c, 723
creating DoS (Denial-of-Service) traffic with,
665??“669
Trojans
Back Orifice, 519??“533
detection software, 519
NetBus, 534??“544
TSGrinder, 354??“356, 716
U
UDP (User Datagram Protocol)
DoS (Denial-of-Service) flood attack,
660??“664
ngrep recognizing, 213
User Datagram Protocol,
see
UDP
User information
gathering with DUMPSEC, 98??“101
gathering with USERDUMP, 96
gathering with USERINFO, 97
USER2SID, 91, 679
USERDUMP, 96, 679
USERINFO, 97, 679
Usernames
adding to Red Hat Version 8 virtual machine,
50
attackers looking for, 222, 353
enumerating from SIDs (Security Identifiers),
93??“95
enumerating SIDs from given, 91
Ettercap intercepting, 564??“565
John the Ripper and, 345
NETWOX/NETWAG providing, 385
V
Video cards, Red Hat Version 8, 53
Virtual computers
defined, 3
switching back to hosts from, 29
VMware Workstation hosting, 10
Virtual machines, 10??“59
installing Red Hat Version 8, 35??“55
beginning installation, 51??“55
installing VMware Tools, 55??“59
New Virtual Machine Wizard,
35??“38
settings, 38??“51
installing Windows 2000 Workstation,
11??“29
formatting hard drive, 19??“20
installing VMware Tools, 29??“34
networking components, 24??“25
New Virtual Machine Wizard, 11??“14
settings for, 21??“24
starting virtual machine, 15??“18
overview of, 10
Visual Route, 126??“127, 694
VMware
P2V Assistant, 3
syntax, 712
VMware Tools
changes after installing, 34
for Red Hat Version 8 virtual machines,
55??“59
for Windows 2000 virtual machines,
29??“34
wizard, 31??“34
VMware Workstation
demo version, 3
hosting virtual computers, 10
installing, 3??“10
installing Red Hat Version 8 virtual machine,
35??“55
installing virtual Windows 2000 Workstation,
11??“29
overview of, 3
spoofing MAC (Media Access Control)
addresses with, 295??“297
Vulnerability scanning, 357??“510
Cerberus, 468??“473
Fake Lock Screen XP, 491??“498
executing, 494??“498
how it works, 491
setting parameters, 492??“493
starting application, 491??“492
syntax, 719
Metasploit, 429??“450
on Linux, 441??“450
syntax for, 717
736
Practical Hacking Techniques and Countermeasures
on Windows, 429??“440
N-Stealth, 414??“420
NETWOX/NETWAG, 379??“385
Nitko, 451??“454
Pluto, 421??“428
Retina, 392??“396
RockXP, 499??“506
SAINT (Security Administrator??™s Integrated
Network Tool), 359??“378
executing against target, 364??“373
how it works, 359
installing, 359??“364
patches, 378
reviewing results, 373??“378
syntax for, 717
SARA (Security Auditor??™s Research Assistant),
402??“413
compiling, 402??“404
executing against target, 404??“407
how it works, 402
reviewing results, 408??“413
syntax for, 717
Shadow Scanner, 455??“467
executing against target, 460??“461
installing, 455
quality and cost of, 467
reviewing results, 462??“467
setting parameters, 458??“459
starting application, 456??“457
syntax for, 719
target assessment, 455??“467
Solar Winds, 386??“391
Web Hack Control Center, 507??“510
WHAX, 474??“490
booting from CD, 474??“475
executing AutoScan, 482??“490
how it works, 474
setting parameters, 476??“481
X-Scan, 397??“401
W
WebGoat, 574??“575, 584??“587
Web Hack Control Center,
see
WHCC scan
Web server target assessment
Nikto, 451??“454
N-Stealth, 414??“420
WEP (Wired Equivalent Privacy), 516
WGateScan, 187??“189, 697
WHAX, 474??“490
booting from CD, 474??“475
executing AutoScan, 482??“490
how it works, 474
setting parameters, 476??“481
WHCC (Web Hack Control Center) scan,
507??“510, 719
Windows
installing amap on, 82??“83
installing Ethereal on, 195
iPDump2 for, 237??“239
licensing requirements, 10
Metasploit for, 429??“440
ngrep for, 219??“222
Nikto for, 454
Restrict Anonymous in versions of,
60??“62
targeting default shares on, 135??“138
Windows 2000 virtual machines
installing virtual Workstation, 11??“29
formatting hard drive, 19??“20
networking components, 24??“25
settings for, 21??“24
starting New Virtual Machine wizard,
11??“14
starting virtual machine, 15??“18
installing VMware Tools, 29??“34
Restrict Anonymous and, 61
Windows Product Activation,
see
WPA file
WinDump, 230??“233, 700??“705
WinFingerprint, 139??“143, 694
Wingate Proxy Servers, 187??“191
Wingate Scanner, 187??“189, 697
WinPcap
installing Ethereal with, 195, 209??“210
installing Ettercap with, 557
Wired Equivalent Privacy,
see
WEP
Wireless, 511??“602
Achilles, 574??“587
configuring Web browser, 576??“578
how it works, 574
launch application, 578??“584
launch WebGoat, 574??“575
manipulate data in real-time,
585??“587
Back Orifice, 519??“533
on attacker??™s computer, 528??“533
how it works, 519
installing remotely, 533
syntax for, 719
Dsniff, 573
Ettercap, 556??“572
changing data, 565??“572
displaying hostnames, 560??“562
how it works, 556
installing, 556??“557
intercepting usernames/passwords,
562??“565
setting parameters, 558??“559
NetBus, 534??“544
on attacker??™s computer, 540??“544
vs.
Pages:
276
277
278
279
280
281
282
283
284
285
286
287
288
289