Ethical Hacking: Evading Ids, Firewalls, And Honeypots [author] Videos Info
Alex, ethical hacker. 1. Firewall Evasion – The First Glance Alex scans the external perimeter. A classic nmap -sS triggers port 80 (HTTP) and 443 (HTTPS) only. Firewall is stateful—drops unsolicited SYN packets to other ports.
Setting: A red-team engagement for a financial firm. Goal: reach the internal database server without triggering alerts. Alex, ethical hacker
POST /upload HTTP/1.1 Content-Type: multipart/form-data; boundary=xxx --xxx Content-Disposition: form-data; name="data" $(echo 'cat /etc/shadow' | base64) A classic nmap -sS triggers port 80 (HTTP)
But the firewall logs spikes. Alex pivots: . Goal: reach the internal database server without triggering
Alex uses fragmentation and decoy scans :
The IDS sees base64 data but doesn't decode context. Alex finds an open SMB share named HR_Confidential . Too easy. A glance at file metadata shows creation time = 2 AM (odd). Also, the server responds with Server: Honeyd 1.5c (a telltale).
nmap -sV --script=honeypot-detection target Confirmed: it’s a (SSH).