Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 35 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 23, 2013, 02:35:12 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Got in over my head trying to help my school, anyone want to give me guidance? on: May 01, 2010, 08:20:12 PM
Personally to me ethics is ends before the means, however if the "ethical" hacker network is really just a bunch of people who look at studies the back to hackforums.net I go, where at least I can get help.
2  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Got in over my head trying to help my school, anyone want to give me guidance? on: May 01, 2010, 07:05:29 PM
This is my first post on ethical hacker network and I hope to become an active member of the communtiy, but please don't flame me if my question is "n00bish" I am still in the process of learning offensive security and could really use help here.

Basically I am trying to convince the administrators at my school to switch the wifi security protocol from WEP to WPA, however they are reluctant to do so and claim it does not need to be done. Even after demonstrating how the password can be stolen they seem to think it doesn't matter if some random person hacks into our network. I wan't to prove them wrong.

I noticed when running a basic IP scan that we have networked security camera's...hehehe *evil look* and I was thinking that a good way to give them a lasting impression would to be to demonstrate how a hacker could gain access to the school's security system on acount of a weak password to the Wifi. Here are the details:

I found the config page for the Dibos cameras at the local ip:
10.1.1.22
Navigating there in a browser gives me something that looks like this (note this is not the page but one I found on someone else's site)
http://209.3.146.51/
*It requires IE to view*

I also found that there was a DIBOS-[lotsofnumbersandletters] workgroup on the network but when trying to "explore" that workgroup it asked for a username and password, it did not work.

I have local admin access on *some* machines with the help of ophcrack, but they seem to not be able to find the workgroup and the 10.1.1.22 page is no different from an admin account

Also, our school keeps a "remote access" citrix client running from which I can run remote-desktop and get onto one of the few local machines that have RDP enabled, from there I can see the Dibos workgroup but cannot access it, however I am a weak user on these remote computers and can't even run Cain and Abel or extract the SAM files with pwdump.

Additionally, I suspect that the Network admin account password is the same as that for the Dibos, the issue is that I don't know how to get the Network admin account although like i previously mentioned I have local admin on a few machines.

Also, I have been using an anonymous e-mail address to communicate with the administration and would like to remain unknown for a while longer so that they don't just put all kinds of security on my user account or pay particular attention to me in the future, thus if it is possible to remain invisible that would also be ideal.

Finally, I understand that the information that you post here may be used for less noble purposes and if you would prefer to PM me your advice rather than post it here than please do so.

Thanks and I look forward to being part of The Ethical Hacker Network,
Javap22
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.072 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.