Netscan Module update 2

Discussion in 'Closed Beta' started by Anashel, Nov 23, 2017.

  1. Anashel

    Anashel Puppet Master Staff Member

    Hi everyone!

    Here is a report on the Netscan module. (working title) Along with internal DNS attacks (using sfuzzer) or WMI scanning on Windows, Netscan will give you another way of hacking into a corporate network.

    Similar to a Man in the Middle attack, you will be able to launch Netscan as soon as you are connected to the Turbine C2 Card via VPN. Scanning the ARP table will reveal IPs and server names on a local network.

    01.jpg

    Unsecured endpoints (file sharing, databases, etc) will be identified. Using the impersonate function, you will be able to enter credentials or execute password attacks to gain higher privileges on the network.

    02.jpg

    From the Netscan module you can automate password attacks, launch fingerprint scans, open a file browser session and initiate database connections. We also introduced another way of hacking: process injection.

    03.jpg

    Using the proper credentials, Stinger OS will let you scan all running process and identify vulnerable one. From there, you will be able to execute scripts and compromised these processes. For example, using a vulnerable process, you can escalate privileges to install an FTP service and open up a file browsing session on a previously secure computer.

    04.jpg

    All in all, netscan is a versatile Swiss army knife, giving you key intel for your offensive actions against a network. Following multiple iterations in the last two weeks, we are now confident moving forward and having you test it in the next beta update.

    Cheers!
     
    andrea, Twosheds, Steelgramps and 6 others like this.
  2. andrea

    andrea Active Agent

    when the final version download for everybody?? :eek:
     
  3. Steelgramps

    Steelgramps Gold Member

    Looks very impressive and usefull!
     
  4. SH4D0WZ0MB1E

    SH4D0WZ0MB1E Active Agent

    Wow! I get busy with end of semester stuff and holidays and come back to find that a lot has changed. Looks like it's going to be fun to play with and a lot more ways to try and access a system. Can't wait to try all of these tools out when I get a chance.
     
  5. Jason

    Jason Active Agent

    I'd imagine sometime this week as the staff were busy as hell with the live event and deserved a break.
     
    zaelong likes this.
  6. deadbeatsaint

    deadbeatsaint Active Agent

    I adore how this is being developed. The more sophisticated (and realistic), the better.
     
  7. Ansuz

    Ansuz New Agent

    I love it. Fantastic work, guys!
     

Share This Page