Advanced NMap Techniques - Hak5 2415

Поделиться
HTML-код
  • Опубликовано: 22 июн 2018
  • Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:
    ____________________________________________
    Dan Tentler joins us to share some tips about NMap and Mass Scan!
    phobos.io/
    / viss
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    Shop → www.hakshop.com
    Subscribe → / hak5
    RSS Feeds → www.hak5.org/subscribe
    Support → / threatwire
    Amazon Associates → amzn.to/2pHgf8T
    Our Site → www.hak5.org
    Contact Us → / hak5
    Threat Wire RSS → shannonmorse.podbean.com/feed/
    Threat Wire iTunes → itunes.apple.com/us/podcast/t...
    Help us with Translations! → ruclips.net/user/timedtext_cs_p...
    For Business Inquiries, please use our contact forms → www.hak5.org/contact
    Producer: Shannon Morse → / @sailorsnubs
    Editor: Perrin M
    Host: Shannon Morse → / snubs
    Host: Darren Kitchen → / hak5darren
    Host: Mubix → / mubix
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • НаукаНаука

Комментарии • 171

  • @slackerengi2401
    @slackerengi2401 6 лет назад +91

    Can we have a Viss segment on the show?
    Like metasploit minute and linux terminal?
    Hell, why not extend it to other pen testers and have them talk about their methods and experiences

  • @navisachar
    @navisachar 5 лет назад +1

    Viss - explains things 100 miles an hour, yet still engaging and comprehensive. Legend !

  • @ilimanjf
    @ilimanjf 6 лет назад +26

    Please feature more folks like Viss on your show! Not only did we learn great technical skills but also got an insight into how these skills can be used and have been used in real-world situations. Got a lot from this one episode!

  • @traviscollins3682
    @traviscollins3682 6 лет назад +8

    Hell yeah! Keep bringing back Viss! Love that dude's talks

  • @bakkasur9614
    @bakkasur9614 6 лет назад

    This is why I love hak5. Gurus showing real stuff.

  • @SOulDie22
    @SOulDie22 5 лет назад +8

    this guys a legend! very good at explaining what hes on about

  • @mark9900
    @mark9900 6 лет назад +16

    Finally I found out why my web is so slow here in Shenzhen, China . You were scanning me . Lol . Learn a lot from you guys . 👍

  • @m1stax-pl01t7
    @m1stax-pl01t7 6 лет назад +2

    Viss has been the man for a while haha.

  • @mikereid8425
    @mikereid8425 6 лет назад +2

    AWESOME video, learning so much

  • @MauricioMartinez0707
    @MauricioMartinez0707 6 лет назад

    This guy knows so much, keep him on the show more often please

  • @volksbugly
    @volksbugly 6 лет назад +4

    xargs is probably my favorite cmdline tool :D but word of advice, first always run your xarged command with an echo first to make sure you set it up right :D

  • @snkd8224
    @snkd8224 5 лет назад +1

    my left ear really loved this episode

  • @Vinayak123-q8p
    @Vinayak123-q8p 2 года назад

    amazing, this could be probably one of the biggest information that i have ever been given. we need such playlist more and more in upcoming days. i hope i made you understand the things that i wanted to make you understand. we need such techniques more and more in upcoming days.

  • @vb6code
    @vb6code 4 года назад

    one of the best videos I have ever seen

  • @MilanAntonijevic
    @MilanAntonijevic 6 лет назад +3

    nice video, thanks for the tips. Just as a hint, grep has a feature that can exclude it from the results, using, for example "grep [n]map", instead of "grep nmap | grep -v grep". Cheers

  • @user-ef5zk5on3d
    @user-ef5zk5on3d 6 лет назад +1

    Very useful video, high level of giving knowledges. Do more vids, please, in this way.

  • @Warlock1515
    @Warlock1515 5 лет назад

    Best nmap video ever♥️😍

  • @HackerPaints
    @HackerPaints 6 лет назад +7

    You guys have great on-screen chemistry. More Viss + Shannon shows please! The content of these shows is fantastic, too. :)

  • @clarenceyoung3041
    @clarenceyoung3041 5 лет назад

    Awesome!! This will help greatly with work!

  • @szmonszmon
    @szmonszmon 6 лет назад +1

    Good for you that we not switched to IPv6 :P Thank you Hak5!

  • @nissanpacific9793
    @nissanpacific9793 6 лет назад +3

    lmao the motion fx in this episode crack me up hahaha

  • @thecomputerinside
    @thecomputerinside 6 лет назад +10

    Viss: Master of FPV drones, tinywhooping, Shodan, and destroying things with LAZERS

  • @garynagle3093
    @garynagle3093 6 лет назад

    Great show.

  • @rev0luci0n
    @rev0luci0n 6 лет назад +1

    Awesome video need moar Viss!

  • @pfsmith007
    @pfsmith007 5 лет назад

    He's talented. Fun to watch.

  • @crunchy1653
    @crunchy1653 6 лет назад +1

    I love Viss!

  • @ericsmith1801
    @ericsmith1801 6 лет назад +1

    Hey Shannon, how about a segment on machine learning applied to penetration testing? I am thinking of finding patterns in traffic analysis perhaps

  • @MrWilde
    @MrWilde 6 лет назад +21

    Once you've done the sweeps then you can do the bleeps and the creeps. ;)

    • @vissago
      @vissago 6 лет назад +2

      i straight thought this in my head while i was saying it, but im no where good as michael winslow so I didn't even try :D

    • @captainblood9616
      @captainblood9616 5 лет назад

      :D Respect + .. I fully lol'd on that one

  • @josephrex7766
    @josephrex7766 5 лет назад

    @vissago I wonder what tools are in your tools directory besides ipscan

  • @dhombios
    @dhombios 6 лет назад

    An episode about analyzing information gathered through nmap and osint tools like spiderfoot or the harvester with elasticsearch (or any big data analysis tool) would be really interesting as all of them just provide a just small piece of information which becomes meaningful when it is integrated with the one found by the other programs used

  • @Cygnus0lor
    @Cygnus0lor 6 лет назад +68

    "This is a laptop..."
    "Oh wow."

    • @mookmerkin1
      @mookmerkin1 5 лет назад +11

      Agreed. A little less fake "wonderment" vocalized on every other sentence would make this much more useful and tolerable video.

    • @Kenneth_the_Philosopher
      @Kenneth_the_Philosopher 5 лет назад +1

      She's nice! Cool it, man.

    • @mookmerkin1
      @mookmerkin1 5 лет назад +4

      @@Kenneth_the_Philosopher Guys like you are the reason she's there, it seems. Why not let her show her brains and add to the video, being something other than a cheerleader?

    • @bendover4728
      @bendover4728 4 года назад +8

      This was like a pr0n video.. "Oh wow! Oh nice! Yeah, yeah! Oh, oh, yes yes.."

    • @mysticgod7406
      @mysticgod7406 4 года назад

      @@bendover4728 Not wanna ruin the purpose of the video.....But Bruh....you're damn right😂😂😂

  • @YuriNiitsuma
    @YuriNiitsuma 6 лет назад

    Greatest video.

  • @lukasandresson3990
    @lukasandresson3990 4 года назад

    I Wonder how many times they have to route the packages to get to the destination. Nmap has a built in function for scanning the subnet.

  • @chizukichan
    @chizukichan 6 лет назад +2

    Vissago Thank you for making Shodan.
    I'm working on a Kodi Plug-In (next step: screen saver) that let's one channel surf through random IP cams and Shodan has been incredibly useful for building a list of them that are online. What's a good way to make the plug-in scale? I'm worried about too many people connecting to the same camera or using the plug-in to "scrape" my API (rate-limiting already implemented but not tested with more than a few machines).
    Also, AWS does not seem like the place to put a REST API that is suggesting people access IP Cams that aren't theirs. Who might be okay with this?

    • @juliavanderkris5156
      @juliavanderkris5156 6 лет назад +2

      Viss didn't make shodan. Shodan is made by John Matherly (aka achillean).
      Viss is still awesome though.

  • @ariafathi5683
    @ariafathi5683 5 лет назад +1

    Which one is the most reliable tool to scan for rdp(3389)? zmap, masscan, nmap or anything else?

  • @ugli1440
    @ugli1440 2 года назад +1

    when he asked if she was familiar with syn/ack handshake hahaha she looked like she died inside. 🤣

  • @RAGHAVENDRASINGH17
    @RAGHAVENDRASINGH17 6 лет назад

    Can you send me link to the machine you are referring?

  • @spicybaguette7706
    @spicybaguette7706 5 лет назад

    xargs is amaaaaaaaazing!

  • @tzisorey
    @tzisorey 6 лет назад +2

    All cool stuff, but the thing that impressed me the most, was his ability to spell parallellelism.

    • @tzisorey
      @tzisorey 6 лет назад

      Might implement the thing about scanning the office's internal network for newly opened ports, though - I do work for a lot of real estate agencies, and not only is the sales staff turnover ridiculously high, but they're all BYO laptops. I've gone bald from the frustrations.

    • @tzisorey
      @tzisorey 6 лет назад

      And don't even get me started on the GeeDee software they insist on using. Not only does it require Borland Database Engine to be in Win3.1 compatibility mode, with Write Cache disabled on all computers, and the /Program Files/GeeDee folder to be excluded from all virus scans - but they only recently got rid of the _requirement_ that PC Anywhere be installed on "the main computer", open to the internet, with _a specific username and password,_ that are *published in their documentation freely available on the internet.*
      ...Not to suggest that these things could be problematic...

  • @SourceCodeDeleted
    @SourceCodeDeleted 6 лет назад

    Does the thumbnail for this video keep changing ?

  • @kingpaimon3644
    @kingpaimon3644 6 лет назад +2

    love u hak5

  • @abnerkantasingh5516
    @abnerkantasingh5516 7 месяцев назад

    Great gold reference

  • @SharpRaccoonTeeth
    @SharpRaccoonTeeth 6 лет назад +25

    Can viss become a host ? He is legend

  • @konate7131
    @konate7131 5 лет назад

    I scan windows 10 with all its options and gives all the ports are filtered, you can help me

  • @ewookiis
    @ewookiis 6 лет назад +4

    So... Cutting is brutal, but I know Viss have a bit of a overload of info to burp ;).

  • @ncktyu
    @ncktyu 5 лет назад

    I have no idea what is going on. What's a good series of videos to begin to understand this

  • @guneshshanbhag6208
    @guneshshanbhag6208 5 лет назад +4

    Ohhhh boy...10 to 2 is 4 hours:)

  • @xlr555usa
    @xlr555usa 6 лет назад +1

    So only ipv4 was being scanned? What about ipv6 addresses?

  • @tubemasterninja01
    @tubemasterninja01 6 лет назад +6

    love the name of the mounted drive on viss' desktop

    • @vissago
      @vissago 6 лет назад +8

      I did that on purpose hoping someone would catch it and frankly im surprised the os let me do that - your'e the first to mention it :D

    • @tubemasterninja01
      @tubemasterninja01 6 лет назад +2

      vissago that’s hilarious! I had to stop and think if I had missed a new way of injecting code :) that made me think for a sec.

    • @stanly720
      @stanly720 6 лет назад +1

      Someone explain this to me

  • @japrogramer
    @japrogramer 6 лет назад

    Why not use gnu parallel?

  • @llortaton2834
    @llortaton2834 2 года назад

    Viss : *talks*
    Girl : *oh wow*

  • @jakethewoz
    @jakethewoz 6 лет назад

    Not used to watching Viss without the doc anymore...

  • @TheSakeCat
    @TheSakeCat 6 лет назад

    I like dan, let's see more dan.

  • @alby_alby
    @alby_alby 6 лет назад +3

    keep hakin :)

  • @BruceWayne-ep9hp
    @BruceWayne-ep9hp 6 лет назад +3

    "I also have problems with reading comprehension."

  • @saturnphp
    @saturnphp 4 года назад

    looking a this I'm getting some ideas on how to get my friends internet down :))

  • @gogogravity
    @gogogravity 5 лет назад

    Tarpitting! Reminded me of LaBrea Tarpit which I used for over a decade and always worked perfectly.

  • @Kenneth_the_Philosopher
    @Kenneth_the_Philosopher 5 лет назад +1

    Smart Guy.

  • @fuckyeahnigge
    @fuckyeahnigge 6 лет назад +4

    shannon mesmerized by viss lol XD

    • @supersonic118boi8
      @supersonic118boi8 6 лет назад

      I know you could tell by body language and eye movement

    • @gaflying3448
      @gaflying3448 5 лет назад +1

      And where she whipped him with the blue cable.

  • @ericsmith1801
    @ericsmith1801 6 лет назад

    Let me guess, the 50 VMs doing portscans are going to be located on servers in India when scanning ports in China, since the two countries don't cooperate that much :)

  • @killivalavan3245
    @killivalavan3245 5 лет назад

    Bro in my vmware kalilinux does not show its wifi Option it shows only wire connection
    how to solve it

    • @indifferent1
      @indifferent1 5 лет назад

      are you using virtual machine without external wifi adapter ? [in that case it will not show wifi]

  • @Trev0rReznik
    @Trev0rReznik 5 лет назад

    Парень реально крут

  • @ericsmith1801
    @ericsmith1801 6 лет назад

    How about randomly scanning 200 million IP addresses using something like the bubble sort algorithm to find live hosts? You might find a larger number of live hosts in a limited amount of time (you would not want to scan all of the 200 million hosts just find a large number of live hosts). A sequential search may not be ideal for efficiently finding live IP nodes.

  • @1nf3c7-tious
    @1nf3c7-tious 4 года назад +1

    Eternal blue almost get me caught by the feds.

  • @killerskincanoe
    @killerskincanoe 6 лет назад

    oh wow

  • @EdwardVarner
    @EdwardVarner 2 года назад

    33:58 What is a SIM (sp?)

  • @mohitr5768
    @mohitr5768 6 лет назад

    Heyyyyy....tentacle boooooiiiii.

  • @frankbaron1608
    @frankbaron1608 5 лет назад

    that look at the camera was so perfect

  • @Gameek
    @Gameek 6 лет назад

    isn't that how wanncry works it's scanns IPs and use eternalblue ??

  • @StuxNETozor
    @StuxNETozor 4 года назад

    There's something I don't get. He said he's scanning hosts for Ethernablue, but how it is possible to scan host behind a public IP ? Is there weakness about NAT/PAT or firewalls ? Is there a way to find private IP behind a router ?
    Asking for documentation ofc, I won't learn it through a YT comment

  • @conceptrat
    @conceptrat 2 года назад

    Would i have been better to use "parallel" instead of "xargs' unless you're backgrounding them all which isn't ideal. Using"parallel" will run all of the commands at the same time and track them.

  • @ajjmunoz
    @ajjmunoz 5 лет назад +1

    I wonder exactly what viss said that required a post production edit 38:31 maybe a "TMI" moment or a slip of the tongue? Trust your techno edit

  • @fredtheilig9636
    @fredtheilig9636 6 лет назад

    Tour Con? TOR Con? I'd love to watch the VNC scan talk.

    • @hak5
      @hak5  6 лет назад

      Toorcon

  • @xealit
    @xealit 5 лет назад

    Cool scripting in the video! But probably a more fitting title would be "techniques to scale nmap" or something alike. ("Scaling nmap to 100mbit"?)

  • @user-xx2wv6wr8u
    @user-xx2wv6wr8u 6 лет назад

    can install steam on kali

    • @stanly720
      @stanly720 6 лет назад

      يآوطن غلآك كبير no

  • @shu172
    @shu172 6 лет назад +1

    is he using some 3rd party terminal on Mac?

    • @vissago
      @vissago 6 лет назад +3

      no, just regular old terminal, but the thing im running inside it is byobu

    • @shu172
      @shu172 6 лет назад +1

      Thanks, btw very interesting video, hoping for more soon

    • @juanj5681
      @juanj5681 6 лет назад +1

      He's ssh'd to his server.

    • @shu172
      @shu172 6 лет назад

      I know that Juan, just been asking about the nonstandard features you can see on the bottom of the window (and got the response from Viss above), cheers

  • @craxxysum1264
    @craxxysum1264 4 года назад +1

    from 10 to 14 are 4 hour dude, the count doesn't start from zero when we are in the time domain :) :) :)

  • @williamknight7608
    @williamknight7608 4 года назад

    Hey Shannon and team, what's the guest's name in this video?

  • @Atom_007
    @Atom_007 6 лет назад

    Legit

  • @Claeys67
    @Claeys67 4 года назад

    29:19
    Viss: So, the idea here is, this is gonna tell us what's up and what's not up, and then what we can do is, we can take that last
    script that we were using, and we can incorporate one into the other and say well, when we get the results of this, ...
    Shannon: ItS sO bEaUtIfUl!
    Viss: ... well it gets more interesting, check it out...
    Shannon: It LoOkS lIkE a UnIcOrN!

    Shannon Morse -- Video Host. Speaker.

  • @bitcanics6892
    @bitcanics6892 5 лет назад

    oh wow, that makes sense, lol

  • @shickster1
    @shickster1 6 лет назад +3

    10-2=5 hours? off by one error.

  • @nemesisc6122
    @nemesisc6122 5 лет назад

    Skip to 9:24 to start the demo

  • @zealsika
    @zealsika 5 лет назад

    neeeeeeeeerrrrrrrrrrrrrrrrd

  • @wilgarcia1
    @wilgarcia1 6 лет назад

    Oh that's not going to tempt us down a rabbit hole, NOT AT ALL =0P

  • @LakeVermilionDreams
    @LakeVermilionDreams 6 лет назад +30

    If you're going to do jump cuts, maybe the animated screen in the back that makes it blatantly and distractingly obvious might need to be reconsidered. Small nitpick, I know, and I mean nothing but friendly advice, so please don't take me wrong! Just my observation

    • @stan464
      @stan464 6 лет назад +1

      LakeVermilionDreams rhheeeeeee??

    • @hak5
      @hak5  6 лет назад +11

      Meh.

    • @tombola3412
      @tombola3412 6 лет назад

      What the hell are you talking about at what time was there a jump cut?

    • @LakeVermilionDreams
      @LakeVermilionDreams 6 лет назад +6

      Hak5 wow no wonder people hate the RUclips comment sections when even the content creators can't even comment something on a productive manner. Normally this channel has been pretty good at interacting with fans, but this sarcasm leaves a bad taste in the mouth.

    • @ko-Daegu
      @ko-Daegu 6 лет назад +3

      LakeVermilionDreams
      Dude it’s not big of a deal ...
      If you have a problem creat your own hak5 ...
      How about that 👶...

  • @michaelgraff6978
    @michaelgraff6978 6 лет назад

    IPv6 is part of the internet.

  • @3x3Qt
    @3x3Qt 6 лет назад +2

    I wish Shannon wouldn’t say “of course” so often. It doesn’t add much to the show, belittles the audience, and makes the guest sound like they’re stating the obvious. Dan is my hero, and he’s very good at explaining things too.

  • @traggerosbourne6877
    @traggerosbourne6877 5 лет назад

    scanning china sounds fun

  • @Quick_and_Dirty
    @Quick_and_Dirty 6 лет назад

    Hi.
    Gently pointing out that it's clear you two did the "Storytime With Viss! Offensive Security Fails" back-to-back with this one.
    From a production point of view, I get that it's convenient to shoot it like that, but couldn't you have at least changed your shirts? Maybe mussed up your hair a little? Changed the lighting?
    If you're going to bill something as being separate shows, maybe it could at least look like it was done on different days?
    :)

  • @bufordmaddogtannen
    @bufordmaddogtannen 4 года назад

    17:04 "So why do you wanna that a 256 as opposed to 128?“
    Because - oh wow - to scan each /24 chunk in one go Dan must tell nmap to work on 256 IPs at once instead of 128, as he explained earlier?
    "Yeah wow. OK. Of course. Ooohhh cool". (😲🤔🤯)

  • @jonyweb7279
    @jonyweb7279 3 года назад

    I'm in love this woman wow is beautiful, waw she just says wow kkkkkkkkkk.. Come to Portugal goooooo wow

  • @intel_da_developer4791
    @intel_da_developer4791 4 года назад

    So hacking the hold internet on port 445 really take forever literally

  • @tjbotes7401
    @tjbotes7401 2 года назад

    what if you can make a bomb instead of flamethrower

  • @neotroncs
    @neotroncs 5 лет назад +1

    ?? Dean Cain is a Hacker ??

  • @zxletul
    @zxletul 4 года назад

    Starts in 9:03. Thx me via Like!! Jejeje

  • @bobbyv3
    @bobbyv3 6 лет назад +4

    Every time I watch these, I get the impression that Snubs is completely clueless as to what her guests are talking about. Lol.

    • @Claeys67
      @Claeys67 4 года назад +1

      Look at her face when viss mentioned something as simple as whois (12:31). 😩️

  • @chris56a
    @chris56a 6 лет назад

    i know this is irrelivant but i saw the ad "cleanmymac" ad on pornhub cant be that reliable...

  • @dxsp1d3r
    @dxsp1d3r 5 лет назад

    Well I have recently got 50 MBPS Plan RIP internet

  •  6 лет назад

    skip to 9 mins in when it gets interesting.