hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Remote Scanner?
Devil
hi..i know there are a couple of remote scanner programms out there like X-scan and FX Scanner...but i tried them...and wasnt very happy of the results i got!!
I wrote a thread in file downloads about XRay....i think its a super programm...but the only problem there is...i cant remote scan with that!!

so i was wondering if somebody can do me a favor and maybe code a programm that spits out answers like this on a remote stro

123.456.7.8 found sql account login:sa passwort: admin

and same for wms iis ntpw and that stuff!!

the important part is that login and password is there...maybe that u can add your own dictunary...and that the logs would be saved right away!!

that possible somehow?? unsure.gif


Devil
priapo
Well, you can use either xscan, scansql or sqllhf to scan sql, ipcscan or ntscan to scan ntpwd. I have used them and they work quite well.
LoCaliSe
xscan it's a Good scan wink.gif
Devil
for real??i guess u guys never used XRay!

U guys gotta try that one and then tell me that Xscan is good!I miss out alot of scans when using Xscan...cause the rechecker...called...roadrunner...or scomething like that doesnt find them ips that i find with Xray!!

Well...i hope someone still can help me out trying to make XRay a remote Scanner or something else like that!!!

Devil
Devil
oh yeah before i forget...realserver would also be a great thing if that could also be scanned...and that all i one programm
internetfury
where can i get that program xray i cant find it i have used all x-scan h-scan ntscan ipcscan so i wanna try xray to see if it is as good or better than ntscan.
ComSec
dont know what your search input was ..took me a few seconds to find

http://www.hackerzhell.co.uk/downloads/Por...p%20Scanner.exe

enjoy
Gravedigger
QUOTE (ComSec @ Dec 22 2003, 02:32 PM)
dont know what your search input was ..took me a few seconds to find

http://www.hackerzhell.co.uk/downloads/Por...p%20Scanner.exe

enjoy

THanx mate for the link.

Gona give it a go with it.

Hope it's good.
Devil
well i got that programm...even posted it in the forum somewhere.....what i wanted was a recompiled version from that...which could scan for wms,webdav and if possible to be a remotescanner which save its logs itself!!
i use XRay every day...its a good programm...just missing a couple of features if u know what i mean!!


Merchantp
if xray is the same xray thats on my HD im pretty sure it's not a remote scanner.
Fractured
I think its more of an IP Scanner rather than a Vulnerability Scanner.
x1`
http://home.hccnet.nl/m3ssi4h.rul3z/

fx scanner is very nice for scanning remote thats if u have permission rights
jimmy
maybe just do a portscan first on the requested service and than load that list in xray and scan at home smile.gif
Buluemoon
have used FX Scanner and really like it but does anyone know how to change the ports that are being scanned?
FakoLy
i use xscan but u need the plugins coz the vulnerabilies scaned bu default by xscan are ooold man
rush
Try scan1000.exe for remote scanning in console.
He can scan several things like:
CODE

Usage: scan1000 <Option> <Parameter>

<Option>:
-p                     <Port|Port-Port> <IP|IP-IP>   Scan port
-cgi                   <IP address>                  Scan cgi hole
-idq                   <Start IP> <End IP>           Scan .idq hole
-pri                   <Start IP> <End IP>           Scan .printer hole
-apache                <Start IP> <End IP>           Scan Apache 1.3.x
-apache2               <Start IP> <End IP>           Scan Apache 2.x
-apachechunked         <Start IP> <End IP>           Scan Apache Win32 Chunked
-uni                   <Start IP> <End IP>           Scan unicode hole
-webdav                <Start IP> <End IP>           Scan Webdav hole
-media                 <Start IP> <End IP>           Scan IIS Media Services
-codered               <Start IP> <End IP>           Scan codered virus host
-ftp                   <Start IP> <End IP>           [-admin]
-um                    <IP addr> [Web path] <Message> Modify web files


Example: scan1000 -webdav 192.168.0.1 192.168.0.255
!
aTahualPa
1000 threads is not really recommend on servers with low speed ~1mbit
i use scan500 or scan100 on server >1mbit


aTa


ph34r.gif

i'll test a sql brute force scanner, any suggestions huh.gif

killpart
i think scan500 is the best remotescanner but he new x-scan v5 is very good with the new samples wks or rpc.
i use scan500: wms, port
x-scan: sql, wks, rpcdcom
ipcscan: ntpw
Devil
i use Xray and its the best.....for real....dont have to recheck anything....u can start hacking what xray gives u!
All i was asking the whole time was,if its possible to recompile Xray that u Remote scan with it!!and maybe make it be able to scan wms and stuff like that!!
Allready used x-scan and Fx scanner i heard it aint that good...so i´m staying with XRay!!

Devil
capster
I have found IPCscan (for ntpass) to be the best. It's fast, and runs via command line. Xscan is cool if u can find a modded version.
Neo2k
I think ipcscan is the worst ntpass scanner lol, X-Ray is very nice but I love FX-Scanner for remote scan (not the 3.0 beta for iis lol)
polax
fxscann it's good scanneur for me wink.gif
x1`
so does fxp scanner have remote ntpass scanner , was it posted in the download section?
PSR
first of all i dont like xray . it's ashittyp orgram which u can reallyo nly use locally. now secondly i dont know but i never saw the source of xray flaiyng round. and even if and i say IF , dude u know how much work that is ? to recompile it to scan webdav , etc etc etc ? and 3. why program a new porg when u there r so many old ones flying round that work ? sure xscan may b old and lousy but if u use the correct settings it will ifnd any password u want . u just better leave it at the default settings. and other ones for fast check are also available , like sqlchk which goes through a 200 K file in 1 hour.
i do not want ot sound disrespectful to ur request man , it's just like inventing the wheel again imho but that is my personal opinion . btw dudes keep to the topic , he didnt ask for scanners he has a specific request .
Devil
@PSR

well....not really sure how hard it is to recompile a programm.....but u are right....i´m using other ones know to....i just thought that xray is so good....it would be super if it could do a couple more features....but not that important anymore!i use xscan like u said....put my own list in it and stuff....even tried scqnsql...but not that happy!!
Well this topic could be closed cause the most people was telling me what they like...and like PSR said...i was asking something else!!


thx anyway
Devil
taggon
I thing xscan it´s net so very well, because this tool it´s not everything finding. I like sfind, thats very good!!!



Sorry my english is not so good sad.gif
DrDoc
I think the fastest and easyiest Remote Scanner is scan500.exe. Fx-Scanner was a good scanner 4 IIS or FTP but 4 sql??

I thought i can only scan IIS or FTP with FXScanner.. :\ or im wrong?

My Tip to scan sql fast is, Port scan with scan500 and the result you can check very easy with x-scan.

Cya Doc

Sorry about my english i know i have to improve it.. biggrin.gif
yoplaboom
Hi
There are also a fxscanner for ipc, sql. The blue or green fx-scanner for exemple. But it's private version. So to fond us it's pretty difficult sad.gif
-Pennywise-
QUOTE
My Tip to scan sql fast is, Port scan with scan500 and the result you can check very easy with x-scan


how can i check ??? can you explain it ???
The Doom Master
QUOTE (-Pennywise- @ Jan 23 2004, 02:28 PM)
QUOTE
My Tip to scan sql fast is, Port scan with scan500 and the result you can check very easy with x-scan


how can i check ??? can you explain it ???

Download the X-Scan there is Readme.txt

there is the list of commands and their usage

pretty Easy for a Starter i think..
Christian
Hi
@killpart u can share the x-scan v5?

I cant find this scanner huh.gif
Knutinho
@ Christian

perhaps u try this page here :-)

GrEEtz

d00m
hey even nmap has support for remote scanning...

There's a project called "remote nmap" with a client-server model for port scanning.. i havent tried it out but anyway :

QUOTE

Remote Nmap (Rnmap) is a pair of client and server programs
which allow for various authorized clients to run their port scans
from a centralized server.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.