scanning
play

Scanning (and some other no-tech hacking) Todays Class Scanning - PowerPoint PPT Presentation

Scanning (and some other no-tech hacking) Todays Class Scanning the Internet for research Scanning the Internet for research Other no-tech hacking Definitions: domain name: google.com unm.edu a registrable


  1. Scanning (and some other no-tech hacking)

  2. Today’s Class • Scanning the Internet for research • Scanning the Internet for “research” • Other no-tech hacking

  3. Definitions: • domain name: • google.com • unm.edu • a registrable entity on the web under the control of a single entity or organization • domain registrar: • an entity that domains are registered with • domain registry: • an entity that maintains a list of all domains that are registered with a top level domain • top level domain (TLD) • COM • EDU • The top level of the domain name system

  4. Definitions • Domain Name System (DNS): • a system that maps domain name to IP address • IP address: • a routable address on the Internet • Name server: • A server that maps domains to IP addresses

  5. Definitions • Hosting Provider: • Have some servers. • Responsible for some IP addresses • AS: • Autonomous system • Routes group of IP addresses on Internet

  6. Whois

  7. How to Measure the Internet?

  8. How to Measure the Internet? • Number of domain names? • unm.edu —> cs.unm.edu, www.unm.edu, etc. • Number of IP addresses? • One IP address might be multiple devices (NAT) • other?

  9. Why? • To see how big it is • To see how influential it is • To see how insecure it is • To see where the insecurities lie

  10. • Google indexes a big part of the web. • Google search has a bunch of advance search operators. • We can use them to find more than just pug pictures. • https://www.exploit-db.com/google-hacking- database/

  11. Shodan • “The search engine for the web” • https://www.shodan.io/

  12. Scanning for research • https://scans.io/ • Looks for information related to various insecure events or potential insecurities.

  13. TLS • TLS/SSL: • transport layer security/secure socket layer • encrypts messages

  14. TLS

  15. Heartbleed • Bug in heartbleed extension of OpenSSL implementation of TLS • https://xkcd.com/1354/ • http://heartbleed.com/ • https://filippo.io/Heartbleed/

  16. Measuring Patch Rate

  17. Comparison to Debian PRNG patch rate

  18. Experiments

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend