|
Video: MS SQL Preauth Attack, Pwdump and John the Ripper |
|
|
|
Follow along as we perform the following hack:
- Exploit of the MSSQL 2000 Hello Buffer Overflow using the C port of the MSF module mssql2000_preauthentication.pm (thanks MC!)
- Add a user to the local administrators group
- Use pwdump3e to connect to the host with our administrative level credentials
- Dump the SAM hashes
- Crack them using John the Ripper
Enjoy and keep an eye out for future videos. Feel free to post comments and suggestions for future videos.
Thanks,
Chris Gates
|