WEBVTT

00:00.440 --> 00:01.070
All right.

00:01.100 --> 00:06.560
We've established that hacking in cyber security is a bad thing.

00:06.980 --> 00:11.210
Ethical hacking a good thing, but hacking a bad thing.

00:11.510 --> 00:18.290
So now that we understand this is something bad, let's go ahead and jump in and talk about what we

00:18.290 --> 00:24.380
see in the industry as the common phases that occur in hacking.

00:24.650 --> 00:30.860
If they're sophisticated, they're going to be in fact, if they have any degree of sophistication,

00:31.070 --> 00:36.860
they're going to be very interested in using a phased approach.

00:37.190 --> 00:39.860
They're going to be professional about it.

00:40.070 --> 00:46.160
They're not just going to download some tool like a script kitty and start firing it off randomly at

00:46.160 --> 00:47.000
your environment.

00:47.300 --> 00:55.130
They are going to use a thoughtful methodology and it typically begins with reconnaissance or recon.

00:55.460 --> 01:04.190
They are going to actively or passively be gaining valuable information against your environment.

01:04.190 --> 01:08.440
So they will want to know layer three IP addresses.

01:08.450 --> 01:11.510
They'll want to know layer two MAC addresses.

01:11.750 --> 01:15.410
They will want to know what service ports you're utilizing.

01:15.650 --> 01:19.220
They will want to know what are those services you're utilizing.

01:19.450 --> 01:24.350
They're going to gain this documentation about your environment.

01:24.890 --> 01:33.770
What's painful about this is I've been instructing for decades in this industry and I beg in my security

01:33.770 --> 01:44.500
classes, I beg students to be, you know, really just hyper conscious of how detailed and how accurate,

01:44.510 --> 01:47.360
how up to date their documentation is.

01:47.600 --> 01:49.550
And they tend not to do this.

01:49.730 --> 01:56.540
And the irony, the painful irony about it is they could go to some of the people that have done attacks

01:56.540 --> 02:02.090
against their network and they can get excellent documentation that those attackers have.

02:02.120 --> 02:04.700
So we don't want to fall into this category.

02:05.480 --> 02:12.050
Actively doing reconnaissance means they're doing things like scanning ports.

02:12.050 --> 02:18.380
They're sending traffic in to our devices and having our devices respond.

02:18.920 --> 02:27.140
The reason this is called active is they're really active in our environment and this is dangerous for

02:27.140 --> 02:30.090
them because we can often catch this.

02:30.440 --> 02:32.420
So we see them doing this.

02:32.420 --> 02:34.460
Hopefully we see them doing this.

02:34.790 --> 02:37.250
And that is the active approach.

02:37.640 --> 02:45.350
Passive is scarier for us because if they're passively doing recon against us, they've probably figured

02:45.350 --> 02:47.570
out a way to eavesdrop.

02:47.900 --> 02:54.650
And now they're capturing our traffic, our packets of traffic, and they're looking at information

02:54.650 --> 03:01.160
inside of those packets that will give them the address, information and things that they need.

03:01.520 --> 03:09.320
So reconnaissance is typically the first phase and be sure you're clear and the differences between

03:09.320 --> 03:10.460
active and passive.

03:11.330 --> 03:19.280
The next phase that we see all the time is a scanning phase, and we're going to actually elaborate

03:19.280 --> 03:20.000
on this.

03:20.240 --> 03:27.110
So we're going to be teaching you about the scanning, but then also the enumeration.

03:27.380 --> 03:34.070
Now, a lot of people consider enumeration just part of scanning, but we're going to break those apart

03:34.070 --> 03:40.460
so that we can really give you detailed information on how this is done in the hacking process.

03:40.940 --> 03:48.830
Scanning might be discovering the ports that are available, and then enumeration is going to be figuring

03:48.830 --> 03:54.320
out the specifics of the services that are available over those ports.

03:54.650 --> 03:58.730
So we'll be breaking, scanning into multiple phases.

03:58.910 --> 04:06.440
But here we just generally from a bird's eye view of this whole discipline, we say it's initially the

04:06.440 --> 04:08.210
active or passive reconnaissance.

04:08.390 --> 04:11.240
Then they'll enter a more active scanning phase.

04:11.480 --> 04:13.140
They'll do enumeration.

04:13.430 --> 04:15.380
They'll gain access.

04:15.620 --> 04:18.980
They'll make sure they can maintain access.

04:19.250 --> 04:22.220
And then they'll work to clear their tracks.

04:22.610 --> 04:31.190
Notice not all hackers are going to possess the level of sophistication to do all of these phases.

04:31.490 --> 04:32.660
Thank goodness.

04:32.960 --> 04:40.250
Thank goodness the world is not made up of hackers that are sophisticated to go through these phases

04:40.460 --> 04:46.580
and to take the time and spend the resources that would be required to do all of this.

04:46.910 --> 04:53.000
But notice and learn these five phases reconnaissance, whether active or passive.

04:53.210 --> 04:54.350
Then scanning.

04:54.560 --> 04:57.200
Then getting into the resources.

04:57.410 --> 04:59.810
Then making sure they can stay in.

04:59.880 --> 05:06.390
Those resources and then trying to clear their tracks so they might be able to, in fact, do it all

05:06.390 --> 05:07.120
over again.

05:07.140 --> 05:08.220
How scary is that?

05:08.550 --> 05:15.900
In fact, part of their maintaining access may have been to install backdoors in Rootkits and various

05:15.900 --> 05:22.860
other bad things that can be used more effectively and efficiently against us in the future.
