Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 21 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow What to use?
Ethical Hacker Community Forums
December 03, 2008, 12:21:44 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: What to use?  (Read 2521 times)
0 Members and 1 Guest are viewing this topic.
danielsen2009
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: July 26, 2007, 12:34:16 AM »

Question.. Im at a school where novell is used to login to the file servers.. or used to gain access to school files. The security manager bet me I couldnt get on the network.. But I cracked the wep and I have access to internet and all (with firewall restrictions) I can get past those, but what i would like to do is get on the file servers. I can see then with an ip but my student id wont work... My friend a mac user actually managed to crash his mac.. or the network did. Our school has a reactive server. He attacked it so it attacked him. What would the best linux distro be to gain access to network files? or is there a way to emulate novell on a computer without installing it? I could partition my hdd to have a novell install but i dont want to do that... Help would be nice!
Logged
LegioX
Newbie
*
Offline Offline

Posts: 25


View Profile
« Reply #1 on: July 26, 2007, 02:27:02 AM »

Yeah, I'm not sure that this is a good idea... You should probably get written permission from the SysAdmin rather than accepting a 'bet'.
Logged

MCSE & MCSA : Security (2003), A+, Network+, Security+, CEH, CCNA, JNCIA-FMW
jimbob
Sr. Member
****
Offline Offline

Posts: 316



View Profile WWW
« Reply #2 on: July 26, 2007, 03:54:51 AM »

Yes, you should really follow LegioX' advice and get written permission before you do anything like this. There have been cases where people have been prosecuted (not always successfully mind you) for doing this kind of thing. I know I've pissed people off in the past by "hacking their unhackable box" when challenged and the loss of good will can also be damaging. As always, the best tool you have is your brain. Ethical hackers need to think outside off the box and the simplest way is usually the best.

I need to stress that I AM NOT SANCTIONING THIS ACTIVITY, but the simplest and I hope most educational way for the sysadmin in question would be to access a terminal he's logged into. Maybe wait for him to log in and offer to buy him a soda if he goes to fetch them (great social engineering trick). You'll probably have admin access to the file servers so plant your flag, wait for a day and then tell them you got in. Patience is an important factor since when you tell him you got in he'll sweat bullets wondering what crazy hack you used. When he finds out he'll either;

a) get mad accuse you of cheating on the bet. (Yeah, people still don't accept social engineering as a hack. That's why it's so successful).
b) have a moment of revelation and realise that he is the weakest link.

I hope this has made you think beyond using technological tools to solve your security problem. My advice is not to do this at all. If you like why not pull the social engineering trick and when the admin returns let him know of his mistake straight off and suggest he pay for the soda instead. People are proud and he might find losing the bet humiliating so meet the bet half way and claim your free soda. Remember, keep your friends close and you sysdamins closer.

Jim
Logged
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 365



View Profile WWW
« Reply #3 on: July 26, 2007, 08:14:31 AM »

Jimbob

I love your ideas and the thinking out side of the box.

Brian
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
danielsen2009
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #4 on: July 26, 2007, 01:00:12 PM »

Ok, ill get written permission, I just installed Novell on my comp. I talked to him and got the server info to login, but what he dosent know is that my novell dosent have all the restrictions that the school computers do, Thanks for your replies! I could have gotten in trouble... well i still can but now i have a piece of paper saying its not my fault.
Logged
kyrow
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #5 on: November 15, 2007, 04:49:37 AM »

Jimbob, you are some kind of god, haha, nice trick.
Logged
dannioni
Newbie
*
Offline Offline

Posts: 44


View Profile
« Reply #6 on: November 16, 2007, 08:25:09 AM »

Great source of inspiration jimbob Tongue
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.045 seconds with 22 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.