Vulnerability scanners are automated tools designed to scan hosts and networks
for known vulnerabilities and weaknesses. There are a number of these tools on
the market. Some are free and others will significantly strain your budget.
Network Associates CyberCop Scanner and Internet Security Systems (ISS) Internet
Scanner are two of the leading commercial scanners in the industry. These tools
essentially perform a series of automated checks against each target, trying to
locate known vulnerabilities. Each tool has a vulnerability signature database
that it can use to test the host for known vulnerabilities. If the vulnerability
does not exist in the database, the tool cannot find it. Additionally, if the
database is not continually updated, the tool will not find the latest
vulnerabilities and will become less effective. Therefore, the number of
vulnerabilities a scanner looks for and the frequency of the updates are
important criteria for selecting the right vulnerability scanner. The problem is
each vendor does not define the term vulnerability in the same way. For
instance, some scanners find one vulnerability and then report each piece of
information that can be gathered as a result of this one vulnerability as
additional vulnerability checks. So a single vulnerability becomes ten as
reported by the scanner.
There are password crackers for almost every password-protected system available. A quick search on the Internet identifies password crackers for Windows NT, UNIX, Novell, PGP, Word, VNC, pcAnywhere, Lotus Notes, Cisco routers, WinZip, and many others. Password crackers can be effective tools to use during penetration testing to help ensure users are selecting strong passwords. If a strong password is used, password crackers can take weeks, months, or even years to crack it. If a weak password is used, the cracker could succeed in hours, minutes, or even seconds. In this chapter we concentrate on OS-specific password crackers and describe their use during testing. L0phtCrack URL: www.L0pht.com Client OS: Windows 9x/NT Target OS: Windows NT Price: Under $100 Description: L0phtCrack is the premier NT password cracker. The first version provided administrators the ability to extract user names and encrypted password hashes from the SAM database and perform a dictionary and brute for...
Comments
Post a Comment