Won't You Be My Neighbor
Wednesday, February 18th, 2009 running time 30:18
Getting to know your neighbors -- Darren takes a trip around your network with nmap, THE open source network security scanner. Want to obscure your OS fingerprint? Make a Windows Box show up as a printer? Shannon's got just the thing. And Matt takes a first look at the Napera N24 smart network switch / security appliance. All that and more on this Hak5 Season 5 Premiere!
Taking a trip around your network with Nmap
This week I talk about network scanning with the definitive open source security scanner Nmap.
Scanning ones own network is ideal whether simply to know your neighbors or keep inventory of your assets. As a black hat it can be the first step in enumerating a target environment and looking for weaknesses.
In order to perform our scan we'll simply need a copy of Nmap. It's available for Windows, Mac, and just about every flavor of Linux, BSD and more. If you're on a debian based system like Ubuntu a simple apt-get install nmap should do you good. If you're looking for a security distribution with nmap (and a ton of other great tools) built in can't speak highly enough of BackTrack. Version 4 beta was just recently released.
The underlying workings of Nmap are better explained in this guide but suffice it to say it takes advantage of TCP's 3-way-handshake and other fancy raw packet tricks to find hosts and open ports. In this segment I set out to introduce the concept and get you started with a few basic examples. If you're interested I recommend Nmap Network Scanning and the official man pages as further reading.
The segment details some commands and their usage in a searching for open MS terminal servers scenario. I highly encourage you to provide feedback either by way of email (darren AT hak5 d0t org) or on our forums. I enjoy doing segments like these but if you have any corrections (more than one way to skin a cat), suggestions for future topics or hacks of your own please let me know.
Obscure your OS Fingerprint
OSfuscate 0.3 by Irongeek is used to camaflouge or obscure your Windows OS. With this tool, it'll show up like another OS of your choice, nothing at all, or even a printer. OSFuscate could be used if you are on a hostile network and need some sort of cloak while going along in your daily routine. It is important to note that this is not a fool proof method for hiding yourself on a network and should not be relied upon for security. however, as a layer of obscurity in addition to your regular security practices you may want to consider it.
It's a simple process to set up OSFuscate on your machine. Go to Start->Run->Regedit. Back up your Parameters folder, found under System->CurrentControlSet->Services->Tcpip->Parameters. You can do this by simply right clicking on the folder, and choosing export. This is basically just to keep yourself form messing up your OS in the process and having no way to return it to normal. You'll notice on Irongeek's website that certain Parameter Registry keys will be subtly changed. You could do this by hand, but OSFuscate makes this task super simple. Open OSFuscate, and choose an OS that you want to pretend to be. Restart your computer and the differences should be in place! Now if someone running NMap snoops your computer, they'll see some other OS other than what you actually have.
You can find more information at Irongeek's Website. And as always, you can email me with any comments or suggestions.
as it really helps us out. :) --Shannon MorseMatt's full review of the Napera N24 can be found on his blog at MattLestock.com.
Thanks for tuning into our season premiere episode. We're very excited about all of the exciting new projects coming up in Season 5. We appreciate and encourage your feedback -- especially on this episode's fresh format, pace, and presentation. We strive to make this show better and better for you every week so let us know how we're doing!
And a big thanks to those who've contributed to the success of Hak5. Your donations are greatly appreciated!
Highlights
Windows Vista
(
15:11, 15:11
)
open source
(
2:31, 2:31
)
operating system
(
5:48, 6:21, 5:48, 6:21
)
Capitol Hill
(
6:04, 6:04
)
Windows Vista
(
15:11, 15:11
)
open source
(
2:31, 2:31
)
operating system
(
5:48, 6:21, 5:48, 6:21
)
Capitol Hill
(
6:04, 6:04
)
Automatically Generated Transcript(may not be 100% accurate) ( more )
" War."
" Coming up on the show getting to know your neighbors and takes a trip around you networked music and math. When let's hear your Ellis fingerprint make windows box look like a prisoner I've got just the thing. And that's its first look at an apparent when people -- smart Gigabit switch. All that and more on this episode of Hak5. The episode of Hak5 is brought to you by. Netflix GoDaddy."
" And square space. And guys -- back in the kitchen last time we're here we're doing a little bit of a cooking chicken noodle soup and feel so well. Today feel much better but guess what nothing like cook until mother a beer. They -- that's all there is -- Com and speaking of last time we're here in the case and we were doing a little bit online brute forcing. Using TS grinder to it you know take advantage of some windows terminal services stuff and in that segment I -- now we'll just find -- target using and as a recurring thing threats that we just like -- is not an Apple would never really. You know dive into written and so this shows pretty much dedicated to you. The network right so -- get some stuff up his skates and on some equals -- and honestly guys. And some examples of how to use and now because I find it's not this isn't meant to be like -- comprehensive but as an introduction and you know learn by example is kind of fun way to start talking about poking around your network seen your neighbors are. So it is the big question is why would we want to scanner network and so highly and that we go about that won't. Principals assistant administrator is really important to know what your assets are the Mac address of the IP addresses the descriptions of all the partners and servers and everything else. You've got littered around your office. And that's kind of important because you what's in -- device filling up. And maybe just as a great -- something you might want to you know poke around some place they've just showed up -- you know look for services and open ports and other fun stuff like -- not gonna get too deep into that. And then just as you know regular users say -- on a public Wi-Fi lowered you know I'm in a dorm and make sure that the guy next few isn't like. Leading malware all over the place because you know that perimeter fire all did you nothing so -- to carry yourself know who your neighbors are. So what are we gonna need to do this obviously and -- It is arguably the best security scanner available -- on the man mine its open source you can get it for. No -- XP it's the Mac OS and even windows and there's a lake Louise -- on and do we for. You can learn by example there. But I'm gonna just go ahead diving here in backtrack for. I guess before get too far maybe should explain a bit of the period but please. Understand that. Too much a lot of period outside the scope of the short segment here. If you want more that just email me but basically the idea behind this at least on the TCP side -- we're taking advantage of the three engine. And thing. Is my target they are 65535. Ports available on the -- sin -- each of those and I get an acknowledgment or Mac packet back. And then there's something there. That's really the back of the book or -- of the book version. I got some links in the show notes and -- books and semis and what you -- read your interest in here. But let's just hadn't died in -- some examples and then you know figure out from there. So I'm gonna go ahead and and backtrack for -- here and I'll just fire up a map and if you don't have this in your. That combines after installing not really easy we're gonna go ahead to scan and or something here which -- and no star. And let that run and just hit -- here a couple of times see how -- % non. Art this is great so we've got a whole bunch of results -- him with scanned through them. We can see if that's an interest in -- that's an interesting ports but really it's not anything that we can. Really easily. Read through and get an understanding. Let's go ahead and target our network. And -- were specifically just interest in Microsoft terminal services that will do this again. And do you nmap. That's key for the port 3389. No that's for that runs. And we're gonna put content and so star and that's -- OG for old gangster option actually to help thing that's preferable and we'll make it. RD PT. To -- TXT great. All right so now we're done and we've got the file RG BT got tax so let's go ahead and take a look at. And there we go got a ton of you know ports for some over opens the -- closed some of them are filtered and that's not really all it wants so. The cool thing is in this format we can just go ahead and pass it to -- and they were looking for open. And now get a much prettier list if you've got three potential targets here. But what do we wanted just the IP address is that we can do some cool stuff we can actually send it back into and map we're gonna -- that cut. Maker -- space and say we want the second field and you concede there we got just TIPs we -- the first field. Or third field that's kind of cool but we just want the second field our -- so let's go ahead. And make -- file add that to file called open RDP that text right. Just make sure that that's fair open and RDP. That and there are there are so we -- to send us right back into and -- so it's gonna save us a little bit of time you can imagine we're doing a gigantic network how this could come into play. So for these three has here this front and map. And I'm gonna use the -- O capital O option here and that's gonna give me. And a -- fingerprint and find out what operating system that target is actually running. Because you know going to do little on -- brute force it's gonna there it's really gonna matter for me at least in this particular service whether it Vista or XP. And in the version of RTP there right. So I'm gonna go ahead and give attack Capitol Hill and our file that we created there. And we should be good to go so let's go ahead let that scan. So we're we have that we've got a new a scan of justice three IP addresses and with attack so we can actually take a look here. At the operating system we could see that this one is running windows server 2003. We can come up here and -- That this one actually is a little unknown. And what not so. And then this one is windows XP so. That we can actually also used this to detect kind of the what the services are so. I mean I know you know that 3389. Is most likely that -- out what service but let's go ahead -- Korea anyway so on this. This post here attentive and no 180. Let's go ahead run and map. Where the attack that's. And we until we'll import 3389. On tenth and no 180. And there we go we have verified that port 3389 is open and it is Microsoft RB RDP or terminal service if you well. So there you go real simple just a couple of Komansky -- started that's way is through religious or playing with it."
" so this must land party these two games we've got a zombie smorgasbord for the got left for dead and zombie panic. You hit up the game servers all month long. Ed ZP dot act five dot org and L four. 28 at 3 PM eastern. You can find all the details about our Lan parties and upcoming Lan parties at Hak5 land dot square space dot com where you can also recommend. Your own game that you want us to play with you for the Hak five's land. -- no idea why I'm doing this with my hands but book's awesome right. Which reminds me we want to thank our fantastic sponsor square space which square space plane started eight dollars a month. And you can get 10% off the life of your contract are using coupon code Hak5. We we talk about simplicity we have square space all the time however if you really want to -- into the nitty gritty there's a feature called wire frame which allows you to edit this yes that's directly and create in crap your website. As you see fit so if you're really good. With CSS -- XHQ -- blah blah blah blah all the other languages that I stopped learning about back when I was in eighth grade. You know. Go ahead future wire free mode on and get 10% off the -- contract by using coupon code Hak5 we're gonna be check in now. A brand new apparent and 24 switch this is gonna be the burst media review -- ever gonna see on this amazing. Network security suites all wrapped into one. And Shannon is coming up with. You know hiding here alas I didn't buyers and Janet take."
" Errands over their right now hacking into a bunch of windows machine next door. I run a windows box. Paranoid so I download this nifty little tool called OS SK zero point three buy are hopeful friend Ironkey. Basically what this told that is is that skier camouflage your windows machine to look like something completely different. You could come up like and all of clinics machine her previous. Doesn't matter it's up to you. -- remember that different OS's they do networking a little bit differently if these tiny minute differences in the registration keys. They used to detect different OS is through and map or any other kind of cool like that. This -- it's not foolproof. It's not a foolproof method when every use that you have to remember that. It's not gonna keep Darren from getting into your machine if he wants to you he could still go in there and find out that you're actually running windows machines so. I suggest. At the least. Firewall or something like that X specially yet here on a hostile network like saves me -- network. Not saying it's bad network or anything it's but just -- So let's Wanda Howell you're going to actually run this tool okay so the first thing you're going to do is pull up your registry editor. Like sale. And you going in here parameters folder this is the folder where all of your. Modifications are going to happen. As you can CDs. Are at the different. Keys that are going to be changed. C going to go into your parameters. And the first thing you want to do is. Export a copy of this just in case you need to back up which I mean to back -- her any rate here's replace -- now. It. My computers popping up ads as if it's a windows machine which it is right now. If you go into one of these registry keys. Go to modify and click on decimal accurately habit TCP windows eyes about -- That is 32767. Now if I wanted to go into one of the OS is ski profiles. Say I'm gonna go -- and know about their windows size is 16384. So there's a big difference right there are ready. If you wanted to that you could probably do this annually just going through every registry key and changing everything by hand but it. OSB skate is going to let you do this and a couple of seconds just a couple of clicks that's I have to do. You're gonna go up to its use OS profile to apply. And I'm gonna go with no golf course. Click apply. Going to ask me to review it. But for a restart now I'm going to show you guys the TCP witness eyes difference now that I've modified it. Site going here to modify click on decimal you can see that the value data is now -- and Novell last press okay and restart my computer. So now that I've read it let's go and daring and see if my computers showing up as a Novell machine. Right so as you can see my computer isn't even showing up with -- And that is not even detecting what kind of -- it hasn't -- that -- now now now has -- click on windows. But I do have to stress how important it is that this isn't security it's obscurity. It's not going to completely protect you found hacking into your windows machine but in mind making bypass it. And if you want to check out more I geeks possibly cool tools you can check out his web sites. Which I have shown it's. You can also email me some feedback in question that's nonstop. -- act act five dot board or standing Hak5 -- way. Next up we're gonna talk about sub net here but we trivia."
" it's it's time for trivia and I gotta confess I really boosted up last week. It was just about as lame as the security and that the password there so anyway. I've actually the responsibility over to snobs who is much better at managing that kind of stuff and I am so look forward to -- nutria goodness. As always you guys can just go ahead and pick up a little. -- there put together it's double the password and punch it in fact I've dot org slash trivia to find out how you can answer to win. Awesome Hak five's -- gifts and all sorts of the fun stuff. This week we are giving away -- ashes -- awesome -- documentary hackers are people to check that out. Now bomb before it -- I wanted. Thank our sponsor GoDaddy get reliable secure web hosting without the long term contract go daddy's hosting plans are bigger and better than ever with 99% up time. 3247. Support and no annual commitment plus as a and a pack five EU dot com domain 749 when you check out with code factory. So next up. Check in with Mac and he was gonna Linda and -- switch."
" In. An era. It turns -- it's an apparent switch. What I'm hungry though. Let's check -- in the parents it's. Our guys it to spam could be telling you about an apparent in 24 now. About a week ago I was offered a chance to participate in the Arab beta program. There's a Hun -- small medium sized business I T managers who. Have now been shipped and having had a chance to play with the Arab and 24. A little bit of background before we exceeded in to what the device does. That the pair is a network switch. It's a Gigabit 24 port switch. Interesting sidebar it has. HDMI cable for -- But. Funny set aside while we're gonna do you use actually take a look at why this which differs from and the other switch could you possibly by now. In windows XP service pack three and Windows Vista there's a feature introduced called windows Nat. Stands for windows network access protection which allows devices on your network to be able to tell. If -- computer has the you know upgraded recently has its stuff turned on. It has the fire wall as an iris and all that other good stuff. So. Why is this important well. If you're managing a network you don't you know this all the meetings that were you don't have all the resources that you know some global -- conglomerate hats. Security resources things of that nature it makes a lot easier to manage you know -- connecting to your firewall her excuse me your network. I'm basically goes through and you know bare -- that page. Are up to snuff to be on your. What we're gonna do is right now we're gonna go ahead we're gonna take a look. At an apparent in 24 this is the first video overview slash review that you guys -- gonna see on the Internet. I can promise you this much. An apparent in to go beta which is what were actually part -- is a very slick web. Cloud slash local on this which kind of software. It's. No La mode which hopefully can be fixed with -- some pretty cool. Outwardly show you actually is gonna pair in her face now this is the story in the cloud but. Which you can actually see here's an overview of the switch which. Our ports are you know unprotected or protected great nice thing is we can actually monitor health of the devices connecting to switch. Much like we you know said earlier. I am plugged into I believe. Port eleven. So here we can enforce health. Now what -- health. Let's go ahead and say health is. You or. Firewalls turned on your anti spyware OS updates and everything is current great. These are things that people and client should have turned on an updated if they're connecting to your network. -- we're gonna do is we're gonna go ahead and -- able the health monitoring for. Clients. So we're gonna hit save. Actually first -- require health diagnosis. Reading it say. So now. If I come over here. And click devices. IBM -- is one actually connected on. And it delete this go back over the switch just make sure that port eleven is enforced. And might try in -- to. -- What we have here we have a a portal which is telling us your computer health has been undiagnosed. Urine newbie I don't know who you are and I don't know what you're she it is containing. So we're gonna do is we're actually download in April which is a 161 kilo byte file. I've actually got three copies are here because I've been testing the crap out of this segment. Health -- we're gonna run health neighbor what this is gonna do is it's actually turn on about five or six different services that are actually going to then report back to the switch. So once the health enabler is Ron it's gonna enable them now it's gotten -- in the fire wall and anything else that you guys have installed. That the switch requires for you to have access now. Until you actually run in authenticate your healthy with the networks which it V land you out of the entire local. -- No pinging no nothing. So now we come back here after we've run the enabler and we click refresh up. Guess what because I know meet health requirements of the switch we have full network access we continue and there is Google. Now. Some -- you -- saying. Why exactly Regan uses switched to maintain health values for PCs well if you have people coming in you have people connect into your network. This works on wireless you -- out 200 different devices into the switch and have them all monitored. It's very easy to set to setup I set it up in about ten minutes. Beyond that you're gonna have. Level uh oh you know. -- can breathe easier knowing that people's firewalls and everything else is turned on. Now you can also enable guest access so that people can access the Internet but none of your local resources on or in -- An apparent is you know a new company was founded by wanted to do two did some crazy stuff with watch guard. But beyond that it's a different way to look at network security and I highly against check -- apparent dot com the -- and 24. And I will go into perhaps a little bit more detail as to turning different stuff on and some other features -- the -- health monitoring. So right now we are going to wrap up the show. And it's been a great one you know everybody sit down and their pumped about this episode so let's wrap up the show and -- guys out of here. And let's bring."
" There's guys -- yeah. You know we would count fists but then we've looked like some others -- are done we just pound -- there we go -- we pound. Here's -- in the house."
" I root beer got aids but he jokes to -- and does mrs. Allegedly you -- you forgot was -- Which was BT's. That cares luck or design where it gets you guys out. It definitely -- by the excited. I am not for the table at the bill well see they don't lately getting in -- police falling apart and up but he witches and in the last thing you look on -- and find your own for about 11 I actually had some let me ask him tonight where you're at the table. -- Amazon.com. Search but he yeah. The what we're not that podcast that disk as he gets the IKEA table we open up a notch. -- Hey good now I idea we had to go Amazon part of what bridge you know easy or rich -- anyway someday. Right said I guess when one. One. If you're in the Virginia area. The big area protect -- have been. Here a lot of stuff on Twitter -- in there it turns out there's that you guys greater Richmond Hampton roads northern Virginia let's get. Yet we have we have last you know last week which -- gone and and it it meeting everybody was absolutely insane. -- so many people's. Signed a bunch stuff for people in Everett -- it's on duties and that guy had big ones you wall you know week. Yeah. -- Anyway. That that there the picture outline of a I forget her name actually but. She was supporting act five is on the rise in real estate. You check out. Twit pick them equipment yet day -- That was fun party. Com we probably should actually do it we're supposed to do in this thing it. So why don't why don't we have some actual viewer questions for you guys who get through this moment but Shannon. Let's think there's beautiful people keep us on the air."
" That flakes. Thank you so -- Netflix is sponsoring so episode of act with Netflix it -- 190000 titles include lots of titles with free shipping both ways to your home. It now vote over forty sipping -- all deliveries happened just. Stick. Netflix plans to -- 99 and as a member you can get it two week free trial membership. Go to www. Netflix.com slash hack it and please don't forget the WW dot do you use."
" The they have no reason to be fallen behind on Battlestar Galactica. Us that some XP it's such on the -- and by. It is great not that. Okay but you'll argue that letter will that only because you that's kind of air wolf if that's world which is inherently. That's in the I want there will be music playing over the current. I would see we were that that would cut your -- I want to let you guys note that the sticker -- packs are totally available. We're sticker we totally love your support because it's what he theorizes that. Austin companies is like snoop on -- the next bad -- cool awesome. Totally like holy com. Awesome totally. We're going Tennessee and it's going to be -- on -- and remember them and not. It can't -- speaking of Tennessee Islam. I -- I have a confession to make -- sky dog because you're watching this I know does anything Scott last. Yeah. Yet it's skydive was completely in which means. All night that we were doing shots. Sky dog and I were doing. But the water. AKA water. You know who are doing shots. I. No not me sky dog -- where pumpkin you by feeding you've blues all. Wow."
" So would that government. It wasn't government. -- That the watching. Appreciate way let the stickers that are available awesome to keep us telling. They get a they that we need to make it even more beautiful -- more importantly take it to -- place that we use that humans. So also war. For a limited time. Packs will include. -- get hacked I've had great that he's not rule applies in that it roulette. Okay now -- But anyway so from now until they run now and let you know when you. -- acts and lewd act five awesome temporary tattoos and check it would be teaching them that. Actions not on the show him ahead show support get your -- over hack -- go or let's sticker and upload your."
" It's just -- anything. Alec. Yeah they're temporary. It rubble and week. --"
" By popular demand. -- Roy is back with pixel perfect yet might remember that you know these restructuring pixel perfect was let go but. You guys brought it back so learn how to do really cool things that photos are in images in Photoshop illustrator and other cool applications. You can catch full episodes every Monday. Noon eastern 9 Pacific Revision 3."
" So I think we had some questions that we might. Oh at a packed."
" this guy. Writes. --"
" You know I've actually -- similar issue with my computer of course. See -- this day I got the steam printer really and it's to lose it. That your printer. A scanner now affects. Gadget porn but so. Anyway -- Windows machine won't shut down arms -- won't sleep or irony if -- things -- such a pain. I and I found you with those other ones -- at the bottom screen. Run that and suspense and command line or run that -- You know."
" Yap second question. In the second question. It's. Is frowned. Jared acts and he's asking evils where this question. His query is. Kill all humans question -- so many new options so little time windows live methods and."
" I think cues and pop up so."
" Hurt. Humans. After torturing them its okay. To. Then the -- we've yeah. That you get -- into season five episode one you can hear it. Platforms wore off quickly or off everywhere else what are and -- and what -- yeah right my site. Built into one we'll see you next week. Trust protect."
" Paul what's -- what we have a problem."
" Okay aren't."
" For the next ten minutes unique. -- You know I know that you keep watching."
" Ready one and David --"
" You won't use blu."
" yeah. -- or what's up. Our guys of this."
" Does one take -- he has left the building."
" War."
" Coming up on the show getting to know your neighbors and takes a trip around you networked music and math. When let's hear your Ellis fingerprint make windows box look like a prisoner I've got just the thing. And that's its first look at an apparent when people -- smart Gigabit switch. All that and more on this episode of Hak5. The episode of Hak5 is brought to you by. Netflix GoDaddy."
" And square space. And guys -- back in the kitchen last time we're here we're doing a little bit of a cooking chicken noodle soup and feel so well. Today feel much better but guess what nothing like cook until mother a beer. They -- that's all there is -- Com and speaking of last time we're here in the case and we were doing a little bit online brute forcing. Using TS grinder to it you know take advantage of some windows terminal services stuff and in that segment I -- now we'll just find -- target using and as a recurring thing threats that we just like -- is not an Apple would never really. You know dive into written and so this shows pretty much dedicated to you. The network right so -- get some stuff up his skates and on some equals -- and honestly guys. And some examples of how to use and now because I find it's not this isn't meant to be like -- comprehensive but as an introduction and you know learn by example is kind of fun way to start talking about poking around your network seen your neighbors are. So it is the big question is why would we want to scanner network and so highly and that we go about that won't. Principals assistant administrator is really important to know what your assets are the Mac address of the IP addresses the descriptions of all the partners and servers and everything else. You've got littered around your office. And that's kind of important because you what's in -- device filling up. And maybe just as a great -- something you might want to you know poke around some place they've just showed up -- you know look for services and open ports and other fun stuff like -- not gonna get too deep into that. And then just as you know regular users say -- on a public Wi-Fi lowered you know I'm in a dorm and make sure that the guy next few isn't like. Leading malware all over the place because you know that perimeter fire all did you nothing so -- to carry yourself know who your neighbors are. So what are we gonna need to do this obviously and -- It is arguably the best security scanner available -- on the man mine its open source you can get it for. No -- XP it's the Mac OS and even windows and there's a lake Louise -- on and do we for. You can learn by example there. But I'm gonna just go ahead diving here in backtrack for. I guess before get too far maybe should explain a bit of the period but please. Understand that. Too much a lot of period outside the scope of the short segment here. If you want more that just email me but basically the idea behind this at least on the TCP side -- we're taking advantage of the three engine. And thing. Is my target they are 65535. Ports available on the -- sin -- each of those and I get an acknowledgment or Mac packet back. And then there's something there. That's really the back of the book or -- of the book version. I got some links in the show notes and -- books and semis and what you -- read your interest in here. But let's just hadn't died in -- some examples and then you know figure out from there. So I'm gonna go ahead and and backtrack for -- here and I'll just fire up a map and if you don't have this in your. That combines after installing not really easy we're gonna go ahead to scan and or something here which -- and no star. And let that run and just hit -- here a couple of times see how -- % non. Art this is great so we've got a whole bunch of results -- him with scanned through them. We can see if that's an interest in -- that's an interesting ports but really it's not anything that we can. Really easily. Read through and get an understanding. Let's go ahead and target our network. And -- were specifically just interest in Microsoft terminal services that will do this again. And do you nmap. That's key for the port 3389. No that's for that runs. And we're gonna put content and so star and that's -- OG for old gangster option actually to help thing that's preferable and we'll make it. RD PT. To -- TXT great. All right so now we're done and we've got the file RG BT got tax so let's go ahead and take a look at. And there we go got a ton of you know ports for some over opens the -- closed some of them are filtered and that's not really all it wants so. The cool thing is in this format we can just go ahead and pass it to -- and they were looking for open. And now get a much prettier list if you've got three potential targets here. But what do we wanted just the IP address is that we can do some cool stuff we can actually send it back into and map we're gonna -- that cut. Maker -- space and say we want the second field and you concede there we got just TIPs we -- the first field. Or third field that's kind of cool but we just want the second field our -- so let's go ahead. And make -- file add that to file called open RDP that text right. Just make sure that that's fair open and RDP. That and there are there are so we -- to send us right back into and -- so it's gonna save us a little bit of time you can imagine we're doing a gigantic network how this could come into play. So for these three has here this front and map. And I'm gonna use the -- O capital O option here and that's gonna give me. And a -- fingerprint and find out what operating system that target is actually running. Because you know going to do little on -- brute force it's gonna there it's really gonna matter for me at least in this particular service whether it Vista or XP. And in the version of RTP there right. So I'm gonna go ahead and give attack Capitol Hill and our file that we created there. And we should be good to go so let's go ahead let that scan. So we're we have that we've got a new a scan of justice three IP addresses and with attack so we can actually take a look here. At the operating system we could see that this one is running windows server 2003. We can come up here and -- That this one actually is a little unknown. And what not so. And then this one is windows XP so. That we can actually also used this to detect kind of the what the services are so. I mean I know you know that 3389. Is most likely that -- out what service but let's go ahead -- Korea anyway so on this. This post here attentive and no 180. Let's go ahead run and map. Where the attack that's. And we until we'll import 3389. On tenth and no 180. And there we go we have verified that port 3389 is open and it is Microsoft RB RDP or terminal service if you well. So there you go real simple just a couple of Komansky -- started that's way is through religious or playing with it."
" so this must land party these two games we've got a zombie smorgasbord for the got left for dead and zombie panic. You hit up the game servers all month long. Ed ZP dot act five dot org and L four. 28 at 3 PM eastern. You can find all the details about our Lan parties and upcoming Lan parties at Hak5 land dot square space dot com where you can also recommend. Your own game that you want us to play with you for the Hak five's land. -- no idea why I'm doing this with my hands but book's awesome right. Which reminds me we want to thank our fantastic sponsor square space which square space plane started eight dollars a month. And you can get 10% off the life of your contract are using coupon code Hak5. We we talk about simplicity we have square space all the time however if you really want to -- into the nitty gritty there's a feature called wire frame which allows you to edit this yes that's directly and create in crap your website. As you see fit so if you're really good. With CSS -- XHQ -- blah blah blah blah all the other languages that I stopped learning about back when I was in eighth grade. You know. Go ahead future wire free mode on and get 10% off the -- contract by using coupon code Hak5 we're gonna be check in now. A brand new apparent and 24 switch this is gonna be the burst media review -- ever gonna see on this amazing. Network security suites all wrapped into one. And Shannon is coming up with. You know hiding here alas I didn't buyers and Janet take."
" Errands over their right now hacking into a bunch of windows machine next door. I run a windows box. Paranoid so I download this nifty little tool called OS SK zero point three buy are hopeful friend Ironkey. Basically what this told that is is that skier camouflage your windows machine to look like something completely different. You could come up like and all of clinics machine her previous. Doesn't matter it's up to you. -- remember that different OS's they do networking a little bit differently if these tiny minute differences in the registration keys. They used to detect different OS is through and map or any other kind of cool like that. This -- it's not foolproof. It's not a foolproof method when every use that you have to remember that. It's not gonna keep Darren from getting into your machine if he wants to you he could still go in there and find out that you're actually running windows machines so. I suggest. At the least. Firewall or something like that X specially yet here on a hostile network like saves me -- network. Not saying it's bad network or anything it's but just -- So let's Wanda Howell you're going to actually run this tool okay so the first thing you're going to do is pull up your registry editor. Like sale. And you going in here parameters folder this is the folder where all of your. Modifications are going to happen. As you can CDs. Are at the different. Keys that are going to be changed. C going to go into your parameters. And the first thing you want to do is. Export a copy of this just in case you need to back up which I mean to back -- her any rate here's replace -- now. It. My computers popping up ads as if it's a windows machine which it is right now. If you go into one of these registry keys. Go to modify and click on decimal accurately habit TCP windows eyes about -- That is 32767. Now if I wanted to go into one of the OS is ski profiles. Say I'm gonna go -- and know about their windows size is 16384. So there's a big difference right there are ready. If you wanted to that you could probably do this annually just going through every registry key and changing everything by hand but it. OSB skate is going to let you do this and a couple of seconds just a couple of clicks that's I have to do. You're gonna go up to its use OS profile to apply. And I'm gonna go with no golf course. Click apply. Going to ask me to review it. But for a restart now I'm going to show you guys the TCP witness eyes difference now that I've modified it. Site going here to modify click on decimal you can see that the value data is now -- and Novell last press okay and restart my computer. So now that I've read it let's go and daring and see if my computers showing up as a Novell machine. Right so as you can see my computer isn't even showing up with -- And that is not even detecting what kind of -- it hasn't -- that -- now now now has -- click on windows. But I do have to stress how important it is that this isn't security it's obscurity. It's not going to completely protect you found hacking into your windows machine but in mind making bypass it. And if you want to check out more I geeks possibly cool tools you can check out his web sites. Which I have shown it's. You can also email me some feedback in question that's nonstop. -- act act five dot board or standing Hak5 -- way. Next up we're gonna talk about sub net here but we trivia."
" it's it's time for trivia and I gotta confess I really boosted up last week. It was just about as lame as the security and that the password there so anyway. I've actually the responsibility over to snobs who is much better at managing that kind of stuff and I am so look forward to -- nutria goodness. As always you guys can just go ahead and pick up a little. -- there put together it's double the password and punch it in fact I've dot org slash trivia to find out how you can answer to win. Awesome Hak five's -- gifts and all sorts of the fun stuff. This week we are giving away -- ashes -- awesome -- documentary hackers are people to check that out. Now bomb before it -- I wanted. Thank our sponsor GoDaddy get reliable secure web hosting without the long term contract go daddy's hosting plans are bigger and better than ever with 99% up time. 3247. Support and no annual commitment plus as a and a pack five EU dot com domain 749 when you check out with code factory. So next up. Check in with Mac and he was gonna Linda and -- switch."
" In. An era. It turns -- it's an apparent switch. What I'm hungry though. Let's check -- in the parents it's. Our guys it to spam could be telling you about an apparent in 24 now. About a week ago I was offered a chance to participate in the Arab beta program. There's a Hun -- small medium sized business I T managers who. Have now been shipped and having had a chance to play with the Arab and 24. A little bit of background before we exceeded in to what the device does. That the pair is a network switch. It's a Gigabit 24 port switch. Interesting sidebar it has. HDMI cable for -- But. Funny set aside while we're gonna do you use actually take a look at why this which differs from and the other switch could you possibly by now. In windows XP service pack three and Windows Vista there's a feature introduced called windows Nat. Stands for windows network access protection which allows devices on your network to be able to tell. If -- computer has the you know upgraded recently has its stuff turned on. It has the fire wall as an iris and all that other good stuff. So. Why is this important well. If you're managing a network you don't you know this all the meetings that were you don't have all the resources that you know some global -- conglomerate hats. Security resources things of that nature it makes a lot easier to manage you know -- connecting to your firewall her excuse me your network. I'm basically goes through and you know bare -- that page. Are up to snuff to be on your. What we're gonna do is right now we're gonna go ahead we're gonna take a look. At an apparent in 24 this is the first video overview slash review that you guys -- gonna see on the Internet. I can promise you this much. An apparent in to go beta which is what were actually part -- is a very slick web. Cloud slash local on this which kind of software. It's. No La mode which hopefully can be fixed with -- some pretty cool. Outwardly show you actually is gonna pair in her face now this is the story in the cloud but. Which you can actually see here's an overview of the switch which. Our ports are you know unprotected or protected great nice thing is we can actually monitor health of the devices connecting to switch. Much like we you know said earlier. I am plugged into I believe. Port eleven. So here we can enforce health. Now what -- health. Let's go ahead and say health is. You or. Firewalls turned on your anti spyware OS updates and everything is current great. These are things that people and client should have turned on an updated if they're connecting to your network. -- we're gonna do is we're gonna go ahead and -- able the health monitoring for. Clients. So we're gonna hit save. Actually first -- require health diagnosis. Reading it say. So now. If I come over here. And click devices. IBM -- is one actually connected on. And it delete this go back over the switch just make sure that port eleven is enforced. And might try in -- to. -- What we have here we have a a portal which is telling us your computer health has been undiagnosed. Urine newbie I don't know who you are and I don't know what you're she it is containing. So we're gonna do is we're actually download in April which is a 161 kilo byte file. I've actually got three copies are here because I've been testing the crap out of this segment. Health -- we're gonna run health neighbor what this is gonna do is it's actually turn on about five or six different services that are actually going to then report back to the switch. So once the health enabler is Ron it's gonna enable them now it's gotten -- in the fire wall and anything else that you guys have installed. That the switch requires for you to have access now. Until you actually run in authenticate your healthy with the networks which it V land you out of the entire local. -- No pinging no nothing. So now we come back here after we've run the enabler and we click refresh up. Guess what because I know meet health requirements of the switch we have full network access we continue and there is Google. Now. Some -- you -- saying. Why exactly Regan uses switched to maintain health values for PCs well if you have people coming in you have people connect into your network. This works on wireless you -- out 200 different devices into the switch and have them all monitored. It's very easy to set to setup I set it up in about ten minutes. Beyond that you're gonna have. Level uh oh you know. -- can breathe easier knowing that people's firewalls and everything else is turned on. Now you can also enable guest access so that people can access the Internet but none of your local resources on or in -- An apparent is you know a new company was founded by wanted to do two did some crazy stuff with watch guard. But beyond that it's a different way to look at network security and I highly against check -- apparent dot com the -- and 24. And I will go into perhaps a little bit more detail as to turning different stuff on and some other features -- the -- health monitoring. So right now we are going to wrap up the show. And it's been a great one you know everybody sit down and their pumped about this episode so let's wrap up the show and -- guys out of here. And let's bring."
" There's guys -- yeah. You know we would count fists but then we've looked like some others -- are done we just pound -- there we go -- we pound. Here's -- in the house."
" I root beer got aids but he jokes to -- and does mrs. Allegedly you -- you forgot was -- Which was BT's. That cares luck or design where it gets you guys out. It definitely -- by the excited. I am not for the table at the bill well see they don't lately getting in -- police falling apart and up but he witches and in the last thing you look on -- and find your own for about 11 I actually had some let me ask him tonight where you're at the table. -- Amazon.com. Search but he yeah. The what we're not that podcast that disk as he gets the IKEA table we open up a notch. -- Hey good now I idea we had to go Amazon part of what bridge you know easy or rich -- anyway someday. Right said I guess when one. One. If you're in the Virginia area. The big area protect -- have been. Here a lot of stuff on Twitter -- in there it turns out there's that you guys greater Richmond Hampton roads northern Virginia let's get. Yet we have we have last you know last week which -- gone and and it it meeting everybody was absolutely insane. -- so many people's. Signed a bunch stuff for people in Everett -- it's on duties and that guy had big ones you wall you know week. Yeah. -- Anyway. That that there the picture outline of a I forget her name actually but. She was supporting act five is on the rise in real estate. You check out. Twit pick them equipment yet day -- That was fun party. Com we probably should actually do it we're supposed to do in this thing it. So why don't why don't we have some actual viewer questions for you guys who get through this moment but Shannon. Let's think there's beautiful people keep us on the air."
" That flakes. Thank you so -- Netflix is sponsoring so episode of act with Netflix it -- 190000 titles include lots of titles with free shipping both ways to your home. It now vote over forty sipping -- all deliveries happened just. Stick. Netflix plans to -- 99 and as a member you can get it two week free trial membership. Go to www. Netflix.com slash hack it and please don't forget the WW dot do you use."
" The they have no reason to be fallen behind on Battlestar Galactica. Us that some XP it's such on the -- and by. It is great not that. Okay but you'll argue that letter will that only because you that's kind of air wolf if that's world which is inherently. That's in the I want there will be music playing over the current. I would see we were that that would cut your -- I want to let you guys note that the sticker -- packs are totally available. We're sticker we totally love your support because it's what he theorizes that. Austin companies is like snoop on -- the next bad -- cool awesome. Totally like holy com. Awesome totally. We're going Tennessee and it's going to be -- on -- and remember them and not. It can't -- speaking of Tennessee Islam. I -- I have a confession to make -- sky dog because you're watching this I know does anything Scott last. Yeah. Yet it's skydive was completely in which means. All night that we were doing shots. Sky dog and I were doing. But the water. AKA water. You know who are doing shots. I. No not me sky dog -- where pumpkin you by feeding you've blues all. Wow."
" So would that government. It wasn't government. -- That the watching. Appreciate way let the stickers that are available awesome to keep us telling. They get a they that we need to make it even more beautiful -- more importantly take it to -- place that we use that humans. So also war. For a limited time. Packs will include. -- get hacked I've had great that he's not rule applies in that it roulette. Okay now -- But anyway so from now until they run now and let you know when you. -- acts and lewd act five awesome temporary tattoos and check it would be teaching them that. Actions not on the show him ahead show support get your -- over hack -- go or let's sticker and upload your."
" It's just -- anything. Alec. Yeah they're temporary. It rubble and week. --"
" By popular demand. -- Roy is back with pixel perfect yet might remember that you know these restructuring pixel perfect was let go but. You guys brought it back so learn how to do really cool things that photos are in images in Photoshop illustrator and other cool applications. You can catch full episodes every Monday. Noon eastern 9 Pacific Revision 3."
" So I think we had some questions that we might. Oh at a packed."
" this guy. Writes. --"
" You know I've actually -- similar issue with my computer of course. See -- this day I got the steam printer really and it's to lose it. That your printer. A scanner now affects. Gadget porn but so. Anyway -- Windows machine won't shut down arms -- won't sleep or irony if -- things -- such a pain. I and I found you with those other ones -- at the bottom screen. Run that and suspense and command line or run that -- You know."
" Yap second question. In the second question. It's. Is frowned. Jared acts and he's asking evils where this question. His query is. Kill all humans question -- so many new options so little time windows live methods and."
" I think cues and pop up so."
" Hurt. Humans. After torturing them its okay. To. Then the -- we've yeah. That you get -- into season five episode one you can hear it. Platforms wore off quickly or off everywhere else what are and -- and what -- yeah right my site. Built into one we'll see you next week. Trust protect."
" Paul what's -- what we have a problem."
" Okay aren't."
" For the next ten minutes unique. -- You know I know that you keep watching."
" Ready one and David --"
" You won't use blu."
" yeah. -- or what's up. Our guys of this."
" Does one take -- he has left the building."
mari1ee
Started discussion: February 18, 2009 @ 9:14am GMT
Episode 501 - Won't You Be My Neighbor [Discussion]
Getting to know your neighbors -- Darren takes a trip around your network with nmap, THE open source network security scanner. Want to obscure your OS fingerprint? Make a Windows Box show up as a printer? Shannon's got just the thing. And Matt takes a first look at the Napera N24 smart network switch / security appliance. All that and more on this Hak5 Season 5 Premiere!
Watch or download now!
Irongeek
12 months ago
Thanks for mentioning my site. :)
computoman
12 months ago
Liked the segment namp. I wonder how hard it would be to spoof that fancy router....
Hak5Matt
12 months ago
We've finally had a chance to recharge our batteries after the barrage of conferences we were attending.
We've hit the ground running on season 5 and are really excited about some of the projects we have planned.
Thanks to you all for watching!
Matt
We've hit the ground running on season 5 and are really excited about some of the projects we have planned.
Thanks to you all for watching!
Matt
n00b Nipple
11 months ago
Comments And Questions
I enjoyed the show boys and girl! It had the right mix of hack tech and timing. I felt that it flowed well and was equally informational and entertaining.Matt - Your network switch segment was pretty good. None the less, I think that Network Access Protection(NAP) was actually being done from a few years back by Cisco and Microsoft. Your switch is definitely not the first.
Speaking of NAP, perhaps that is subject material for a future episode. In my opinion, NAP is a nice idea but, it is fraught with problems. One of the biggest problems is that it relies on agent software on the host PC. Said agent software is almost exclusively Windows so Macs, Linux, Printers and other appliances are all SOL. But, the lack of an agent isn't really all bad. Frankly, the last thing I want on my system is YET ANOTHER service gumming up my system and causing issues due to bad design or bugs. Furthermore, I'll never install some strange EXE that is offered in a popup the moment that I plug into a new network. That sounds like a recipe for disaster. And if any of my users are caught installing such stuff, they will be summarily flogged! (As if they could install anything.)
Darren - You used the word "tack", when referring to a dash (-), in this episode and at least one other. It is only the third time that I have ever heard of this usage. Two of those times were by you and all three times have been in the past couple of months. My question is; what is the origin of this term? Is it a regional thing or perhaps a military origin?
noob Nipple










