Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 18 guests online
EH-Net Donations

Enter Amount:
$

EH-Net News Feeds
Latest Additions
Google Ads
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow CEH - Certified Ethical Hackerarrow CEH - Official Course Modules v4arrow CEH Study Group -- Module 5: System Hacking
EH-Net
March 19, 2010, 01:37:39 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: CEH Study Group -- Module 5: System Hacking  (Read 6962 times)
0 Members and 1 Guest are viewing this topic.
Oyle
Moderator
Sr. Member
*****
Offline Offline

Posts: 264


"Man. Nature. Technology".


View Profile WWW
« on: April 05, 2006, 01:35:42 PM »

Module Objectives:

* Understand the Following:
Remote Password Guessing
Eavsedropping
Denial of Service
Buffer Overflows Need to know for exam!
Privilege escalation
Password Cracking
keystroke loggers
sniffers
Remote control and backdoors
Port redirection
Covering tracks
hiding files

Module V pg.1
Logged

MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".

From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
                  -Tapeworm
Oyle
Moderator
Sr. Member
*****
Offline Offline

Posts: 264


"Man. Nature. Technology".


View Profile WWW
« Reply #1 on: June 24, 2006, 01:08:31 PM »



====System Hacking====

•   Assuming that NetBIOS TCP port 139 is open, the most effective method of breaking into NT/2000 is password guessing.
•   Attempting to connect to an enumerated share (IPC$ or C$) and trying to guess username/password.
•   Default admin$, C$, or %Systemdrive% shares are a good starting place.

If an attacker fails in a manual attack, he can choose to automate the task. There are several free programs that can do this, including Legion, Jack the Ripper, NetBIOS Auditing Tool (NAT; do not confuse with Network Address Translation), and L0phtcrack, (LC4) among them.
The simplest of these automation methods take advantage of the NET command line utility. This involves a simple loop using the NT4/2000 command shell. All the attacker has to do is to create a simple username and password file. He can then pipe this file into a FOR command.

C:\>FOR /F “token=1,2*”%i in (credentials.txt)
Do net use \\target\IPC$ %i /u: %j

Automated password attacks can be divided into two basic categories, dictionary attacks and brute force attacks.
•   A simple dictionary attack involves loading a dictionary file (a text file full of dictionary words) into a cracking application such as L0pthcrack or John the Ripper, and running it against user accounts loaded by the application. The larger the word and word fragment selection, the more effective the dictionary attack.
•   The brute force method is the most inclusive – though slow. Usually, it tries every possible letter and number combination in its automated exploration. 
•   A hybrid approach is one which combines features of both the methods mentioned above. It usually starts with a dictionary and then tries combinations such as two words together or a word and numbers. 
Logged

MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".

From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
                  -Tapeworm
Dr.VaMpIrE
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #2 on: May 25, 2007, 06:18:31 PM »

 Grin THANX
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.058 seconds with 27 queries.
 
Polls
Best Career Move in 2010:
 
Support EH-Net

eh-net_amazonstore.jpg
Help Support EH-Net with Our Amazon Store


cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2010 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.