Cybercrime is knocking, are you ready: Series 5
INFORMATION GATHERING: ENUMERATION
We’ll begin by delving into the world of imagination.
Imagine a potential intruder who intends to ultimately break into a house, which quietly sits inside a protective perimeter wall in your city suburb.
Consider, they’ve spent days, weeks (or months) figuring out intrusion weaknesses from afar.
First, they didn’t even know the location of the house. After extensive research, they were able to locate the house (from far away that they initially used a set of binoculars).
Many days later, the intruder drew closer and (without your knowledge), regularly hang about in the neighbourhood, outside your perimeter wall trying to figure out the exploitable weaknesses in the habits of the people who live inside the house.
One day, after having been outside observers for long, they decide enough is enough. They (probably using discreet means) get past the perimeter to check what’s happening inside the perimeter, but outside the walls of the house, to pick on more exploitable security weaknesses that have not been externally observable.
While inside, (and most likely disguised), they check and list the number of doors and windows, tap them to check the open, squeaky, old, rusted and unlocked, peep through, listen to voices, lurk towards the backside of the house, greeting and chatting with the house occupants who happen to be standing in the doors (if any).
As I write, this gets me thinking….this trespasser would most-likely be face-masked and in rubber gloves, as they check out the location of CCTV cameras and security lights around the house, any informed prowler today would, I think!
Cunning as they always are, they climb up to the roof to check for any exploitable entry points, say in the attic area.
What do you think is going on here?
The potential intruder, who had for long been passive outside the perimeter wall, is now transitioning and becoming active in their quest to break into the house.
Leveraging from the foregoing imagination, now you know what ENUMERATION in computer hacking is all about.
In the cyber world, hackers enumerate network resources, network shares and routing tables. They obtain machine names, users and groups from the active directory. They are able to pick on applications running and their banners.
By the way, I got to alert you that a conversation involving technology like ours, will usually be dotted with some technical lingo and I am imploring you to open your heart to some new beginnings!
Hackers extract usernames and email IDs aided by the Simple Network Management Protocol (SNMP). They are able to discover the use of default passwords, and as you well know, with passwords, many users play it safe by maintaining default password, whenever given chance.
To enumerate open ports, they employ the power of TCP/IP and UDP protocols as well as utilizing remote procedure calls, a tool to request for services from programs located in other computers on a network even without having to understand the network’s details, in the first place.
Technically, using a NetBIOS (Network Basic Input/Output system tools like netbios enumerator, nbtstat, hyena, NSAuditor and Superscan on a given IP address, hackers are able to get host names, labels/identifiers assigned to devices connected to a computer network.
Done easily, a smart hacker uses Nmap to fast track their information discovery process for computer systems information technically referred to as SNMP, NTP, SMTP and DNS data.
In the end, let’s face the facts (even when they are unpleasant), without a whine. A network administrator with a cybersecurity mindset at Matia’s institution could have reduced the chances of successful hacker enumeration intrusion by turning off SNMP functionalities and disabling DNS zone transfers. And if this had been done, wonderful!
Never the less, away from the technical terminology, I’ve got some news.
In as much as we know that many animal species around the world are dwindling in number and becoming endangered, for the populace of the hacker species, in particular, is growing every day. And as CEO or CFO, are you ready?
In series 5, we will look at VULNERABILITY ANALYSIS
