hacker

hacker etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
hacker etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

28 Aralık 2017 Perşembe

Penetration Tests With Nessus (Chapter 1) Nessus İle Sızma Testleri




Hello  everyone. Today I will write to you about "Nessus Vulnerability Scanner"

This is the first part of my wiriting about nessus  in this section I will talk about simple scans and setup 

You can follow us on twitter @berkdusunur
Okay let's start :)

Nessus Linux Installation

You should first download the appropriate for your system.
You can view the packages in this;

https://www.tenable.com/products/nessus/select-your-operating-system 

I downloaded the debian package.  Let's go to setup :)


dpkg  -i Nessus-7.0.0-debian6_amd64.deb 





We got the activation code after opening Tenable membership. I then connected with the 8834 port scanner and entered the necessary information




Meanwhile I downloaded the "metasploitable 2" virtual machine.  Then started broadcasting with VirtualBox

FOr a short time IP Address for vulnerability researcher
Now right click on the new scan option


I will choose a simple network scan to be an example

after...


We enter the target name and ip address 212.83.175.136


This part asks if you want to do the scanning at the widespread ports or not


This section asks how to perform a scan on the web application.

We started scanning


Continues to scan I will have a coffee :) Nessus gives  more healthier result than its competitors.

I am using nessus with remote server because  I do not have to wait for slow scans


Many security vulnerabilities have been achieved.


In the second part we will explain how to exploit these vulnerabilities.

Thank you for reading.

E-Mail for your questions berkdusunurx@gmail.com

14 Kasım 2017 Salı

What İs Honeypot ? - Trap Systems - Hacker Hunt (Honeypot - Hacker Avı )




What İs Honeypot ? - Trap Systems - Hacker Hunt (Honeypot - Hacker Avı )



Trap computer systems that detect attacks that may come in advance, mislead the attacker against unauthorized access, and time out the attacker

(Gelebilecek saldırıları önceden tespit edip yetkisiz erişimlere karşı saldırganı yanıltan saptıran ve saldırgana vakit kaybettiren tuzak bilgisayar sistemleridir)


It is usually the fragments of a trap that mimic the real system that appears to be part of a computer application or a service that contains a vulnerability
(Genellikle zaafiyet içeren bir bilgisayarın uygulamanın veya bir servisin parçası gibi görünen gerçek sistemin taklidini yapan tuzak parçalarıdır )



Access to honeypots is considered an enemy because there is no reason for the end user to communicate with the imitated trap system. After the Honeypot is examined, the necessary defenses are made

(Son kullanıcının taklit edilen tuzak sistem ile iletişime geçmesi için herhangi bir sebebi bulunmadığı için honeypotlara yapılan erişimler düşman olarak kabul edilir. Honeypot incelendikten sonra gerekli defans yapılır)

What Does Honeypot Do? (Honeypot Ne İşe Yarar?)

Protecting real systems helps to collect data so that the necessary defensive security can be established. It is important in terms of attracting the attacker's attention and saving time.
(Gerçek sistemlerin korunması ve gerekli defansif güvenliğin oluşturulabilmesi için veri toplanmasına yarar. Saldırganın dikkatinin başka yöne çekilip zaman kazanılması için büyük önem taşır)



The Advantages Of Using Honeypots (Honeypot Sistemlerin Avantajları) 

Actual Data Collection (Gerçek Veri Toplama) 

The data collected reflects the truts of more

False Alerts (Yanlış Uyarılar)

Intrusion detection systems and fırewalls mostly gives false alerts. Collects data from honeypot systems but completely accurate 
(Saldırı tespit sistemleri ve güvenlik duvarları genellikle yanlış uyarılar verir fakat honeypot sistemler herzaman doğru veriler getirir)

Usually Free Software (Genellikle Ücretsiz Yazılımlar)

Honeypot systems are usually free and open software. The cost is there most of the time 
(Honeypot Sistemler genellikle ücretsiz ve özgür yazılımlardır. Bu da çoğu zaman maliyeti düşürür)

Basic Systems (Basit Sistemler)

Realistic systems on the user side, and indispensible security
(Gerçekçi sistemleri kullanıcı taraflı arayüz ve güvenlik için vazgeçilmezdir)

Kippo SSH Hacker Hunt Fake Service
https://github.com/desaster/kippo/wiki/Running-Kippo

FTP Hacker Hunt Fake Service
https://github.com/alexbredo/honeypot-ftp

MySQL Hacker Hunt Fake Service
https://github.com/schmalle/MysqlPot


Thank You For Reading