Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 20 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow CEH - Certified Ethical Hackerarrow CEH - Official Course Modules v4arrow CEH Study Group -- Module 5: System Hacking
Ethical Hacker Community Forums
November 23, 2008, 02:17:01 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: CEH Study Group -- Module 5: System Hacking  (Read 4513 times)
0 Members and 1 Guest are viewing this topic.
Oyle
Moderator
Sr. Member
*****
Offline Offline

Posts: 264


"Man. Nature. Technology".


View Profile WWW
« on: April 05, 2006, 01:35:42 PM »

Module Objectives:

* Understand the Following:
Remote Password Guessing
Eavsedropping
Denial of Service
Buffer Overflows Need to know for exam!
Privilege escalation
Password Cracking
keystroke loggers
sniffers
Remote control and backdoors
Port redirection
Covering tracks
hiding files

Module V pg.1
Logged

MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".

From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
                  -Tapeworm
Oyle
Moderator
Sr. Member
*****
Offline Offline

Posts: 264


"Man. Nature. Technology".


View Profile WWW
« Reply #1 on: June 24, 2006, 01:08:31 PM »



====System Hacking====

•   Assuming that NetBIOS TCP port 139 is open, the most effective method of breaking into NT/2000 is password guessing.
•   Attempting to connect to an enumerated share (IPC$ or C$) and trying to guess username/password.
•   Default admin$, C$, or %Systemdrive% shares are a good starting place.

If an attacker fails in a manual attack, he can choose to automate the task. There are several free programs that can do this, including Legion, Jack the Ripper, NetBIOS Auditing Tool (NAT; do not confuse with Network Address Translation), and L0phtcrack, (LC4) among them.
The simplest of these automation methods take advantage of the NET command line utility. This involves a simple loop using the NT4/2000 command shell. All the attacker has to do is to create a simple username and password file. He can then pipe this file into a FOR command.

C:\>FOR /F “token=1,2*”%i in (credentials.txt)
Do net use \\target\IPC$ %i /u: %j

Automated password attacks can be divided into two basic categories, dictionary attacks and brute force attacks.
•   A simple dictionary attack involves loading a dictionary file (a text file full of dictionary words) into a cracking application such as L0pthcrack or John the Ripper, and running it against user accounts loaded by the application. The larger the word and word fragment selection, the more effective the dictionary attack.
•   The brute force method is the most inclusive – though slow. Usually, it tries every possible letter and number combination in its automated exploration. 
•   A hybrid approach is one which combines features of both the methods mentioned above. It usually starts with a dictionary and then tries combinations such as two words together or a word and numbers. 
Logged

MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".

From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
                  -Tapeworm
Dr.VaMpIrE
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #2 on: May 25, 2007, 06:18:31 PM »

 Grin THANX
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.042 seconds with 25 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.