Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 47 guests and 3 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow General Certificationarrow OSarrow Redirecting traffic
EH-Net
May 22, 2013, 06:23:20 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Redirecting traffic  (Read 7029 times)
0 Members and 1 Guest are viewing this topic.
hack_newbie
Newbie
*
Offline Offline

Posts: 9


View Profile
« on: January 24, 2012, 02:19:17 AM »

Hi all.

I have read that windows 2003 server supports LM authentication for backward compatibility with older windows machine. In my lab setup, i have windows 2003 server, backtrack r4, and windows 98 and windows xp. Now the communication is genuine between 2003 server and windows xp but i need to redirect 2003 authentication to windows 98 so that passwords are sent in lm hashes rather than ntlm. This is hypothetical at this point. Before actually doing this setup, i just need to know am i thinking in the right direction ? can i sniff lm hashes using this way ?
Logged
millwalll
Guest
« Reply #1 on: January 24, 2012, 04:14:08 AM »

What are you trying to do ? Why are you trying to sniff the hashes ? are you not better to just attack the machine direct and then dump the hashes for cracking ?
Logged
3xban
Hero Member
*****
Offline Offline

Posts: 608


View Profile WWW
« Reply #2 on: January 24, 2012, 08:27:03 AM »

Agree with Jamie, if you find a Windows 98 system still in a production environment there are many things you can do to it that are probably much easier than having to dump hashes.  Shoot if password caching is enabled, I think Win98 stores them in plaintext. 

You're average environment will be Windows 2003, Windows XP SP2/SP3.  You will also see more Windows 2008 boxes.  What you should also try and add to the lab is a Windows 7 system.  Eventually enterprises will have to move to it and many are gearing up for that move.  They will either go physical migrations or possibly using VDI solutions so they can maintain their legacy apps on XP. 

Logged

Certs: GCWN
(@)Dewser
hack_newbie
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #3 on: January 25, 2012, 01:10:49 AM »

Dear Sir,

Sorry i think i wasnt able to explain properly. I dont have any win98 in my environment. See my assumptions (based on my research)

1) Windows 2003 server and windows xp are genuine machines that need to perform authentication (most likely ntlm)
2) I introduce windows 98 in between as MITM.
3) Now when win2003 needs to perform authentication with windows xp like this
\\<windows-xp-ip>
i want to redirect traffic to windows 98 so that authentication is now forced to LM, so that i can sniff the passwords.

I hope its clear, kindly suggest now
Logged
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #4 on: January 25, 2012, 08:33:10 AM »

Is this in your own lab? Are you just trying to sniff LM passwords? If so, why don't you just change the box to allow LM hashes? http://technet.microsoft.com/en-us/library/cc738867(WS.10).aspx

If you're practicing port forwarding, just use something like this: http://www.quantumg.net/portforward.php
Logged

hack_newbie
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #5 on: January 26, 2012, 12:37:52 AM »

Dear Sir,

Port redirection is for MITM machine. what i am thinking is, the machine in between should redirect the traffic to another malicious machine. The link you forwarded will redirect from the destination, not from the MITM machine. Kindly correct me if i am wrong

And yes this is for my lab setup
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.072 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.