Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1
Let's start digging a little bit deeper.
2
We've run Unmap.
3
We've seen what ports are open what services are running behind the sports.
4
We've even seen what versions these services have.
5
But I want more information.
6
I want to start finding what vulnerabilities that I can exploit and to do that as we've seen before
7
we use an ability scanner and the hacking for beginner scores.
8
We went over Nessus on Windows and they call it Linux tutorial.
9
I showed you how to install Nessus on Kalli.
10
So what I'm going to do now is I'm going to start the NSA service and I do that using these slashy ATC
11
slash and ADOT the slash Nessus d start commands.
12
Now that it's up and running I actually don't remember what port exactly the NSA service runs on.
13
So I'm going to use one of the commands that we've learnt before which is then stack command to see
14
what services are running on my machine.
15
And here we go.
16
There it is.
17
This is the SSD running on board eight eighty four.
18
So I've opened the page and you might notice that this looks a little bit different than the previous
19
Nessus and the previous videos.
20
And this is because this is an updated video with the latest Nessus version.
21
So it does look a little bit different.
22
However the core of it and how we do the scans is pretty much still exactly the same.
23
I'm going to log in using my username and password that I created during the installation process.
24
And I'm going to start and you scan
25
you see here a lot of different options that we talk about in more advanced courses.
26
For now all I'm going to do is I'm going to go with the basic network scan so I'm going to click on
27
that.
28
I'm going to name my scan at this floatable too.
29
I'll leave that description empty and my target is the IP address of the disposable machine.
30
I'll save it.
31
And remember after you save it you need to launch the scan.
32
It will not start automatically.
33
So I'm going to launch it and you see now the green arrows spinning around telling me that the scan
34
is running to see where my scan progresses.
35
I can double click on it and if I want to go back I can go back to my scans so it's still running here.
36
Notice the difference between the running and the completed scans.
37
Let me double click on it again.
38
And now you might see a slight difference.
39
The Nessus graphical interface now so I can actually go and look at the vulnerabilities that the see
40
what vulnerabilities have been discovered so far.
41
Keep in mind that the scan is still running.
42
So if I go back to my scans it's still going on.
43
There will be more vulnerabilities to be discovered.
44
I'm going to speed the video up a little bit and now that the scan is complete I can go to the vulnerabilities
45
and start looking at them one by one.
46
On the right hand side there's some scan details it tells me the name of the scan what the status is
47
what their policy I use so I use the basic network scan here.
48
The scanner.
49
So this is if I'm using multiple scanners.
50
When did it start.
51
When did it end and how long it took.
52
So in my case it took about seven minutes.
53
Obviously I'm going to keep the video running for seven minutes so I just fast forward to the end of
54
the scan.
55
So don't be surprised if you see the scan taking a lot longer than the length of this video.
56
You'll also notice that the vulnerabilities are grouped by criticality from the highest to the lowest
57
critical risk is the highest and the ratings of criticality.
58
Then you have under that the high medium low and info.
59
Keep in mind though just because a vulnerability is medium or low that does not mean we get to ignore
60
it and the hacking for beginners scores.
61
We saw how we managed to break into our target using a low severity vulnerability for the purpose of
62
the.
63
However we're going to be focusing on some of the most critical ones because going through one hundred
64
and eight vulnerabilities will end up dragging this video on for days.
65
So let's focus on the more critical ones and to see the details of any vulnerability I can just click
66
on it and read the description of what an attacker can do and what the results can be.
67
Just to go back on the point of the criticality of vulnerabilities if I do a quick search for FTB you'll
68
notice that Nessus returned only one finding which is the FTB server detection meaning that Messis managed
69
to detect that that is NFD service running.
70
However Mazur's did not tell me that this FTB the server that we just exploited is actually vulnerable.
71
So for some reason whatever that reason might be Nessa's failed to detect that that particular FTB server
72
is actually vulnerable and is exploitable.
73
So for some particular reason mezzos failed to detect that this particular FTB server is vulnerable.
74
Now again I do not want to concern you or myself with reason of why this happened.
75
It could be that the scan got interrupted that the service crashed that the network is unreliable whatever
76
it is and this is why we never ever rely on just one tool output.
77
This is why we investigate using a map.
78
We investigate using Nessus.
79
We investigate manually by connecting to each service and we investigate using a lot of other tools
80
as well.
81
So do keep that in mind just because the vulnerability scanner does not say it's vulnerable.
82
That does not mean it's not vulnerable.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.