Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 22 guests and 2 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Pentesting Server
EH-Net
May 26, 2013, 03:56:39 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Pentesting Server
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Pentesting Server (Read 9106 times)
0 Members and 1 Guest are viewing this topic.
jonas
Newbie
Offline
Posts: 46
Pentesting Server
«
on:
May 10, 2010, 09:06:18 AM »
Hi again guys.
I'm doing a pentest (for edu purposes) on a single company server, and I'm stuck...
After doing my research using nmap, amap, nessus, nikto2 etc i've found this:
OS: Windows Server 2003
22: SSH(2) Not sure which sshd.
25: SMTP (xxxx.domain.local)
53: DNS
80: HTTP (IIS6-SP1, SSL2, Not hosting any websites that i know of)
113(Closed): IDENT
389: LDAP (Nothing found mining...)
443: HTTPS (SSL from digicert.com)
444: SNPP (Found Fortinet/Fortigate firewall)
3389: MS-TERM (v4)
Internal IP found: 10.10.147.11
I found no exploits for the services (Im sure they exist...). The only thing i can think of atm is bruteforcing or fuzzing the SSH server.
Trojans, on-site (wlan), socialEng etc is out of the question. Just direct targeting remotely. Any thoughts on how to proceed, except bruteforcing which is kinda loud...
ps: All testing is done with "safe-checks" as they wouldnt be so happy if any services went down...
Thx guys.
«
Last Edit: May 10, 2010, 09:11:49 AM by jonas
»
Logged
bamed
Newbie
Offline
Posts: 48
Re: Pentesting Server
«
Reply #1 on:
May 10, 2010, 11:39:08 AM »
First of all, I'm going to assume you're doing this with permission, otherwise you're in the wrong place. Secondly, you said they "wouldnt be so happy if any services went down...". Sounds like you shouldn't be playing with this server even with permission. Setup a test server if you're just trying to learn. You shouldn't be learning on live in-production servers. Nothing good can come from it.
Maybe you can clone the system, or use some P2V tools to create a virtual copy of it?
Then you can be as aggressive as you want without worrying about shutting anything down, and you won't crash anything unknowingly and thus bring down the wrath of your employer.
Logged
chown -R bamed ./base
jonas
Newbie
Offline
Posts: 46
Re: Pentesting Server
«
Reply #2 on:
May 10, 2010, 11:54:00 AM »
Yeah, i usually setup VMware environments, but then i know everything about it. The reason im doing this "live" is because i don't have any knowledge about the system. And yes, im allowed to test on this server. They have multiple servers, but im restricted to this IP only. Which kinda sux a little bit because there is no proper FTP or WEB service running on this one. =)
If the services is down i can restart them (i have remote access, logmein), but its still a live server so im guessing its not that popular anyways...
I'd appreciate some concrete "actions" here instead of doubting my intensions =)
Logged
bamed
Newbie
Offline
Posts: 48
Re: Pentesting Server
«
Reply #3 on:
May 10, 2010, 12:13:37 PM »
jonas,
I mean no offense, I just don't think practicing on a live server is a great idea.
At any rate, I think you still need to do some more recon. What SMTP server is running? Can you connect to it and enumerate any usernames? Some info on that process can be found at
http://forums.remote-exploit.org/tutorials-guides/19158-smtp-enumeration.html
.
I'd also spend some more time trying to figure out what SSH server is running. SSH is not a normal service for a Windows Server, so finding out which server could help...
Those are the things that come to mind. I'm sure others might have more suggestions.
Logged
chown -R bamed ./base
chrisj
Hero Member
Offline
Posts: 1163
Re: Pentesting Server
«
Reply #4 on:
May 10, 2010, 12:18:04 PM »
might try telneting to the ports and seeing if you get any banner information from them. Might help in finding out what programs are running the open services.
Logged
OSWP, Sec+
ziggy_567
Sr. Member
Offline
Posts: 361
Re: Pentesting Server
«
Reply #5 on:
May 10, 2010, 01:47:12 PM »
I would also add that if they are serving DNS, SMTP, HTTP from the same host, they are not following best-practices of having a single purpose per server. It is likely that you will find misconfigurations in an environment like this.
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
Dengar13
Sr. Member
Offline
Posts: 380
Re: Pentesting Server
«
Reply #6 on:
May 10, 2010, 02:08:56 PM »
This might be a dumb question, but are you testing this internally or externally? I am assuming externally since you said you found an internal IP address.
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
snortymcsnort
Newbie
Offline
Posts: 17
Re: Pentesting Server
«
Reply #7 on:
May 10, 2010, 03:11:07 PM »
If you use the -A option with nmap you may get a better idea of which specific applications/versions are running
Logged
jonas
Newbie
Offline
Posts: 46
Re: Pentesting Server
«
Reply #8 on:
May 10, 2010, 03:12:38 PM »
Thx for the feedback everybody.. I'll look at it ASAP. Dengar13, externally. If i wasnt at school (in another country) i would jump in the car cracking the wep encryption they are still using, and then its pretty straight forward =)
I found the internal IP due to a flaw in .asp. Make that misconf...
Logged
bamed
Newbie
Offline
Posts: 48
Re: Pentesting Server
«
Reply #9 on:
May 10, 2010, 03:18:02 PM »
If you're scanning externally, there's a chance you aren't directly scanning a Windows server. It looks like you're actually scanning a firewall appliance, and certain ports are forwarded to internal servers. So SSH could be the appliance, or an internal server. IIS is on the Windows Server. etc.
Logged
chown -R bamed ./base
jonas
Newbie
Offline
Posts: 46
Re: Pentesting Server
«
Reply #10 on:
May 10, 2010, 03:46:08 PM »
Yeah. Just noticed. SSH port OS guess was 97% Fortigate100-A... (Which i know is true...) Seems like I'm hitting the firewall..
Edit: Bamed: That SMTP enumeration, will it fuck anything up? Looking at the python script it looks like regular string input, but now, im not an expert.
«
Last Edit: May 10, 2010, 03:53:15 PM by jonas
»
Logged
Equix3n-
Sr. Member
Offline
Posts: 386
Re: Pentesting Server
«
Reply #11 on:
May 10, 2010, 10:13:31 PM »
You don't have to use script. You can do this manually using VRFY and EXPN commands. It would be better if you firstly try the script in your test lab before actually using it on a company machine.
Logged
sil
Hero Member
Offline
Posts: 549
Re: Pentesting Server
«
Reply #12 on:
May 10, 2010, 10:21:15 PM »
Quote from: jonas on May 10, 2010, 03:12:38 PM
If i wasnt at school (in another country) i would jump in the car cracking the wep encryption they are still using, and then its pretty straight forward =)
For starters, you state go to school but your pentesting a server for a company
in another country
. So how would you even know what type of wireless encryption they're using? Sounds pretty fishy if you ask me. Hey if you can get the work more power to you but I can't think of a reputable company that would allow a student to fiddle with production servers.
Secondly, your writing leads me to believe you're very inexperienced. A pentest - remotely - is usually an indication of a grey hat / black hat test most likely a blackhat since you have no idea what you're targeting (is it Windows or is it Fortinet).
With that said, a blackhat is a blackhat is a blackhat. Brute forcing would be optimal way to go on THAT machine. There are alternative mechanisms to allow for non-noisy brute forcing with timing variables. Chances are (I would hope), whomever configured the Fortinet, configured it to solely allow trusted sites to SSH in so unless you can even ATTEMPT ONCE to log in, your SOL.
In that case I would... Not go further into telling you what I would do because as stated, some things in your initial post just don't add up.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
jonas
Newbie
Offline
Posts: 46
Re: Pentesting Server
«
Reply #13 on:
May 11, 2010, 08:19:47 AM »
I don't even know why i bother.. But for starters, Im from norway, but i moved abroad 1 year ago to study, hence the company is in another country -> norway. And you think i magically know what wireless encryption they are using? No, i've been there with the it-consultant in charge, which i did some work for setting up SMB networks. "Fiddling" with production servers is up until now just information gathering, so please get over it. Im asking on this forum to learn, not get criticized. If everybody were experts you wouldn't need a forum. Im just looking for constructive criticism to learn, thats all. And yeah, I am allowed to establish a SSH connection and try to log in.
If i wanted to do some shit, i'd steal a car...
Edit: And yes, i was allowed just for education purposes as stated earlier. I remember to ask for a contract next time and send you with their signature.
«
Last Edit: May 11, 2010, 08:53:19 AM by jonas
»
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: Pentesting Server
«
Reply #14 on:
May 11, 2010, 08:54:45 AM »
Me, I believe you jonas.
But if you start reading the other threads, you will see that many newcomers are trying to get help on how to do bad stuff and no one here wants to be part of that...
That being said, have fun and brute force these services!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Calendar Of Events
: Cyber Readiness Challenge - Prague, CZ
(3) by
VeifyVido
News Items and General Discussion About EH-Net
: Салют фанаты
(6) by
VeifyVido
General Certification
: Security Tube Python Scripting Expert - Community content?
(1) by
VeifyVido
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(95) by
zeebee
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.