亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? ntsec.html

?? a collection of mega hacking tools
?? HTML
?? 第 1 頁 / 共 5 頁
字號:
<html>

<head>

<title>Networking and NT Security Issues</title>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

</head>



<body bgcolor="#000000" text="#ffffff" link="#ffffff" vlink="#ffffff">

<div align="center"> 

  <table width="680" border="0" cellspacing="2" cellpadding="2" align="center">

    <tr> 

      <td width="693"> 

        <pre>

                        :::::::::   ::::::::  :::::::::  ::::::::::

                        :+:    :+: :+:    :+: :+:    :+: :+:

                        +:+    +:+ +:+        +:+    +:+ +:+

                        +#++:++#+  +#++:++#++ +#++:++#:  :#::+::#

                        +#+    +#+        +#+ +#+    +#+ +#+

                        #+#    #+# #+#    #+# #+#    #+# #+#

                        #########   ########  ###    ### ###



              	             <a href="http://blacksun.box.sk" target="_blank">http://blacksun.box.sk</a>

                           _____________________________

    ______________________I       <b>   Topic:</b>             I_____________________

   \                      I                             I                    /

    \     HTML by:        I     <b>Networking and NT</b>       I   Written by:     /

    >                     I      <b>Security Issues</b>        I                  <

   /      <a href="mailto:black_mesa@hacktik.org">Martin L.</a>       I_____________________________I   <i>&lt;log-file&gt;</i>      \

  /___________________________>                    <_________________________\</pre>

      </td>

    </tr>

  </table>

<p>&nbsp;</p></div>

<p><font color="#ff0000">====[ START ]=====</font></p>

<p><b>&lt;Cypher&gt;</b> ============== Networking and NT Security Issues =================<br>

  <b>&lt;Cypher&gt;</b> first things first, so i'll start with a little story about NetBIOS,

  oki?<br>

  <b>&lt;m0ded&gt;</b> k go<br>

  <b>&lt;Cypher&gt;</b> as probably most of u know NetBIOS (aka Network Input/Output

  System) was originally developed to be<br>

  <b>&lt;Cypher&gt;</b> an API (app programming interface)<br>

  <b>&lt;Cypher&gt;</b> for the client (software) to be able to use and access resources

  of the LAN<br>

  <b>&lt;Cypher&gt;</b> actually, NetBIOS is the interface for accessing networking services<br>

  <b>&lt;Cypher&gt;</b> its a software (layer) to connect a network system with the hardware<br>

  <b>&lt;Cypher&gt;</b> computers on a NetBIOS-compatible LAN talk to each other by establishing

  a session, a NetBIOS session, or by<br>

  <b>&lt;Cypher&gt;</b> datagrams or broadcasting methods<br>

  <b>&lt;Cypher&gt;</b> questions so far?<br>

  <b>&lt;Sub&gt;</b> no<br>

  <b>&lt;QX-Mat&gt;</b> .<br>

  <b>&lt;m0ded&gt;</b> go on<br>

  <b>&lt;Freezer&gt;</b> nope<br>

  <b>&lt;Cypher&gt;</b> ok<br>

  <b>&lt;Cypher&gt;</b> there is a thing in NT called the IPC<br>

  <font color="#ff0000">*** DR_CooL has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> which is an &quot;InterProcess Communication&quot;<br>

  <b>&lt;Cypher&gt;</b> used for Server-to-Server communications<br>

  <b>&lt;Cypher&gt;</b> this is actually a default NT share<br>

  <font color="#ff0000">*** TTT has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> hey DR_CooL, TTT<br>

  <b>&lt;m0ded&gt;</b> a hidden NT share?<br>

  <b>&lt;Olaf&gt;</b> Hi TTT<br>

  <b>&lt;TTT&gt;</b> Hi, cypher!<br>

  <b>&lt;Cypher&gt;</b> m0ded, yes kinda<br>

  <b>&lt;TTT&gt;</b> You already started?<br>

  <font color="#ff0000">*** elad sets mode: +m</font><br>

  <font color="#ff0000">*** elad sets mode: +v Cypher</font><br>

  <b>&lt;elad&gt;</b> now lecture.<br>

  <b>&lt;Cypher&gt;</b> :)<br>

  <font color="#ff0000">*** elad sets mode: +o Cypher</font><br>

  <font color="#ff0000">*** ChanServ sets mode: -o Cypher</font><br>

  <b>&lt;Cypher&gt;</b> so<br>

  <b>&lt;Cypher&gt;</b> anyhow, the IPC is a hidden NT share, as m0ded sayed<br>

  <font color="#ff0000">*** elad sets mode: -m</font><br>

  <b>&lt;DR_CooL&gt;</b> that's better<br>

  <b>&lt;Cypher&gt;</b> a malicious ;-) user could connect to it<br>

  <b>&lt;Cypher&gt;</b> and gather information about the system<br>

  <b>&lt;Cypher&gt;</b> this is done by an NT command (yep, microsoft gave us that)<br>

  <b>&lt;Cypher&gt;</b> the NBTSTAT command<br>

  <b>&lt;Cypher&gt;</b> it establishes a NULL Session (no credentials required) to the

  targer system<br>

  <b>&lt;Cypher&gt;</b> target<br>

  <b>&lt;Cypher&gt;</b> its syntax is simple (from the prompt of course):<br>

  <b>&lt;Cypher&gt;</b> nbtstat -a 123.123.123.123<br>

  <b>&lt;Cypher&gt;</b> nbtstat -a &lt;IP&gt;<br>

  <font color="#ff0000">*** _sniper_on_moon- has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> by using this command u'll get the ....wait... let me quote this<br>

  <b>&lt;DR_CooL&gt;</b> and what indormation does it give ?<br>

  <b>&lt;Cypher&gt;</b> &quot;NetBIOS Remote Machine Name Table&quot;<br>

  <b>&lt;Cypher&gt;</b> this is actually the first step to gathering information the

  remote machine<br>

  <b>&lt;Cypher&gt;</b> and, btw, i didn't mention this before, but info gathering is

  about 60% (if not more) of the job<br>

  <font color="#ff0000">*** FrEEkY[cooking] is now known as FrEEkY</font><br>

  <b>&lt;Cypher&gt;</b> now lets try to establish that NUll session<br>

  <b>&lt;Cypher&gt;</b> there is another &quot;kewl&quot; command<br>

  <b>&lt;Cypher&gt;</b> the &quot;net&quot; command<br>

  <b>&lt;Sub&gt;</b> net use<br>

  <b>&lt;m0ded&gt;</b> use is a parameter<br>

  <b>&lt;Cypher&gt;</b> yep<br>

  <b>&lt;Cypher&gt;</b> it has many useful features (read the manual) but we'll mostly

  focus on &quot;net use&quot; and &quot;net view&quot;<br>

  <b>&lt;Cypher&gt;</b> net view lets us see the<br>

  <b>&lt;Cypher&gt;</b> shares on the machine (depending on its security policy of course)<br>

  <b>&lt;Cypher&gt;</b> net view \\IP_ADDRESS might get us ether the shares or the &quot;Access

  is denied&quot; msg<br>

  <b>&lt;Cypher&gt;</b> if it gives us the shares, then...well... this part is done<br>

  <b>&lt;Cypher&gt;</b> but if not<br>

  <b>&lt;Cypher&gt;</b> we will try the next thing:<br>

  <b>&lt;Cypher&gt;</b> net use \\IP_ADDRESS\ipc$ &quot;&quot; /user:&quot;&quot;<br>

  <b>&lt;Cypher&gt;</b> which means, connect to the IPC share (ipc$ - the default share)

  with a &quot;&quot; (blank) password<br>

  <b>&lt;Cypher&gt;</b> and with the &quot;&quot; (blank) user name<br>

  <b>&lt;TTT&gt;</b> and now?<br>

  <b>&lt;Cypher&gt;</b> as i said, the IPC needs no credentials<br>

  <b>&lt;Cypher&gt;</b> if we get the &quot;The Command completed successfully&quot;

  msg<br>

  <b>&lt;Cypher&gt;</b> then we have established the null session and now we can get

  that list of shares<br>

  <b>&lt;Cypher&gt;</b> meaning issue the &quot;net view \\IP&quot; command<br>

  <b>&lt;Cypher&gt;</b> so, actually the list of shares is usually unavailable until

  u establish the null session<br>

  <b>&lt;Cypher&gt;</b> questions?<br>

  <b>&lt;m0ded&gt;</b> yeah<br>

  <b>&lt;Sub&gt;</b> can you establish a null session any other way?<br>

  <b>&lt;m0ded&gt;</b> what u mean a null session?<br>

  <font color="#ff0000">*** TTT has joined #bsrf</font><br>

  <b>&lt;_zach-&gt</b>; where no credntilas are required<br>

  <b>&lt;_zach-&gt</b>; from you<br>

  <font color="#ff0000">*** Esamurai has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> Sub, the null session can be established by the built-in &quot;net

  use&quot; command or any other &quot;null session establishment&quot; tools

  (there are plenty)<br>

  <b>&lt;_zach-&gt</b>; to conenct<br>

  <b>&lt;FrEEkY&gt;</b> I have an addition<br>

  <b>&lt;_zach-&gt</b>; to the target<br>

  <b>&lt;Cypher&gt;</b> m0ded, null session<br>

  <b>&lt;Cypher&gt;</b> right zach<br>

  <b>&lt;_zach-&gt</b>; :)<br>

  <b>&lt;Cypher&gt;</b> m0ded answer = zach<br>

  <b>&lt;FrEEkY&gt;</b> if you turn your filesharing on and then after your in you turn

  it off, it can get the neccesary files on your computer to mask you as a part

  of the network<br>

  <b>&lt;Cypher&gt;</b> its a connection throught the IPC share<br>

  <b>&lt;_zach-&gt</b>; w00t<br>

  <b>&lt;Sub&gt;</b> so, what packets would you have to send to establish a null session,

  if you were coding an exploit for instance?<br>

  <b>&lt;Cypher&gt;</b> Sub, i haven't actually tryed &quot;raw&quot; connection to ipc

  yet...<br>

  <b>&lt;tcg&gt;</b> whats an ipc share<br>

  <b>&lt;Cypher&gt;</b> tcg, its a default (hidden) NT share (one of them, at least)<br>

  <b>&lt;QX-Mat&gt;</b> Can we carry on?<br>

  <b>&lt;Cypher&gt;</b> QX-Mat, of course<br>

  <font color="#ff0000">*** DR_CooL has quit IRC (Ping timeout)</font><br>

  <font color="#ff0000">*** _sniper_on_moon- is now known as sniper</font><br>

  <b>&lt;TTT&gt;</b> Has anyone a log from beginning of the lesson?<br>

  <b>&lt;m0ded&gt;</b> yes me<br>

  <b>&lt;Sub&gt;</b> me<br>

  <b>&lt;FrEEkY&gt;</b> I do<br>

  <b>&lt;Cypher&gt;</b> lets now move to a bit different direction - securing NT<br>

  <b>&lt;tcg&gt;</b> why nt got that?<br>

  <b>&lt;TTT&gt;</b> okay<br>

  <b>&lt;Cypher&gt;</b> tcg, inner communications</font><br>

  <font color="#ff0000">*** Samcon has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> now, the basic steps/checklist<br>

  <b>&lt;tcg&gt;</b> what is it good for?<br>

  <b>&lt;Cypher&gt;</b> to &quot;start&quot; securing an NT machine<br>

  <b>&lt;FrEEkY&gt;</b> securing an NT machine, orignall idea<br>

  <b>&lt;QX-Mat&gt;</b> )<br>

  <b>&lt;Cypher&gt;</b> first thing, and the obvious one<br>

  <b>&lt;Cypher&gt;</b> is Passwords<br>

  <b>&lt;Cypher&gt;</b> (duh) ;)<br>

  <b>&lt;Cypher&gt;</b> unfortunatly, many admins neglect password policies, for some

  reason<br>

  <b>&lt;dr3x&gt;</b> min_password_length = 12 :)<br>

  <b>&lt;tcg&gt;</b> but I can't telnet an nt box<br>

  <b>&lt;tcg&gt;</b> so who cares<br>

  <b>&lt;Cypher&gt;</b> putting passwords, such as &quot;john&quot; on a &quot;john&quot;

  user account<br>

  <b>&lt;Sub&gt;</b> tcg: there is a telnetd for NT<br>

  <b>&lt;Cypher&gt;</b> dr3x, good, but can the &quot;dumb&quot; user remember it?<br>

  <b>&lt;tcg&gt;</b> password guessing is out of fashion<br>

  <b>&lt;elad&gt;</b> tcg; you can install some ssh server and ssh to it, yeah :)<br>

  <b>&lt;dr3x&gt;</b> nope<br>

  <b>&lt;elad&gt;</b> why would a sane person want to use telnet? :)<br>

  <b>&lt;tcg&gt;</b> haha<br>

  <font color="#ff0000">*** sniper has quit IRC (Ping timeout)</font><br>

  <b>&lt;TTT&gt;</b> you can do interesting things with telnet, which you can't do with

  ssh<br>

  <b>&lt;FrEEkY&gt;</b> tcg: you can get into NBTSTAT in a whole other way, to get info

  on the computer so you can access it better with telnet<br>

  <b>&lt;elad&gt;</b> hahahha!<br>

  <b>&lt;elad&gt;</b> ok lets let cypher go on with his lecture<br>

  <b>&lt;Olaf&gt;</b> whith telnet we can do everything!!!<br>

  <b>&lt;Cypher&gt;</b> good idea, elad...<br>

  <b>&lt;QX-Mat&gt;</b> Olaf: true!<br>

  <b>&lt;Cypher&gt;</b> shall we continue??<br>

  <b>&lt;Sub&gt;</b> yes<br>

  <b>&lt;m0ded&gt;</b> yeah<br>

  <b>&lt;Slayer[reading_eating]&gt;</b> yes<br>

  <b>&lt;m0ded&gt;</b> <b>&lt;Cypher&gt;</b> putting passwords, such as &quot;john&quot; on

  a &quot;john&quot; user account<br>

  <b>&lt;tcg&gt;</b> say<br>

  <b>&lt;Cypher&gt;</b> so obviously, the admin has to put proper password policies,

  which include (mostly):<br>

  <b>&lt;tcg&gt;</b> a password that is like the username isn't good right?<br>

  <b>&lt;Cypher&gt;</b> tcg, yeah :)<br>

  <b>&lt;Cypher&gt;</b> password age:<br>

  <b>&lt;tcg&gt;</b> ??<br>

  <b>&lt;Cypher&gt;</b> the amount of time the password remains valid<br>

  <b>&lt;Cypher&gt;</b> this is sometimes not set, or disabled on some accounts<br>

  <b>&lt;FrEEkY&gt;</b> I've never thought of microsoft passwords as being a problem

  <br>

  <b>&lt;Cypher&gt;</b> causing one password to last &quot;a lifetime&quot;<br>

  <b>&lt;Cypher&gt;</b> so its better to put a password age as something about 30 days<br>

  <b>&lt;tcg&gt;</b> all these stuff are right both for nt4 and win2k?<br>

  <b>&lt;Cypher&gt;</b> tcg, yes<br>

  <b>&lt;tcg&gt;</b> my password is complex. its my username backwards. :)<br>

  <b>&lt;tcg&gt;</b> and nt3.51?<br>

  <b>&lt;Olaf&gt;</b> I'm using a secure unix which acepts guest!!!!<br>

  <b>&lt;_zach-&gt</b>; ./dns Olaf<br>

  <b>&lt;_zach-&gt</b>; lol<br>

  <b>&lt;m0ded&gt;</b> heh<br>

  <b>&lt;elad&gt;</b> like<br>

  <b>&lt;Slayer[reading_eating]&gt;</b> :)<br>

  <b>&lt;elad&gt;</b> shut the fuck up and let him get to the questions part<br>

  <b>&lt;elad&gt;</b> or i will rape your mothers<br>

  <b>&lt;tcg&gt;</b> hahaha<br>

  <b>&lt;elad&gt;</b> to death<br>

  <b>&lt;Cypher&gt;</b> besides the password also has to be good, meaning a combination

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
欧美精品自拍偷拍动漫精品| 一区二区成人在线观看| 中文字幕一区三区| 日本中文字幕一区二区有限公司| 麻豆精品精品国产自在97香蕉| 99久久99久久综合| 久久综合av免费| 亚洲123区在线观看| www.性欧美| 久久久天堂av| 久久超碰97中文字幕| 欧美日韩一区二区在线观看视频 | 欧美日本精品一区二区三区| 国产欧美精品国产国产专区| 久久99在线观看| 欧美精品在线观看播放| 亚洲精品高清在线| 成人高清在线视频| 久久久久久久久久看片| 精品一区二区三区视频| 精品国产一区二区精华| 美女久久久精品| 欧美一区二区三区免费在线看| 亚洲午夜影视影院在线观看| 色综合久久综合| 综合在线观看色| 成人黄色网址在线观看| 国产精品无人区| 高清不卡在线观看| 欧美韩日一区二区三区四区| 国产精品一区二区在线观看网站| 精品日韩av一区二区| 久久精品国产99久久6| 欧美一级日韩免费不卡| 日本亚洲最大的色成网站www| 欧美午夜不卡在线观看免费| 亚洲国产精品久久久久秋霞影院| 91看片淫黄大片一级在线观看| 日本不卡不码高清免费观看| 在线一区二区三区四区五区 | 日韩av一级片| 91精品国产高清一区二区三区| 亚洲v中文字幕| 欧美一区二区三区免费观看视频| 日产国产欧美视频一区精品| 精品国产乱码久久久久久影片| 久久国内精品自在自线400部| 精品国产乱码久久久久久图片| 国内精品在线播放| 国产精品污污网站在线观看| 91在线小视频| 亚洲成年人网站在线观看| 717成人午夜免费福利电影| 久久成人免费网| 亚洲国产成人午夜在线一区| 一本一道综合狠狠老| 视频一区中文字幕国产| 久久这里只精品最新地址| 国产麻豆欧美日韩一区| 国产精品国产精品国产专区不蜜| 欧美亚洲一区二区在线观看| 美女脱光内衣内裤视频久久影院| 久久久国产精华| 在线免费观看日本一区| 美日韩黄色大片| 国产精品久久99| 欧美一区二区精品在线| 岛国av在线一区| 亚洲影院在线观看| 久久久精品tv| 欧美性生活一区| 粉嫩绯色av一区二区在线观看| 曰韩精品一区二区| 2021国产精品久久精品| 91免费国产在线观看| 老司机精品视频导航| 亚洲精品国产a| 国产视频一区在线播放| 91精品国产综合久久久久久久 | 欧美一区二区三区四区久久| 粉嫩蜜臀av国产精品网站| 五月婷婷另类国产| 中文字幕一区二区三区四区不卡| 欧美一区二区大片| 91麻豆国产福利在线观看| 狠狠久久亚洲欧美| 午夜在线成人av| ...xxx性欧美| 国产欧美久久久精品影院| 在线成人小视频| 91丨九色porny丨蝌蚪| 国产精品一区二区久久精品爱涩| 亚洲第一福利视频在线| 一色桃子久久精品亚洲| 久久久久久久网| 欧美一卡二卡在线| 欧美日韩精品一二三区| 色婷婷精品大视频在线蜜桃视频| 成人午夜激情片| 精品午夜一区二区三区在线观看| 婷婷成人激情在线网| 亚洲在线观看免费视频| 亚洲色图19p| 中文字幕日本乱码精品影院| 欧美一区二区三区免费在线看 | 久久精品一区四区| 欧美变态tickle挠乳网站| 欧美精品一二三| 欧美日韩中文国产| 欧美综合一区二区三区| 日本精品一区二区三区高清 | 高清成人免费视频| 国产很黄免费观看久久| 国产在线一区二区综合免费视频| 蜜桃一区二区三区四区| 日韩国产高清在线| 日韩精品福利网| 蜜臀av一区二区在线观看| 九色综合国产一区二区三区| 精品一区二区三区免费| 狠狠色丁香久久婷婷综合丁香| 黄网站免费久久| 国产suv精品一区二区883| 成人av网址在线观看| 99re成人精品视频| 一本久久a久久免费精品不卡| 在线观看亚洲一区| 欧美理论在线播放| 欧美成人一区二区| 国产午夜久久久久| 国产精品久久久久国产精品日日| 一区二区三区四区五区视频在线观看 | 欧美国产乱子伦| 亚洲天堂免费在线观看视频| 亚洲伦理在线精品| 日本一区中文字幕| 国产福利精品导航| 在线免费观看日本一区| 欧美一区二区三区不卡| 日本一区二区三区国色天香| 亚洲精品中文在线| 91婷婷韩国欧美一区二区| 在线一区二区视频| 欧美不卡123| 亚洲欧美二区三区| 日韩在线播放一区二区| 国产精品综合视频| 在线一区二区三区做爰视频网站| 9191久久久久久久久久久| 久久蜜臀中文字幕| 一区二区三区欧美亚洲| 日本中文字幕一区| 9色porny自拍视频一区二区| 欧美久久一二区| 中文字幕巨乱亚洲| 亚洲不卡av一区二区三区| 国产一区亚洲一区| 在线观看一区二区精品视频| 久久久一区二区三区捆绑**| 亚洲精品网站在线观看| 麻豆成人在线观看| 色婷婷av一区二区三区gif| 久久无码av三级| 亚洲二区在线视频| 成人免费的视频| 日韩三区在线观看| 亚洲乱码中文字幕综合| 国产成人av一区| 日韩一二三区不卡| 亚洲精品日韩一| 国产大片一区二区| 日韩精品专区在线影院观看 | 久88久久88久久久| 欧美中文字幕一区二区三区 | 欧美激情在线一区二区| 午夜国产精品一区| 日本电影欧美片| 国产精品第13页| 国产精品小仙女| 精品人在线二区三区| 亚洲第一综合色| 91麻豆蜜桃一区二区三区| 国产欧美一二三区| 激情综合色综合久久| 91精品国产美女浴室洗澡无遮挡| 伊人一区二区三区| 99精品黄色片免费大全| 国产精品久久久久影院老司| 国产成人久久精品77777最新版本| 欧美一区二区视频在线观看2020| 图片区小说区国产精品视频| 欧美伊人久久大香线蕉综合69| 中文字幕中文字幕在线一区| 国产成人精品影视| 国产亚洲精品超碰| 久久国产免费看| 精品久久久久香蕉网| 精品一区二区三区免费播放| 亚洲精品一区二区三区精华液| 精品一区二区三区蜜桃|