|
Title: Redirecting traffic Post by: hack_newbie on January 24, 2012, 02:19:17 AM Hi all.
I have read that windows 2003 server supports LM authentication for backward compatibility with older windows machine. In my lab setup, i have windows 2003 server, backtrack r4, and windows 98 and windows xp. Now the communication is genuine between 2003 server and windows xp but i need to redirect 2003 authentication to windows 98 so that passwords are sent in lm hashes rather than ntlm. This is hypothetical at this point. Before actually doing this setup, i just need to know am i thinking in the right direction ? can i sniff lm hashes using this way ? Title: Re: Redirecting traffic Post by: millwalll on January 24, 2012, 04:14:08 AM What are you trying to do ? Why are you trying to sniff the hashes ? are you not better to just attack the machine direct and then dump the hashes for cracking ?
Title: Re: Redirecting traffic Post by: 3xban on January 24, 2012, 08:27:03 AM Agree with Jamie, if you find a Windows 98 system still in a production environment there are many things you can do to it that are probably much easier than having to dump hashes. Shoot if password caching is enabled, I think Win98 stores them in plaintext.
You're average environment will be Windows 2003, Windows XP SP2/SP3. You will also see more Windows 2008 boxes. What you should also try and add to the lab is a Windows 7 system. Eventually enterprises will have to move to it and many are gearing up for that move. They will either go physical migrations or possibly using VDI solutions so they can maintain their legacy apps on XP. Title: Re: Redirecting traffic Post by: hack_newbie on January 25, 2012, 01:10:49 AM Dear Sir,
Sorry i think i wasnt able to explain properly. I dont have any win98 in my environment. See my assumptions (based on my research) 1) Windows 2003 server and windows xp are genuine machines that need to perform authentication (most likely ntlm) 2) I introduce windows 98 in between as MITM. 3) Now when win2003 needs to perform authentication with windows xp like this \\<windows-xp-ip> i want to redirect traffic to windows 98 so that authentication is now forced to LM, so that i can sniff the passwords. I hope its clear, kindly suggest now Title: Re: Redirecting traffic Post by: cd1zz on January 25, 2012, 08:33:10 AM Is this in your own lab? Are you just trying to sniff LM passwords? If so, why don't you just change the box to allow LM hashes? http://technet.microsoft.com/en-us/library/cc738867(WS.10).aspx
If you're practicing port forwarding, just use something like this: http://www.quantumg.net/portforward.php Title: Re: Redirecting traffic Post by: hack_newbie on January 26, 2012, 12:37:52 AM Dear Sir,
Port redirection is for MITM machine. what i am thinking is, the machine in between should redirect the traffic to another malicious machine. The link you forwarded will redirect from the destination, not from the MITM machine. Kindly correct me if i am wrong And yes this is for my lab setup
Powered by SMF 1.1.18 |
SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com |