extreme
Jun 8 2004, 02:47 AM
In your opinion, what would be the best FTP brute force program.. I wish to crack Microsoft FTP that comes with every XP, and I wish to try one bruteforcgin one char at a time, because I don't believe in wordlist..
Any sugestion what tool should I use?
SCVirus
Jun 8 2004, 03:00 AM
thc hydra. Nice and fast, efficient command line and a nice gtk2 gui (if your into that kinda thing).
extreme
Jun 8 2004, 03:25 AM
It also reads passes from TXT file.. It doesn't brute every character...
EXPLOiTED
Jun 8 2004, 12:16 PM
WHat about Brutus, www.hoobie.net/brutus...........and umm...what you gona do about max failed login restrictions
extreme
Jun 8 2004, 01:59 PM
Yeah, I remembered Brutus in meanwhile, and offocurse got troble with max logins...
Now I don't know what to do.. I never penetraded anything by bruteforcing..
Box is running few services which can be Bruteforced...
FTP
Telnet
Webserver(when I try to browse a box via IE, it gives me User/Pass window, so I guess it should give full administrative access if I crack the pass)
...So what would you brute from all these services and with which tool?
andydis
Jun 8 2004, 03:05 PM
extreme,
as below,
letme know ifits 2 watuwant
SeNSeMaNN
Jun 8 2004, 06:10 PM
andydis, thx a lot but this doesnt work with ftp´s like serv-u or bulletproof ftp
extreme
Jun 9 2004, 07:35 AM
Yeah, good one. But for some reason, it won't work over Terminal Service... Or Symantec blocked it.. Don't know..
I just got error "Invalid Win32 Application".. Wierd...
What about Telnet hbruteforcing?? Any simmilar tool?Maybe it is even better to brute telnet login because it should have max tryes..
ComSec
Jun 10 2004, 05:42 PM
scan the server grab the banner... look for an exploit to match the product as for BF if an admin has any sense he will install antihammer and block all attempts after 3 failed login's also banning the offending IP's
extreme
Jun 10 2004, 06:25 PM
Yeah, comsec, I know. But I am talking about ordinary XP mashine which is behind router I think, but no firewalls, and never runned updates I think... Has only default services like Microsoft FTP, Telnet, and three ports open
4444, 1723, and 80(no website there and index.html is protected with pass), so no third party softwares for which I could get exploit..
Don't see any way in except bruting ports 21,23, or 80...
443 is not open so SSL bug is no go..
Guess I don't have to mention PRC either..
Oh, BTW, is Router able to block traffic from public RAT, but undetectable version(custom ports, IE injection to bypass firewalls etc.)? I mean, could it have some packet signatures or something and stop it that way?..
B1G
Jun 14 2004, 01:24 PM
i need something like Brutus, but for dos
Can you help me?
SeNSeMaNN
Jun 14 2004, 07:52 PM
is this uns12 a good scanner ? i think it has problems with servu and all pwd which have more than 3 places..
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.