Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 37 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Penetrating Xp Sp3
EH-Net
May 25, 2012, 01:32:07 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Penetrating Xp Sp3  (Read 7689 times)
0 Members and 1 Guest are viewing this topic.
brianW85428
Newbie
*
Offline Offline

Posts: 8


View Profile
« on: September 17, 2008, 04:50:23 PM »

Im starting to fall in love with The Ethical Hacker Network!  Grin
Okay here is my set up:

Host Operating system: Windows XP Sp3
Vmware Guest: Windows Xp Sp3
Vmware Guest: Backtrack 3

First, a question that is far over my head, im not sure if you can classify this as a question but here goes  Wink

When your trying to find vulnerabilitys, do you find them for the opearating system (sp3) or the programs that the OS is running? For instance, Would i try to exploit Windows or A program that is running? So if you cant exploit the operating system it self, you wouldnt be able to exploit a "Out of the box SP3?"

You may be wondering why im asking this question;
Well i really like to explore things, i love hacking, programming etc,
BUT im very determined to be ethical, (Truthfully is scares me to even test my own virtual machines)  Grin And i cant seem to hack anything on Sp3, so i tried finding a Windows 2000 ISO, turned out unsuccessful  Sad
Does anyone know were i can find one?   I have serached forever  Huh

=) Thanks in advance please feel free to ask any questions

Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3916


Editor-In-Chief


View Profile WWW
« Reply #1 on: September 17, 2008, 04:56:27 PM »

Awe... we're blushing.  Kiss

As for vulns... both.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
brianW85428
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #2 on: September 17, 2008, 05:05:55 PM »


As for vulns... both.

Don

Okay, so were searching for both types of vunerabilitys,
I know metasploit isnt going to have every single exploit know to man,
So were would i find exploits?
 Smiley
Thanks don
Logged
apollo
Full Member
***
Offline Offline

Posts: 142


View Profile WWW
« Reply #3 on: September 17, 2008, 06:20:08 PM »

That's a great question.  I usually look for exploits 3 places if I"m looking to find something fairly quickly.

The first place I look is metasploit.  If they have it, I check to make sure that my platform and revision numbers are good for the application and then I would try that.

The second place is http://www.milw0rm.com/.  milw0rm is searchable and is updated pretty frequently when people release public exploits.

The third place is securityfocus (http://www.securityfocus.com)  For there, you can search for vendor, product, and revision and then look for what type of vulnerability you need to exploit.  This is slightly more tedious.  If you are looking for remote exploits, just go through and look for the word remote in the title, that is normally a good way to do it, and then look on the exploit tab and see what's there.  Sometimes the exploits are crippled, so you may have to do some tweaking to get it to work.

Also, if you have some cash to drop, Immunity Canvas has a lot of good exploits and is a lot more point and click. 

As for finding an OS, this probably doesn't need to be said, but XP SP3 has all of the SP1 and 2 patches rolled into it, so it's not going to have as many goodies.  Your best bet, is to install XP and not any SPs.  That should pretty much be metasploit gold Smiley

Have fun, and remember that these exploits are sometimes noticable, so if you start learning to do this stuff on machines that aren't yours, you will probably get caught.

- Ryan
Logged

CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
NickFnord
Full Member
***
Offline Offline

Posts: 117



View Profile WWW
« Reply #4 on: September 18, 2008, 04:53:41 AM »

I'd highly recommend subscribing to the bugtraq mailing list - this is where a lot of new vulnerabilities get posted, and you'll see vulnerabilities that you may not understand - you can then go off and try to understand them by downloading a copy of the software in question and experimenting yourself.

But seeing as you're new, I'd strongly recommend following a tutorial or finding a program with an existing vulnerability and using it to understand what's going.

try this example of a buffer overflow vulnerability using a similar setup to what you have (I think I've linked to this one before in your previous thread - yes, I am Madirish.net fanboy).

It's a very easy to read tutorial for exploiting a known bug in an old version of an FTP server. 

You shouldn't be worried about attacking your own virtual machine - to start with you should be choosing your exploits for the sole purpose of understanding the process and the vulnerability - knowledge and discovery is the goal, not trashing your box.  and even if you do end up trashing it, just rebuild the VMware image.

If you want a learning path, try what I'm doing:  I've taken the course outline for the offensive security 101 course found here and am working through each module teaching myself as much as I can about different vulnerabilities and attack vectors. 

Don't forget, there's also non-network related attacks such as XSS and SQL injection that you can play arround with also - download a copy of SQL server and build yourself a simple ASP or php website and hack it!
Logged
Eth!cal
Newbie
*
Offline Offline

Posts: 10


View Profile
« Reply #5 on: September 18, 2008, 09:12:26 AM »

Hi ,

Try this
www.damnvulnerablelinux.org

try to download win2k 4 in 1
1.pro
2.server
3.Adv ser
4.data se
http://isohunt.com/torrent_details/46588796/Windows+2000?tab=summary

also i recommend  ( Build Y Own Security Lab: A Field Guide for Network Testing)  look at Amazon.com

Logged
toggmeister
Newbie
*
Offline Offline

Posts: 22


View Profile
« Reply #6 on: September 18, 2008, 02:12:05 PM »

As for other exploits, try:

Packetstormsecurity
w3af
Inguma

The latter two are great open-source frameworks, w3af for web apps (now windows installer), inguma (both os but easier to install on Linux) has a lot of oracle but also some general exploit stuff.

Hope this helps

Togg
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3916


Editor-In-Chief


View Profile WWW
« Reply #7 on: September 19, 2008, 02:29:32 PM »

You can check some of the latest news coming out of many of the sites suggested above using EH-Net's RSS News Feed Pase:

http://www.ethicalhacker.net/component/option,com_newsfeeds/catid,14/Itemid,27/

Hope this helps,
Don
Logged

CISSP, MCSE, CSTA, Security+ SME
sgt_mjc
Sr. Member
****
Offline Offline

Posts: 294


View Profile
« Reply #8 on: September 19, 2008, 03:40:47 PM »

Don't feel too bad with having problems getting in to XP Sp3, we're having problems with a clean NT box. Try any and all of the above. The first thing though is to identify even possible vulnerabilities. Once you wind them, start looking for one that will give you access to the root of the machine or other juicy pieces of info like a DB admin log-in. Have fun.
Logged

Mike Conway
CISSP
CompTia Security +
C|EH
LSOChris
Guest
« Reply #9 on: September 19, 2008, 09:01:32 PM »

i dont know of any remotes for SP3 but slap office 2003 on there and you have some vulnerabilities.
Logged
toggmeister
Newbie
*
Offline Offline

Posts: 22


View Profile
« Reply #10 on: September 20, 2008, 05:10:01 AM »

Further to ChrisG posts, slap a user on their with a profile not completely tied down and give them unfettered internet access. 

In my experience users are the worst applications you can ever install on a machine  Grin
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.427 seconds with 24 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.