Neo_
Jan 20 2004, 03:15 PM
Hi,
there are a lot of exploits to have a shell on a computer, but what are you doing when you hack all the computers around ?
I know pwdump4, and cain to crack the sam, and maybe find Admin access for all the others computers.
I think i can find an ipc on a computer in DMZ, and so, i could remotely scan others computer...
I think i can sniff, with a program, maybe? but how ?
Is there another way ?
Except test the same exploit on the range ?
Dinos
Jan 20 2004, 04:13 PM
Hack the first computer, take the sam db and brake the passwords.
If you are lucky or you managed with the first attempt to brake on a PDC (primary domain controller) you will find the administrator password.
Use a tool from that machine that enables you to use ipc connections to send and execute files. On top of my head fluxay scanner has this functionality.
Regards,
Dinos
GhostCow
Jan 20 2004, 09:49 PM
cool.
Neo2k
Jan 21 2004, 01:02 PM
nice post, i hope som1 had some infos about this
jak3c
Jan 21 2004, 08:50 PM
yes good information about this ! exellent !
dmg
Jan 21 2004, 09:00 PM
You have to get very lucky for this to work. Grab the Admin password of a PDC and psexec to the rest of the lan (net view might give you some hostnames, ping them to get te IP) Never found a LAN where this worked though.
mamep
Jan 21 2004, 10:40 PM
and usually some lazy admins have the same pass in labs

don't forget this..
and also u can use Ipcscan to search easy passwords
Trojan^kid
Jan 22 2004, 12:22 AM
what about lan worms spread the file to all pcs
any one have them ?
Krogoth
Jan 22 2004, 02:36 AM
i've used dameware and it shows if a box is a pdc. too bad my isp has blocked port 139 now. anyone has any idea if there is a dos tool to see if it can list client/server/pdc of that box.
nice topic Neo. i think you gotta have the domain admin rights to penetrate the lan.
tibbar
Jan 22 2004, 10:15 AM
your isp has blocked port 139...so what.
correct me if i am wrong, but you can use any outgoing port, and still connect to port 139 the other end.
zero-maitimax
Jan 22 2004, 10:26 AM
| QUOTE (Trojan^kid @ Jan 22 2004, 12:22 AM) |
what about lan worms spread the file to all pcs any one have them ? |
w32.chainsaw and a other program does it . it olso had a subseven engine in it..
but well it doens't work any more it's about 3years old..
well there was a worm could opasoft i think.. it search on local network... and install it selft and goes on the internet to update him zelf..
tolf
Jan 23 2004, 03:04 AM
you could also just exploit a workstation and grab the local admin account... Most corporate LAN's have the same local admin password for each machine for help desk support and so on..
Go forth young one..
billkennedy32
Jan 23 2004, 03:15 AM
ettercap my son
tolf
Jan 25 2004, 11:37 AM
ettercap with caution young padeowan... Ive done on an internal assignment pen test assignemnt and droped the whole gateway for 10 minutes.... but yes very effective..
Krogoth
Jan 25 2004, 02:49 PM
| QUOTE (tibbar @ Jan 22 2004, 10:15 AM) |
your isp has blocked port 139...so what.
correct me if i am wrong, but you can use any outgoing port, and still connect to port 139 the other end. |
i'm not sure how to use any outgoing port. do you think you can give an example?
hdlgp
Jan 25 2004, 02:51 PM
Try to use Dameware tool for hack the computers lan, is the best.
esorone
Jan 25 2004, 08:04 PM
Just scan the internal Lan on open ports. Then use appropiate hackmethod for that kind of port.
flashb4ck
Jan 26 2004, 02:08 PM
the best proggi 4 lans is LANGUARD NETWORK scanner

it'll show ya all the most bugs in a system and dcom works great on privat networks or wlan ;D
Neo_
Jan 26 2004, 09:10 PM
| QUOTE (flashb4ck @ Jan 26 2004, 02:08 PM) |
the best proggi 4 lans is LANGUARD NETWORK scanner 
it'll show ya all the most bugs in a system and dcom works great on privat networks or wlan ;D |
dcom ? it works better on lan ?
Bombers
Jan 26 2004, 10:47 PM
Lan hacking is great, it's allso old hack way

i hacked a few networks,
here is a few tips for this kind of hacking!
so you crack the administrator password ?
first scan the range for open 139, 445,3389,6129
139,145 -->ipc hacking...
3389 --->remote desktop connetion(i love this way)
6129 ----->this means that there is ranning dameware server...
there is allso telnet hacking , but i don't know how to use it

if you know any more ways post it
-=@cIdBuRn=-
Feb 4 2004, 04:36 PM
and how can i started a deamon (servu) ???
but i canīt connecting to 192.168.0.2 *g*
How can i connecting to a Lan Computer (192.168.0.2) with a running Serv-U

??
emailpack
Feb 29 2004, 11:49 PM
It isn't easy but it is farely from good.
Guys stop reading stupid fake ass server scripts wasting your time on some stupid idiot servers instead (filtered) your own bios chip and get it fixed thats true hacking your own goddamn (filtered) SERVER. NOBODY HACKS YOU BACK UNLESS A SATELITE IS SPOTTING YOU ON TOP OF YOUR HOUSE.
laughable? no ISP's are ready 2 blast the big spy shit on your network neighbourhood;) fbi has launched the potential of a new program ...
cyber terrorists won't be easy 2 controll but hackers will be easy 2 hold down.
What the problem will be is this:
if you won't learn 2 program stuff you won't be able 2 do the hackin within 10 years. You need 2 take the (filtered) step on the (filtered) programming language take the first next step XML and stop wasting your time doing nonsense i know it you know it just do it and you will thanks me, visit china maybe peepz could help you.
adios/.
Trojan^kid
Mar 1 2004, 12:08 AM
Hmmm
192.168.0.2
first thing is send aserver of
assasin2
or NRAT
or Beast 2.06
then u can connect to the pc

Cheers
xzibit
Mar 1 2004, 02:49 AM
| QUOTE (-=@cIdBuRn=- @ Feb 4 2004, 04:36 PM) |
and how can i started a deamon (servu) ???
but i canīt connecting to 192.168.0.2 *g*
How can i connecting to a Lan Computer (192.168.0.2) with a running Serv-U ?? |
ur pretty much screwed. The only way u can connect to them is if they connect to u. Like a reverse/connectback shell or whatever u call it. Or somehow u could get into the router config and set the host in the DMZ. This way the router is not spoofing there IP or blocking u from connecting
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.