited to the list of words.
- Brute force attack: Trying every possible combination of words.This can take very long.

A tool on Kali Linux which you can use for this is John the ripper.

For brute force there are multiple tools available like:

Aircrack-NG for Wifi
John the Ripper
L0pthCrack
THC Hydra

As you can see they all have exotic names :)

Alsost all websites work with parameters, not strange to think that these parameters can be manipulated in some way. Parameters work in general with Post and Get commands on the.
With the Get request you can read the parameters from an URL of command. 

One tool to be able to manipulate parameters is Burp Suite. This tool works as a proxy server between your browser and the webserver so you can manipulate data. I thought that Burp Suite wasn;t that easy to use, a lot of options and dependencies, but the teacher showed us many possibilities of the tool… So try it sometimes, it’s free.

Parameters are also often stored in cookies. So cookies are a good place to manipulate parameters. Way back it was more common, lately only very bad programmed websites write parameters in a cookie.

The worst example is a cookie with the parameter “admin=false” . I don’t have to tell you what would be possible with that ;).


<h1>Step five: Dynamic file inclusion</h1>
One last technique to use is Dynamic File inclusion on a website. With this technique you use a vulnerability where you place a file on the server and execute it with malicious code. 


As you can see you can use a whole set of tools to get eventually to your target with positive result.  If you like this content you should have a look at Kali Linux , in this linux image all these tools are present. Just be aware not to use them in a real environment because it’s against the law :)


Well I hope you liked this post, I loved writing it and I am for sure continue with a lot more studying Ethical hacking,

Take care, stay safe, 

Peter


---

<br>
<center><h4><b>I am with QURATOR, are You?<b> </h4></center>


<center><a href="https://steemit.com/@qurator"><img src="https://cdn.steemitimages.com/DQmdbayK1c8wHTdwEyghnUs922mVTm2J69Tr7yT4TGUXGZn/image.png"></a></center>
<br>
---
<center><h4><b>I am using Esteem </b> </h4></center>
<center><a href="https://steemit.com/@esteem"><img src="https://steemitimages.com/640x0/https://img.esteem.ws/zsbwxrhug2.jpg"></a></center>

<br>
---
![Alt text](https://steemitimages.com/640x0/https://steemitimages.com/DQmdWG7QanG3ZEgJQ4SiLkyQ5BKtxGU7jrrnwDTqsz3r177/Logo_Side-by_side_1000.png)

<i><center>I fully support @s3rg3 and @exyle, who are witness with their developer group @blockbrothers for the Steem blockchain. If you want to support them, they would appreciate your vote [here](https://steemit.com/~witnesses).
<br>
They are the creators of Steemify, THE notification app for your Steemit account for IOS. </center></i>
<br>
___


<center>![steem-banner.jpg](https://steemitimages.com/DQmZ3UhNiAn3AkPEYVGRZ1afAzg7bEofMw6pQ7c6t9wMTTZ/steem-banner.jpg)</center>








👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 23 others
👎  
properties (23)
authorverhp11
permlinkmy-second-day-of-ethical-hacking
categorylife
json_metadata{"links":["https://steemit.com/life/@verhp11/my-first-day-of-ethical-hacking","https://www.kalilinux.in/2018/12/dirb.html","https://resources.infosecinstitute.com/introduction-nikto-web-application-vulnerability-scanner/#gref","http://sqlmap.org/","http://webstore.com/index.php?p=content&pageid=1","http://webstore.com/index.php?p=content&pageid=2","https://hsploit.com/password-cracking-john-ripper-cracking-rar-zip-linux-passwords/","https://steemit.com/@qurator","https://steemit.com/@esteem","https://steemit.com/~witnesses"],"image":["https://img.esteem.ws/g7v1deby6w.png","https://img.esteem.ws/3gcn85dou3.png","https://img.esteem.ws/lvqfvnfix2.png","https://img.esteem.ws/84zammfhvi.png","https://img.esteem.ws/ofrm50m372.png","https://cdn.steemitimages.com/DQmdbayK1c8wHTdwEyghnUs922mVTm2J69Tr7yT4TGUXGZn/image.png","https://steemitimages.com/640x0/https://img.esteem.ws/zsbwxrhug2.jpg","https://steemitimages.com/640x0/https://steemitimages.com/DQmdWG7QanG3ZEgJQ4SiLkyQ5BKtxGU7jrrnwDTqsz3r177/Logo_Side-by_side_1000.png","https://steemitimages.com/DQmZ3UhNiAn3AkPEYVGRZ1afAzg7bEofMw6pQ7c6t9wMTTZ/steem-banner.jpg"],"users":["s3rg3","exyle","blockbrothers"],"tags":["life","oc","stem","hacking","blog"],"app":"esteem/2.2.0-surfer","format":"markdown+html","community":"esteem.app"}
created2019-09-27 11:29:18
last_update2019-09-27 11:29:18
depth0
children14
last_payout2019-10-04 11:29:18
cashout_time1969-12-31 23:59:59
total_payout_value2.993 HBD
curator_payout_value3.291 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length7,078
author_reputation101,983,719,324,115
root_title"My Second day of Ethical hacking"
beneficiaries
0.
accountesteemapp
weight1,000
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id90,995,888
net_rshares19,288,465,549,925
author_curate_reward""
vote details (88)
@bozz ·
Wow, that is pretty awesome.  I like how in depth they are getting into this for you.  It is also really cool that you can do some real time tasks to apply the skills and tools that you are learning about.  I might have to look for one of these types of classes close to me.
properties (22)
authorbozz
permlinkpyhnsp
categorylife
json_metadata{"tags":["life"],"app":"steemit/0.1"}
created2019-09-27 11:55:48
last_update2019-09-27 11:55:48
depth1
children2
last_payout2019-10-04 11:55:48
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length274
author_reputation2,292,737,484,050,443
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id90,996,586
net_rshares0
@verhp11 ·
Awesome isn't it. I have really learned a lot, inlcuding my new course after this one... OSCP :) is more indepth, and a lab exam of 24 hours hahaha.... A realtime hack to be placed...
properties (22)
authorverhp11
permlinkpyhph6
categorylife
json_metadata{"tags":["life"],"app":"steemit/0.1"}
created2019-09-27 12:31:57
last_update2019-09-27 12:31:57
depth2
children1
last_payout2019-10-04 12:31:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length183
author_reputation101,983,719,324,115
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id90,997,483
net_rshares0
@bozz ·
Very cool!
properties (22)
authorbozz
permlinkpyhpnm
categorylife
json_metadata{"tags":["life"],"app":"steemit/0.1"}
created2019-09-27 12:35:57
last_update2019-09-27 12:35:57
depth3
children0
last_payout2019-10-04 12:35:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length10
author_reputation2,292,737,484,050,443
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id90,997,576
net_rshares0
@culgin ·
$0.02
I used to be a pentester for a living. This is a pretty decent overview of how hacking usually works
👍  ,
properties (23)
authorculgin
permlinkre-verhp11-2019928t95332468z
categorylife
json_metadata{"tags":["life","oc","stem","hacking","blog"],"app":"esteem/2.2.2-mobile","format":"markdown+html","community":"esteem.app"}
created2019-09-28 01:53:33
last_update2019-09-28 01:53:33
depth1
children2
last_payout2019-10-05 01:53:33
cashout_time1969-12-31 23:59:59
total_payout_value0.011 HBD
curator_payout_value0.011 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length100
author_reputation170,100,255,531,223
root_title"My Second day of Ethical hacking"
beneficiaries
0.
accountesteemapp
weight300
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id91,016,490
net_rshares119,209,079,536
author_curate_reward""
vote details (2)
@verhp11 ·
$0.02
Thank you @culgin , you're not working anymore in the field of Ethical hacking?
👍  ,
properties (23)
authorverhp11
permlinkpyj38y
categorylife
json_metadata{"users":["culgin"],"app":"steemit/0.1"}
created2019-09-28 06:27:00
last_update2019-09-28 06:27:00
depth2
children1
last_payout2019-10-05 06:27:00
cashout_time1969-12-31 23:59:59
total_payout_value0.011 HBD
curator_payout_value0.011 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length79
author_reputation101,983,719,324,115
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id91,021,352
net_rshares116,205,708,109
author_curate_reward""
vote details (2)
@culgin ·
I now do more coordination of pentests and other security assessments. No longer doing field work. Haha..
properties (22)
authorculgin
permlinkre-verhp11-2019928t1565132z
categorylife
json_metadata{"tags":["esteem"],"app":"esteem/2.2.2-mobile","format":"markdown+html","community":"esteem.app"}
created2019-09-28 07:06:54
last_update2019-09-28 07:06:54
depth3
children0
last_payout2019-10-05 07:06:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length105
author_reputation170,100,255,531,223
root_title"My Second day of Ethical hacking"
beneficiaries
0.
accountesteemapp
weight300
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id91,022,143
net_rshares0
@esteemapp ·
Thanks for mentioning eSteem app. Kindly join our [Discord](https://discord.gg/UkUCWG8) or [Telegram](https://t.me/esteemapp) channel for more benefits and offers on [eSteem](https://esteem.app), don't miss our amazing updates.<br>Follow @esteemapp as well!
properties (22)
authoresteemapp
permlinkre-2019927t15626411z
categorylife
json_metadata{"tags":["esteem"],"app":"esteem/2.0-welcome","format":"markdown+html","community":"esteem.app"}
created2019-09-27 13:06:27
last_update2019-09-27 13:06:27
depth1
children0
last_payout2019-10-04 13:06:27
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length257
author_reputation420,443,679,514,793
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id90,998,415
net_rshares0
@novacadian ·
*Novacadian gives a tip of his white hat to @verhp11.* 😎
properties (22)
authornovacadian
permlinkpyhng6
categorylife
json_metadata{"tags":["life"],"users":["verhp11"],"app":"steemit/0.1"}
created2019-09-27 11:48:06
last_update2019-09-27 11:48:06
depth1
children1
last_payout2019-10-04 11:48:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length56
author_reputation28,322,414,163,470
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id90,996,364
net_rshares0
@verhp11 ·
$0.04
thanks @novacadian :)
👍  
properties (23)
authorverhp11
permlinkpyhnmf
categorylife
json_metadata{"tags":["life"],"users":["novacadian"],"app":"steemit/0.1"}
created2019-09-27 11:51:54
last_update2019-09-27 11:51:54
depth2
children0
last_payout2019-10-04 11:51:54
cashout_time1969-12-31 23:59:59
total_payout_value0.020 HBD
curator_payout_value0.020 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length21
author_reputation101,983,719,324,115
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id90,996,497
net_rshares199,660,392,051
author_curate_reward""
vote details (1)
@steem-plus ·
SteemPlus upvote
Hi, @verhp11!

You just got a **2.32%** upvote from SteemPlus!
To get higher upvotes, earn more SteemPlus Points (SPP). On your Steemit wallet, check your SPP balance and click on "How to earn SPP?" to find out all the ways to earn.
If you're not using SteemPlus yet, please check our last posts in [here](https://steemit.com/@steem-plus) to see the many ways in which SteemPlus can improve your Steem experience on Steemit and Busy.
properties (22)
authorsteem-plus
permlinkmy-second-day-of-ethical-hacking---vote-steemplus
categorylife
json_metadata{}
created2019-09-28 01:30:36
last_update2019-09-28 01:30:36
depth1
children0
last_payout2019-10-05 01:30:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length434
author_reputation247,952,188,232,400
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id91,016,050
net_rshares0
@steem-ua ·
#### Hi @verhp11!

Your post was upvoted by @steem-ua, new Steem dApp, using UserAuthority for algorithmic post curation!
Your **UA** account score is currently 3.504 which ranks you at **#6938** across all Steem accounts.
Your rank has not changed in the last three days.

In our last Algorithmic Curation Round, consisting of 113 contributions, your post is ranked at **#97**.
##### Evaluation of your UA score:

* You're on the right track, try to gather more followers.
* Your contribution has not gone unnoticed, keep up the good work!
* Try to work on user engagement: the more people that interact with you via the comments, the higher your UA score!


**Feel free to join our [@steem-ua Discord server](https://discord.gg/KpBNYGz)**
properties (22)
authorsteem-ua
permlinkre-my-second-day-of-ethical-hacking-20190929t225633z
categorylife
json_metadata"{"app": "beem/0.21.0"}"
created2019-09-29 22:56:33
last_update2019-09-29 22:56:33
depth1
children0
last_payout2019-10-06 22:56:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length740
author_reputation23,214,230,978,060
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id91,074,406
net_rshares0
@tattoodjay ·
Such an interesting read, I am no expert in this area but know enough to be dangerous, but I have members in my team who use these or similar methods and tools when they conduct Vulnerability and security assessments
properties (22)
authortattoodjay
permlinkpyiib3
categorylife
json_metadata{"app":"steemit/0.1"}
created2019-09-27 22:54:39
last_update2019-09-27 22:54:39
depth1
children2
last_payout2019-10-04 22:54:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length216
author_reputation2,630,179,179,572,454
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id91,013,318
net_rshares0
@verhp11 ·
Thanks @tattoodjay , it indeed can be dangerous. Although nowadays a lot of sites and webapplications are pretty safe out of the box, it's the afterwork and customization which introduces some risks :)
properties (22)
authorverhp11
permlinkpyj49k
categorylife
json_metadata{"users":["tattoodjay"],"app":"steemit/0.1"}
created2019-09-28 06:48:57
last_update2019-09-28 06:48:57
depth2
children1
last_payout2019-10-05 06:48:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length201
author_reputation101,983,719,324,115
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id91,021,774
net_rshares0
@tattoodjay ·
yes indeed, we have many applications and sites that have customization or are built inhouse ( which slowly there are less of) and I have seen from the reports how those can be risky if not done well <div class="pull-right"><sub><a href="/@steemreply/steemreply-stay-in-touch-with-your-steem-network">Posted with <img src="http://steemreply.com/logo-comment.png"/></a></sub></div>
properties (22)
authortattoodjay
permlinkre-pyj49k
categorylife
json_metadata""
created2019-09-28 09:46:12
last_update2019-09-28 09:46:12
depth3
children0
last_payout2019-10-05 09:46:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length380
author_reputation2,630,179,179,572,454
root_title"My Second day of Ethical hacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id91,025,339
net_rshares0