1 of 35

Ethical Hacking Fundamentals

Module 02

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

2 of 35

Creative idea

Module Objectives

1

2

3

4

5

6

7

Understanding Tactics, Techniques, and Procedures (TTPs)

Overview of Indicators of Compromise (IoCs)

Overview of Hacking Concepts and Hacker Classes

Understanding Different Phases of Hacking Cycle

Understanding Ethical Hacking Concepts and Its Scope

Overview of Ethical Hacking Tools

Understanding the Cyber Kill Chain Methodology

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

3 of 35

Module Flow

Understand Cyber Kill Chain Methodology

1

Discuss Hacking Concepts and Hacker Classes

2

Understand Different Phases of Hacking Cycle

3

Discuss Ethical Hacking Concepts, Scope, and Limitations

4

Ethical Hacking Tools

5

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

4 of 35

Reconnaissance

Weaponization

Delivery

Exploitation

Installation

Command and Control

Actions on Objectives

Create a deliverable malicious payload using �an exploit and a backdoor

Gather data on the target �to probe for weak points

Send weaponized bundle to the victim using email, USB, etc.

Exploit a vulnerability �by executing code on �the victim’s system

Install malware on �the target system

Create a command and control channel to communicate and �pass data back and forth

Perform actions to achieve intended objectives/goals

  • The cyber kill chain methodology is a component of intelligence-driven defense for the identification and prevention of malicious intrusion activities
  • It helps security professionals to understand the adversary’s tactics, techniques, and procedures beforehand

Cyber Kill Chain Methodology

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

5 of 35

Tactics, Techniques, and Procedures (TTPs)

“Tactics” are the guidelines that describe the way an attacker performs the attack from beginning to the end

Tactics

“Procedures” are organizational approaches that threat actors follow to launch an attack

Procedures

“Techniques” are the technical methods used by an attacker to achieve intermediate results during the attack

Techniques

The term Tactics, Techniques, �and Procedures (TTPs) refers to the patterns of activities and methods associated with specific threat actors or groups of threat actors

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

6 of 35

Command and Control Server

HTTP User Agent

Use of Command-Line Interface

Unspecified Proxy Activities

Internal Reconnaissance

Use of PowerShell

Adversary Behavioral Identification

Data Staging

Use of DNS Tunneling

Use of Web Shell

  • Adversary behavioral identification involves the identification of the common methods or techniques followed by an adversary to launch attacks on or to penetrate an organization’s network
  • It gives the security professionals insight into upcoming threats and exploits

Adversary Behaviors

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

7 of 35

Indicators of Compromise (IoCs) are the clues, artifacts, and pieces of forensic data found on the network or operating system of an organization that indicate a potential intrusion or malicious activity in the organization’s infrastructure

IoCs act as a good source of information regarding the threats that serve as data points in the intelligence process

Security professionals need to perform continuous monitoring of IoCs to effectively and efficiently detect and respond to evolving cyber threats

01

03

02

Indicators of Compromise (IoCs)

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

8 of 35

Categories of Indicators of Compromise

Understanding IoCs helps security professionals to quickly detect the threats against the organization and protect the organization from evolving threats

  • Used to identify specific behavior related to malicious activities
  • Examples include document executing PowerShell script, and remote command execution

Behavioral Indicators

  • Used to send malicious data to the target organization or individual
  • Examples include the sender’s email address, email subject, and attachments or links

Email Indicators

  • Useful for command and control, malware delivery, identifying the operating system, and other tasks
  • Examples include URLs, domain names, and IP addresses

Network Indicators

  • Found by performing an analysis of the infected system within the organizational network
  • Examples include filenames, file hashes, registry keys, DLLs, and mutex

Host-Based Indicators

For this purpose, IoCs are divided into four categories:

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

9 of 35

Understand Cyber Kill Chain Methodology

1

Discuss Hacking Concepts and Hacker Classes

2

Understand Different Phases of Hacking Cycle

3

Discuss Ethical Hacking Concepts, Scope, and Limitations

4

Ethical Hacking Tools

5

Module Flow

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

10 of 35

Hacking refers to exploiting system vulnerabilities and compromising security controls to gain unauthorized or inappropriate access to a system’s resources

It involves modifying system or application features to achieve a goal outside of the creator’s original purpose

Hacking can be used to steal and redistribute intellectual property, leading to business loss

What is Hacking?

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

11 of 35

Some hack with malicious intent such as to steal business data, credit card information, social security numbers, email passwords, and other sensitive data

An intelligent individual with excellent computer skills who can create and explore computer software and hardware

For some hackers, hacking is a hobby to see how many computers or networks they can compromise

Some hackers’ intentions can either be to gain knowledge or to probe and do illegal things

Who is a Hacker?

01

02

03

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

12 of 35

Black Hats

Individuals with extraordinary computing skills; they resort to malicious or destructive activities and are also known as crackers

White Hats

Individuals who use their professed hacking skills for defensive purposes and are also known as security analysts

Gray Hats

Individuals who work both offensively and defensively at various times

Suicide Hackers

Individuals who aim to bring down the critical infrastructure for a "cause" and are not worried about facing jail terms or any other kind of punishment

Script Kiddies

An unskilled hacker who compromises a system by running scripts, tools, and software that were developed by real hackers

Hacker Classes/Threat Actors

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

13 of 35

Hacker Classes/Threat Actors (Cont’d)

Cyber Terrorists

Industrial Spies

Hacker Teams

Hacktivist

State-Sponsored Hackers

Individuals with a wide range of skills who are motivated by religious or political beliefs to create the fear through the large-scale disruption of computer networks

Individuals who perform corporate espionage by illegally spying on competitor organizations and focus on stealing information such as blueprints and formulas

A consortium of skilled hackers having their own resources and funding. They work together in synergy for researching the state-of-the-art technologies

Individuals who promote a political agenda by hacking, especially by using hacking to deface or disable website

Individuals employed by the government to penetrate and gain top-secret information from, and damage the information systems of other governments

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

14 of 35

Insider

Any employee (trusted person) who has access to critical assets of an organization. They use privileged access to violate rules or intentionally cause harm to the organization’s information system

Organized Hackers

Miscreants or hardened criminals who use rented devices or botnets to perform various cyber-attacks to pilfer money from victims

Criminal Syndicates

Groups of individuals that are involved in organized, planned, and prolonged criminal activities. They illegally embezzle money by performing sophisticated cyber-attacks

Hacker Classes/Threat Actors (Cont’d)

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

15 of 35

Understand Cyber Kill Chain Methodology

1

Discuss Hacking Concepts and Hacker Classes

2

Understand Different Phases of Hacking Cycle

3

Discuss Ethical Hacking Concepts, Scope, and Limitations

4

Ethical Hacking Tools

5

Module Flow

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

16 of 35

  • Involves acquiring information without directly interacting with the target
  • For example, searching public records or news releases

Passive Reconnaissance

  • Involves directly interacting with the target by any means
  • For example, telephone calls to the target’s help desk or technical department

Active Reconnaissance

Hacking Phase: Reconnaissance

  • Reconnaissance refers to the preparatory phase where an attacker seeks to gather information about a target prior to launching an attack

Reconnaissance Types

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

17 of 35

Hacking Phase: Scanning

Network Scanning Process

Scanning can include the use of dialers, port scanners, network mappers, ping tools, and vulnerability scanners

Scanning refers to the pre-attack phase when the attacker scans the network for specific information based on information gathered during reconnaissance

Attackers extract information such as live machines, port, port status, OS details, device type, and system uptime to launch attack

Sends �TCP/IP probes

Gets network �information

Attacker

Network

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

18 of 35

The attacker can escalate privileges to obtain complete control of the system

Examples include password cracking, buffer overflows, denial of service, and session hijacking

Gaining access refers to the point where the attacker obtains access to the operating system or applications on the target computer or network

The attacker can gain access at the operating system, application, or network levels

Hacking Phase: Gaining Access

03

04

01

02

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

19 of 35

Maintaining access refers to the phase when the attacker tries to retain their ownership of the system

Attackers may prevent the system from being owned by other attackers by securing their exclusive access with backdoors, rootkits, or Trojans

Attackers can upload, download, or manipulate data, applications, and configurations on the owned system

Attackers use the compromised system to launch further attacks

1

3

2

4

Hacking Phase: Maintaining Access

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

20 of 35

Clearing tracks refers to the activities carried out by an attacker to hide malicious acts

01

The attacker overwrites the server, system, and application logs to avoid suspicion

03

The attacker’s intentions include obtaining continuing access to the victim’s system, remaining unnoticed and uncaught, and deleting evidence that might lead to their prosecution

02

Hacking Phase: Clearing Tracks

Attackers always cover their tracks to hide their identity

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

21 of 35

Understand Cyber Kill Chain Methodology

1

Discuss Hacking Concepts and Hacker Classes

2

Understand Different Phases of Hacking Cycle

3

Discuss Ethical Hacking Concepts, Scope, and Limitations

4

Ethical Hacking Tools

5

Module Flow

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

22 of 35

Ethical hacking involves the use of hacking tools, tricks, and techniques to identify vulnerabilities and ensure system security

It focuses on simulating the techniques used by attackers to verify the existence of exploitable vulnerabilities in a system’s security

Ethical hackers perform security assessments for an organization with the permission of concerned authorities

What is Ethical Hacking?

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

23 of 35

Why Ethical Hacking is Necessary

Reasons why organizations recruit ethical hackers

Ethical hacking is necessary as it allows for counter attacks against malicious hackers through anticipating the methods used to break into the system

To beat a hacker, you need to think like one!

To enhance security awareness at all levels in a business

To analyze and strengthen an organization’s security posture

To uncover vulnerabilities in systems and explore their potential as a security risk

To help safeguard customer data

To prevent hackers from gaining access �to the organization’s information systems

To provide adequate preventive measures in order to avoid security breaches

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

24 of 35

Why Ethical Hacking is Necessary (Cont’d)

How much time, effort, and money are required to obtain adequate protection?

What can an intruder do with that information? (Gaining Access and Maintaining Access phases)

5

2

Are the information security measures in compliance with legal and industry standards?

Does anyone at the target organization notice the intruders’ attempts or successes? (Reconnaissance and Covering Tracks phases)

6

3

Are all components of the information system adequately protected, updated, and patched?

What can an intruder see on the target system? (Reconnaissance and Scanning phases)

4

1

Ethical Hackers Try to Answer the Following Questions

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

25 of 35

  • Unless the businesses already know what they are looking for and why they are hiring an outside vendor �to hack systems in the first place, chances are there would not be much to gain from the experience
  • An ethical hacker can only help the organization to better understand its security system; it is up to the organization to place the right safeguards on the network
  • Ethical hacking is a crucial component of risk assessment, auditing, counter fraud, and information systems security best practices
  • It is used to identify risks and highlight remedial actions. It also reduces ICT costs by resolving vulnerabilities

Scope and Limitations of Ethical Hacking

Scope

Limitations

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

26 of 35

  • In-depth knowledge of major operating environments such as Windows, Unix, Linux, and Macintosh
  • In-depth knowledge of networking concepts, technologies, and related hardware and software
  • A computer expert adept at technical domains
  • Knowledgeable about security areas and related issues
  • High technicalknowledge for launching sophisticated attacks
  • The ability to learn and adopt new technologies quickly
  • Strong work ethics and good problem solving and communication skills
  • Committed to the organization’s security policies
  • An awareness of local standards and laws

Skills of an Ethical Hacker

Non-Technical Skills

Technical Skills

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

27 of 35

Understand Cyber Kill Chain Methodology

1

Discuss Hacking Concepts and Hacker Classes

2

Understand Different Phases of Hacking Cycle

3

Discuss Ethical Hacking Concepts, Scope, and Limitations

4

Ethical Hacking Tools

5

Module Flow

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

28 of 35

Reconnaissance Using Advanced Google Hacking Techniques

Popular Google advanced search operators

Google hacking refers to the use of advanced Google search operators for creating complex search queries to extract sensitive or hidden information that helps attackers find vulnerable targets

Search operators

Description

[cache:]

Displays the web pages stored in the Google cache

[link:]

Lists web pages that have links to the specified web page

[related:]

Lists web pages that are similar to the specified web page

[info:]

Presents some information that Google has about a particular web page

[site:]

Restricts the results to those websites in the given domain

[allintitle:]

Restricts the results to those websites containing all the search keywords in the title

[intitle:]

Restricts the results to documents containing the search keyword in the title

[allinurl:]

Restricts the results to those containing all the search keywords in the URL

[inurl:]

Restricts the results to documents containing the search keyword in the URL

[location:]

Finds information for a specific location

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

29 of 35

http://www.webextractor.com

https://whois.domaintools.com

Web Data Extractor

It extracts targeted contact data (email, phone, and fax) from the website, extracts the URL and meta tags (title, description, keyword) for website promotion, and so on

Reconnaissance Tools

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

30 of 35

IMCP Traceroute

TCP Traceroute

UDP Traceroute

Reconnaissance Tools (Cont’d)

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

31 of 35

Scanning Tools

Nmap

https://nmap.org

MegaPing

http://www.magnetosoft.com

Use Nmap to extract information such as live hosts on the network, open ports, services (application name and version), types of packet filters/ firewalls, as well as operating systems and versions used

Includes scanners such as Comprehensive Security Scanner, Port scanner (TCP and UDP ports), IP scanner, NetBIOS scanner, and Share Scanner

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

32 of 35

Scanning Tools (Cont’d)

Possible OS is Windows

https://sourceforge.net

In Unicornscan, the OS of the target machine can be identified by observing the TTL values in the acquired scan result

Unicornscan

Hping2/Hping3

http://www.hping.org

NetScanTools Pro

https://www.netscantools.com

SolarWinds Port Scanner

https://www.solarwinds.com

PRTG Network Monitor

https://www.paessler.com

OmniPeek Network Protocol Analyzerhttps://www.liveaction.com

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

33 of 35

Enumeration Tools

The nbtstat utility in Windows displays NetBIOS over TCP/IP (NetBT) protocol statistics, NetBIOS name tables for both the local and remote computers, and the NetBIOS name cache

Nbtstat Utility

NetBIOS Enumerator helps to enumerate details, such as NetBIOS names, Usernames, Domain names, and MAC addresses, for a given range of IP addresses

NetBIOS Enumerator

Attackers specify an IP range to enumerate NetBIOS information

Obtain information, such as NetBIOS names, usernames, domain names, and MAC addresses

Other NetBIOS Enumeration Tools:

Advanced IP Scanner

https://www.advanced-ip-scanner.com

Global Network Inventory

http://www.magnetosoft.com

Nsauditor Network Security Auditorhttps://www.nsauditor.com

Hyena

https://www.systemtools.com

http://nbtenum.sourceforge.net

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

34 of 35

Module Summary

1

This module has discussed the cyber kill chain methodology, TTPs, and IoCs in detail

4

It has discussed ethical hacking concepts such as its scope and limitations and the skills of an ethical hacker

2

It also discussed hacking concepts and hacker classes

5

Finally, this module ended with an overview of ethical hacking tools

3

This module also discussed in detail on different phases of hacking cycle

6

In the next module, we will discuss in detail on information security threats, vulnerabilities, and malware concepts

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.

35 of 35

Thank You

Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.