Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 47 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 23, 2013, 02:26:34 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 [3] 4
31  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Pass-the-hash question on: November 13, 2009, 04:54:04 PM
This is capture I have gathered using smb module from s1
Code:
msf auxiliary(smb) > run
[*] Auxiliary module execution completed

[*] Server started.
msf auxiliary(smb) > [*] Captured 10.10.20.133:6252 victim LMHASH:000000000000000000000000000000000000000000000000 NTHASH:e4c33d3f1f2ef7952138d27242654f7a010100000000000029a52bd3b164ca013e2d8eb406b3f0d400000000020000000000000000000000 OS: LM:
[*] Captured 10.10.20.133:6252 victim LMHASH:000000000000000000000000000000000000000000000000 NTHASH:3a453950d098e9b59f88eaa5628bee520101000000000000f9ea2fd3b164ca0112a09ea79a0a637900000000020000000000000000000000 OS: LM:
[*] Captured 10.10.20.133:6252 victim LMHASH:000000000000000000000000000000000000000000000000 NTHASH:95782ca14bd78a4c70be953811709d71010100000000000098bb33d3b164ca01ae0245df301f235500000000020000000000000000000000 OS: LM:
[*] Captured 10.10.20.133:6252 victim LMHASH:000000000000000000000000000000000000000000000000 NTHASH:8ea08aa689958a547540711096d14aee0101000000000000680138d3b164ca0190afd31a5d8b575a00000000020000000000000000000000 OS: LM:
[*] Captured 10.10.20.133:6252 victim LMHASH:000000000000000000000000000000000000000000000000 NTHASH:aec3bb6e5d2f6f12bd83c0ef46a9e139010100000000000069bc3cd3b164ca015948d33cd527cce100000000020000000000000000000000 OS: LM:
[*] Captured 10.10.20.133:6252 victim LMHASH:000000000000000000000000000000000000000000000000 NTHASH:1ded841a3d184703ef5b115de99d8b3001010000000000004a2941d3b164ca0153d0e59769fe94de00000000020000000000000000000000 OS: LM:
[*] Captured 10.10.20.133:6252 victim LMHASH:000000000000000000000000000000000000000000000000 NTHASH:e8b28d52e979c73f8ef6e8d6dd00ec120101000000000000094845d3b164ca016abaf5dd251d583700000000020000000000000000000000 OS: LM:

You can see that for the same session (loading one page once) I gathered multiple NTLM hash values. And these values need "some processing" before getting the real NTLM hash
32  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Pass-the-hash question on: November 13, 2009, 04:24:21 PM
Thank you BillV.

I tried the sniffed hash with metasploit and and smbshell but it did not work. So I'm guessing it works only with pass-the-hash tool kit I have to try it with this tool though before I conclude.

Here is my environment if that can help.

I have one domain one (Name DC) workstation connect to the domain (Named W1) and one workstation that is in workgroup (s1). I also have an ubuntu version running metasploit 3.3rc1 and nessus 4.

I have cain and able installed on s1 and use it to sniff connections between DC and W1 and also between W1 and s1. The hashes I sniffed I used in metasploit and smbshell as mentioned before, but with not luck.

I tried running smb module in metasploit and had s1 connect to it via URL link with image source set as \\ubuntu\image\trick.gif. But I did not capture anything when I open the html page from s1.

Any idea? Did I do anything wrong?

Thanks in advance for the help.

33  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Pass-the-hash question on: November 12, 2009, 08:46:03 PM
Is it possible to use a sniffed hash for a connection between Windows XP station and Windows 2003 domain controller in pass-the-hash technique?

Or it is possible only if one used a tool like pass-the-hash tool kit on the Windows XP station, or had it authenticate to a station that is running metasploit smb module?

Thanks
34  Columns / Linn / Re: [Article]-Review: SANS SEC542 - Web App Penetration Testing and Ethical Hacking on: May 05, 2009, 11:38:54 PM
apollo,

Thanks much for answering my question! What you said makes a lot of sense. It made me consider taking this course soon.

I wonder how your writing will be before 12 am? Wink
35  Columns / Linn / Re: [Article]-Review: SANS SEC542 - Web App Penetration Testing and Ethical Hacking on: May 04, 2009, 12:25:54 PM
I'm interested in this course.

The review mentioned few times things like this:

A series of new tools were introduced throughout the day, each time discussing basic usage and then utilizing the tool to discuss one of the principles of recon.

One can learn basics from the man of each tool. Or books like this

The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws

So what else does this course give other than basic tools usage? Concepts explanations (for example) which is done very well in the book above.

Please note I pay for the training, not my employer and I don't have huge budget so I want to make sure that I get the max. value for the money I spend.

Thanks

36  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Debian Weak Keys Vuln. on: March 24, 2009, 11:48:42 AM
Thank you hunter for the input.
37  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Nmap version scanning results on: March 18, 2009, 10:31:25 PM
IPS no, ACLs yes.
38  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Nmap version scanning results on: March 17, 2009, 02:26:20 PM
me = baffled too Smiley
39  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Debian Weak Keys Vuln. on: March 17, 2009, 02:25:08 PM
The system was patch.

BTW there was/is no trust relationship between the client(any client) and this server.

Thank you all
40  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Nmap version scanning results on: March 17, 2009, 12:46:09 PM
Yes everytime I run nmap with -A against a set of machines, and with -sV against the same set.
41  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / BackTrack to the Max Cracking the Perimeter on: March 15, 2009, 04:15:51 PM
Did anyone here take this training?

What do you think of it?
42  Ethical Hacking Discussions and Related Certifications / GPEN - GIAC Certified Penetration Tester / Re: SANS 542: Build Your Own Army of Darkness: XSS Frameworks for Zombies and Profit on: March 13, 2009, 05:41:32 PM
Thank you Seth.
43  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Debian Weak Keys Vuln. on: March 13, 2009, 04:07:11 PM
Thanks everyone for your responses. The server is not in production (world accessiable), but it is in use internally. What I was/still wanted to know is how one will be able to attack it, if sniffing is not an option and 3 failed login will ban the IP.

Is there other kind of attacks against this vuln. that does not require brute forcing or sniffing?

I will patch the server anyways, but I'm trying to understand the visibility of the attack.

Thx.
44  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / RFI, could this be a false alarm? on: March 13, 2009, 09:14:13 AM
If a system does not have any scripting language installed, but IDS reports that this system is trying to attack a system behind an IDS using Remote File Inclusion, can I say the IDS is wrong and this is false positive?

thx
45  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Debian Weak Keys Vuln. on: March 13, 2009, 09:10:16 AM
Thank you guys. SSH is enable on the system, but no keys were generated, the system stores another system's key (Call sysA) now only sysA can call this system via SSH. I'm be wrong, but because of this I don't think the system is vulnerable.
Pages: 1 2 [3] 4
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.071 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.