Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

1.You are given permission to use your credentials to run some basic security ch

ID: 3916553 • Letter: 1

Question

1.You are given permission to use your credentials to run some basic security checks on the Alexander Rocco domain. You don’t have access to Nessus or OpenVAS, so you have to use other tools to enumerate the domain. After some research, you come across the enum4linux tool. To make sure your boss is okay with this tool, you need to tell him why you want to use enum4linux and what it’s capable of. Write a one-page memo on the enum4linux tool in which you describe the goal of your enumeration and the checks available in enum4linux. Your memo should persuade your boss into letting you use the tool for enumeration purposes.

2.Many network administrators are aware of security problems but fail to properly configure their networks and systems. What can be done to facilitate secure operating system configurations?

3.After conducting enumeration of the Alexander Rocco network, you discover several Windows computers with shared folders for the Help Desk Depart- ment. You’re concerned when you access one of the shared folders containing information for help desk personnel and find an Excel spreadsheet listing e-mail addresses and passwords for all employees. Help desk employees use this shared folder to access the Excel spreadsheet if users call saying they have forgotten their passwords and need this information even when they’re away from their offices. Based on this information, write a one-page memo to the IT manager, Donald Lee, describing the steps you would take after this discovery. The memo should also mention any information you find in the OSSTMM that relates to your discovery and offer recommendations.

Explanation / Answer

Please Note: As per Chegg Answering Guidelines, I have answered the first question. Please Post Separate for Separate Questions.

Q1) Answer)

Working in the we need to use the credentials to run some basic security checks on the Alexander Rocco domain. As we don't have access to the Nessus or OpenVAS,

so we have to use other tools to enumerate the domain. One such tool is enum4linux which allows enumerating information from the Windows and Samba machines and thus we can use this for our purpose. The enum4linux tool allows the user to:

RID cycling

User listing

Listing of the group member’s info

Sharing the enumeration once done

Looking at the host and determining whether it is a workgroup or a domain

Remote OS identification

And also, password policy checks, on the system for Alexander Rocco domain.

This enum4linux tool can be used by us thus without any problems to enumerate the machines in Windows or Samba and this should permit the boss to let you use the tool for enumeration purposes.