hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

andydis
two questiosn if any body has any help or readme's?

1) i read somewhere that it is possible to get into a network via their proxy..
for example they have a proxy to connect to the outside world, so why couldnt you reverse that and from extrernal location use the proxy to maybe scan for iis servers/ webpages/ intranet on their networks?

for example my external ip: 212.19.80.50
proxy server: 212.19.80.1 (internal is 192.168.0.1)


IE settings are set to proxy via 212.19.80.1 with port

when opeing IE request maybe 192.168.0.1
???????????????????????????????????????????????
hope you got that ¿


2)same for defualt gateways.,

say the same server has routing and remote access installed, and im on a pc from inside the network with ip of 192.168.0.2 defualt gateway
is set to 192.168.0.1 and can access straight over the web with no proxy enabled (ill leave out DNS ).

is there a way to reverse so that if i was on my external ip i could add a second defualt gateway to get in?

now i know ehn i always connect to the net from anywhere i always have a default gateway set fro me by ISP and cannot be changed, and you cannot have 2 defualt gateways, but maybes thers a program or something that can use the gateway as a ip router to the internal network?

would i have to setup some route add commands on the server?

cheers

*oh by the way those ip's are purely theoritcal and i doont own them, just put in the first ones that came into my head..
FiNaLBeTa
Network device swith (3) :

u can use it to change you're networksettings verry fast.
you set the settings from youre ISP(proxysettings, network), and save them, then you set the other settings, and save them.
you can switch between them bye an icon in the taskbar.
andydis
but surely even if i change the default gateway very fast i cannot access 212.19.80.1 defualt gateway without having an ip of defualt gateway of my isp becuase there would be no path/route to 212 address?
FiNaLBeTa
i don't understand you anymore, but this is what we use when the pc is in multiple networks.
it works. (default dhpc server is saved two)
GSecur
OK the only thing you can do to an internal network if connected to open openproxy would be browse intranet webpages (I say this of course meaning you do not root the proxy it self)

Meaning you set you browser to use the open proxy. Now you mus guess the internal network scheme of the target network ie: 192.168 or 10.1, youo would then open your browser and simply type http://192.168.1.8

Now this request would be forwarded through the proxy and if the proxy was configured to handle internal request as well it would bringyou up a internal website if the system was actually a webserver.

Now of course this will not always work as many proxy servers are configured not to relay internal HTTP requests.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.