1 gfi languard network security scanner. 2 contents introduction features source & installation...

24
1 GFI LANguard Network Security Scanner

Upload: scarlett-wilson

Post on 22-Dec-2015

225 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

1

GFI LANguard Network Security Scanner

Page 2: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

2

Contents

Introduction Features Source & Installation Testing environment Results Conclusion

Page 3: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

3

Introduction

Importance of Network security Internal SecurityExternal Security

Purpose of GFI LANguard Enable Network admins to perform

Security audit Remote system analysis

Page 4: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

4

Features

Security Audit Results in a verbose

manner Flexible scanning

Scan one computer Scan range of computers Scan list of computers Domain specific scan

Page 5: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

5

Features (Cont…)

System detection SNMP , NETBIOS

queries , Ping Sweep

Configuring ports for port scan

Page 6: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

6

Features (Cont..)

Enumeration of entry pointsSNMP holesCGI holesOpen sharesRogue , Backdoor usersWeak network passwords

Page 7: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

7

Features (Cont…)

AlertsWell known security problems are clearly

identified Intelligent scanning Listing of hot-fixes & service packs

Page 8: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

8

Features (Contd..)

Remote Machine shutdown Exploitation of NetBIOS vulnerability Enabling auditing Sending spoofed messages Scheduling scans & automatic update of

scans Gathering information & displaying using

report generator

Page 9: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

9

Features (Contd..)

Scripting Language: LANS: LANguard Scripting language GFI LANguard contains its own scripting

editorAllows users to create custom script which will

be executed on the remote host as when accessed

Page 10: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

10

Features (Contd..)

Tools: SNMP Walk

By performing SNMP walk potential hackers or malicious users will get lot of information about the system

Page 11: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

11

Features (Contd..)

Tools (Contd..) Trace route

DNS look up

Page 12: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

12

Tools (Contd..) SNMP Audit

SNMP audit allows to detect weak community strings.

Page 13: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

13

Tools (Contd..) MS-SQL Audit

Page 14: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

14

Tools (Contd..) Enumerated

Computers

Page 15: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

15

Source & Installation

Downloaded GFILANguard from www.gfi.com

Minimum requirements as set by vendorOS: Win 2000/2003/XP IE 5.1 +Client for Microsoft networks be installedNo personal firewall settings

Page 16: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

16

Testing Environment

Setting options:

Page 17: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

17

Testing Environment (Contd..)

Page 18: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

18

Testing Environment (Contd..)

Page 19: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

19

Results

Source IP address : 137.207.234.120 CASE -1 :

Destination IP: 137.207.234.138 Scan parameters: As specified earlier

Page 20: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

20

Page 21: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

21

Results (Contd..)

CASE –II : SunSolaris

Page 22: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

22

Results (Contd..) Script execution:

hostname = "agardel2" # my desktop computer

// name of the system from which the script is running

ip = dnslookup(hostname) // using the function dnslookup if ip <> "" echo("hostname: " + hostname) echo("resolved as: " + ip, _color_blue) # now backwards:) hostname = ReverseDnsLookup(ip) if hostname <> "" echo("back to: " + hostname,) end if else echo("unable to resolve " + hostname + " !", \ _color_red) end if

Page 23: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

23

Conclusion

GFI LANguard is a very good tool in detecting and analysis of vulnerabilities User – defined Scripting language : LANSVerbose representation of DataGenerating Reports

Page 24: 1 GFI LANguard Network Security Scanner. 2 Contents Introduction Features Source & Installation Testing environment Results Conclusion

24

References

www.gfi.com