EC-Council Certified Ethical Hacker (CEH) v12 flashcards
189 free flashcards. Tap a card to flip it.
WPA2-Personal PSK Cracking
Flip cardRecovering the Pre-Shared Key (PSK) for a WPA2-Personal network, typically after capturing a 4-way handshake, often involves offline dictionary or brute-force attacks.
- Requires capturing the 4-way handshake between a client and AP.
- Attacks are performed offline against the captured handshake.
- PSK strength directly impacts the feasibility of cracking.
Memory trick: Handshake captured, now dictionary words unlock the key.
Kismet Wireless Sniffer
Flip cardKismet is a powerful open-source wireless network detector, sniffer, and intrusion detection system. It passively collects 802.11 frames to discover wireless networks (APs and clients), SSIDs, detect hidden networks, and identify rogue access points or other wireless anomalies.
- Operates in passive mode, avoiding active probing.
- Analyzes raw 802.11 frames (beacon, probe, data).
- Used for network discovery, mapping, and intrusion detection.
Memory trick: Kismet listens passively to discover all wireless secrets.
WPA3-Personal SAE
Flip cardSimultaneous Authentication of Equals (SAE) is the key exchange protocol used in WPA3-Personal, replacing the WPA2 4-way handshake, to provide stronger security against offline dictionary attacks.
- Mandatory for WPA3-Personal networks.
- Provides forward secrecy and resistance to side-channel attacks.
- Makes passive offline dictionary attacks significantly harder or impossible.
Memory trick: SAE secures the WPA3 handshake, no more easy dictionary guesses.
2.4 GHz Interference Sources
Flip cardThe 2.4 GHz Wi-Fi frequency band is prone to interference from a multitude of non-Wi-Fi devices, including microwave ovens, cordless phones, Bluetooth devices, and baby monitors, due to their shared use of this unlicensed spectrum.
- Shared with many common household and industrial devices.
- Fewer non-overlapping channels (3 in most regions).
- Leads to slower speeds and unreliable connections if not properly managed.
Memory trick: 2.4 GHz is the crowded party where everyone brings their noisemakers.
Aireplay-ng Deauthentication
Flip cardAireplay-ng is a tool within the Aircrack-ng suite used to inject frames into a wireless network, most notably for deauthentication attacks to capture WPA/WPA2 handshakes.
- Part of the Aircrack-ng suite.
- Used to send deauthentication frames to clients.
- Forces clients to reconnect, allowing handshake capture for cracking.
Memory trick: Aireplay's ghost deauths, Airodump sniffs the handshake.
Evil Twin Attack
Flip cardA type of attack where a rogue wireless access point (AP) mimics a legitimate one, often using the same SSID, to trick unsuspecting users into connecting to it. Once connected, the attacker can intercept, monitor, or manipulate their network traffic.
- Uses a rogue AP with a spoofed SSID.
- Often targets open or easily guessable networks.
- Facilitates man-in-the-middle attacks.
Memory trick: Spoofed APs create Evil Twins for data interception.
Kismet Wireless Reconnaissance
Flip cardKismet is a passive wireless network detector, sniffer, and intrusion detection system that identifies wireless networks, clients, and their relationships without actively transmitting.
- Operates in passive mode, minimizing detection.
- Identifies APs, clients, SSIDs (including hidden ones).
- Can visualize network topology and client-AP associations.
Memory trick: Kismet silently watches, mapping the hidden Wi-Fi world.
PEAP (MSCHAPv2) Offline Cracking
Flip cardPEAP (Protected Extensible Authentication Protocol) using MSCHAPv2 as its inner authentication method can be vulnerable to offline dictionary attacks if the MSCHAPv2 hashes are captured within EAPOL frames.
- PEAP creates an encrypted tunnel for inner EAP methods.
- MSCHAPv2 is a common inner method, but its hashes can be cracked offline.
- Tools like EAPHammer or Responder can be used to capture and crack these hashes.
Memory trick: EAPOL frames hide PEAP's MSCHAPv2, a crackable secret.
802.11w (Management Frame Protection)
Flip cardAn IEEE standard that enhances wireless network security by providing integrity protection and confidentiality for management frames (such as deauthentication, disassociation, and beacon frames). This prevents attackers from forging these frames to disrupt network operations or perform denial-of-service attacks.
- Protects management frames from spoofing and tampering.
- Uses Message Integrity Check (MIC) for integrity.
- Crucial for mitigating deauthentication and disassociation DoS attacks.
Memory trick: 802.11w protects management frames from rogue disconnections.
WPA/WPA2 4-Way Handshake MIC
Flip cardThe Message Integrity Code (MIC) is a cryptographic checksum included in the WPA/WPA2 4-way handshake messages. It ensures the integrity of the handshake messages and is critical for offline passphrase cracking, as a correct passphrase will yield a matching MIC.
- Verifies integrity of handshake messages.
- Calculated using the Pairwise Transient Key (PTK).
- Used to confirm a guessed passphrase in offline cracking.
Memory trick: MIC is the Key to Cracking Passwords.
WPS Reaver Attack
Flip cardThe Reaver attack is an online brute-force attack against Wi-Fi Protected Setup (WPS) PINs. It exploits a design flaw in WPS where the Access Point (AP) confirms the correctness of the first four digits of the PIN and the last three digits (plus checksum) separately, effectively dividing an 8-digit PIN into two smaller, easier-to-brute-force sections.
- Exploits WPS PIN validation in two halves.
- Significantly reduces brute-force attempts.
- Typically an online attack, can be slow but effective.
Memory trick: Reaver divides the WPS PIN, conquering it in two halves.
MAC Address Filtering Bypass
Flip cardMAC address filtering, a basic wireless security measure, can be easily bypassed by an attacker who spoofs the MAC address of an authorized device.
- Relies on the uniqueness of MAC addresses for access control.
- MAC addresses are easily discoverable for active clients.
- Spoofing allows an attacker to impersonate an authorized device.
Memory trick: MAC filtering's a ghost, easily spoofed by a clever host.
802.11w (PMF)
Flip cardIEEE 802.11w, or Protected Management Frames (PMF), is a standard that enhances wireless network security by protecting management frames from tampering and spoofing.
- Protects deauthentication, disassociation, and other management frames.
- Mitigates denial-of-service attacks against wireless networks.
- Mandatory in WPA3 for enhanced security.
Memory trick: 802.11w shields management frames from malicious hands.
Wireless Denial-of-Service
Flip cardWireless Denial-of-Service (DoS) attacks aim to prevent legitimate users from accessing a wireless network or its services, often by overwhelming the access point or exploiting vulnerabilities.
- Can involve deauthentication floods, jamming, or exploiting AP vulnerabilities.
- Impacts availability of the wireless network.
- Targeted attacks against AP firmware are a specific form of DoS.
Memory trick: DoS: Disrupting service, making Wi-Fi a mess.
5 GHz Interference Sources
Flip cardVarious devices can cause interference in the 5 GHz wireless band, impacting Wi-Fi network performance and reliability.
- 5 GHz Wi-Fi offers higher bandwidth and less congestion than 2.4 GHz.
- Sources of interference include radar, satellite communication, and certain cordless phones.
- Dynamic Frequency Selection (DFS) is used by Wi-Fi to avoid radar interference.
Memory trick: Radar's pulse disrupts 5 GHz Wi-Fi's flow.
Rainbow Table Limitations in WPA2-Personal
Flip cardRainbow tables are generally inefficient for cracking WPA2-Personal due to the use of the SSID as a salt in the PBKDF2 key derivation function. This requires a unique rainbow table to be precomputed for each potential SSID, rendering the approach impractical for universal attacks.
- SSID acts as a salt during PMK generation.
- Different SSIDs produce different PMKs for the same passphrase.
- Requires a separate rainbow table for each SSID, making it unscalable.
Memory trick: SSID's salt makes Rainbow Tables impractical for WPA2.
Enhanced Open (OWE)
Flip cardEnhanced Open (Opportunistic Wireless Encryption) is a Wi-Fi standard (integrated into WPA3) that provides individualized data encryption for open, public Wi-Fi networks. It secures communication between the client and the access point without requiring any pre-shared key or user authentication credentials.
- Provides opportunistic encryption for open Wi-Fi.
- Based on Diffie-Hellman key exchange for per-client session keys.
- Protects against passive eavesdropping on open networks.
Memory trick: OWE encrypts Open Wi-Fi, protecting every user's private flow.
PEAP (Protected Extensible Authentication Protocol)
Flip cardA protocol that encapsulates EAP (Extensible Authentication Protocol) methods within a TLS (Transport Layer Security) tunnel, providing secure authentication, especially for username/password-based systems over 802.1X networks.
- Commonly used with WPA2-Enterprise and 802.1X.
- Establishes a secure TLS tunnel before client authentication.
- Protects EAP methods like MSCHAPv2 from eavesdropping.
Memory trick: Enterprise networks Protect Credentials with Strong Tunnels.
EAP-TLS Mutual Authentication
Flip cardEAP-TLS (Extensible Authentication Protocol-Transport Layer Security) uses digital certificates for mutual authentication, where both the client and the authentication server verify each other's identity.
- Requires a Public Key Infrastructure (PKI).
- Provides strong protection against Man-in-the-Middle attacks.
- Client trusts the server's certificate, and the server trusts the client's certificate.
Memory trick: EAP-TLS: Both sides show their certificates, no fakes allowed.
PBKDF2 in WPA/WPA2
Flip cardPBKDF2 (Password-Based Key Derivation Function 2) is a key stretching algorithm used in WPA/WPA2-Personal to derive the Pairwise Master Key (PMK) from the human-readable passphrase (PSK) and the SSID. Its iterative nature makes offline brute-force attacks computationally expensive.
- Takes passphrase, salt (SSID), iteration count, and key length as input.
- Generates the 256-bit PMK.
- Core component of WPA/WPA2-Personal security, and its weakness to dictionary attacks.
Memory trick: PBKDF2 hashes the Passphrase and SSID to create the PMK.
Evil Twin Attack Facilitation
Flip cardAn Evil Twin attack often uses deauthentication frames to disconnect legitimate clients from their access points, compelling them to search for and connect to the attacker's rogue access point, which mimics the legitimate network's SSID.
- Deauthentication forces clients off network.
- Clients automatically search for known SSIDs.
- Rogue AP receives connections, enabling traffic interception.
Memory trick: Deauth + Rogue AP = Evil Twin's Deceptive Lure.
802.11 Deauthentication Frame
Flip cardAn 802.11 deauthentication frame is a management frame used to terminate an existing connection between a wireless client and an access point.
- It is an unauthenticated frame, making it vulnerable to spoofing.
- Attackers use it to force clients to disconnect and reauthenticate.
- This action generates a 4-way handshake, which can be captured for cracking.
Memory trick: Deauth frames unplug clients, making handshakes appear.
WPA3-Enterprise with EAP-TLS
Flip cardThe most secure current wireless standard combining WPA3's enhanced cryptographic protections and key management with EAP-TLS for robust mutual authentication using digital certificates, offering superior defense against various wireless attacks.
- WPA3 provides Forward Secrecy and improved key management.
- EAP-TLS uses client and server certificates for mutual authentication.
- Offers the strongest protection against passive eavesdropping and impersonation.
Memory trick: WPA3 Enterprise and EAP-TLS provide the ultimate security shield.
Aircrack-ng for WEP Cracking
Flip cardAircrack-ng is a powerful suite of tools used for auditing and cracking WEP and WPA/WPA2 wireless networks. For WEP, it leverages vulnerabilities like weak Initialization Vectors (IVs) and packet injection to gather enough data to statistically derive the WEP key.
- Uses statistical attacks (e.g., FMS attack).
- Requires collecting a large number of IVs.
- Can perform packet injection to accelerate IV collection.
Memory trick: Aircrack-ng is the undisputed champion for WEP key cracking.
Cross-Site Request Forgery (CSRF)
Flip cardAn attack that forces an end user to execute unwanted actions on a web application in which they are currently authenticated.
- Exploits trust in a user's browser, not the user directly.
- Often uses social engineering to trick victims.
- Anti-CSRF tokens are a common defense mechanism.
Memory trick: CSRF doesn't need to 'script' anything, just 'trick' with a link.
Session Fixation
Flip cardAn attack where the attacker tricks a user into authenticating with a session ID chosen by the attacker, allowing the attacker to impersonate the user.
- Relies on the server not regenerating session IDs upon successful authentication.
- Often facilitated by social engineering or XSS to deliver the fixed session ID.
- Countermeasure: regenerate session IDs on every successful login.
Memory trick: Fixed sessions mean an attacker can 'fix' their entry.
Server-Side Request Forgery (SSRF)
Flip cardA web security vulnerability that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
- Can target internal networks, cloud instance metadata, or local files.
- Often used to bypass firewalls or access internal services.
- Mitigation involves input validation and restricting server-side requests.
Memory trick: SSRF makes the 'Server Request For' the attacker.
Directory Traversal
Flip cardA web application vulnerability that allows an attacker to read arbitrary files on the web server by manipulating file paths in URLs or other input fields.
- Also known as Path Traversal.
- Exploits insufficient validation of user-supplied input.
- Can lead to disclosure of sensitive information like configuration files or password files.
Memory trick: Path to the 'passwd' leads to trouble.
Secure File Uploads
Flip cardA set of security measures to prevent malicious files from being uploaded and executed on a web server.
- Always perform server-side validation.
- Validate file type (magic bytes), extension, and size.
- Store uploaded files in non-executable directories.
- Rename files to prevent path traversal and ensure unique names.
Memory trick: Uploads need a 'Magic Whitelist' on the server.
NoSQL Injection
Flip cardAn injection attack that exploits vulnerabilities in NoSQL databases by injecting malicious NoSQL query syntax to bypass authentication, retrieve unauthorized data, or execute arbitrary commands.
- Targets databases like MongoDB, Cassandra, Redis.
- Syntax varies depending on the specific NoSQL database.
- Often involves manipulating JSON or BSON queries.
Memory trick: NoSQL means 'No Standard Query Language' for injection.
Denial of Service (DoS)
Flip cardAn attack aimed at making a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet.
- Can target network bandwidth, server resources, or applications.
- Distinguished from DDoS by originating from a single source.
- Common methods include SYN floods, ICMP floods, and HTTP floods.
Memory trick: Too many requests will deny service.
Web Application Firewall (WAF)
Flip cardA security solution that monitors, filters, and blocks HTTP traffic to and from a web application, protecting against web-based attacks.
- Operates at Layer 7 (Application Layer) of the OSI model.
- Protects against common vulnerabilities like SQL Injection, XSS, and CSRF.
- Can be network-based, host-based, or cloud-based.
Memory trick: WAF is the 'Watchman Against Frauds' for web apps.
XML External Entity (XXE) Injection
Flip cardA web application vulnerability that allows an attacker to interfere with an application's processing of XML data, often leveraging features of XML parsers to access local files or internal resources.
- Exploits external entity declarations (DOCTYPE) within XML.
- Can lead to information disclosure, server-side request forgery (SSRF), or denial of service.
- Mitigation includes disabling DTDs or external entities in XML parsers.
Memory trick: XXE means 'eXploiting External Entities' in XML.
Cross-Site Tracing (XST)
Flip cardAn attack that leverages the HTTP TRACE method to steal HTTPOnly cookies, often in conjunction with a reflected XSS vulnerability.
- Exploits web servers that allow the HTTP TRACE method.
- Allows an attacker to view raw request headers, including HTTPOnly cookies.
- Mitigation: Disable the HTTP TRACE method on web servers.
Memory trick: TRACE reflects, XSS steals cookies.
Input Validation (Whitelisting)
Flip cardA security practice where only explicitly defined 'good' input patterns are accepted, and all other input is rejected.
- More secure than blacklisting.
- Reduces the attack surface significantly.
- Applicable to various input types: strings, numbers, file uploads.
Memory trick: Whitelist means 'only the good guys get in'.
Nmap http-enum Script
Flip cardAn Nmap script used to enumerate applications, directories, and files on web servers by attempting to find common or hidden resources.
- Part of Nmap's Scripting Engine (NSE).
- Helps discover potential attack surface.
- Uses wordlists for common paths and filenames.
Memory trick: Enum-erate means 'list everything' for the web.
Directory Listing
Flip cardA web server configuration where browsing a directory URL without a specific file (e.g., `index.html`) displays a list of all files and subdirectories within that directory.
- Also known as Directory Browsing or Indexing.
- Exposes server structure and potentially sensitive files.
- Should be disabled in production environments.
Memory trick: Listing directories is like leaving the 'secret' door open.
Nmap Ping Scan (-sn)
Flip cardAn Nmap scan type focused solely on host discovery, determining which hosts on a network are online without performing port scanning.
- Uses ICMP echo requests, TCP SYN to 443, and TCP ACK to 80 by default.
- Generates less traffic than full port scans.
- Useful for identifying live hosts without being overly intrusive.
Memory trick: Ping Scan: 'Are you there? Just a quick hello, no need to open the door!'
TheHarvester
Flip cardAn open-source intelligence (OSINT) tool used for gathering publicly available information such as email addresses, subdomains, hostnames, and employee names from various public sources.
- OSINT gathering tool
- Collects emails, hostnames, subdomains
- Uses search engines, PGP servers, etc.
- Passive reconnaissance
Memory trick: The Harvester harvests emails from the open internet.
Subdomain Enumeration
Flip cardThe process of discovering all subdomains associated with a target domain to identify additional entry points or assets for a penetration test.
- Expands attack surface
- Uses various DNS record types (A, AAAA, NS, MX)
- Leverages search engines, passive DNS, brute-forcing
- Can reveal hidden or forgotten assets
Memory trick: Subdomains are like finding all the hidden rooms in a big house.
Verbose Error Message Countermeasures
Flip cardVerbose error message countermeasures involve configuring web applications and servers to display generic, non-informative error messages to users, thereby preventing the leakage of sensitive internal details like database connection strings, file paths, and application versions.
- Sensitive information in errors aids attackers in enumeration and exploitation.
- Custom error pages should be implemented to hide internal details.
- Error logging should still capture full details internally for debugging.
- A fundamental security hygiene practice for web applications.
Memory trick: Errors are secrets; show only a blank page, not the whole story.
Service Banner Grabbing Countermeasures
Flip cardActions taken to prevent the disclosure of detailed service and OS version information from server banners or default error messages, which can be used by attackers for targeted exploits.
- Server banners reveal versions
- Modify or remove default banners
- Genericize error messages
- Reduce attack surface
Memory trick: Don't shout your software version to the world.
Nmap ARP Ping (-PR)
Flip cardAn Nmap host discovery method that sends ARP requests to identify live hosts on a local Ethernet network. It operates at Layer 2 and does not traverse routers.
- Operates at Layer 2 (Data Link Layer).
- Does not cross subnet boundaries.
- Effective for local network host discovery.
- Less likely to trigger NIDS compared to Layer 3 pings.
Memory trick: Pings are like knocking; ARP is like asking your neighbor directly.
Web Content Enumeration
Flip cardThe process of discovering hidden files, directories, and other sensitive content on a web server, often using brute-force with wordlists.
- Targets web servers
- Uses tools like dirb, gobuster, wfuzz
- Aims to find unlinked or forgotten content
Memory trick: Web content is like finding secret rooms in a website.
Insecure Deserialization
Flip cardInsecure Deserialization is a vulnerability where an application deserializes untrusted data, allowing an attacker to manipulate objects or inject malicious code.
- Can lead to remote code execution, privilege escalation, or denial of service.
- Occurs when an application reconstructs an object from a data stream without verifying its integrity.
- Prevented by not deserializing untrusted data or using secure serialization formats/libraries.
Memory trick: Data Transforms, Dangers Lurk.
Client-Side vs. Server-Side Validation
Flip cardClient-side validation occurs in the user's browser for user experience, while server-side validation occurs on the server for security and data integrity.
- Client-side validation is easily bypassed by attackers.
- Server-side validation is crucial for security, as it cannot be bypassed by the client.
- Both types of validation should be used: client-side for usability, server-side for security.
Memory trick: Validate Everywhere, Trust Nowhere.
HTTP Basic Authentication over HTTP
Flip cardHTTP Basic Authentication sends credentials (username:password) Base64 encoded in the Authorization header. When used over unencrypted HTTP, these are easily intercepted and decoded.
- Base64 encoding is not encryption; it's reversible.
- Vulnerable to eavesdropping attacks if not combined with encryption (e.g., TLS/SSL).
- Should always be used with HTTPS to protect credentials in transit.
Memory trick: Auth Always Needs Encryption.
Dictionary Attack
Flip cardA Dictionary Attack is a type of brute-force attack that attempts to gain unauthorized access to a computer system by systematically trying a list of common words, phrases, and passwords.
- More efficient than pure brute-force for common passwords.
- Relies on users choosing weak or easily guessable passwords.
- Mitigated by strong password policies, account lockout, and multi-factor authentication.
Memory trick: Passwords Tested, Access Gained.
DNS Zone Transfer Countermeasure
Flip cardMeasures taken to prevent unauthorized disclosure of DNS zone data through zone transfers, typically by restricting which hosts can perform them.
- Zone transfers disclose network topology
- Restrict to authorized secondary DNS servers only
- Implement Access Control Lists (ACLs)
Memory trick: Restrict the transfer to trusted friends only, not strangers.
ARP Ping Scan (-PR)
Flip cardAn Nmap host discovery method that uses ARP requests to find live hosts on a local Ethernet network. It's very fast and effective for local subnet scanning as it operates at Layer 2.
- Operates at Layer 2 (Data Link)
- Sends ARP requests, listens for ARP replies
- Only works on local subnet
- Bypasses most Layer 3 firewall rules
Memory trick: ARP is like shouting 'who's here?' on your street.
Reliable UDP Port Scanning
Flip cardDue to UDP's connectionless nature, reliably determining if a UDP port is open often requires sending specific application-layer payloads and analyzing the responses, rather than relying solely on the absence of ICMP 'port unreachable' messages.
- UDP scans are slower and less reliable than TCP scans.
- Absence of 'ICMP port unreachable' can mean open, filtered, or host down.
- Sending protocol-specific queries (e.g., DNS, SNMP, NTP) provides definitive proof of an open service.
- Nmap's `-sU` scan often uses this method with its default scripts.
Memory trick: UDP is silent; send a message to hear it truly speak.
DNS Zone Transfer
Flip cardA DNS zone transfer is a mechanism where a secondary DNS server requests a copy of the entire DNS zone file from a primary DNS server. If misconfigured, an attacker can request and obtain this full list of domain records.
- Used to replicate DNS data between servers.
- Should be restricted to authorized secondary DNS servers.
- If allowed for unauthorized requests, it's a critical information disclosure vulnerability.
- Can reveal all hosts, subdomains, and their IP addresses within a domain.
Memory trick: Naming conventions are a map; a zone transfer is the key to read it all.
Nmap Traceroute (--traceroute)
Flip cardAn Nmap option that maps the network path to a target host by sending packets with increasing Time To Live (TTL) values, identifying each intermediate router (hop).
- Maps network path to target
- Identifies intermediate routers/hops
- Uses increasing TTL values
- Useful for network topology mapping
Memory trick: Traceroute traces the route, hop by hop.
DNS Zone Transfer Countermeasures
Flip cardCountermeasures against DNS zone transfers primarily involve configuring DNS servers to restrict zone transfer requests only to authorized secondary DNS servers, preventing unauthorized access to full domain record lists.
- Zone transfers are typically restricted by IP address.
- Essential for preventing comprehensive network mapping by attackers.
- Applies to both primary and secondary DNS servers.
- Often overlooked, leading to significant information disclosure.
Memory trick: Hide your footprints, especially the DNS map to your house.
SYN Stealth Scan (-sS)
Flip cardAn Nmap scan technique that sends a SYN packet and, upon receiving a SYN/ACK, immediately sends an RST packet to avoid completing the TCP handshake, making it less detectable.
- Does not complete TCP 3-way handshake
- Less likely to be logged by target systems
- Requires raw packet privileges
Memory trick: SYN is stealthy because it doesn't say 'hello' all the way.
Nmap Host Discovery (TCP Ping)
Flip cardNmap's TCP ping (SYN or ACK scan) is a host discovery technique that sends TCP packets to specified ports on target hosts to determine if they are live, especially useful when ICMP is blocked.
- `-PS` sends a SYN packet; `-PA` sends an ACK packet.
- A SYN/ACK response (for -PS) or RST response (for -PA) indicates a live host.
- More stealthy than a full port scan for host discovery.
- Requires specifying common open ports (e.g., 80, 443, 22) for best results.
Memory trick: Ping for life, but if ICMP sleeps, use TCP to peek.
Shodan
Flip cardShodan is a search engine that lets users find specific types of devices connected to the internet, including servers, routers, webcams, and industrial control systems, by filtering based on various criteria like ports, services, and banners.
- Often called the 'search engine for hackers'.
- Can discover publicly exposed services, open ports, and vulnerable devices.
- Useful for identifying IoT devices, database instances, and cloud storage buckets.
Memory trick: Shodan sees all, even the hidden cloud, if it's on the Net.
ARP Cache for Host Discovery
Flip cardThe ARP (Address Resolution Protocol) cache stores mappings between IP addresses and MAC addresses of devices on the local network that a system has recently communicated with.
- Accessed via `arp -a` on Windows/Linux.
- Provides a list of live hosts that have communicated with the compromised machine.
- A passive and native way to discover local network hosts.
Memory trick: ARP's cache remembers who's local, even when others forget.
Xmas Scan (-sX)
Flip cardAn Nmap scan technique that sets the FIN, PSH, and URG flags in the TCP header to probe ports. It can be stealthy as open ports on some OSes may not respond, while closed ports send an RST.
- Sets FIN, PSH, URG flags
- Open ports (Unix/Linux) often send no response
- Closed ports send RST
- Can bypass some firewalls/IDS
Memory trick: Xmas lights (FIN, PSH, URG) blink to reveal hidden ports.
SMB Enumeration
Flip cardSMB enumeration is the process of extracting detailed information from a target system's Server Message Block (SMB) service, including shared folders, user lists, group memberships, and system information.
- SMB runs on TCP ports 139 (NetBIOS over TCP/IP) and 445 (SMB direct host).
- Tools like `enum4linux`, `smbclient`, and Nmap scripts (e.g., `smb-enum-shares`) are used.
- Can reveal sensitive data, user accounts, and potential pivot points.
Memory trick: SMB shares secrets; enum4linux and smbclient unlock them.