{"id":199,"date":"2018-07-12T07:14:46","date_gmt":"2018-07-12T07:14:46","guid":{"rendered":"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/?post_type=chapter&#038;p=199"},"modified":"2019-05-14T09:50:09","modified_gmt":"2019-05-14T09:50:09","slug":"vpn-and-extranet","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/chapter\/vpn-and-extranet\/","title":{"rendered":"VPN and Extranet"},"content":{"raw":"<div><span style=\"float: right;\"><a href=\"https:\/\/youtu.be\/kKP6lWRjnGg\" target=\"_blank\" rel=\"noopener\"><img src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a>\r\n<\/span><\/div>\r\n\r\n<strong>The VPN Consortium defines three types of VPNs:<\/strong>\r\n\r\n&nbsp;\r\n\r\n\u25a0 Trusted\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">A trusted VPN is one in which the service provider assures that no one else will be using the same circuit. Its own security team ensures that your network is not available to other people.<\/p>\r\n\r\n<ul>\r\n \t<li>\u25a0 Secure<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify\">In a secure VPN, the data is encrypted and authenticated at each end. A secure trusted VPN can provide a higher level of assurance that data will reach the other end without being subject to snooping and tampering.<\/p>\r\n\r\n<ul>\r\n \t<li>\u25a0 Hybrid<\/li>\r\n<\/ul>\r\nA hybrid VPN is both trusted and secure.\r\n\r\n&nbsp;\r\n\r\n<strong>Snooping:<\/strong>\r\n<ul>\r\n \t<li>Any person is accessing someone else\u2019s data or data belonging to company in an unauthorized way, it is called snooping.<\/li>\r\n \t<li>Snooping includes observing someone's computer screen when E-mail appears on that screen or inspecting what someone is typing.<\/li>\r\n \t<li>Snooping involves software programs that can monitor activity remotely either on a computer or network device.<\/li>\r\n<\/ul>\r\n<strong>Extranet:<\/strong>\r\n\r\n&nbsp;\r\n\r\nExtranet can be created in two ways.\r\n<ul>\r\n \t<li>An external website that requires some form of authentication.<\/li>\r\n \t<li>Create an external application server running Terminal Services (or similar software).<\/li>\r\n<\/ul>\r\n<strong>Fundamentals of Secure Network Design:<\/strong>\r\n<ul>\r\n \t<li>To secure both the gateways into the extranet and the boundary between the extranet and the internal network.<\/li>\r\n<\/ul>\r\n<strong>Dual homed host:<\/strong>\r\n<ul>\r\n \t<li>A dual-homed host is a term used to reference a type of firewall that uses two (or more) network interfaces.<\/li>\r\n \t<li>One connection is an internal network and the second connection is to the internet.<\/li>\r\n \t<li>A dual-homed host works as a simple firewall provided there is no direct IP traffic between the Internet and the inside network.<\/li>\r\n<\/ul>\r\n<img class=\"size-full wp-image-200 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-115.png\" alt=\"\" width=\"538\" height=\"305\" \/>\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>A dual-homed host is a system that has at least two network interfaces.<\/li>\r\n \t<li>Expose the external interface directly to the external network.<\/li>\r\n \t<li style=\"text-align: justify\">The external network could be the Internet, or it could be attached to any two networks with differing levels of trust.<\/li>\r\n \t<li>The host is hardened at system level to make it more resistant to intruders.<\/li>\r\n \t<li>The external interface may or may not be screened with a packet-filtering router or firewall.<\/li>\r\n \t<li>Systems that expose a VPN are typically dual-homed hosts by necessity.<\/li>\r\n \t<li style=\"text-align: justify\">The dual-homed host exposes services by running those services directly, or by proxying the services, or by allowing users to log directly into the dual-homed host.<\/li>\r\n \t<li>If compromised, all servers in the extranet are now exposed directly to the external net-work.<\/li>\r\n<\/ul>\r\n<strong>Solution..<\/strong>\r\n<ul>\r\n \t<li>severely restrict the services made available by it .<\/li>\r\n \t<li>- Do not allow users to log directly on to the dual-homed host .<\/li>\r\n \t<li style=\"text-align: justify\">- System aggressively locked down in kiosk mode can sometimes be used to explore the internal network, and sometimes intruders can break the kiosk mode<\/li>\r\n \t<li style=\"text-align: justify\">- Allow external users to log on remotely\u2014external users do not require to install special software in most cases.<\/li>\r\n \t<li style=\"text-align: justify\">When dealing with Internet-exposed systems or any system dual-homed between networks of differing trust levels - assume that the external system will be compromised at some point in the future.<\/li>\r\n \t<li>- Monitor the activity<\/li>\r\n \t<li>- Be ready for rebuilding<\/li>\r\n \t<li>- Hardened any system connected to DHH.<\/li>\r\n<\/ul>\r\n<strong>The dual-homed host:<\/strong>\r\n<ul>\r\n \t<li>Acts as a Proxy for internal network users and \/ or external network users<\/li>\r\n \t<li>If acting as a router, it has packet filtering capabilities.<\/li>\r\n<\/ul>\r\nDrawback: All permissible communication is done through the bastion host. This introduces degradation in performance.\r\n\r\n&nbsp;\r\n\r\n<strong>Screened Host:<\/strong>\r\n<ul>\r\n \t<li>A <em>screened host<\/em> sits behind a firewall that exposes only that system to the external network.<\/li>\r\n<\/ul>\r\n<strong>Advantage :<\/strong>\r\n\r\n&nbsp;\r\n\r\nThe firewall might be able to provide more protection to the system than the system\u2019s own network filters could.\r\n\r\n&nbsp;\r\n\r\n<strong>Disadvantage :<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The firewall can be configured (possibly intentionally) to allow access to other systems in the extranet to and from the external network.If the service that the screened host provides to the external network can be compromised , the attacker has access to the other extranet hosts.<\/p>\r\n&nbsp;\r\n\r\nAdvantage of having firewall:\r\n<ul>\r\n \t<li>Alert on unusual activity<\/li>\r\n \t<li>Impose restrictions on outbound traffic as much as possible.<\/li>\r\n \t<li style=\"text-align: justify\">The damage is limited and the attacker\u2019s work is at least slowed down, If an attacker has compromised a host behind a firewall but is unable to either upload new tools or to make the compromised host download new tools from the outside.<\/li>\r\n<\/ul>\r\n<img class=\"size-full wp-image-201 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-116.png\" alt=\"\" width=\"565\" height=\"241\" \/>\r\n\r\n&nbsp;\r\n\r\nThe packet filter:\r\n<ul>\r\n \t<li>Filters IP traffic and permits only allowable traffic to pass between the screened host and the Internet.<\/li>\r\n \t<li>No direct traffic flow is allowed between internal hosts and the Internet.<\/li>\r\n<\/ul>\r\n<img class=\"size-full wp-image-202 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-117.png\" alt=\"\" width=\"543\" height=\"359\" \/>\r\n<ul>\r\n \t<li>Screened subnet is variation of the dual-homed gateway and screened host firewall.<\/li>\r\n \t<li style=\"text-align: justify\">Incorporates two firewalls - one firewall between externally exposed systems and the extranet hosts, and another firewall between the extranet hosts and the internal network.A perimeter network is formed between two packet filters\u00a0 Compromising of the bastion host does not allow sniffing of internal communication because there is inner packet filter which gives extra protection. A publicly accessible server such as www-server can be hosted in the perimeter network. Where firewall should<span style=\"text-align: initial;font-size: 1em\"> be placed?<\/span><\/li>\r\n<\/ul>\r\n<strong>Option 1 Bastion host<\/strong>\r\n<ul>\r\n \t<li>The bastion host toplogy is well suited for relatively simple networks and for those that don't offer any public Internet services.<\/li>\r\n \t<li>This is the only boundary. If anyone breaks the boundary, the protected network gets clear access to the protected network can be gained.<\/li>\r\n \t<li style=\"text-align: justify\">Enough if firewall is used for filtering traffic of internet in corporate network. For hosting a Web site or deployment of e-mail server, this protection is not sufficient.<\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\n<strong>Option 2 Screened subnet<\/strong>\r\n<ul>\r\n \t<li>The screened subnet ensures that organizations will offer services securely to all users of internet.<\/li>\r\n \t<li>Servers hosting public services got placed in the Demilitarized Zone(DMZ), which has boundary on both sides provided by firewall, one side the Internet and the other side trusted network.Split screened Subnets<\/li>\r\n \t<li>With a split screened subnet, the extranet hosts are dual-homed\u2014A front-end network segment is usually very restricted, and A back-end segment is less restricted and can be used to administer the systems. The limits of the network created by bastion<span style=\"text-align: initial;font-size: 1em\"> host with dual home <\/span>forms<span style=\"text-align: initial;font-size: 1em\"> two separate networks.\u00a0<\/span>This guards<span style=\"text-align: initial;font-size: 1em\"> in depth:<\/span><\/li>\r\n \t<li>Proxy services can interpret application protocols, so dual-homed bastion host improves control on the communication links.<\/li>\r\n \t<li>There is an outer packet filter that provides protection to the bastion host from hosts on external network.<\/li>\r\n \t<li>There is an inner packet filter that provides protection to the bastion host from hosts in internal network.<\/li>\r\n<\/ul>\r\n<img class=\"size-full wp-image-203 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-118.png\" alt=\"\" width=\"572\" height=\"445\" \/>\r\n\r\n&nbsp;\r\n\r\nPenetration Testing an Extranet\r\n<ul>\r\n \t<li>Check how your extranet is configured.<\/li>\r\n \t<li>Test the packet filtering rules to see extra ports left open\u2026<\/li>\r\n \t<li>Use ports scanning<\/li>\r\n \t<li>- Check the changes in what is being accessed by changing the source port<\/li>\r\n \t<li>- Look for open ports<\/li>\r\n<\/ul>\r\nPort scanning\r\n<ul>\r\n \t<li>Port numbers use 16 bits and range from 0 to 65535.<\/li>\r\n \t<li>Port numbers below 1024 are reserved ports.<\/li>\r\n \t<li>All others are high or registered ports<\/li>\r\n \t<li>OS will give a port number from 1024 through 5000 when user asks for a port<\/li>\r\n \t<li>Port numbers above 5000 is infrequently used.<\/li>\r\n \t<li>netstat \u2013a shows the state of all sockets<\/li>\r\n \t<li>netstat \u2013n shows network addresses as numbers<\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\n&nbsp;\r\n<table class=\"aligncenter\" border=\"1\">\r\n<tbody>\r\n<tr>\r\n<td style=\"width: 142.063px\">Active Connections<\/td>\r\n<td style=\"width: 148.063px\"><\/td>\r\n<td style=\"width: 235.063px\"><\/td>\r\n<td style=\"width: 107.063px\"><\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 142.063px\"><\/td>\r\n<td style=\"width: 148.063px\">Proto Local Address<\/td>\r\n<td style=\"width: 235.063px\">Foreign Address<\/td>\r\n<td style=\"width: 107.063px\">State<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 142.063px\">TCP<\/td>\r\n<td style=\"width: 148.063px\">192.168.1.7:52718<\/td>\r\n<td style=\"width: 235.063px\">74.125.130.125:5222<\/td>\r\n<td style=\"width: 107.063px\">ESTABLISHED<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 142.063px\">TCP<\/td>\r\n<td style=\"width: 148.063px\">192.168.1.7:52826<\/td>\r\n<td style=\"width: 235.063px\">198.211.121.246:80\u00a0 CLOSE_WAIT<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n&nbsp;\r\n\r\nCheckpoints:\r\n<ul>\r\n \t<li>Failure to use least privilege<\/li>\r\n \t<li>Inadequate separation of different levels of asset<\/li>\r\n \t<li>High-level internal users on extranet systems<\/li>\r\n \t<li>High-level extranet accounts being used on systems you don\u2019t control<\/li>\r\n \t<li>High-level accounts logging on to different segments of the extranet<\/li>\r\n \t<li>Systems dual-homed between the extranet and the internal network<\/li>\r\n \t<li>Lack of intrusion detection systems<\/li>\r\n<\/ul>\r\nExploring the internal network\r\n<ul>\r\n \t<li>ipconfig \/all<\/li>\r\n<\/ul>\r\n<img class=\"alignnone size-full wp-image-205\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-120.png\" alt=\"\" width=\"1405\" height=\"1786\" \/>\r\n\r\n&nbsp;\r\n\r\n<img class=\"size-large wp-image-206 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-121-1024x619.png\" alt=\"\" width=\"1024\" height=\"619\" \/>\r\n\r\n&nbsp;\r\n\r\nnslookup:\r\n<ul>\r\n \t<li><strong>nslookup <\/strong>is a command line tool available to network administrator. This command is used for querying the Domain Name System(DNS) so that domain name or IP address is obtained.<\/li>\r\n<\/ul>\r\nping:\r\n<ul>\r\n \t<li>The command : for \/l %d in (1,1,254) do ping \u2013a \u2013n 1 192.168.21.%d -a Resolve addresses to hostnames -n count Number of echo requests to send.<\/li>\r\n \t<li>C:\\Users\\laptop&gt;ping -a -n<span style=\"text-align: initial;font-size: 1em\"> 1 192.168.21.6Pinging 192.168.21.6 with 32 bytes of data: Reply from 192.168.22.1: Destination host unreachable.<\/span><\/li>\r\n \t<li>Ping statistics for 192.168.21.6: Packets: Sent = 1, Received = 1, Lost = 0 (0% loss),C:\\Users\\laptop&gt;ping -a -n 1 192.168.21.7<\/li>\r\n \t<li>Pinging 192.168.21.7 with 32 bytes of data: Reply from 192.168.22.1: Destination host unreachable.<\/li>\r\n \t<li>Ping statistics for 192.168.21.7:Packets: Sent = 1, Received = 1, Lost = 0 (0% loss),<\/li>\r\n<\/ul>\r\nTake the inventory of the subnet:\r\n\r\n<img class=\"size-large wp-image-207 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-122-1024x560.png\" alt=\"\" width=\"1024\" height=\"560\" \/>\r\n\r\n&nbsp;\r\n\r\n<img class=\"size-large wp-image-208 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-123-861x1024.png\" alt=\"\" width=\"861\" height=\"1024\" \/>\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<img class=\"size-large wp-image-209 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-124-1024x599.png\" alt=\"\" width=\"1024\" height=\"599\" \/>\r\n<div>\r\n\r\nWho is in charge of the network?\r\n\r\n&nbsp;\r\n\r\nC:\\&gt;net localgroup administrators\u00a0<span style=\"text-align: initial;font-size: 1em\">Alias name\u00a0 administrators\u00a0<\/span><span style=\"text-align: initial;font-size: 1em\">Comment\u00a0 Administrators have complete and\u00a0 \u00a0 unrestricted access\u00a0\u00a0<\/span><span style=\"text-align: initial;font-size: 1em\">to the computer\/domain\u00a0<\/span><span style=\"text-align: initial;font-size: 1em\">Members<\/span>\r\n\r\n<\/div>\r\n&nbsp;\r\n\r\n------------------------------------------------------------------------------\r\n\r\nExtAdmin Domain Admins What users are in the Domain admins group?\r\n<ul>\r\n \t<li>C:\\&gt;net group \"domain admins\" \/domain The request will be processed at a domain controller for domain extranet.example.com Group name\u00a0 \u00a0Domain Admins\u00a0\u00a0<span style=\"font-size: 1em;text-align: initial\">Comment\u00a0 Designated administrators of the domain\u00a0<\/span>Members<\/li>\r\n<\/ul>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n-----------------------------------------------------------------\r\n\r\n<\/div>\r\n<div>\r\n\r\nDCAdmin\u00a0 ralph\u00a0<span style=\"text-align: initial;font-size: 1em\">INTERNAL\\_svc\u00a0\u00a0<\/span><span style=\"text-align: initial;font-size: 1em\">The command completed successfully.\u00a0<\/span><span style=\"text-align: initial;font-size: 1em\">Username is known then passwords can be tried from (passwords.txt)<\/span>\r\n\r\n<\/div>\r\n<ul>\r\n \t<li><strong>Net use command <\/strong>connects \/ disconnects the computer from a shared resource, or allow to view the information about current computer connections. This command also controls persistent network connections.<\/li>\r\n \t<li>Use <strong>net use command<\/strong> without any parameters to retrieve a list of network current connections. C:\\&gt;for \/f %d in (passwords.txt) do net use \\\\127.0.0.1 \/user:EXTRANET-TS1 \\ExtAdmin %d Look for a share<\/li>\r\n \t<li>C:\\&gt;net view \\\\extranet-web1Shared resources at \\\\extranet-web1 Share name Type Used as Comment WebRoot\u00a0\u00a0 Disk The command completed successfully<\/li>\r\n<\/ul>\r\n\r\n<table>\r\n<tbody>\r\n<tr>\r\n<td><strong>you can view video on VPN and Extranet<\/strong><\/td>\r\n<td><a href=\"https:\/\/youtu.be\/kKP6lWRjnGg\" target=\"_blank\" rel=\"noopener\"><img class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n\r\n<strong>Suggested Reading:<\/strong>\r\n<ol>\r\n \t<li>Cryptography and Network Security Principles and Practice by William Stallings, sixth Edition, PEARSON.<\/li>\r\n \t<li>Security in Computing by Charles Pfleeger &amp; Shari Lawrence Pfleeger, fourth Edition, PEARSON.<\/li>\r\n \t<li>Network Security by Charlie Kaufman, Radia Perlman, Mike Speciner, second Edition, PHI.<\/li>\r\n \t<li>The Complete Reference \u2013 Network Security by Roberta Bragg, Mark Rhodes-Ousley &amp; Keith Strassberg, Tata McGraw Hill<\/li>\r\n \t<li>Network Security Bible by Eric Cole, Ronald Krutz, James Conley, Wiley<\/li>\r\n \t<li>Hacking 6 Exposed by Stuart McClure, Joel Scambray &amp; George Kurtz , Tata McGraw Hill .<\/li>\r\n \t<li><a href=\"http:\/\/www.snort.org\/\">www.snort.org<\/a><\/li>\r\n \t<li><a style=\"text-align: initial;font-size: 1em\" href=\"https:\/\/nmap.org\/\">https:\/\/nmap.org<\/a><\/li>\r\n<\/ol>","rendered":"<div><span style=\"float: right;\"><a href=\"https:\/\/youtu.be\/kKP6lWRjnGg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a><br \/>\n<\/span><\/div>\n<p><strong>The VPN Consortium defines three types of VPNs:<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>\u25a0 Trusted<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">A trusted VPN is one in which the service provider assures that no one else will be using the same circuit. Its own security team ensures that your network is not available to other people.<\/p>\n<ul>\n<li>\u25a0 Secure<\/li>\n<\/ul>\n<p style=\"text-align: justify\">In a secure VPN, the data is encrypted and authenticated at each end. A secure trusted VPN can provide a higher level of assurance that data will reach the other end without being subject to snooping and tampering.<\/p>\n<ul>\n<li>\u25a0 Hybrid<\/li>\n<\/ul>\n<p>A hybrid VPN is both trusted and secure.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Snooping:<\/strong><\/p>\n<ul>\n<li>Any person is accessing someone else\u2019s data or data belonging to company in an unauthorized way, it is called snooping.<\/li>\n<li>Snooping includes observing someone&#8217;s computer screen when E-mail appears on that screen or inspecting what someone is typing.<\/li>\n<li>Snooping involves software programs that can monitor activity remotely either on a computer or network device.<\/li>\n<\/ul>\n<p><strong>Extranet:<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Extranet can be created in two ways.<\/p>\n<ul>\n<li>An external website that requires some form of authentication.<\/li>\n<li>Create an external application server running Terminal Services (or similar software).<\/li>\n<\/ul>\n<p><strong>Fundamentals of Secure Network Design:<\/strong><\/p>\n<ul>\n<li>To secure both the gateways into the extranet and the boundary between the extranet and the internal network.<\/li>\n<\/ul>\n<p><strong>Dual homed host:<\/strong><\/p>\n<ul>\n<li>A dual-homed host is a term used to reference a type of firewall that uses two (or more) network interfaces.<\/li>\n<li>One connection is an internal network and the second connection is to the internet.<\/li>\n<li>A dual-homed host works as a simple firewall provided there is no direct IP traffic between the Internet and the inside network.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-200 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-115.png\" alt=\"\" width=\"538\" height=\"305\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-115.png 538w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-115-300x170.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-115-65x37.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-115-225x128.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-115-350x198.png 350w\" sizes=\"auto, (max-width: 538px) 100vw, 538px\" \/><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>A dual-homed host is a system that has at least two network interfaces.<\/li>\n<li>Expose the external interface directly to the external network.<\/li>\n<li style=\"text-align: justify\">The external network could be the Internet, or it could be attached to any two networks with differing levels of trust.<\/li>\n<li>The host is hardened at system level to make it more resistant to intruders.<\/li>\n<li>The external interface may or may not be screened with a packet-filtering router or firewall.<\/li>\n<li>Systems that expose a VPN are typically dual-homed hosts by necessity.<\/li>\n<li style=\"text-align: justify\">The dual-homed host exposes services by running those services directly, or by proxying the services, or by allowing users to log directly into the dual-homed host.<\/li>\n<li>If compromised, all servers in the extranet are now exposed directly to the external net-work.<\/li>\n<\/ul>\n<p><strong>Solution..<\/strong><\/p>\n<ul>\n<li>severely restrict the services made available by it .<\/li>\n<li>&#8211; Do not allow users to log directly on to the dual-homed host .<\/li>\n<li style=\"text-align: justify\">&#8211; System aggressively locked down in kiosk mode can sometimes be used to explore the internal network, and sometimes intruders can break the kiosk mode<\/li>\n<li style=\"text-align: justify\">&#8211; Allow external users to log on remotely\u2014external users do not require to install special software in most cases.<\/li>\n<li style=\"text-align: justify\">When dealing with Internet-exposed systems or any system dual-homed between networks of differing trust levels &#8211; assume that the external system will be compromised at some point in the future.<\/li>\n<li>&#8211; Monitor the activity<\/li>\n<li>&#8211; Be ready for rebuilding<\/li>\n<li>&#8211; Hardened any system connected to DHH.<\/li>\n<\/ul>\n<p><strong>The dual-homed host:<\/strong><\/p>\n<ul>\n<li>Acts as a Proxy for internal network users and \/ or external network users<\/li>\n<li>If acting as a router, it has packet filtering capabilities.<\/li>\n<\/ul>\n<p>Drawback: All permissible communication is done through the bastion host. This introduces degradation in performance.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Screened Host:<\/strong><\/p>\n<ul>\n<li>A <em>screened host<\/em> sits behind a firewall that exposes only that system to the external network.<\/li>\n<\/ul>\n<p><strong>Advantage :<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>The firewall might be able to provide more protection to the system than the system\u2019s own network filters could.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Disadvantage :<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The firewall can be configured (possibly intentionally) to allow access to other systems in the extranet to and from the external network.If the service that the screened host provides to the external network can be compromised , the attacker has access to the other extranet hosts.<\/p>\n<p>&nbsp;<\/p>\n<p>Advantage of having firewall:<\/p>\n<ul>\n<li>Alert on unusual activity<\/li>\n<li>Impose restrictions on outbound traffic as much as possible.<\/li>\n<li style=\"text-align: justify\">The damage is limited and the attacker\u2019s work is at least slowed down, If an attacker has compromised a host behind a firewall but is unable to either upload new tools or to make the compromised host download new tools from the outside.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-201 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-116.png\" alt=\"\" width=\"565\" height=\"241\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-116.png 565w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-116-300x128.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-116-65x28.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-116-225x96.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-116-350x149.png 350w\" sizes=\"auto, (max-width: 565px) 100vw, 565px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>The packet filter:<\/p>\n<ul>\n<li>Filters IP traffic and permits only allowable traffic to pass between the screened host and the Internet.<\/li>\n<li>No direct traffic flow is allowed between internal hosts and the Internet.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-202 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-117.png\" alt=\"\" width=\"543\" height=\"359\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-117.png 543w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-117-300x198.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-117-65x43.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-117-225x149.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-117-350x231.png 350w\" sizes=\"auto, (max-width: 543px) 100vw, 543px\" \/><\/p>\n<ul>\n<li>Screened subnet is variation of the dual-homed gateway and screened host firewall.<\/li>\n<li style=\"text-align: justify\">Incorporates two firewalls &#8211; one firewall between externally exposed systems and the extranet hosts, and another firewall between the extranet hosts and the internal network.A perimeter network is formed between two packet filters\u00a0 Compromising of the bastion host does not allow sniffing of internal communication because there is inner packet filter which gives extra protection. A publicly accessible server such as www-server can be hosted in the perimeter network. Where firewall should<span style=\"text-align: initial;font-size: 1em\"> be placed?<\/span><\/li>\n<\/ul>\n<p><strong>Option 1 Bastion host<\/strong><\/p>\n<ul>\n<li>The bastion host toplogy is well suited for relatively simple networks and for those that don&#8217;t offer any public Internet services.<\/li>\n<li>This is the only boundary. If anyone breaks the boundary, the protected network gets clear access to the protected network can be gained.<\/li>\n<li style=\"text-align: justify\">Enough if firewall is used for filtering traffic of internet in corporate network. For hosting a Web site or deployment of e-mail server, this protection is not sufficient.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Option 2 Screened subnet<\/strong><\/p>\n<ul>\n<li>The screened subnet ensures that organizations will offer services securely to all users of internet.<\/li>\n<li>Servers hosting public services got placed in the Demilitarized Zone(DMZ), which has boundary on both sides provided by firewall, one side the Internet and the other side trusted network.Split screened Subnets<\/li>\n<li>With a split screened subnet, the extranet hosts are dual-homed\u2014A front-end network segment is usually very restricted, and A back-end segment is less restricted and can be used to administer the systems. The limits of the network created by bastion<span style=\"text-align: initial;font-size: 1em\"> host with dual home <\/span>forms<span style=\"text-align: initial;font-size: 1em\"> two separate networks.\u00a0<\/span>This guards<span style=\"text-align: initial;font-size: 1em\"> in depth:<\/span><\/li>\n<li>Proxy services can interpret application protocols, so dual-homed bastion host improves control on the communication links.<\/li>\n<li>There is an outer packet filter that provides protection to the bastion host from hosts on external network.<\/li>\n<li>There is an inner packet filter that provides protection to the bastion host from hosts in internal network.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-203 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-118.png\" alt=\"\" width=\"572\" height=\"445\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-118.png 572w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-118-300x233.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-118-65x51.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-118-225x175.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-118-350x272.png 350w\" sizes=\"auto, (max-width: 572px) 100vw, 572px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Penetration Testing an Extranet<\/p>\n<ul>\n<li>Check how your extranet is configured.<\/li>\n<li>Test the packet filtering rules to see extra ports left open\u2026<\/li>\n<li>Use ports scanning<\/li>\n<li>&#8211; Check the changes in what is being accessed by changing the source port<\/li>\n<li>&#8211; Look for open ports<\/li>\n<\/ul>\n<p>Port scanning<\/p>\n<ul>\n<li>Port numbers use 16 bits and range from 0 to 65535.<\/li>\n<li>Port numbers below 1024 are reserved ports.<\/li>\n<li>All others are high or registered ports<\/li>\n<li>OS will give a port number from 1024 through 5000 when user asks for a port<\/li>\n<li>Port numbers above 5000 is infrequently used.<\/li>\n<li>netstat \u2013a shows the state of all sockets<\/li>\n<li>netstat \u2013n shows network addresses as numbers<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<table class=\"aligncenter\">\n<tbody>\n<tr>\n<td style=\"width: 142.063px\">Active Connections<\/td>\n<td style=\"width: 148.063px\"><\/td>\n<td style=\"width: 235.063px\"><\/td>\n<td style=\"width: 107.063px\"><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 142.063px\"><\/td>\n<td style=\"width: 148.063px\">Proto Local Address<\/td>\n<td style=\"width: 235.063px\">Foreign Address<\/td>\n<td style=\"width: 107.063px\">State<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 142.063px\">TCP<\/td>\n<td style=\"width: 148.063px\">192.168.1.7:52718<\/td>\n<td style=\"width: 235.063px\">74.125.130.125:5222<\/td>\n<td style=\"width: 107.063px\">ESTABLISHED<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 142.063px\">TCP<\/td>\n<td style=\"width: 148.063px\">192.168.1.7:52826<\/td>\n<td style=\"width: 235.063px\">198.211.121.246:80\u00a0 CLOSE_WAIT<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>Checkpoints:<\/p>\n<ul>\n<li>Failure to use least privilege<\/li>\n<li>Inadequate separation of different levels of asset<\/li>\n<li>High-level internal users on extranet systems<\/li>\n<li>High-level extranet accounts being used on systems you don\u2019t control<\/li>\n<li>High-level accounts logging on to different segments of the extranet<\/li>\n<li>Systems dual-homed between the extranet and the internal network<\/li>\n<li>Lack of intrusion detection systems<\/li>\n<\/ul>\n<p>Exploring the internal network<\/p>\n<ul>\n<li>ipconfig \/all<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-205\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-120.png\" alt=\"\" width=\"1405\" height=\"1786\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-120.png 1405w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-120-236x300.png 236w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-120-768x976.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-120-806x1024.png 806w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-120-65x83.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-120-225x286.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-120-350x445.png 350w\" sizes=\"auto, (max-width: 1405px) 100vw, 1405px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-206 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-121-1024x619.png\" alt=\"\" width=\"1024\" height=\"619\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-121-1024x619.png 1024w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-121-300x181.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-121-768x464.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-121-65x39.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-121-225x136.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-121-350x212.png 350w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-121.png 1401w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>nslookup:<\/p>\n<ul>\n<li><strong>nslookup <\/strong>is a command line tool available to network administrator. This command is used for querying the Domain Name System(DNS) so that domain name or IP address is obtained.<\/li>\n<\/ul>\n<p>ping:<\/p>\n<ul>\n<li>The command : for \/l %d in (1,1,254) do ping \u2013a \u2013n 1 192.168.21.%d -a Resolve addresses to hostnames -n count Number of echo requests to send.<\/li>\n<li>C:\\Users\\laptop&gt;ping -a -n<span style=\"text-align: initial;font-size: 1em\"> 1 192.168.21.6Pinging 192.168.21.6 with 32 bytes of data: Reply from 192.168.22.1: Destination host unreachable.<\/span><\/li>\n<li>Ping statistics for 192.168.21.6: Packets: Sent = 1, Received = 1, Lost = 0 (0% loss),C:\\Users\\laptop&gt;ping -a -n 1 192.168.21.7<\/li>\n<li>Pinging 192.168.21.7 with 32 bytes of data: Reply from 192.168.22.1: Destination host unreachable.<\/li>\n<li>Ping statistics for 192.168.21.7:Packets: Sent = 1, Received = 1, Lost = 0 (0% loss),<\/li>\n<\/ul>\n<p>Take the inventory of the subnet:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-207 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-122-1024x560.png\" alt=\"\" width=\"1024\" height=\"560\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-122-1024x560.png 1024w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-122-300x164.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-122-768x420.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-122-65x36.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-122-225x123.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-122-350x191.png 350w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-122.png 1404w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-208 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-123-861x1024.png\" alt=\"\" width=\"861\" height=\"1024\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-123-861x1024.png 861w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-123-252x300.png 252w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-123-768x913.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-123-65x77.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-123-225x268.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-123-350x416.png 350w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-123.png 1405w\" sizes=\"auto, (max-width: 861px) 100vw, 861px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-209 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-124-1024x599.png\" alt=\"\" width=\"1024\" height=\"599\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-124-1024x599.png 1024w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-124-300x175.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-124-768x449.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-124-65x38.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-124-225x132.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-124-350x205.png 350w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-124.png 1395w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<div>\n<p>Who is in charge of the network?<\/p>\n<p>&nbsp;<\/p>\n<p>C:\\&gt;net localgroup administrators\u00a0<span style=\"text-align: initial;font-size: 1em\">Alias name\u00a0 administrators\u00a0<\/span><span style=\"text-align: initial;font-size: 1em\">Comment\u00a0 Administrators have complete and\u00a0 \u00a0 unrestricted access\u00a0\u00a0<\/span><span style=\"text-align: initial;font-size: 1em\">to the computer\/domain\u00a0<\/span><span style=\"text-align: initial;font-size: 1em\">Members<\/span><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n<p>ExtAdmin Domain Admins What users are in the Domain admins group?<\/p>\n<ul>\n<li>C:\\&gt;net group &#8220;domain admins&#8221; \/domain The request will be processed at a domain controller for domain extranet.example.com Group name\u00a0 \u00a0Domain Admins\u00a0\u00a0<span style=\"font-size: 1em;text-align: initial\">Comment\u00a0 Designated administrators of the domain\u00a0<\/span>Members<\/li>\n<\/ul>\n<div>\n<p>&nbsp;<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<\/p>\n<\/div>\n<div>\n<p>DCAdmin\u00a0 ralph\u00a0<span style=\"text-align: initial;font-size: 1em\">INTERNAL\\_svc\u00a0\u00a0<\/span><span style=\"text-align: initial;font-size: 1em\">The command completed successfully.\u00a0<\/span><span style=\"text-align: initial;font-size: 1em\">Username is known then passwords can be tried from (passwords.txt)<\/span><\/p>\n<\/div>\n<ul>\n<li><strong>Net use command <\/strong>connects \/ disconnects the computer from a shared resource, or allow to view the information about current computer connections. This command also controls persistent network connections.<\/li>\n<li>Use <strong>net use command<\/strong> without any parameters to retrieve a list of network current connections. C:\\&gt;for \/f %d in (passwords.txt) do net use \\\\127.0.0.1 \/user:EXTRANET-TS1 \\ExtAdmin %d Look for a share<\/li>\n<li>C:\\&gt;net view \\\\extranet-web1Shared resources at \\\\extranet-web1 Share name Type Used as Comment WebRoot\u00a0\u00a0 Disk The command completed successfully<\/li>\n<\/ul>\n<table>\n<tbody>\n<tr>\n<td><strong>you can view video on VPN and Extranet<\/strong><\/td>\n<td><a href=\"https:\/\/youtu.be\/kKP6lWRjnGg\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Suggested Reading:<\/strong><\/p>\n<ol>\n<li>Cryptography and Network Security Principles and Practice by William Stallings, sixth Edition, PEARSON.<\/li>\n<li>Security in Computing by Charles Pfleeger &amp; Shari Lawrence Pfleeger, fourth Edition, PEARSON.<\/li>\n<li>Network Security by Charlie Kaufman, Radia Perlman, Mike Speciner, second Edition, PHI.<\/li>\n<li>The Complete Reference \u2013 Network Security by Roberta Bragg, Mark Rhodes-Ousley &amp; Keith Strassberg, Tata McGraw Hill<\/li>\n<li>Network Security Bible by Eric Cole, Ronald Krutz, James Conley, Wiley<\/li>\n<li>Hacking 6 Exposed by Stuart McClure, Joel Scambray &amp; George Kurtz , Tata McGraw Hill .<\/li>\n<li><a href=\"http:\/\/www.snort.org\/\">www.snort.org<\/a><\/li>\n<li><a style=\"text-align: initial;font-size: 1em\" href=\"https:\/\/nmap.org\/\">https:\/\/nmap.org<\/a><\/li>\n<\/ol>\n","protected":false},"author":4,"menu_order":23,"template":"","meta":{"_acf_changed":false,"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":["miss-hiteishi-diwanji"],"pb_section_license":""},"chapter-type":[],"contributor":[58],"license":[],"class_list":["post-199","chapter","type-chapter","status-publish","hentry","contributor-miss-hiteishi-diwanji"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/users\/4"}],"version-history":[{"count":9,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/199\/revisions"}],"predecessor-version":[{"id":462,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/199\/revisions\/462"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/199\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/media?parent=199"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapter-type?post=199"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/contributor?post=199"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/license?post=199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}