0:13 how you can collect the information. 0:16 There is stuff like Shodan. 0:19 Maybe you've seen it. 0:21 And we can put like google.com. 0:24 So what can we see? 0:25 We can see a big amount of different hosts. 0:32 Or maybe let's put some other company. 0:35 random.com maybe better, right? 0:38 Much better. 0:38 So random.com, we can navigate to Shodan. 0:43 And inside Shodan, we can see that this website was already analyzed. 0:50 So what is Shodan? 0:51 There are like five services like this, like Shodan, ZoomEye, Census. 0:55 And you should know all those websites when you're doing the penetration testing or vulnerability assessment, or you're owning the company, which can end up here. 1:05 So this website. 1:08 Is using completely legal methods. 1:11 It is just scanning the full internet. 1:14 All day long, it is scanning the full internet. 1:17 And when it will find your website, it will just say, like, myjrandom.com, for example. 1:27 And it will try to put it here. 1:30 analyze your SSL certificate. 1:32 So in SSL certificate, by the way, you can find subdomains. 1:38 So potentially, if you are creating some subdomain, which you call hidden.random.com, you can... 1:51 Accidentally put it in the certificate and people can find it. 1:56 So for subdomains, we'll have like a separate talk. 1:59 And here we can see on the port 80, we have Nginx. 2:04 And on port 443, we also have Nginx. 2:09 And port 80 is redirecting to port 443. 2:13 And here is the SSL certificate. 2:15 So the NGINX is the service system which was created in ex-employee of Rambler around 15 years ago. 2:28 When a guy working in Rambler, in Russian company Rambler.ru, so he worked there and he was seeing a big amount of traffic is going on the Apache server. 2:39 And those Apache server and IIS servers, they were not able to handle big amount of traffic. 2:45 So that guy, he created the NGINX, which will allow you to get a big amount of traffic and to not go down. 2:57 So NGINX is just a proxy. 3:00 We can say a local proxy, which is balancing the traffic. 3:04 And the SSL certificate is the certificate which you can create yourself or which you can buy and insert into your HTTP website. 3:16 And it will basically become HTTPS. 3:20 So HTTP is not protected protocol. 3:25 HTTP is the protocol which is using the clear text. 3:29 So if, for example, you will be accessing the website which I deployed on HTTP, and we will be in the same network with you, I will see your traffic. 3:39 And I will see all your sessions. 3:41 But with HTTPS, 3:44 The traffic is encrypted with those keys, public keys. 3:48 So a hacker cannot see what is going on. 3:52 For FTP, there is FTPS. 3:55 For SSH, it already has the key, basically. 3:59 For RDP, it also has the keys. 4:02 So nowadays, you can just get a SSL certificate for free. 4:07 You can generate your own or you can go to Cloudflare and you will be able to get it. 4:12 So yesterday I was deploying a certificate, which took me like five minutes. 4:17 So now it's not a big problem. 4:20 So what we can see here, port 25, port 80, port 443. 4:26 In port 25, we can see that there is E. 4:30 SMTP server, which means that it is potentially interesting attack vector. 4:35 So what you need to do, you need to go, for example, here and find SMTP and read about that SMTP. 4:48 Like more information and you can try to hack it. 4:52 So based on the protocols, this one, you see 25. 4:59 So that protocol is saying hello, help, quit, awoos, reset. 5:05 And you can use software which is called Telnet to communicate. 5:09 Here we can clearly see that those guys are using Telnet. 5:12 So what they're doing, they're scanning internet after they're using like Telnet, for example. 5:17 To connect and grab the banner. 5:19 So this, what I'm showing you now, is just a basic recon. 5:23 You can do it yourself manually, or you can use the third-party services. 5:28 Also, obviously, a part of recon is who is. 5:33 For example, what is who is? 5:38 This is a super basic information block. 5:40 Nice. 5:43 So what can we see here? 5:46 We can see here the phone of the guy, and we can collect here the information of the location of that specific person who registered that specific domain. 5:58 So why do we need to collect? 6:00 We need to collect all information. 6:02 Before we are starting to attack the system, we can find basically attack surface. 6:11 So attack surface is part of that stuff. 6:15 A little bit later, I will show you how all that stuff is automated. 6:20 And I will also show you how you can do it more automatically. 6:23 Now I just showed you a few examples of how you can use the websites. 6:28 For example, ZoomEye is also interesting stuff. 6:34 We can access it. 6:35 It is Chinese. 6:37 Random.com. 6:40 So they want you to get a subscription, but the idea here, this is the same. 6:48 This is the same as Shodan. 6:50 Sometimes you can get here more information. 6:53 Sometimes you can get here less information. 6:55 And here it is also detected the technologies. 6:59 So now we can clearly understand that this website is located in the US. 7:05 It is running Linux operating system. 7:08 It is hosted in Amazon and it is running Nginx. 7:13 And in the backend, it is Express.js. 7:17 So a server. 7:19 For each hosting, for each type of port protocol, you have a specific methodology on how to hack it. 7:29 So here is an example. 7:30 example of how you're doing the Amazon internal test. 7:33 So it's not, this one is basically on how you can audit the Amazon if this is yours. 7:44 So if you don't want to get hacked, you just generate the key inside the Amazon. 7:51 You just go to Amazon. 7:53 Amazon key. 7:57 No, this one. 8:03 API key, not that key. 8:06 So you just go to Amazon and you generate the API key. 8:14 And based on that API key, you just put it here. 8:17 So when you bought hosting, they provide you ability to 8:22 interact with that hosting using API key. 8:25 When you bought that hosting, you can get that key and it would adhere. 8:31 So this software is called Scout Cloud, for example. 8:37 It is free software. 8:39 So what it is doing? 8:41 It is connecting to that specific 8:44 it is connecting to your hosting and it will analyze all the services which you have there. 8:49 How it is working? 8:51 It has the templates and based on those templates, it is checking if you're matching that pattern or not. 9:00 have the hosting of pictures, which is allowed to be seen by everyone. 9:09 For example, this is different from if you are storing the passport data. 9:13 And if you open that specific service, which is called S3 bucket, 9:18 to everyone. 9:19 It means that somebody will download those passports, definitely, within like five minutes. 9:25 So from your side, you need to audit your cloud from behind. 9:31 And there are some automations around this stuff. 9:34 For AWS, they have like attack vectors. 9:39 And AWS, 9:44 Vectors Research, AWS. 9:47 Attack. 9:50 Attack checks. 9:51 So this is list of the most vulnerable services which you can buy. 9:58 Amazon has like maybe 50 different services. 10:01 Some of them are potentially dangerous. 10:04 So if you will open the database externally, somebody can connect it. 10:09 If you will open your file hosting externally, somebody can connect to it. 10:14 Or if you put the like no password or if you put a weak password. 10:19 So there are a list of 10:23 specific services on the hosting itself, which you need to focus on. 10:29 Meaning of check is 10:30 that you see this is list of services. 10:33 So this is list of services and you can go here. 10:38 I'll just show you. 10:44 I think it's here, AWS rules, rule sets. 10:55 So, for example, this is check. 10:58 So this check is checking if your service is exposed to the internet or not. 11:06 If it's exposed to the internet, it will say, look, it looks like potentially all your services are deployed to the internet. 11:13 Is this what you wanted or you didn't even know this? 11:17 So I had like a big amount of examples where developers are sharing with me some production information. 11:25 And they're saying like, look, we deployed to production, all good. 11:28 And I'm like scanning externally. 11:30 And I'm saying like, look, man, you have like 20 ports open. 11:33 What is going on? 11:34 Everything is open. 11:35 Your database, everything. 11:36 And he's saying, how? 11:38 I don't know. 11:40 I just deployed it and I didn't expect that it will be exposed. 11:43 So sometimes developers don't know that it will be exposed. 11:46 So there are like checks internal and external. 11:50 So you should understand. 11:50 Penetration testers, they're doing external checks. 11:53 So here I just showed you an example of internal check, but we are discussing external stuff. 12:01 So this is an example of checks. 12:05 This is just a checklist.
0:13 how you can collect the information. 0:16 There is stuff like Shodan. 0:19 Maybe you've seen it. 0:21 And we can put like google.com. 0:24 So what can we see? 0:25 We can see a big amount of different hosts. 0:32 Or maybe let's put some other company. 0:35 random.com maybe better, right? 0:38 Much better. 0:38 So random.com, we can navigate to Shodan. 0:43 And inside Shodan, we can see that this website was already analyzed. 0:50 So what is Shodan? 0:51 There are like five services like this, like Shodan, ZoomEye, Census. 0:55 And you should know all those websites when you're doing the penetration testing or vulnerability assessment, or you're owning the company, which can end up here. 1:05 So this website. 1:08 Is using completely legal methods. 1:11 It is just scanning the full internet. 1:14 All day long, it is scanning the full internet. 1:17 And when it will find your website, it will just say, like, myjrandom.com, for example. 1:27 And it will try to put it here. 1:30 analyze your SSL certificate. 1:32 So in SSL certificate, by the way, you can find subdomains. 1:38 So potentially, if you are creating some subdomain, which you call hidden.random.com, you can... 1:51 Accidentally put it in the certificate and people can find it. 1:56 So for subdomains, we'll have like a separate talk. 1:59 And here we can see on the port 80, we have Nginx. 2:04 And on port 443, we also have Nginx. 2:09 And port 80 is redirecting to port 443. 2:13 And here is the SSL certificate. 2:15 So the NGINX is the service system which was created in ex-employee of Rambler around 15 years ago. 2:28 When a guy working in Rambler, in Russian company Rambler.ru, so he worked there and he was seeing a big amount of traffic is going on the Apache server. 2:39 And those Apache server and IIS servers, they were not able to handle big amount of traffic. 2:45 So that guy, he created the NGINX, which will allow you to get a big amount of traffic and to not go down. 2:57 So NGINX is just a proxy. 3:00 We can say a local proxy, which is balancing the traffic. 3:04 And the SSL certificate is the certificate which you can create yourself or which you can buy and insert into your HTTP website. 3:16 And it will basically become HTTPS. 3:20 So HTTP is not protected protocol. 3:25 HTTP is the protocol which is using the clear text. 3:29 So if, for example, you will be accessing the website which I deployed on HTTP, and we will be in the same network with you, I will see your traffic. 3:39 And I will see all your sessions. 3:41 But with HTTPS, 3:44 The traffic is encrypted with those keys, public keys. 3:48 So a hacker cannot see what is going on. 3:52 For FTP, there is FTPS. 3:55 For SSH, it already has the key, basically. 3:59 For RDP, it also has the keys. 4:02 So nowadays, you can just get a SSL certificate for free. 4:07 You can generate your own or you can go to Cloudflare and you will be able to get it. 4:12 So yesterday I was deploying a certificate, which took me like five minutes. 4:17 So now it's not a big problem. 4:20 So what we can see here, port 25, port 80, port 443. 4:26 In port 25, we can see that there is E. 4:30 SMTP server, which means that it is potentially interesting attack vector. 4:35 So what you need to do, you need to go, for example, here and find SMTP and read about that SMTP. 4:48 Like more information and you can try to hack it. 4:52 So based on the protocols, this one, you see 25. 4:59 So that protocol is saying hello, help, quit, awoos, reset. 5:05 And you can use software which is called Telnet to communicate. 5:09 Here we can clearly see that those guys are using Telnet. 5:12 So what they're doing, they're scanning internet after they're using like Telnet, for example. 5:17 To connect and grab the banner. 5:19 So this, what I'm showing you now, is just a basic recon. 5:23 You can do it yourself manually, or you can use the third-party services. 5:28 Also, obviously, a part of recon is who is. 5:33 For example, what is who is? 5:38 This is a super basic information block. 5:40 Nice. 5:43 So what can we see here? 5:46 We can see here the phone of the guy, and we can collect here the information of the location of that specific person who registered that specific domain. 5:58 So why do we need to collect? 6:00 We need to collect all information. 6:02 Before we are starting to attack the system, we can find basically attack surface. 6:11 So attack surface is part of that stuff. 6:15 A little bit later, I will show you how all that stuff is automated. 6:20 And I will also show you how you can do it more automatically. 6:23 Now I just showed you a few examples of how you can use the websites. 6:28 For example, ZoomEye is also interesting stuff. 6:34 We can access it. 6:35 It is Chinese. 6:37 Random.com. 6:40 So they want you to get a subscription, but the idea here, this is the same. 6:48 This is the same as Shodan. 6:50 Sometimes you can get here more information. 6:53 Sometimes you can get here less information. 6:55 And here it is also detected the technologies. 6:59 So now we can clearly understand that this website is located in the US. 7:05 It is running Linux operating system. 7:08 It is hosted in Amazon and it is running Nginx. 7:13 And in the backend, it is Express.js. 7:17 So a server. 7:19 For each hosting, for each type of port protocol, you have a specific methodology on how to hack it. 7:29 So here is an example. 7:30 example of how you're doing the Amazon internal test. 7:33 So it's not, this one is basically on how you can audit the Amazon if this is yours. 7:44 So if you don't want to get hacked, you just generate the key inside the Amazon. 7:51 You just go to Amazon. 7:53 Amazon key. 7:57 No, this one. 8:03 API key, not that key. 8:06 So you just go to Amazon and you generate the API key. 8:14 And based on that API key, you just put it here. 8:17 So when you bought hosting, they provide you ability to 8:22 interact with that hosting using API key. 8:25 When you bought that hosting, you can get that key and it would adhere. 8:31 So this software is called Scout Cloud, for example. 8:37 It is free software. 8:39 So what it is doing? 8:41 It is connecting to that specific 8:44 it is connecting to your hosting and it will analyze all the services which you have there. 8:49 How it is working? 8:51 It has the templates and based on those templates, it is checking if you're matching that pattern or not. 9:00 have the hosting of pictures, which is allowed to be seen by everyone. 9:09 For example, this is different from if you are storing the passport data. 9:13 And if you open that specific service, which is called S3 bucket, 9:18 to everyone. 9:19 It means that somebody will download those passports, definitely, within like five minutes. 9:25 So from your side, you need to audit your cloud from behind. 9:31 And there are some automations around this stuff. 9:34 For AWS, they have like attack vectors. 9:39 And AWS, 9:44 Vectors Research, AWS. 9:47 Attack. 9:50 Attack checks. 9:51 So this is list of the most vulnerable services which you can buy. 9:58 Amazon has like maybe 50 different services. 10:01 Some of them are potentially dangerous. 10:04 So if you will open the database externally, somebody can connect it. 10:09 If you will open your file hosting externally, somebody can connect to it. 10:14 Or if you put the like no password or if you put a weak password. 10:19 So there are a list of 10:23 specific services on the hosting itself, which you need to focus on. 10:29 Meaning of check is 10:30 that you see this is list of services. 10:33 So this is list of services and you can go here. 10:38 I'll just show you. 10:44 I think it's here, AWS rules, rule sets. 10:55 So, for example, this is check. 10:58 So this check is checking if your service is exposed to the internet or not. 11:06 If it's exposed to the internet, it will say, look, it looks like potentially all your services are deployed to the internet. 11:13 Is this what you wanted or you didn't even know this? 11:17 So I had like a big amount of examples where developers are sharing with me some production information. 11:25 And they're saying like, look, we deployed to production, all good. 11:28 And I'm like scanning externally. 11:30 And I'm saying like, look, man, you have like 20 ports open. 11:33 What is going on? 11:34 Everything is open. 11:35 Your database, everything. 11:36 And he's saying, how? 11:38 I don't know. 11:40 I just deployed it and I didn't expect that it will be exposed. 11:43 So sometimes developers don't know that it will be exposed. 11:46 So there are like checks internal and external. 11:50 So you should understand. 11:50 Penetration testers, they're doing external checks. 11:53 So here I just showed you an example of internal check, but we are discussing external stuff. 12:01 So this is an example of checks. 12:05 This is just a checklist.