It should
be fairly easy to compromise.
Vulnerability Scanning 421
Lab 67: Vulnerability Scanner
Exploit Data from Target Computer: Pluto
Prerequisites: None
Countermeasures: Secure ACLs, Bastion computers
Description: An overall security scanner, including a multithreaded port
scanner, Common Gateway Interface (CGI) scanner, port fingerprinting,
Microsoft Structured Query Language (MSSQL) audit, FTP audits,
SMTP audits, Network Basic Input/Output System (NetBIOS) audits,
and password audits.
Procedure: Start, set the parameters, and execute.
Open the audits.ini file.
Enter the correct path the *.audit files and save.
422 Practical Hacking Techniques and Countermeasures
Double-click the Pluto icon to start the application.
The Pluto scanner will start with the Address field highlighted.
Vulnerability Scanning 423
Change the IP address to the target IP Address or Hostname.
Place your mouse over Config on the left side of the screen. This is actually
a button but the mouse icon will not change. Click on Config and the Options
screen will appear.
424 Practical Hacking Techniques and Countermeasures
Drag the slider bar for the Number of Threads as far to the right as
possible. Click Apply. The screen will close.
*Note: Do NOT click on Password Brute Force as this function creates windows
errors (this is a fluke in Pluto??™s code).
Click on Config again and click on the Brute Force tab. Review the location
and names of the Password and Usernames files.
Pages:
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159