HN user

opsdisk

390 karma

https://opsdisk.com

Posts12
Comments52
View on HN

https://scan17.com/

Automated network port change detection. Scan17 provides a solution to the question:

So your CTO decides to outsource firewall management - and the vendor carelessly leaves a network port open, exposing your production database. How does your team find out before an attacker?

Think of it as nmap port scan diff-ing. If a network port goes from closed to open you get an email or webhook alert. There is a REST API for automated workflows and privately hosted engines will be supported for some plans. There is a wait-list form on the website if you want to stay in the loop.

If you work in infosec / cyber security and are interested in being an early product designer / beta tester, let's chat! See my profile for how to get in touch.

If you're looking at going even deeper into SSH tunneling and port redirection, I recently made The Cyber Plumber's Handbook free: https://github.com/opsdisk/the_cyber_plumbers_handbook

I made it free to the HN community a few years back [1]. There is a paid interactive lab portion (details in the repo) if you are looking for hands-on experience.

Book Overview

This book is packed with practical and real world examples of SSH tunneling and port redirection in multiple realistic scenarios. It walks you through the basics of SSH tunneling (both local and remote port forwards), SOCKS proxies, port redirection, and how to utilize them with other tools like proxychains, nmap, Metasploit, and web browsers.

Advanced topics included SSHing through 4 jump boxes, throwing exploits through SSH tunnels, scanning assets using proxychains and Metasploit's Meterpreter, browsing the Internet through a SOCKS proxy, utilizing proxychains and nmap to scan targets, and leveraging Metasploit's Meterpreter portfwd command.

[1] https://news.ycombinator.com/item?id=19946941

I made this free to the HN community a few years back [1], but decided to make it available to everyone via a GitHub repo. There is a paid interactive lab portion (details in the repo) if you are looking for hands-on experience.

Book Overview

This book is packed with practical and real world examples of SSH tunneling and port redirection in multiple realistic scenarios. It walks you through the basics of SSH tunneling (both local and remote port forwards), SOCKS proxies, port redirection, and how to utilize them with other tools like proxychains, nmap, Metasploit, and web browsers.

Advanced topics included SSHing through 4 jump boxes, throwing exploits through SSH tunnels, scanning assets using proxychains and Metasploit's Meterpreter, browsing the Internet through a SOCKS proxy, utilizing proxychains and nmap to scan targets, and leveraging Metasploit's Meterpreter portfwd command.

[1] https://news.ycombinator.com/item?id=19946941

Article was perfect timing for me. The company I work at started one of these and I'm in the middle of trying to grow an idea/product. Great food for thought for long term strategy / positioning if it does go anywhere.