Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 48 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow brute force with bounce attack ?!
EH-Net
May 21, 2013, 01:41:38 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: brute force with bounce attack ?!  (Read 6742 times)
0 Members and 1 Guest are viewing this topic.
rebrov
Full Member
***
Offline Offline

Posts: 130



View Profile
« on: July 25, 2010, 06:35:54 AM »

i want to know how to brute force or crack telnet passwords or watever FTP even with bounce proxy attack ..whether its LAN attack or WAN connection attack

and if its LAN attack with bounce proxy ...will it be appear like it coming from WAN Huh

Logged
Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« Reply #1 on: July 27, 2010, 05:23:55 AM »

Can you explain it more clearly? I'm not able to understand what you really mean.
Logged
yatz
Full Member
***
Offline Offline

Posts: 222


View Profile WWW
« Reply #2 on: July 27, 2010, 11:09:29 AM »

Two things-

In a "bounce attack," you need to have access to an FTP site first.  Basically you connect into an FTP server and then use that server to execute your brute force attack.  A flaw in the FTP design allows arbitrary communication from one connection so you cannot be detected without the FTP server being traced first.

Secondly, this theoretically is the same as using netcat relays.  Just set up a relay and then execute your brute force attack at the relay.

Does this make sense?
Logged

"Live as though you would die tomorrow, learn as though you would live forever."

CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
yatz
Full Member
***
Offline Offline

Posts: 222


View Profile WWW
« Reply #3 on: July 27, 2010, 12:36:05 PM »

Also, here is the metasploit module that lets you scan using ftp bounce

http://www.metasploit.com/modules/auxiliary/scanner/portscan/ftpbounce

Seems pretty simple.  There also seems to be an nmap option for this as well.
Logged

"Live as though you would die tomorrow, learn as though you would live forever."

CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
rebrov
Full Member
***
Offline Offline

Posts: 130



View Profile
« Reply #4 on: July 28, 2010, 06:24:07 PM »

Two things-

In a "bounce attack," you need to have access to an FTP site first.  Basically you connect into an FTP server and then use that server to execute your brute force attack.  A flaw in the FTP design allows arbitrary communication from one connection so you cannot be detected without the FTP server being traced first.

Secondly, this theoretically is the same as using netcat relays.  Just set up a relay and then execute your brute force attack at the relay.

Does this make sense?

yes make sense ..however Smiley

with netcat relays u need to penetrate pc first and setup netcat relay on this machine right ??

what i mean is not to scan like that NMAP options with FTP bounce i know this one and not that option in METASPLOIT

but

i mean that option in hydra ....hydra can crack telnet and ftp and smtp via FTP bounce right ??

but i can't find open FTP servers to do that and if i found secure 1 still the tracing will be easy because its just 1 server

not like chains of proxies and thats what i meant

1st - where can i find open FTP server to try this ?
2nd - is there a way to cracking via chains of proxies
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #5 on: July 28, 2010, 08:45:50 PM »

I'm not sure where you're looking for these FTP servers to test this with, but you should just set this up in your own test lab. I don't know of any FTP servers/versions off the top of my head, but you should be able to find some with a little Googling. Keep in mind that this a pretty old attack, so it's going to (should) be remedied in current FTP servers. Finding this has been very rare in my personal experience.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
ziggy_567
Sr. Member
****
Offline Offline

Posts: 361


View Profile
« Reply #6 on: July 29, 2010, 08:32:37 AM »

Most FTP servers should have remedied this, but you can often accomplish this method with network printers...
Logged

--
Ziggy


eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
rebrov
Full Member
***
Offline Offline

Posts: 130



View Profile
« Reply #7 on: July 29, 2010, 05:02:08 PM »

i know its old attack but its stealthy ...then do u have the backup attack Smiley

the problem is i dont know how to use chain proxies instead of FTP to brute force or dic attack specified telnet so the crackign method wont show as from my ip
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.57 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.