Shodan For Penetration Testers (Defcon 18)

Posted By: SecurityTube_Bot
Posted On: Mon 21 Feb 2011
Views: 6057
Share this video:
Share it on Facebook Share it on Twitter Share it on Reddit Share it on Digg Share it on Stumbleupon
Support SecurityTube:


Description:

This is the video of the talk titled "SHODAN for Penetration Testers" given by Michael Schearer ("theprez98") at Defcon 18 this year.

SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. This presentation will focus on the applications of SHODAN to penetration testers, and in particular will detail a number of case studies demonstrating passive vulnerability analysis including default passwords, descriptive banners, and complete pwnage. For penetration testers, SHODAN is a game-changer, and a goldmine of potential vulnerabilities.

Michael Schearer ("theprez98") is a government contractor who spent nearly nine years in the United States Navy as a combat-experienced EA-6B Prowler Electronic Countermeasures Officer. He also spent nine months on the ground doing counter-IED work with the U.S. Army. He is a graduate of Georgetown University's National Security Studies Program and a previous presenter at DEFCON, and has spoken at ShmooCon, HOPE and internationally at CONFidence (Poland) and HackCon (Norway) as well as other numerous conferences. Michael is a licensed amateur radio operator and an active member of the Church of WiFi. He lives in Maryland with his wife and four children.



The talk includes the following:
  • What is SHODAN?
  • Basic Operations
  • Penetration Testing
  • Case Study 1: Cisco Devices
  • Case Study 2: Default Passwords
  • Case Study 3: Infrastructure Exploitation
  • Other Examples
  • The Future
  • Conclusions
The PDF of the presentation can be downloaded here.


Tags: basics ,


Comments (None)

Login to post a comment