hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

JIC
OK, here's a tutorial I wrote a while ago when I was part of the warez scene. I've updated it to accomodate for latest changes. Should be useful for anyone on the warez scene who wants to start scanning.

Stage 1. - Download and Installation

First you need a programme. Now there are a couple of programmes out on the market but I find Grim Ping does the job and for the purpose of this guide, this is the programme we shall use.

Download the latest version of Grim's, available at

h**p://grimsping.cjb.net/cgi-bin/download.cgi?Ping

(Version 1.7.5 has been released!) and install.


Stage 2. - Configuration

If this is your first time running Grim's you will need to make
some small changes to the configuration.

Go to 'Options'...

Then click on the PubFind tab and go to General.

Now the Threads section can be altered depending on your own
Internet connection. As a rule the faster your connection the
more threads can be checked. As I am only on a 56k I tend to
leave my threads on 30. If you have cable then you can increase
it higher. Try going up in units of 10's and see what works for you.

Now click on the FireWall Tab.

It's entirely up to you if you want to use a firewall or not.
Personally I don't but it's YOUR decision. Some people I've
talked to say its a must, others say its a waist of time and
slows the scanning down. Its up to you!

Click onto the Logging Tag. In here you will have to select 'Log
Wingates during scan' (If you didn't already know, Wingate's can
be used as Proxies)

Click the Permissions tab at the top.

Make sure the 'Log Directory permissions' tag is selected.

Click the 'Logging' tab

Make sure 'Log OS Type', 'Log FXP stats', 'Log resumability' and
'log speed of 5 kbyte chunk' tag's are selected. Click SAVE!

That's it! Simple ey!

Now its time to start scanning.

Stage 3. - Scanning

Because the FBI and other various agencies are out to try and
catch scanners and FXP groups it is essential that you check an
IP range before you scan.

There are a few sites and posts that lists IP ranges to stay
away from. Alternatively I have posted a copy here...

http://forums.governmentsecurity.org/index...?showtopic=1227

For lists of other IP addresses, check out...

h**p://www.ipindex.de

Basically what you need to know is there are three categories of
IP addresses. There are large companies that work in the range

0.x.x.x to 127.x.x.x
This range is great if we can get pubs here but bear in mind
that big companies have greater security so BE CAREFULL!
Medium sized companies can be found in the range 128.0.x.x to
191.255.x.x and Small companies and home users can be found in the 192.0.0.x to 223.255.255.x ranges.

Once you have decided what range to scan, you will need to
create a queue. In Grim's hit F6. This will bring up the queue
box.

Insert the relevant IP address i.e. 127.100.50 the last two
boxes always stay the same 1 - 254. Click the 'Add Multiple
Ranges' button and insert the number of extra ranges to scan. I
usually set mine to about 255 or 510 (a long queue requires
little intervention.) and close the box.

That's it! Click go (or the traffic light sign) in the top left corner and see those pubs come running in.

That's it! Simple!

The results we are interested in are any that are in your perms.log (to get this hit F2).
jurk-off
is this hacking related or just scanning anon ftps huh.gif
OneNight
Anohter great grims ping scanning tut is to be found here:

www.jtpfxp.net

Theres other good articles there also...
ComSec
nice tut JIC...thanks for sharing
JIC
Its just scanning for anonomous pubs via Port 21.
GSecur
It's not what I am normaly into, but good none the less wink.gif
PSR
grims ping now that brings back memories , jagging around , locking dirs , unlocking dirs , checking .... on 2nd thought i'm glad those days are over biggrin.gif

none the less a very good tut and i recommend to ppl to read before yellign out i wanna scan iis ,sql and hack blablabla
danceswithwolves
used grim for the first time and had bingo on server with writeacces upspeed of 60kb and downspeed of 260kb

think grim is working just fine by me..... ph34r.gif
babbacool
you can also use Ping Companion with you file perms.log ....

CODE
Features
Advanced proxy usage to protect privacy
Checks upload access and upload speed
Checks download access and download speed
Checks list access
Checks delete access
Checks FXP access and FXP speed
Determines available hard drive space


babbacool
And of course I agree with PSR....

It's better to first try this tool before asking immediately "how can I hack SQL, IIS........"

It's a good way to start I think...

And before asking how to hack people should really better ask "how can I configure serv-u ?"

Because in fact most of people just want to put a serv-u on the box they have exploited.
[Sunny]
Oh yeah the good old times .
Grims Ping is a realy nice scanner . But i think pubs are outdated . The stuff will be to fast deleted , most servers are slow , and no many are out there .

But 4 noobs i think it is a good way to get in buisness ;D
pe0n
QUOTE
And before asking how to hack people should really better ask "how can I configure serv-u ?"


i agree babbacool smile.gif

i just configured my Serv-U with JAstats and JAcheck - not that easy rolleyes.gif
mal.one
nice tut for beginners to get into scaning, i agree but as far as my experience conering pubs goes i godda say that there are still at least some out there and if u r lucky ya get fast one...at least 4 people who aint got that high standart ...
Chuckey
Thanks for Sharing the info an dtut, as a beginer I think I'll start here... done lots of scan for Ms03/NT etc but not knowing what to do with em properly doesn't help. so i think I'll take a step back or at the start smile.gif
Before I be one to stat asking how to root blink.gif

Thanks again
Chuckey ph34r.gif
dotcom
Man this brings me back biggrin.gif

Thank you for sharing, more than a bit outdated tho... might add things like using it remotely would be a useful addition...
jead99
Thanks for the sharing the tut m8 smile.gif
Chuckey
Reet got all that going but cant get the compaion to work and do I just copy the results to the perm log plz smile.gif

All aboutface with me ...I actually hae all the remote stuff going and all the files ...lol but if anyone could help with how i check with companion that would be great.

Thanks Chuckey ph34r.gif
jetprice
Well how fun, telling people how to scan for FXP... should i report this or not ... hmm let me think about it.
Dalrok
thank you for the basics
hellraiza
nice help thnx m8
flashb4ck
another site with a good blacklist

http://www.ip-index.de/files/blacklist.htm


its 0 day updated and all countries are in own categories


hf
Lusty
Thanks.. I'll try it out.. can't get enough of that kins og programs biggrin.gif
garcia
a good tuto thank you I leaves to look at
goodmantoday
I used Ping to get some ips and there anonymous/ftpclient@home.com why is that did i do something wrong
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.