axora
Feb 13 2004, 01:59 PM
Anybody in here who could give me some information about "terminal hacking windows systems" on port 3389 on a lan?
PL3X59
Feb 13 2004, 02:23 PM
try a null session to get the pass ...
try to scan it with any nt password scanner ...
ipcscan
ntscan ...
or
Tscrack ...
there is some topics which speaking of the teminal exploits ...
like enables them for exemple ...
pleX
s54
Feb 13 2004, 06:17 PM
| QUOTE (PL3X59 @ Feb 13 2004, 02:23 PM) |
try a null session to get the pass ... |
He asked for port 3389 attacks

- anyways the "TSCrack" part of your reply is right
demesmaeker
Feb 13 2004, 11:33 PM
the other answers are okay too..because if you find an adminaccount with ipcscan or ntscan, you can also log in at the terminal server with that account :->
boshcash
Feb 14 2004, 03:41 AM
note that u cant log in with an account with null password
Zekk
Feb 14 2004, 04:46 AM
tscrack is your best bet
boshcash
Feb 14 2004, 05:27 AM
i dont think Remote Desktop has any exploit till now , maybe after the leak of the source code , something appears
s54
Feb 14 2004, 10:47 AM
| QUOTE (demesmaeker @ Feb 13 2004, 11:33 PM) |
| the other answers are okay too..because if you find an adminaccount with ipcscan or ntscan, you can also log in at the terminal server with that account :-> |
Wrong. It was specifically asked for a port 3389 based attack. Anyway, good try
muts
Feb 16 2004, 04:11 PM
ay) TSgrind and Tscrack are your best bets. Personally i have had little luck with bruteforcing RDP, especially with no prior information od usernames (By SMB enumeration for example).
be) Account restriction on null passwords are usually set on Windows XP (not sure bout 2003, but it makes sense). XP supports only one terminal session, which forces the active user to lock out - so it's not that great.
LittleHacker
Feb 24 2004, 08:40 AM
How about using HyperTerminal?
I mean using a Telephone Number istead of IP !
PL3X59
Feb 24 2004, 10:11 AM
s54
TS are on NT system ...
maybe null session is possible.
but TSCRACK is not very fast ...
you can also try nt scan with 3389port :-p
boshcash,
null password is possible on 2K servers
like administrator / [/null]
Terminal services ....... So goodd
lol
french PL3X ;-)
s54
Feb 24 2004, 10:56 AM
Don't try correcting me when I ain't wrong. He asked for a solution based on port 3389. Null session ain't the way then.
PL3X59
Feb 24 2004, 11:14 AM
:-p
I don't want to correct u
i just say that it is possible like this
peace :-p
starwilli
Feb 24 2004, 06:55 PM
tscrack is your best
Leonnetje
Feb 24 2004, 07:20 PM
| QUOTE (starwilli @ Feb 24 2004, 06:55 PM) |
| tscrack is your best |
It can be the best, but it's awefully slow !!!
cenobite
Feb 24 2004, 08:56 PM
bruteforcing the shit takes a load of time + you need a big dictionary..
i suggest you scan for open ports, and try to get a shell..
then use the net.exe to add an account
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.