Showing posts with label snmp. Show all posts
Showing posts with label snmp. Show all posts

Tuesday, August 9, 2011

Tech-Xpress-Guide so far... from learnings of year 2010

GitHub Repo ~ https://github.com/abhishekkr/a-techXpress-guide

As in what I picked up nicely last year, I did Uploaded few How-To Express Guide in past few months on my SlideShare page ~
http://www.slideshare.net/AbhishekKr/documents

Tech-Xpress-Guide so far ~

[] using SNMP  for secure remote resource monitoring ~
http://www.slideshare.net/AbhishekKr/an-express-guide-ltlt-snmp-for-secure-rremote-resource-monitoring

[] using Nagios for quick & efficient IT Infrastructure monitoring
http://www.slideshare.net/AbhishekKr/an-express-guide-ltlt-nagios-for-it-infrastructure-monitoring

[] using Cacti for IT Infrastructure monitoring with nice analytic graphing
http://www.slideshare.net/AbhishekKr/an-express-guide-cacti-for-it-infrastructure-monitoring-graphing

[] using Zabbix for IT Infrastructure monitoring with easy-to-use Web UI
http://www.slideshare.net/AbhishekKr/an-express-guide-zabbix-for-it-monitoring

[] using DummyNet to mock different Network latencies & bandwidth for testing or other purpose
http://www.slideshare.net/AbhishekKr/an-express-guide-dummynet-for-tweaking-network-latencies-bandwidth

[] creating and using Solaris Native Zones {similar to Linux LXC but much efficient}
http://www.slideshare.net/AbhishekKr/a-tech-xpressguidesolariszonesnativenlxbranded

[] Ethernet Bonding in *Nix for Load Balancing
http://www.slideshare.net/AbhishekKr/a-tech-xpressguideethernetbondingfornics

[] setting up Squid Cache Proxy service
http://www.slideshare.net/AbhishekKr/a-tech-xpressguidesquidforloadbalancingncacheproxy

[] setting Syslog Centralization for *nix machines
http://www.slideshare.net/AbhishekKr/a-tech-xpressguidesyslogcentralizationloggingwithwindows

Wednesday, January 19, 2011

[net-security] Internal Network Scan : major NeXpose work

Background:
Even if a network has strong intrusion detection and prevention mechanism implemented, it is as safe as machines present within the network. If any network device within the network is infected with Trojan, Virus or even running a vulnerable service; it could lead to the compromise of entire network.

Execution Method:
Rapid7 team of Metasploit, have a network vulnerability assessment tool named 'NeXpose'.
It has a huge, regularly updating database of exploits and vulnerabilities to be tested against limited set of machines in its Community Version.

First start scanning the subnets with the best network scanner, NMap revealing some interesting information about Machines, Ports and services running on those ports.

Next, launch NeXpose Scans for all machines identified in the first step in small batches. Here, NeXpose will again do some NMap like testing and a lot more extra self-checking of whether certain exploit is useful against the machine.
Keep a record of all machines with exploitable services and tried hacking those using Metasploit and tools specific to vulnerabilities.


Also use tools like SNMPFuzz, Hunt mainly on server like machines... say AD Server, etc.; you could get lucky anytime.

Tools/Technology Used:
NMap, Rapid7's NeXpose, Metasploit, SNMP Fuzzer, SNScan, Hunt