亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? ntsec.html

?? a collection of mega hacking tools
?? HTML
?? 第 1 頁 / 共 5 頁
字號:
<html>

<head>

<title>Networking and NT Security Issues</title>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

</head>



<body bgcolor="#000000" text="#ffffff" link="#ffffff" vlink="#ffffff">

<div align="center"> 

  <table width="680" border="0" cellspacing="2" cellpadding="2" align="center">

    <tr> 

      <td width="693"> 

        <pre>

                        :::::::::   ::::::::  :::::::::  ::::::::::

                        :+:    :+: :+:    :+: :+:    :+: :+:

                        +:+    +:+ +:+        +:+    +:+ +:+

                        +#++:++#+  +#++:++#++ +#++:++#:  :#::+::#

                        +#+    +#+        +#+ +#+    +#+ +#+

                        #+#    #+# #+#    #+# #+#    #+# #+#

                        #########   ########  ###    ### ###



              	             <a href="http://blacksun.box.sk" target="_blank">http://blacksun.box.sk</a>

                           _____________________________

    ______________________I       <b>   Topic:</b>             I_____________________

   \                      I                             I                    /

    \     HTML by:        I     <b>Networking and NT</b>       I   Written by:     /

    >                     I      <b>Security Issues</b>        I                  <

   /      <a href="mailto:black_mesa@hacktik.org">Martin L.</a>       I_____________________________I   <i>&lt;log-file&gt;</i>      \

  /___________________________>                    <_________________________\</pre>

      </td>

    </tr>

  </table>

<p>&nbsp;</p></div>

<p><font color="#ff0000">====[ START ]=====</font></p>

<p><b>&lt;Cypher&gt;</b> ============== Networking and NT Security Issues =================<br>

  <b>&lt;Cypher&gt;</b> first things first, so i'll start with a little story about NetBIOS,

  oki?<br>

  <b>&lt;m0ded&gt;</b> k go<br>

  <b>&lt;Cypher&gt;</b> as probably most of u know NetBIOS (aka Network Input/Output

  System) was originally developed to be<br>

  <b>&lt;Cypher&gt;</b> an API (app programming interface)<br>

  <b>&lt;Cypher&gt;</b> for the client (software) to be able to use and access resources

  of the LAN<br>

  <b>&lt;Cypher&gt;</b> actually, NetBIOS is the interface for accessing networking services<br>

  <b>&lt;Cypher&gt;</b> its a software (layer) to connect a network system with the hardware<br>

  <b>&lt;Cypher&gt;</b> computers on a NetBIOS-compatible LAN talk to each other by establishing

  a session, a NetBIOS session, or by<br>

  <b>&lt;Cypher&gt;</b> datagrams or broadcasting methods<br>

  <b>&lt;Cypher&gt;</b> questions so far?<br>

  <b>&lt;Sub&gt;</b> no<br>

  <b>&lt;QX-Mat&gt;</b> .<br>

  <b>&lt;m0ded&gt;</b> go on<br>

  <b>&lt;Freezer&gt;</b> nope<br>

  <b>&lt;Cypher&gt;</b> ok<br>

  <b>&lt;Cypher&gt;</b> there is a thing in NT called the IPC<br>

  <font color="#ff0000">*** DR_CooL has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> which is an &quot;InterProcess Communication&quot;<br>

  <b>&lt;Cypher&gt;</b> used for Server-to-Server communications<br>

  <b>&lt;Cypher&gt;</b> this is actually a default NT share<br>

  <font color="#ff0000">*** TTT has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> hey DR_CooL, TTT<br>

  <b>&lt;m0ded&gt;</b> a hidden NT share?<br>

  <b>&lt;Olaf&gt;</b> Hi TTT<br>

  <b>&lt;TTT&gt;</b> Hi, cypher!<br>

  <b>&lt;Cypher&gt;</b> m0ded, yes kinda<br>

  <b>&lt;TTT&gt;</b> You already started?<br>

  <font color="#ff0000">*** elad sets mode: +m</font><br>

  <font color="#ff0000">*** elad sets mode: +v Cypher</font><br>

  <b>&lt;elad&gt;</b> now lecture.<br>

  <b>&lt;Cypher&gt;</b> :)<br>

  <font color="#ff0000">*** elad sets mode: +o Cypher</font><br>

  <font color="#ff0000">*** ChanServ sets mode: -o Cypher</font><br>

  <b>&lt;Cypher&gt;</b> so<br>

  <b>&lt;Cypher&gt;</b> anyhow, the IPC is a hidden NT share, as m0ded sayed<br>

  <font color="#ff0000">*** elad sets mode: -m</font><br>

  <b>&lt;DR_CooL&gt;</b> that's better<br>

  <b>&lt;Cypher&gt;</b> a malicious ;-) user could connect to it<br>

  <b>&lt;Cypher&gt;</b> and gather information about the system<br>

  <b>&lt;Cypher&gt;</b> this is done by an NT command (yep, microsoft gave us that)<br>

  <b>&lt;Cypher&gt;</b> the NBTSTAT command<br>

  <b>&lt;Cypher&gt;</b> it establishes a NULL Session (no credentials required) to the

  targer system<br>

  <b>&lt;Cypher&gt;</b> target<br>

  <b>&lt;Cypher&gt;</b> its syntax is simple (from the prompt of course):<br>

  <b>&lt;Cypher&gt;</b> nbtstat -a 123.123.123.123<br>

  <b>&lt;Cypher&gt;</b> nbtstat -a &lt;IP&gt;<br>

  <font color="#ff0000">*** _sniper_on_moon- has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> by using this command u'll get the ....wait... let me quote this<br>

  <b>&lt;DR_CooL&gt;</b> and what indormation does it give ?<br>

  <b>&lt;Cypher&gt;</b> &quot;NetBIOS Remote Machine Name Table&quot;<br>

  <b>&lt;Cypher&gt;</b> this is actually the first step to gathering information the

  remote machine<br>

  <b>&lt;Cypher&gt;</b> and, btw, i didn't mention this before, but info gathering is

  about 60% (if not more) of the job<br>

  <font color="#ff0000">*** FrEEkY[cooking] is now known as FrEEkY</font><br>

  <b>&lt;Cypher&gt;</b> now lets try to establish that NUll session<br>

  <b>&lt;Cypher&gt;</b> there is another &quot;kewl&quot; command<br>

  <b>&lt;Cypher&gt;</b> the &quot;net&quot; command<br>

  <b>&lt;Sub&gt;</b> net use<br>

  <b>&lt;m0ded&gt;</b> use is a parameter<br>

  <b>&lt;Cypher&gt;</b> yep<br>

  <b>&lt;Cypher&gt;</b> it has many useful features (read the manual) but we'll mostly

  focus on &quot;net use&quot; and &quot;net view&quot;<br>

  <b>&lt;Cypher&gt;</b> net view lets us see the<br>

  <b>&lt;Cypher&gt;</b> shares on the machine (depending on its security policy of course)<br>

  <b>&lt;Cypher&gt;</b> net view \\IP_ADDRESS might get us ether the shares or the &quot;Access

  is denied&quot; msg<br>

  <b>&lt;Cypher&gt;</b> if it gives us the shares, then...well... this part is done<br>

  <b>&lt;Cypher&gt;</b> but if not<br>

  <b>&lt;Cypher&gt;</b> we will try the next thing:<br>

  <b>&lt;Cypher&gt;</b> net use \\IP_ADDRESS\ipc$ &quot;&quot; /user:&quot;&quot;<br>

  <b>&lt;Cypher&gt;</b> which means, connect to the IPC share (ipc$ - the default share)

  with a &quot;&quot; (blank) password<br>

  <b>&lt;Cypher&gt;</b> and with the &quot;&quot; (blank) user name<br>

  <b>&lt;TTT&gt;</b> and now?<br>

  <b>&lt;Cypher&gt;</b> as i said, the IPC needs no credentials<br>

  <b>&lt;Cypher&gt;</b> if we get the &quot;The Command completed successfully&quot;

  msg<br>

  <b>&lt;Cypher&gt;</b> then we have established the null session and now we can get

  that list of shares<br>

  <b>&lt;Cypher&gt;</b> meaning issue the &quot;net view \\IP&quot; command<br>

  <b>&lt;Cypher&gt;</b> so, actually the list of shares is usually unavailable until

  u establish the null session<br>

  <b>&lt;Cypher&gt;</b> questions?<br>

  <b>&lt;m0ded&gt;</b> yeah<br>

  <b>&lt;Sub&gt;</b> can you establish a null session any other way?<br>

  <b>&lt;m0ded&gt;</b> what u mean a null session?<br>

  <font color="#ff0000">*** TTT has joined #bsrf</font><br>

  <b>&lt;_zach-&gt</b>; where no credntilas are required<br>

  <b>&lt;_zach-&gt</b>; from you<br>

  <font color="#ff0000">*** Esamurai has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> Sub, the null session can be established by the built-in &quot;net

  use&quot; command or any other &quot;null session establishment&quot; tools

  (there are plenty)<br>

  <b>&lt;_zach-&gt</b>; to conenct<br>

  <b>&lt;FrEEkY&gt;</b> I have an addition<br>

  <b>&lt;_zach-&gt</b>; to the target<br>

  <b>&lt;Cypher&gt;</b> m0ded, null session<br>

  <b>&lt;Cypher&gt;</b> right zach<br>

  <b>&lt;_zach-&gt</b>; :)<br>

  <b>&lt;Cypher&gt;</b> m0ded answer = zach<br>

  <b>&lt;FrEEkY&gt;</b> if you turn your filesharing on and then after your in you turn

  it off, it can get the neccesary files on your computer to mask you as a part

  of the network<br>

  <b>&lt;Cypher&gt;</b> its a connection throught the IPC share<br>

  <b>&lt;_zach-&gt</b>; w00t<br>

  <b>&lt;Sub&gt;</b> so, what packets would you have to send to establish a null session,

  if you were coding an exploit for instance?<br>

  <b>&lt;Cypher&gt;</b> Sub, i haven't actually tryed &quot;raw&quot; connection to ipc

  yet...<br>

  <b>&lt;tcg&gt;</b> whats an ipc share<br>

  <b>&lt;Cypher&gt;</b> tcg, its a default (hidden) NT share (one of them, at least)<br>

  <b>&lt;QX-Mat&gt;</b> Can we carry on?<br>

  <b>&lt;Cypher&gt;</b> QX-Mat, of course<br>

  <font color="#ff0000">*** DR_CooL has quit IRC (Ping timeout)</font><br>

  <font color="#ff0000">*** _sniper_on_moon- is now known as sniper</font><br>

  <b>&lt;TTT&gt;</b> Has anyone a log from beginning of the lesson?<br>

  <b>&lt;m0ded&gt;</b> yes me<br>

  <b>&lt;Sub&gt;</b> me<br>

  <b>&lt;FrEEkY&gt;</b> I do<br>

  <b>&lt;Cypher&gt;</b> lets now move to a bit different direction - securing NT<br>

  <b>&lt;tcg&gt;</b> why nt got that?<br>

  <b>&lt;TTT&gt;</b> okay<br>

  <b>&lt;Cypher&gt;</b> tcg, inner communications</font><br>

  <font color="#ff0000">*** Samcon has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> now, the basic steps/checklist<br>

  <b>&lt;tcg&gt;</b> what is it good for?<br>

  <b>&lt;Cypher&gt;</b> to &quot;start&quot; securing an NT machine<br>

  <b>&lt;FrEEkY&gt;</b> securing an NT machine, orignall idea<br>

  <b>&lt;QX-Mat&gt;</b> )<br>

  <b>&lt;Cypher&gt;</b> first thing, and the obvious one<br>

  <b>&lt;Cypher&gt;</b> is Passwords<br>

  <b>&lt;Cypher&gt;</b> (duh) ;)<br>

  <b>&lt;Cypher&gt;</b> unfortunatly, many admins neglect password policies, for some

  reason<br>

  <b>&lt;dr3x&gt;</b> min_password_length = 12 :)<br>

  <b>&lt;tcg&gt;</b> but I can't telnet an nt box<br>

  <b>&lt;tcg&gt;</b> so who cares<br>

  <b>&lt;Cypher&gt;</b> putting passwords, such as &quot;john&quot; on a &quot;john&quot;

  user account<br>

  <b>&lt;Sub&gt;</b> tcg: there is a telnetd for NT<br>

  <b>&lt;Cypher&gt;</b> dr3x, good, but can the &quot;dumb&quot; user remember it?<br>

  <b>&lt;tcg&gt;</b> password guessing is out of fashion<br>

  <b>&lt;elad&gt;</b> tcg; you can install some ssh server and ssh to it, yeah :)<br>

  <b>&lt;dr3x&gt;</b> nope<br>

  <b>&lt;elad&gt;</b> why would a sane person want to use telnet? :)<br>

  <b>&lt;tcg&gt;</b> haha<br>

  <font color="#ff0000">*** sniper has quit IRC (Ping timeout)</font><br>

  <b>&lt;TTT&gt;</b> you can do interesting things with telnet, which you can't do with

  ssh<br>

  <b>&lt;FrEEkY&gt;</b> tcg: you can get into NBTSTAT in a whole other way, to get info

  on the computer so you can access it better with telnet<br>

  <b>&lt;elad&gt;</b> hahahha!<br>

  <b>&lt;elad&gt;</b> ok lets let cypher go on with his lecture<br>

  <b>&lt;Olaf&gt;</b> whith telnet we can do everything!!!<br>

  <b>&lt;Cypher&gt;</b> good idea, elad...<br>

  <b>&lt;QX-Mat&gt;</b> Olaf: true!<br>

  <b>&lt;Cypher&gt;</b> shall we continue??<br>

  <b>&lt;Sub&gt;</b> yes<br>

  <b>&lt;m0ded&gt;</b> yeah<br>

  <b>&lt;Slayer[reading_eating]&gt;</b> yes<br>

  <b>&lt;m0ded&gt;</b> <b>&lt;Cypher&gt;</b> putting passwords, such as &quot;john&quot; on

  a &quot;john&quot; user account<br>

  <b>&lt;tcg&gt;</b> say<br>

  <b>&lt;Cypher&gt;</b> so obviously, the admin has to put proper password policies,

  which include (mostly):<br>

  <b>&lt;tcg&gt;</b> a password that is like the username isn't good right?<br>

  <b>&lt;Cypher&gt;</b> tcg, yeah :)<br>

  <b>&lt;Cypher&gt;</b> password age:<br>

  <b>&lt;tcg&gt;</b> ??<br>

  <b>&lt;Cypher&gt;</b> the amount of time the password remains valid<br>

  <b>&lt;Cypher&gt;</b> this is sometimes not set, or disabled on some accounts<br>

  <b>&lt;FrEEkY&gt;</b> I've never thought of microsoft passwords as being a problem

  <br>

  <b>&lt;Cypher&gt;</b> causing one password to last &quot;a lifetime&quot;<br>

  <b>&lt;Cypher&gt;</b> so its better to put a password age as something about 30 days<br>

  <b>&lt;tcg&gt;</b> all these stuff are right both for nt4 and win2k?<br>

  <b>&lt;Cypher&gt;</b> tcg, yes<br>

  <b>&lt;tcg&gt;</b> my password is complex. its my username backwards. :)<br>

  <b>&lt;tcg&gt;</b> and nt3.51?<br>

  <b>&lt;Olaf&gt;</b> I'm using a secure unix which acepts guest!!!!<br>

  <b>&lt;_zach-&gt</b>; ./dns Olaf<br>

  <b>&lt;_zach-&gt</b>; lol<br>

  <b>&lt;m0ded&gt;</b> heh<br>

  <b>&lt;elad&gt;</b> like<br>

  <b>&lt;Slayer[reading_eating]&gt;</b> :)<br>

  <b>&lt;elad&gt;</b> shut the fuck up and let him get to the questions part<br>

  <b>&lt;elad&gt;</b> or i will rape your mothers<br>

  <b>&lt;tcg&gt;</b> hahaha<br>

  <b>&lt;elad&gt;</b> to death<br>

  <b>&lt;Cypher&gt;</b> besides the password also has to be good, meaning a combination

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
国产一区高清在线| 日本久久电影网| 日本精品视频一区二区三区| 欧美一区二区三区在| 亚洲三级电影网站| 久久99久久久久| 欧美日韩一区二区三区不卡| 中文一区在线播放| 美国av一区二区| 欧美日韩久久一区| 亚洲视频一二区| 国产成人av电影在线| 日韩一区二区三区电影 | 国产欧美视频一区二区| 日本不卡在线视频| 在线观看亚洲精品视频| 国产精品成人一区二区艾草 | 秋霞成人午夜伦在线观看| 色哟哟亚洲精品| 中文字幕一区日韩精品欧美| 国模无码大尺度一区二区三区| 欧美一二三区在线| 日本va欧美va精品发布| 欧美一级片在线看| 捆绑调教美女网站视频一区| 欧美裸体一区二区三区| 一二三区精品福利视频| 色哟哟一区二区在线观看| 亚洲激情六月丁香| 91蜜桃婷婷狠狠久久综合9色| 日本一区二区在线不卡| 成人激情午夜影院| 亚洲欧洲日产国产综合网| 成人h版在线观看| 1000部国产精品成人观看| 成人手机在线视频| 麻豆成人综合网| 欧美一级爆毛片| 蜜桃传媒麻豆第一区在线观看| 91精品国产综合久久精品麻豆 | 亚洲色图.com| 一本久久精品一区二区| 亚洲一二三四区| 欧美精品xxxxbbbb| 免费欧美高清视频| 久久这里只精品最新地址| 国产精品一色哟哟哟| 欧美激情一区二区三区在线| 91在线视频网址| 亚洲精品伦理在线| 91精品国产综合久久久蜜臀粉嫩| 免费一级片91| 中文乱码免费一区二区| 97久久超碰国产精品| 亚洲福利一区二区三区| 精品日本一线二线三线不卡| 床上的激情91.| 亚洲制服丝袜一区| 欧美不卡在线视频| www.久久精品| 天堂一区二区在线免费观看| 久久蜜桃av一区精品变态类天堂 | 一区在线观看免费| 欧美日韩国产色站一区二区三区| 日本不卡一区二区| 国产区在线观看成人精品| 色婷婷精品大视频在线蜜桃视频 | 国产高清在线观看免费不卡| 18成人在线观看| 精品三级在线观看| 色婷婷久久久综合中文字幕| 麻豆久久久久久久| 成人免费在线视频观看| 日韩一区二区在线看| 成人激情综合网站| 久久精品国产99| 亚洲欧美电影一区二区| 26uuu久久综合| 欧美午夜精品电影| 成人综合婷婷国产精品久久免费| 肉色丝袜一区二区| 亚洲视频在线一区| 国产日韩在线不卡| 日韩一区二区麻豆国产| 91视频在线看| 国产成人亚洲综合a∨婷婷| 亚洲国产成人va在线观看天堂| 精品久久久久久久久久久院品网 | 91成人在线观看喷潮| 国产乱人伦偷精品视频免下载 | 久久99久久久欧美国产| 亚洲一区二区三区爽爽爽爽爽 | 91在线观看美女| 国产一区91精品张津瑜| 天堂蜜桃91精品| 一区二区三区中文字幕电影| 国产精品美女视频| 国产午夜亚洲精品午夜鲁丝片 | 久国产精品韩国三级视频| 亚洲国产精品久久人人爱| 亚洲欧美日韩国产另类专区| 国产精品免费视频一区| 久久精品免费在线观看| 精品免费日韩av| 日韩免费视频一区二区| 欧美男女性生活在线直播观看| 91蜜桃免费观看视频| voyeur盗摄精品| 成人av免费观看| 成人精品鲁一区一区二区| 福利一区二区在线| 岛国精品在线播放| 国产91精品一区二区麻豆网站 | 欧美肥大bbwbbw高潮| 欧美三级三级三级爽爽爽| 欧洲另类一二三四区| 欧美性受极品xxxx喷水| 欧美探花视频资源| 欧美日韩国产天堂| 日韩丝袜情趣美女图片| 欧美不卡视频一区| 精品国产不卡一区二区三区| 精品国产百合女同互慰| 国产调教视频一区| 国产精品美女久久久久久| 亚洲色图欧美偷拍| 亚洲电影中文字幕在线观看| 亚洲成av人片www| 卡一卡二国产精品| 国产成人在线网站| 91在线播放网址| 欧美日韩一区高清| 日韩免费高清视频| 欧美激情在线免费观看| 亚洲人成亚洲人成在线观看图片| 一区二区成人在线视频| 视频一区二区三区中文字幕| 美女一区二区久久| 国产成人精品网址| 色综合久久久久综合| 欧美精品乱码久久久久久按摩| 欧美videossexotv100| 亚洲国产激情av| 亚洲综合一区二区精品导航| 精品中文字幕一区二区| 99久久精品情趣| 91精品中文字幕一区二区三区| 欧美大尺度电影在线| 国产精品久久国产精麻豆99网站 | 韩国一区二区三区| 久久这里只精品最新地址| 亚洲日韩欧美一区二区在线| 日韩av在线发布| 风间由美中文字幕在线看视频国产欧美| 色婷婷亚洲精品| 欧美精品一区二区三区在线 | 国产婷婷一区二区| 亚洲成人在线网站| 国产成人在线视频播放| 欧美日韩国产小视频在线观看| 国产欧美日韩综合| 青青草成人在线观看| 91婷婷韩国欧美一区二区| 欧美一卡2卡三卡4卡5免费| ...xxx性欧美| 国精品**一区二区三区在线蜜桃| 欧美在线小视频| 日本一二三不卡| 久热成人在线视频| 精品视频在线视频| 综合欧美亚洲日本| 国产九色sp调教91| 欧美一区二区三区视频在线| 一区二区三区蜜桃| 波多野结衣欧美| 欧美精品一区二区三区蜜臀| 午夜精品福利久久久| 91麻豆免费看| 中国色在线观看另类| 国产麻豆91精品| 欧美大片在线观看一区二区| 亚洲午夜日本在线观看| 91一区二区在线| 日本一区二区在线不卡| 国产黄色成人av| 久久综合视频网| 麻豆精品精品国产自在97香蕉| 欧美日韩视频在线观看一区二区三区| 亚洲女同一区二区| av在线不卡网| 国产精品美女久久久久aⅴ| 国产麻豆日韩欧美久久| 精品国产免费一区二区三区四区| 日本视频一区二区三区| 91.com视频| 日本 国产 欧美色综合| 欧美精品久久久久久久久老牛影院 | 粉嫩在线一区二区三区视频| 久久精品视频一区二区| 国产在线精品一区二区三区不卡|