Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 18 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Penetrating Xp Sp3
Ethical Hacker Community Forums
January 08, 2009, 01:07:29 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Penetrating Xp Sp3  (Read 3028 times)
0 Members and 1 Guest are viewing this topic.
brianW85428
Newbie
*
Offline Offline

Posts: 8


View Profile
« on: September 17, 2008, 04:50:23 PM »

Im starting to fall in love with The Ethical Hacker Network!  Grin
Okay here is my set up:

Host Operating system: Windows XP Sp3
Vmware Guest: Windows Xp Sp3
Vmware Guest: Backtrack 3

First, a question that is far over my head, im not sure if you can classify this as a question but here goes  Wink

When your trying to find vulnerabilitys, do you find them for the opearating system (sp3) or the programs that the OS is running? For instance, Would i try to exploit Windows or A program that is running? So if you cant exploit the operating system it self, you wouldnt be able to exploit a "Out of the box SP3?"

You may be wondering why im asking this question;
Well i really like to explore things, i love hacking, programming etc,
BUT im very determined to be ethical, (Truthfully is scares me to even test my own virtual machines)  Grin And i cant seem to hack anything on Sp3, so i tried finding a Windows 2000 ISO, turned out unsuccessful  Sad
Does anyone know were i can find one?   I have serached forever  Huh

=) Thanks in advance please feel free to ask any questions

Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2435


Editor-In-Chief


View Profile WWW
« Reply #1 on: September 17, 2008, 04:56:27 PM »

Awe... we're blushing.  Kiss

As for vulns... both.

Don
Logged

CISSP, MCSE, CEH, Security+ SME
brianW85428
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #2 on: September 17, 2008, 05:05:55 PM »


As for vulns... both.

Don

Okay, so were searching for both types of vunerabilitys,
I know metasploit isnt going to have every single exploit know to man,
So were would i find exploits?
 Smiley
Thanks don
Logged
apollo
Jr. Member
**
Offline Offline

Posts: 51


View Profile WWW
« Reply #3 on: September 17, 2008, 06:20:08 PM »

That's a great question.  I usually look for exploits 3 places if I"m looking to find something fairly quickly.

The first place I look is metasploit.  If they have it, I check to make sure that my platform and revision numbers are good for the application and then I would try that.

The second place is http://www.milw0rm.com/.  milw0rm is searchable and is updated pretty frequently when people release public exploits.

The third place is securityfocus (http://www.securityfocus.com)  For there, you can search for vendor, product, and revision and then look for what type of vulnerability you need to exploit.  This is slightly more tedious.  If you are looking for remote exploits, just go through and look for the word remote in the title, that is normally a good way to do it, and then look on the exploit tab and see what's there.  Sometimes the exploits are crippled, so you may have to do some tweaking to get it to work.

Also, if you have some cash to drop, Immunity Canvas has a lot of good exploits and is a lot more point and click. 

As for finding an OS, this probably doesn't need to be said, but XP SP3 has all of the SP1 and 2 patches rolled into it, so it's not going to have as many goodies.  Your best bet, is to install XP and not any SPs.  That should pretty much be metasploit gold Smiley

Have fun, and remember that these exploits are sometimes noticable, so if you start learning to do this stuff on machines that aren't yours, you will probably get caught.

- Ryan
Logged
NickFnord
Newbie
*
Offline Offline

Posts: 47



View Profile WWW
« Reply #4 on: September 18, 2008, 04:53:41 AM »

I'd highly recommend subscribing to the bugtraq mailing list - this is where a lot of new vulnerabilities get posted, and you'll see vulnerabilities that you may not understand - you can then go off and try to understand them by downloading a copy of the software in question and experimenting yourself.

But seeing as you're new, I'd strongly recommend following a tutorial or finding a program with an existing vulnerability and using it to understand what's going.

try this example of a buffer overflow vulnerability using a similar setup to what you have (I think I've linked to this one before in your previous thread - yes, I am Madirish.net fanboy).

It's a very easy to read tutorial for exploiting a known bug in an old version of an FTP server. 

You shouldn't be worried about attacking your own virtual machine - to start with you should be choosing your exploits for the sole purpose of understanding the process and the vulnerability - knowledge and discovery is the goal, not trashing your box.  and even if you do end up trashing it, just rebuild the VMware image.

If you want a learning path, try what I'm doing:  I've taken the course outline for the offensive security 101 course found here and am working through each module teaching myself as much as I can about different vulnerabilities and attack vectors. 

Don't forget, there's also non-network related attacks such as XSS and SQL injection that you can play arround with also - download a copy of SQL server and build yourself a simple ASP or php website and hack it!
Logged
Eth!cal
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #5 on: September 18, 2008, 09:12:26 AM »

Hi ,

Try this
www.damnvulnerablelinux.org

try to download win2k 4 in 1
1.pro
2.server
3.Adv ser
4.data se
http://isohunt.com/torrent_details/46588796/Windows+2000?tab=summary

also i recommend  ( Build Y Own Security Lab: A Field Guide for Network Testing)  look at Amazon.com

Logged
toggmeister
Newbie
*
Offline Offline

Posts: 22


View Profile
« Reply #6 on: September 18, 2008, 02:12:05 PM »

As for other exploits, try:

Packetstormsecurity
w3af
Inguma

The latter two are great open-source frameworks, w3af for web apps (now windows installer), inguma (both os but easier to install on Linux) has a lot of oracle but also some general exploit stuff.

Hope this helps

Togg
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2435


Editor-In-Chief


View Profile WWW
« Reply #7 on: September 19, 2008, 02:29:32 PM »

You can check some of the latest news coming out of many of the sites suggested above using EH-Net's RSS News Feed Pase:

http://www.ethicalhacker.net/component/option,com_newsfeeds/catid,14/Itemid,27/

Hope this helps,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
sgt_mjc
Full Member
***
Offline Offline

Posts: 166


View Profile
« Reply #8 on: September 19, 2008, 03:40:47 PM »

Don't feel too bad with having problems getting in to XP Sp3, we're having problems with a clean NT box. Try any and all of the above. The first thing though is to identify even possible vulnerabilities. Once you wind them, start looking for one that will give you access to the root of the machine or other juicy pieces of info like a DB admin log-in. Have fun.
Logged

Mike Conway
CompTia Security +
C|EH
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #9 on: September 19, 2008, 09:01:32 PM »

i dont know of any remotes for SP3 but slap office 2003 on there and you have some vulnerabilities.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
toggmeister
Newbie
*
Offline Offline

Posts: 22


View Profile
« Reply #10 on: September 20, 2008, 05:10:01 AM »

Further to ChrisG posts, slap a user on their with a profile not completely tied down and give them unfettered internet access. 

In my experience users are the worst applications you can ever install on a machine  Grin
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.055 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.