open source intelligence (osint)- testcases for pentesters

27
OSINT Testcases for Pentesters @upgoingstar | [email protected]

Upload: shubham-mittal

Post on 21-Jan-2017

1.455 views

Category:

Data & Analytics


13 download

TRANSCRIPT

Page 1: Open Source Intelligence (OSINT)- Testcases for Pentesters

OSINTTestcases for Pentesters

@upgoingstar | [email protected]

Page 2: Open Source Intelligence (OSINT)- Testcases for Pentesters

Who Am I?• Shubham Mittal• 4+ years of experience ~ Offensive & Defensive roles.• InfoSec Consultant. Trainer @ Nullcon. • Interests in PT, OSINT, Infrastructure Security.• Projects: Datasploit • Biker, Beat Boxer, Blogger.

@upgoingstar | shubhammittal.net | [email protected]

Page 3: Open Source Intelligence (OSINT)- Testcases for Pentesters

Internet gives you RAW Data. Harvest it.

OSINT – Open Source Intelligence(Intelligence on Information publicly available)

Page 4: Open Source Intelligence (OSINT)- Testcases for Pentesters

WhoIs Records – First things first.• Reveals Email ID• Reveals Contact Person• Some Other Basic information.

Page 5: Open Source Intelligence (OSINT)- Testcases for Pentesters

DNS Records• CNAME Records – Gives you subdomains• MX Records – Check for attacks on Mail Server.• A records – IP Addresses

Page 6: Open Source Intelligence (OSINT)- Testcases for Pentesters

Domain History• Abc.com uses Cloudflare / Incapsula / Sucuri. • All DNS Traffic is routed.• Domain History reveals earlier IP Addresses. • If IP still hosts the website, Bypass all rate limiting, firewall rules, etc.

Page 7: Open Source Intelligence (OSINT)- Testcases for Pentesters

Wappalyzer• Profiles the technologies a website is using. • Vulnerabilities associated with these technologies can also be listed

via CVEDetails.com.• Have fun. ;)

• Buildwith is also a good option, though automating Wappalyzer is easy. • Both available as Firefox Addons as well.

Page 8: Open Source Intelligence (OSINT)- Testcases for Pentesters

PunkSpider, OpenVuln, SSl labs, etc.• Pass domain and check for vulnerabilities found by scanners / other

researchers. • SSL Labs scans all the SSL / TLS related issue. You get niche testing

done without hitting from your own IP.

Page 9: Open Source Intelligence (OSINT)- Testcases for Pentesters

Search Engines• Shodan | Censys | ZoomEye – Computer Search Engines• NerdyData | GitRob | MeanPath – Code Search Engines• Pipl | Yasni – People Search Engines• TrueCaller - Phone number Search Engine• Google | Yandex | Bing – General Search Engines• DuckDuckGo – Combines multiple search engine• WolfRamAlpha – Computational Search Engine

Page 10: Open Source Intelligence (OSINT)- Testcases for Pentesters

• Computer Search Engine• Locate exposed portals / legacy dashboards.

• Code Search Engines• Look for vulnerable codes. Juicy targets. Wow.

• People Search Engines• Profiling specific User

• TrueCaller / ThatsThem• Phone number lookup.

Page 11: Open Source Intelligence (OSINT)- Testcases for Pentesters

Enumerate Subdomains• Trickiest part. • Knock.py type scripts available for brute-forcing the subdomains.• Too much noise, not that effective. Can’t brute force longer subdomain

names. • WolfRamAlpha - Advanced Data • DNSDumpster• Netcraft

• Automate! Hit It!

Page 12: Open Source Intelligence (OSINT)- Testcases for Pentesters

Extract files, Extract meta data from them.• Filetype search via Google /

Yandex / Bing / etc.• Spider the site. • Extract all files, eg. PDF, SWF, etc. • Extract Metadata• Run Exif Tool ~ Application

version, author, etc.

Page 13: Open Source Intelligence (OSINT)- Testcases for Pentesters

Enumerate Emails Associated.• Emailhunter• SimplyEmail.py

Page 14: Open Source Intelligence (OSINT)- Testcases for Pentesters

Breach Status?• Have I Been Pwned?• Breach or Clear?• If email is found to be a part of breach? Is the breach data public?• Quite often, people use same password for more than one account.

Page 15: Open Source Intelligence (OSINT)- Testcases for Pentesters

Osint on Email• Find Gravatar• Tinyeye.com / Google Reverse Image Search / FindFace• Information from Facebook / Google Plus / Blog / Linkedin• Harvest username. • ClearBit

Page 16: Open Source Intelligence (OSINT)- Testcases for Pentesters

Osint on Username• UserSherlock / NameCheck / Knowem• Tweets. Woah! Woah! Woah!• Instagram Check-ins / Facebook Check-ins• Github repos > Employees don’t give a shit to Security. • ApiKeys? Access Tokens? Passwords? DB Creds? What not?• Secret keys once committed, cannot be deleted, Unless the whole repo is

deleted.

• Gravatar / Profile Image > Reverse Image Search.

Page 17: Open Source Intelligence (OSINT)- Testcases for Pentesters

Create list of targeted passwords ~ username

Page 18: Open Source Intelligence (OSINT)- Testcases for Pentesters

Search domain in Github• https://github.com/search?q=“example.com”&type=Code

• Specifically check Server side codes, .php, .py, .asp, .jsp, etc.

• No High Sev bug > Get creds from Git. w00t w00t. :D

Page 19: Open Source Intelligence (OSINT)- Testcases for Pentesters

Trace check-ins from Instagram / Facebook

Page 20: Open Source Intelligence (OSINT)- Testcases for Pentesters

Facebook Stuff.• http://graph.tips/• https://inteltechniques.com/intel/OSINT/facebook.html

Page 21: Open Source Intelligence (OSINT)- Testcases for Pentesters

Check S3 buckets / Windows blobs for access controls. • bucketfinder.rb < searches s3 buckets based on keywords.

• Bucket name nomenclature:• https://bucketname.s3.amazonaws.com• https://s3.amazonaws.com/bucketname

• Install aws-cli, configure it. Free credits from AWS will get you aws secret keys and api keys.

• By default AWS buckets are private. But devs are too smart sometimes ;)

• Simple checks• aws s3 ls s3://bucketname• aws s3 mv ../../Downloads/filename.txt s3://bucketname

Page 22: Open Source Intelligence (OSINT)- Testcases for Pentesters

Obtain Government Data [Pan Card / Voter Card Information]• Name + DoB = Pan Card Information

• Name + DoB + Native Place = Voter card Information • http://electoralsearch.in/##resultArea

• DoB : Username Osint / Social media.

• DD/MM is public. YYYY can be enumerated from Linkedin profile.

Page 23: Open Source Intelligence (OSINT)- Testcases for Pentesters

Visualize Data• Maltego • Various python Libraries• Lumio• ElasticSearch / Kibana

Page 24: Open Source Intelligence (OSINT)- Testcases for Pentesters

Monitoring and Alerting• Use streaming APIs if possible• Dump data in ES / MongoDb / Db of your choice.• Calculates hashes. Alerting on top of it. • For Elasticsearch, ElastAlert is cool. (Frequency / Spike / Negation /

etc.) http://nullcon.net/website/nullcon-2016/training/attack-monitoring-using-elasticsearch-logstash-kibana.php

• Facilitates alerts on Jira, Hipcha, Slack, Email, Bash Commands ~ (Perform an action).

Page 26: Open Source Intelligence (OSINT)- Testcases for Pentesters

Quick Basic Demo?https://github.com/upgoingstar/datasploit

Page 27: Open Source Intelligence (OSINT)- Testcases for Pentesters