+ All Categories
Home > Documents > CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything...

CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything...

Date post: 18-Aug-2020
Category:
Upload: others
View: 0 times
Download: 0 times
Share this document with a friend
10
CIS 700/002 : Special Topics : Maltego Sangdon Park CIS 700/002: Security of EMBS/CPS/IoT Department of Computer and Information Science School of Engineering and Applied Science University of Pennsylvania March 17, 2017
Transcript
Page 1: CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything unlawful, misleading, malicious, or discriminatory. You will not do anything that

CIS 700/002 : Special Topics :Maltego

Sangdon Park CIS 700/002: Security of EMBS/CPS/IoT

Department of Computer and Information Science School of Engineering and Applied Science

University of Pennsylvania

March 17, 2017

Page 2: CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything unlawful, misleading, malicious, or discriminatory. You will not do anything that

Brief Introduction

•  Software used for reconnaissance – Visualize publically available information

2

Page 3: CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything unlawful, misleading, malicious, or discriminatory. You will not do anything that

Terminology

•  Entity –  It is represented as a node on a graph and can be

anything such as a domain, person, phone number, etc.

–  20 entities + custom entities •  Transform

–  It is a piece of code that takes one entity to another

•  Machine –  It chains multiple transforms together to automate

common/tedious tasks.

3 https://docs.paterva.com/en/user-guide/getting-started/

Page 4: CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything unlawful, misleading, malicious, or discriminatory. You will not do anything that

Caution!

•  Data crawling may be illegal depending on the terms of use of websites

4

Page 5: CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything unlawful, misleading, malicious, or discriminatory. You will not do anything that

Run a machine

5

Page 6: CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything unlawful, misleading, malicious, or discriminatory. You will not do anything that

Build My Entity Graph from Scratch

6

Page 7: CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything unlawful, misleading, malicious, or discriminatory. You will not do anything that

Maltego OpenSSL Heartbleed Transform

7 https://disk0nn3ct.svbtle.com/maltego-openssl-heartbleed-transform

Page 8: CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything unlawful, misleading, malicious, or discriminatory. You will not do anything that

Maltego OpenSSL Heartbleed Transform

8

Page 9: CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything unlawful, misleading, malicious, or discriminatory. You will not do anything that

Reference

•  cis.upenn.edu/~sangdonp/demo-maltego.html

9

Page 10: CIS 700/002 : Special Topics : Maltego · 17/03/2017  · You will not use Facebook to do anything unlawful, misleading, malicious, or discriminatory. You will not do anything that

Practice Problems

•  Check the heartbleed vulnerability of all webservers under *.cis.upenn.edu domain

•  What is the most used server technologies of *.paterva.com sites?

10


Recommended