Senin, 30 Januari 2012

IG ( information gathering )



     A way to enter a network or security then we have to do some process, to begin entering the network or systems then perform the IG (information  gathering ). IG (information  gathering ) is a process to collect information passively or actively. with technical and non technical processes. Examples results to scan local host:

1. result scan GUI tool autoscan

 


can to find OS, port udp, net bios, ssh, TCP, HTTP, host name

2. result scan GUI tool netivera

 

3. result scan terminal tool nmap

root@bt:~# nmap 192.168.0.0/24

Starting Nmap 5.61TEST4 ( http://nmap.org ) at 2012-01-29 17:30 WIT
Nmap scan report for 192.168.0.21
Host is up (0.00066s latency).
Not shown: 995 closed ports
PORT      STATE SERVICE
22/tcp    open  ssh
80/tcp    open  http
139/tcp   open  netbios-ssn
445/tcp   open  microsoft-ds
10000/tcp open  snet-sensor-mgmt
MAC Address: 08:00:27:F9:C1:BB (Cadmus Computer Systems)

Nmap scan report for 192.168.0.40
Host is up (0.00042s latency).
Not shown: 997 closed ports
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
6566/tcp open  sane-port
MAC Address: 10:78:D2:36:65:A4 (Elitegroup Computer System CO.)

Nmap scan report for 192.168.0.63
Host is up (0.00058s latency).
All 1000 scanned ports on 192.168.0.63 are filtered
MAC Address: 08:00:27:A2:A6:32 (Cadmus Computer Systems)

Nmap scan report for 192.168.0.88
Host is up (0.00045s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure
MAC Address: 00:23:8B:F6:C6:B7 (Quanta Computer)

Nmap scan report for 192.168.0.89
Host is up (0.00035s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure
MAC Address: 00:1D:72:1A:56:9C (Wistron)

Nmap scan report for 192.168.0.91
Host is up (0.00046s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure
MAC Address: 00:23:5A:EF:0D:A2 (Compal Information (kunshan) CO.)

Nmap scan report for 192.168.0.98
Host is up (0.00028s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure
MAC Address: 00:26:22:9B:AC:54 (Compal Information (kunshan) CO.)

Nmap scan report for 192.168.0.99
Host is up (0.00040s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure
MAC Address: 60:EB:69:06:22:EC (Quanta computer)

Nmap scan report for 192.168.0.100
Host is up (0.00026s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure
MAC Address: 00:16:36:48:B4:93 (Quanta Computer)

Nmap scan report for 192.168.0.102
Host is up (0.00034s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure
MAC Address: 00:23:5A:2A:EB:2E (Compal Information (kunshan) CO.)

Nmap scan report for 192.168.0.103
Host is up (0.00023s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure
MAC Address: 54:04:A6:71:E7:E9 (Asustek Computer)

Nmap scan report for 192.168.0.104
Host is up (0.000031s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure

Nmap scan report for 192.168.0.105
Host is up (0.00023s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure
MAC Address: 00:1D:72:0D:BB:13 (Wistron)
can find out what ports look and find out mac address such as:
Host is up (0.00027s latency).
Not shown: 997 closed ports
PORT STATE SERVICE
139/tcp open netbios-ssn
445/tcp open microsoft-ds
902/tcp open iss-realsecure
MAC Address: 00:1D:72:0D:BB:13 (Wistron)


 


4. result scan GUI wireshark and to reed xplico
       xplico is to extract from Internet traffic data capture applications in it. and to read such data has been scanned in order to read wiresharkxplico is to extract from Internet traffic data capture applications in it. and to read such data has been scanned in order to read wireshark



can to find reading data out os. Monitoring data beraktifitas.ethernet

5. result scan GUI Zenmap



know the host and service in the form (netbios, http, ssh, tcpwrapped, vmware). By knowing the hostname, port, protocol, version and state

Tidak ada komentar:

Posting Komentar