SECURITY TIPS FOR THE DAY, TODAY'S SECURITY TIPS, IS ON OFFENSIVE SECURITY AND BUG BOUNTY (HACKING VIA ASN):
ASN:
Which stands for Autonomous Security Number, is a way by which block of IP addresses, belonging to an organization are represented. These blocks of IP addresses are registered by the five (5) RIRs (Regional Internet Registries), and work in close relationship with IANA (Internet Assigned Number Authority).
By accessing the ASN record of an organization (which of course is publicly available), hacking becomes not just possible, it becomes very easy. This arises from the fact that these records obtained are verified and trusted.
However, the only limitation of hacking through ASN, is that you must be good with the following:
1. Writing POCS:
This is as a result of most of these IP addresses not being tied to a web application, which demands the use of OWASP TOP10, but rather to servers running various operating systems, requiring you to write exploit codes, in order to gain root access to the server.
2. Hunting for CVE’s:
If you specialize in hunting bugs through ASN, then ensure that you are up-to-date with disclosed vulnerabilities and POC codes, as these IP addresses, might be running one or more services that are pertinent to the disclosed vulnerabilities.
3. Good With NMAP:
Although you might be lucky to experience some security misconfigured vulnerabilities, by the IT professionals of the organization, most times you wouldn’t. So, learn how to bypass firewalls using NMAP scanning, to uncover the underlying services, ports, and service versions.
To be able to hack, you must understand what is running in the background.
4. Expert Skill in Using Metasploit:
Using metasploit database to search for reported exploit codes and POCS, and using these POC, to compromise the target is a required skill.
HOW TO THEN HACK THROUGH ASN:
A. Get the targeted organization’s name. e.g. “FixitGearWare”.
B. Next use an ASN lookup tool you know, to search for the organization’s domain name. The trusted lookup tool for this is:
hackertarget.com/as-ip-looku…
C. Extract all the AS Prefixes in a text file, and if you have an automation tool to massively conduct NMAP scan on these addresses, use them. Alternatively, use NMAP tool.
D. Read the records found and see which is vulnerable.
E. Use your Metasploit tool to see what can be hacked, alternatively crawl the internet to find documented POCS (e.g. exploit-db).
F. Exploit the vulnerability.
G. Report the vulnerability.
NOTE:
While we didn’t go deep into describing some tricks, this is more than enough for you to think outside the box. As we do believe that the concept of learning and figuring things out, does increase your hacking mindset. Think deeply, there is something we are trying to communicate here.
Find this post interesting? Give us a follow, and also do not forget to share with your passionate cybersecurity friends.
Want to get this information first hand ? Click the discord link below and Join. Thank you 🙂
Discord:
discord.com/invite/XGSczQaDR…
#ASNLookup #NetworkHacking #CyberSecurity #EthicalHacking #PenTesting #InfoSec #NetworkSecurity #CyberThreats #HackingTools #TechSecurity #debian #advisory
#indiancert #cyberswachhtakendra #staysafeonline #cybersecurity #besafe #staysafe #mygov #Meity