Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Internet Scanning - Current State and Lessons Learned

Black Hat via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the world of internet-wide scanning and its implications for cybersecurity in this 26-minute Black Hat conference talk. Delve into Project Sonar's raw data sets and community engagement, examining the latest results from implementing databases, search engines, and trending features. Learn about investigative tools for data correlation and a trending database monitoring security improvements by country and industry. Discover new scan types and their potential applications through demonstrations and data processing examples. Uncover recent findings on vulnerabilities and misconfigurations lurking in the internet's deep corners, including statistics on the SSL Heartbleed vulnerability. Gain insights into various topics such as SNMP process listing and credential retrieval, Telnet Linux shells, serial port servers, and ElasticSearch code execution. Understand the scope of Sonar data, including sizes and record counts, and explore practical use cases like asset discovery and NAT-PMP and DNS findings.

Syllabus

Intro
Outline
Internet-wide scanning
Research / Finding history
SNMP - list processes, get credentials
Telnet: Linux Shells
Serial Port Servers
Example Remote Serial Ports
ElasticSearch, code execution is a feature
Sonar - Data overview
Sonar - Data sizes and record counts
Recent findings - NAT-PMP
Recent findings - DNS
Example Use-Case Asset Discovery

Taught by

Black Hat

Reviews

Start your review of Internet Scanning - Current State and Lessons Learned

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.