Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
The second program that we'll use 2
2
for network mapping is Nmap. 3
3
Now in the previous lecture we used netdiscover 4
4
and we seen how nice it is to quickly discover 5
5
all the devices connected to our network, 6
6
see their MAC address and maybe get the vendor. 7
7
Nmap takes scanning to a whole new level. 8
8
It might be a little bit slower than netdiscover 9
9
but it will show you much much more information 10
10
about the target. 11
11
So you'll be able to see the open ports, 12
12
you'll be able to see the running programs 13
13
or the running services on these open ports. 14
14
You'll be able to determine the computer name, 15
15
the operating system running on that computer. 16
16
If you are in a network, you'll be able to discover 17
17
all of the connected clients. 18
18
You'll be able to bypass security, bypass firewalls 19
19
and so much more. 20
20
Nmap is actually a huge tool and there are books 21
21
and complete courses done just to teach Nmap. 22
22
The Nmap book would actually be a really good read 23
23
once you're done with this course. 24
24
Now because this tool is huge, we're not gonna be able 25
25
to cover of all its uses but in this lecture, 26
26
I'm gonna show you the basics of this tool, 27
27
how to use it to discover all the connected clients 28
28
and see useful information about them. 29
29
And we'll actually use it more when we get 30
30
to the gaining access section. 31
31
We're actually going to be using Zenmap 32
32
which is the graphical user interface of Nmap. 33
33
So to run it in Terminal you just have to type Zenmap 34
34
or you can find it under your Applications menu. 35
35
Now as you can see, it has a very very simple interface. 36
36
The first thing that we see is the target input box, 37
37
in here you can put your target. 38
38
You can scan any IP that you can reach, 39
39
whether it's a personal computer, whether it's a server, 40
40
whether it's an IP for a web-server for a website, 41
41
for example, that you want to discover all the open ports 42
42
and all the running services on it. 43
43
Or, like what we're going to do right now, 44
44
we can put a range similar to what we did with netdiscover 45
45
and it will scan this whole range, discover all the live IPs 46
46
of the connected machines on the same network 47
47
and display information about them. 48
48
Now we'll have a look on how to scan servers 49
49
in the gaining access section. 50
50
So for now, since we are still 51
51
in the network hacking section 52
52
we're gonna put a range to discover all the connected 53
53
clients and see useful information about them. 54
54
So, right now I'm actually connected to my wireless network, 55
55
that's why I'm gonna specify the whole range on that network 56
56
and we seen how to get that in the previous lecture. 57
57
So it's 192.168.11 58
58
over 24. 59
59
At the bottom you can see the command, 60
60
this is actually the Nmap command that will be executed 61
61
when I hit the Scan button. 62
62
So like I said, Zenmap, what we're using right now 63
63
is just a graphical interface 64
64
that will run this Nmap command in the background 65
65
and show me the results. 66
66
So, if you know a custom Nmap command you can put it here 67
67
or if you just want to see Nmap in Terminal 68
68
you can literally copy this command, paste it in Terminal 69
69
and it will give you the same results that you would get 70
70
if you run it here. 71
71
Alternatively, if you don't really know much about Nmap 72
72
and it's commands, you can use 73
73
one of the ready profiles in here. 74
74
So in this lecture we're actually gonna be using 75
75
a number of these profiles and we'll see the difference 76
76
between them, in terms of speed 77
77
and the information gathered. 78
78
So I'm gonna start with the Pink scan. 79
79
This is a very quick scan, it literally just pings 80
80
every possible IP in the range, and if it gets a response, 81
81
it will record this response and it will show me 82
82
the devices that devices that gave me a response 83
83
which means that these are the devices 84
84
connected to the network. 85
85
Now a lot of devices do not respond to pinged requests 86
86
even if they are alive, so the list that you'll get 87
87
in the scan might not include all the devices 88
88
connected to your network. 89
89
Now once the scan's done, as you can see, we can see 90
90
the list of all the connected devices in here. 91
91
And in here we can also see the MAC addresses 92
92
for each of these devices. 93
93
We also can see the vendor, so for example, we can see 94
94
that the device at 192.168.11 is a Cisco device, 95
95
this actually my router 96
96
and it is made by Cisco so this is correct. 97
97
So we can go ahead and start looking for exploits 98
98
in this device. 99
99
We can also see the 192.168.10 is a HTC device 100
100
and again, this is a HTC phone, this is correct. 101
101
And since it's HTC then we know that it's probably 102
102
running on Android. 103
103
So as you can see, we're getting more information 104
104
about the connected clients. 105
105
Again, we can see the 192.168.12 is an Apple device, 106
106
so it could be a phone, a tablet or a Mac. 107
107
We can see the next device is a Dell. 108
108
So again, it was a very quick scan but as you can see 109
109
it still gave us much more information 110
110
than what we got from netdiscover. 111
111
The next scan that I wanna show you is the Quick scan. 112
112
Now this is gonna be slightly slower than the Pink Scan 113
113
but it's gonna show us more information. 114
114
So right now, you can see that the scan is showing us 115
115
the same information that we seen before with the Pink scan 116
116
but it's also showing us the open ports on each one 117
117
of the discovered devices. 118
118
So it's able to discover the following ports 119
119
in the router and we can see that port 80 is open. 120
120
This is actually the port used for the router settings 121
121
page because it runs on a webserver, so this is correct. 122
122
Again we have our Apple device here that we said 123
123
it might a phone or a computer or a tablet, 124
124
but we can see now it has port 22 open. 125
125
So this is a port for a service called SSH 126
126
which is designed to allow remote access 127
127
to the system it's running on. 128
128
Again, if you go on all the other devices 129
129
you can see all the open ports and the services running 130
130
on each one of these ports. 131
131
Now, in the next lecture, we'll build up on this. 132
132
We'll see how to gather even more information 133
133
and you'll see how important information gathering is 134
134
because we're going to use the gathered information 135
135
to hack into an iPhone that is connected 136
136
to the same network.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.