Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Information gathering is one of the most important steps 2
2
when it comes to hacking or penetration testing. 3
3
If you think of it, you can't really gain access to a system 4
4
if you don't have enough information about it. 5
5
So, for example, let's say you're connected to a network 6
6
and one of the devices connected to this network 7
7
is your target. 8
8
Now for you to hack into that target, 9
9
first you need to discover all of the connected clients 10
10
to this network, get their MAC address, their IP address, 11
11
and then from there try to maybe gather more information 12
12
or run some attacks in order to gain access to your target. 13
13
Now, there are a number of programs 14
14
that will do this for you. 15
15
Examples are NetDiscover and Nmap, 16
16
which do this job really, really well. 17
17
So in this lecture, we'll start with the simpler one, 18
18
which is NetDiscover and see how to use it to quickly map 19
19
the network we're connected to. 20
20
And in the next lecture, 21
21
I'm gonna show you how to use Nmap 22
22
to gather detailed information about all 23
23
of the clients connected to the same network. 24
24
So, I have my Kali terminal in here, and if I do ifconfig, 25
25
you'll see I have eth0, it has an IP address. 26
26
And like I said, this is the virtual interface created 27
27
by VirtualBox when we set the Kali machine 28
28
to use a NAT network. 29
29
Now, I also said that this NAT network behaves exactly like 30
30
an Ethernet network. 31
31
And as far as the Kali machine is concerned, 32
32
it thinks that it is connected to a real wired network. 33
33
And as you can see in here, 34
34
it's telling me that wired connected. 35
35
Now, I have my virtual Windows machine right here. 36
36
It is configured to use the same NAT network 37
37
as the Kali machine. 38
38
Remember, we're still in the network hacking section, 39
39
so both you and the target machine need to be connected 40
40
to the same network. 41
41
So as far as these two computers are concerned, 42
42
they think that they are connected to the same network. 43
43
So what I wanna do right now is use NetDiscover 44
44
and see how we can use it to discover all devices connected 45
45
to the same network. 46
46
Now the method that I'm gonna show you 47
47
will work exactly the same, 48
48
whether you're using it against a virtual network, 49
49
like I'm doing right now, or against real network, 50
50
and even if your target is a Wi-Fi or a wireless network. 51
51
So all you have to do is type the name of the program, 52
52
which is NetDiscover, and then type dash r 53
53
to specify an IP range to search for. 54
54
This needs to be arranged that can be accessed by you. 55
55
So right now you can see that my IP is 10.0.2.16 56
56
and I can only access IPs on the same subnet. 57
57
So IPs on the same subnet start at 10.0.2.0, 58
58
and they would end at 10.0.2.254 59
59
because 254 is the last IP that a client can have. 60
60
So, my range is gonna be 10.0.2.1 61
61
and I wanna search for clients that might have an IP 62
62
of 10.0.2.1, 10.0.2.2, 10.0.2.3, 63
63
all the way up to 10.0.2.254. 64
64
So instead of manually typing all of these IPs, 65
65
I can just type over 24 66
66
and NetDiscover will automatically know 67
67
that I'm trying to search for all of the IPs 68
68
that start at 10.0.2.1 and end at 10.0.2.254. 69
69
So this is a way of specifying an IP range 70
70
for the whole subnet. 71
71
So if I hit enter now, you'll see that NetDiscover 72
72
will show me all the IPs of the devices connected 73
73
to the same network. 74
74
And note that the first three parts of the IPs 75
75
are always the same because they are on the same subnet. 76
76
And I also have the Mac addresses of these clients 77
77
and Net discovers also attempting 78
78
to guess the device vendor. 79
79
Now, if I press queue, this will quit the program. 80
80
And right now, we have a list of all the connected clients 81
81
to the same network. 82
82
Now, like I said, you can also use this method 83
83
to discover clients connected to the same Wi-Fi network. 84
84
The only thing is, right now, if I do ifconfig, 85
85
you can see that my Kali machine 86
86
does not have a wireless adapter, 87
87
it's not connected to a Wi-Fi network. 88
88
And like I said before, 89
89
you cannot access the built in wireless card 90
90
from a virtual machine. 91
91
Therefore, if you want to do this 92
92
or run any of the wireless attacks that we're gonna see 93
93
in the future against a real computer 94
94
and a real wireless network, 95
95
you're gonna need to use a wireless adapter. 96
96
Now, I'm gonna include links in the description 97
97
that will help you pick a good adapter 98
98
that works with Kali Linux. 99
99
But right now I actually have one, 100
100
and I'm just gonna connect it 101
101
and use it just to prove to you, 102
102
if things work on the virtual machines connected 103
103
to the virtual network, 104
104
they will work exactly the same against a real network 105
105
with real machines. 106
106
So, I'm gonna connect my adapter now. 107
107
And if I do ifconfig, it's still not showing up, 108
108
so I'm gonna connect it from my devices, USB, 109
109
and click on the adapter name, 110
110
and let's see if it shows up now. 111
111
Perfect, as you can see, I have an adapter now called Lan0. 112
112
And what I'm gonna do is, 113
113
I need to connect this adapter to a Wi-Fi network first 114
114
before I can discover all the connected clients 115
115
to this network. 116
116
So I'm gonna go to my network manager, 117
117
I'm gonna click in here 118
118
and you wanna click on Select Network. 119
119
And as you can see, automatically now, 120
120
it's actually connected to a network. 121
121
But in your case, you'd wanna select a network 122
122
and click on Connect, 123
123
and then it will ask you for the password. 124
124
So now I'm actually connected 125
125
and you'll see if I do ifconfig again. 126
126
Right now, lan0 has an IP address. 127
127
So this means that it is connected to a network 128
128
and this means that we can use it now with NetDiscover. 129
129
So again, I'm gonna use the exact same command 130
130
that I used before just to show you and prove to you 131
131
that if this works against virtual machines, 132
132
it will work against real machines. 133
133
And the only difference is going to be the IP. 134
134
So I'm gonna remove this IP. 135
135
And as you can see right now, my IP is 192.168.1.8. 136
136
So therefore, the range that I'm gonna look 137
137
for is gonna start at 192.168.1.1, 138
138
and I'm gonna leave the over 24 here 139
139
because this will tell NetDiscover that I want to start 140
140
at 192.168.1.1 and finish at 192.168.254. 141
141
So if I hit enter now. 142
142
Now, this did not work and I know why. 143
143
In order for this to work, 144
144
you actually have to disable the NAT network. 145
145
So to disable the NAT network, we're gonna go on devices, 146
146
we're gonna go on network, 147
147
and we're gonna uncheck the Connect Network Adapter. 148
148
So now once done with this, 149
149
if we just run the exact same command again. 150
150
As you can see, it's discovering all the connected clients, 151
151
all their IP addresses, all their MAC addresses, 152
152
and it's guessing the manufacturer, 153
153
and you can see it's also discovering 154
154
some Apple devices here. 155
155
So as you can see, 156
156
it's working perfectly using the exact same command. 157
157
Now, I only did this just to show you 158
158
that if things work against virtual machines 159
159
and I guess virtual networks, 160
160
then they will work against real machines 161
161
because these virtual machines and virtual networks 162
162
are modeled of a real machines. 163
163
And as far as the machines are concerned, 164
164
they actually think they are real computers 165
165
and real machines.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.