Select a local organization, and conduct a passive reconnaissance. This should include searching job
boards, the organizations own website, user groups/bulletin boards, social networking sites,
www.archive.org, etc. Gather as much information about the target network as you can.
Project 6.2: Port Scanners
Use your favorite search engine to locate at least two other port scanners. Download and install them,
then try them on your own machine or a designated lab computer. Compare and contrast these tools to
Nmap. Are they easier to use? More informative?
Project 6.3: MBSA
Download and install MBSA and run a vulnerability scan on your own computer or on a designated lab
computer. What problems did you find? Was the tool easy to use?
WEB RESOURCES
• http://www.youtube.com/watch?v=h-9rHTLHJTY SQL Injection Demo
• http://www.youtube.com/watch?v=r79ozjCL7DA Cross site scripting demo
CHAPTER REVIEW/ANSWERS TO TEST YOUR SKILLS
Multiple Choice Questions
1.
1.
SQL injection is based on what?
2.
Which of the following is a vulnerability scanner specifically for Windows systems?
3.
How can you prevent cross-site scripting?
4.
What is an advantage of using Nessus?