Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 36 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
Bypassing ftp password
EH-Net
May 19, 2013, 09:00:07 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
Bypassing ftp password
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Bypassing ftp password (Read 16075 times)
0 Members and 1 Guest are viewing this topic.
maksimu
Newbie
Offline
Posts: 3
Bypassing ftp password
«
on:
September 11, 2007, 11:39:38 AM »
Hi, I'm new in hacking. Actually I'm not a hacker I'm just taking security course in college and professor told us "If we can hack he's server and gain root access and add user then we'll get A in that class and don't have to show up anymore". :-\
So, can any body help me to figure out how to do that or just give me some suggestions about that.
I used NMap to scan he's IP and only FTP, SSH and HTTP ports are open.
So I was thinking to get that access through FTP. How Can I do that?
Here is professors IP: <modified>
«
Last Edit: September 11, 2007, 01:26:54 PM by don
»
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: Bypassing ftp password
«
Reply #1 on:
September 11, 2007, 01:30:36 PM »
The IP address you posted is public. Probably not a good idea to post that, especially if it has been purposely left open for your class to get in. So hope you don't mind that I removed it.
Speaking of which, try putting http://<removed ip address> in your browser and see what comes up. This will give you a clue on how to proceed.
Other than that, it wouldn't be fair if we got your A for you, now would it?
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
Negrita
Sr. Member
Offline
Posts: 299
Re: Bypassing ftp password
«
Reply #2 on:
September 11, 2007, 02:22:30 PM »
Hmmm... telnet can be so useful when you know how to get the most out of it.
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
maksimu
Newbie
Offline
Posts: 3
Re: Bypassing ftp password
«
Reply #3 on:
September 11, 2007, 02:30:35 PM »
Don, thank you for your reply.
Quote
Other than that, it wouldn't be fair if we got your A for you, now would it?
No, it is fair. Professor said that we can use any sources to do that. He'll give us an A if we can demonstrate it how we did it. (If you want, I can give you he's e-mail to prove it, but I think it is not necessary)
By the we on that server he's hosting he's own website, here is how you can get there:
http://<removed ip address>/~hlin/sec370.htm
I know that there is Red Hat linux and Apache server, but I don't know what I can use to do that.
Quote
Hmmm... telnet can be so useful when you know how to get the most out of it.
Telnet port is
closed
Logged
Negrita
Sr. Member
Offline
Posts: 299
Re: Bypassing ftp password
«
Reply #4 on:
September 11, 2007, 05:14:43 PM »
I wasn't talking about the port, I was talking about the protocol.
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
LSOChris
Guest
Re: Bypassing ftp password
«
Reply #5 on:
September 11, 2007, 06:21:03 PM »
i sent you a PM but for everyone else and since its for a class and for you to learn.
start with a FULL port scan and service version id of the IP
nmap -A x.x.x.x -p 1-65535
so things to look at would be what versions of SSH, FTP, and apache is the box running and what kernel version is it. that will help us get you started and help you narrow down your search for usable exploits.
-chris
Logged
EmanoN
Newbie
Offline
Posts: 41
Re: Bypassing ftp password
«
Reply #6 on:
September 12, 2007, 04:04:31 PM »
At least one person tried to answer his question rather than being vague or delete anything. Hacking FTP is very basic stuff. The very first thing you should do is see if you can log on anonymous. If not, try a few attempts to guess the password. If still no luck, try running a FTP password cracker. The only downside is you will be logged if there is any kind of security. If I am worried about hiding, then I run an nmap scan as previously mentioned to try and see what version of FTP is running. If its an older 3rd party software, I might be able to exploit it with a simple easy to find online exploit. If not, I might have to download a copy of the FTP program and Fuzz it myself, but we are getting a bit more advanced for the readers here I gather.
Logged
p0et
Full Member
Offline
Posts: 197
Re: Bypassing ftp password
«
Reply #7 on:
September 16, 2007, 12:34:37 AM »
Hey maksimu,
Looks like you've been given pretty good advise to get yourself started with this project of yours. You said you're new to this so I thought I would suggest you google for an exploit or vuln on whatever version of FTP, SSH, etc.. that you find through your nmap scan. You can also search with your results via Metasploit, mimlw0rm or a number of other exploit publishing sites.
Good luck!
Logged
GCIH, Security+, Network+, A+, MCP, DCSE
maksimu
Newbie
Offline
Posts: 3
Re: Bypassing ftp password
«
Reply #8 on:
September 22, 2007, 06:55:45 PM »
After scanning with NESSUS I found three holes in that System. Now I don't know how to use those holes to gain access.
Here is one hole (quotes from NESSUS report):
Quote
unknown (7101/tcp)
The remote X Font Service for TrueType (xfstt) might be vulnerable to a buffer
overflow which may lead to code execution or a denial of service.
An attacker may use this flaw to
gain root on this host
remotely
or prevent X11 from working properly.
Note that Nessus did not actually check for the flaw
so this might be a false positive
Solution: Upgrade to the latest version of xfstt
Risk Factor : High
So, what do I need to do to gain root access?
Thanks!
Logged
nitinceh
Newbie
Offline
Posts: 5
Re: Bypassing ftp password
«
Reply #9 on:
September 28, 2007, 03:33:50 PM »
Quote from: maksimu on September 11, 2007, 11:39:38 AM
Hi, I'm new in hacking. Actually I'm not a hacker I'm just taking security course in college and professor told us "If we can hack he's server and gain root access and add user then we'll get A in that class and don't have to show up anymore".
So, can any body help me to figure out how to do that or just give me some suggestions about that.
I used NMap to scan he's IP and only FTP, SSH and HTTP ports are open.
So I was thinking to get that access through FTP. How Can I do that?
Here is professors IP: <modified>
Dear,
you need to come out of the world of Security and Hacking, and have a look at exploits and developments of Shellcodes, also you can keep an eye on major 0-day vulnerabilities listings.
see, to make u understand better, it depends on what OS is running on the he's OS /PC/Server, then u also need the open ports, along with this u will need the most accurate Service information running on those specific open ports, now with armed with all this information , you can now start your hunt , since you are not into hacking, so you can try to search exploits or shellcodes for those services which are found running.
if you are a lucky one , you may find a couple or four, and then you can obtain a shell/root/admin/user privileges and if it is just user level rights, then u may need to escalate your privileges to that of an Admin/root.
Hope this will help you in understanding how to hack/get into he's computer/pc/server.
Thanks
Nitin Kushwaha
India
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(83) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(6) by
Grendel
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.