hackNos: Os-hackNos Walkthrough

by Vince
in Blog
Hits: 3261

It's been a while since I've played on Vulnhub and there are a ton of new machines.  In fact, I just saw a stat that showed this is the first year where there have been over 100 submissions.  I guess I've got a lot of catching up to do -- or not.  Anyway, it's the holiday weekend and I have some time to kill so I went to see what was new and hackNos is one of the first few.

This box is fairly straightforward as long as you don't get bogged down on any particular avenue.  It's also possible to get the root flag without actually becoming root but I couldn't let that stand so I rooted it as well.  More on that in a moment. 

First, we kick off with Nmap:

Read more

Network Segmentation

by Vince
in Blog
Hits: 1515

While performing a penetration test recently, I managed to pivot from a workstation to a VoIP server.  One of the main reasons this occurred is due to the fact that the network was not segmented.  So what is network segmentation?  It's breaking up the network into logical parts while isolating some devices from other devices.

I think most WiFi networks these days have a "guest network" which is essentially the same concept.  We're isolating the guests from the rest of our network but we're still allowing them access to the Internet.  With our network, we're able to do this with several different technologies but it can be done for as little as $20-$30. 

In the picture below, I've created a basic network:

Read more

GoPhish : Phishing and More...

by Vince
in Blog
Hits: 10550

"Gophish is a powerful, open-source phishing framework that makes it easy to test your organization's exposure to phishing."

Depending on where you look, and what they are trying to sell you, the percentage of attacks from phishing range from 30% - 90%.  The Verizon Data Breach Investigations Report shows the percentage dropped in 2019 from 2018 by about 40%.  Regardless, phishing is still an easy and viable attack vector.  I can send phishing emails over and over again and the recipient only needs to make a mistake once.  It's simple and it's effective.

For phishing awareness training, there are pay services, there are services that offer phishing as a secondary feature -- like Duo, and there are free products like GoPhish.  Not only can you use phishing awareness tools test phishing, you can also use them as a tripwire of sorts -- more on that at the end of this post. 

Read more