Forums: Explore A Lan From A Shell - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Explore A Lan From A Shell help needed

#1 User is offline   cartman 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 62
  • Joined: 16-August 03

Post icon  Posted 09 July 2004 - 05:27 PM

so, i've a shell on the ip xx.xx.xx.xx and i've the user/pass administrator

With the cmd "net view" I've this result

Server Name Remark

------------------------------------
\\PC1
\\PC2
\\PC3
\\PC4
....
The command completed successfully.

how can i obtain access to the other pc on the lan from my shell ?????


Thx for your help and sorry for my bad english ;)
0

#2 User is offline   ArEs 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 60
  • Joined: 16-December 03

Posted 09 July 2004 - 06:03 PM

first u xan try cracking the admin password...maybe all pcs have the same ...second of cause scan vor vulns on network ( enough threads atm discussing that)
0

#3 Guest_Metathron_*

  • Group: Guests

Posted 09 July 2004 - 11:03 PM

the easiest way , you should scan with scan1000 the port 445

then write a bat which will execute the old LSASS exploit without asking the administrator

and mostly you'll get some shells ;)

Meta
0

#4 User is offline   Milka 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 85
  • Joined: 10-August 03

Posted 10 July 2004 - 01:22 PM

or when you have domain pass try psexec :)

You can download it @ http://www.sysintern...iles/psexec.zip

easy using :)

for example:

psexec \\ip -u Administrator -p password cmd
0

#5 User is offline   tibbar 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 1,423
  • Joined: 14-October 03

Posted 10 July 2004 - 11:05 PM

several methods. 1) use pwdump to get that machines admin pwd hash, then bruteforce it and hope the other pcs use the same admin pwd --> psexec

2) install two shells on this pc, set one shell up to listen remotely on port xxx and then use the other shell to run lsass exploit on the other pc on the net. hopefully you will get a shell on the nc listener.

3) look for netbios shares on the other pcs, and hope for one that does not require authentication and has write access to c. then install a trojan in their startup folder and wait.

4) scan the other pcs, maybe they have a weak ftp pass etc.

5) if 1,2,3,4 fail, install a packet sniffer on this pc. then log all packets during the morning login time, and snatch the hashes that way (assuming its a network login), if not then hope to catch some hashes used to authenticate to the fileserver.
If you want to read more about my security research, visit Tibbar.org
0

#6 Guest_Metathron_*

  • Group: Guests

Posted 10 July 2004 - 11:35 PM

you neednt set up an other shell

you can send the shell to your home ... but exploiting must be done in the lan
0

#7 User is offline   tibbar 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 1,423
  • Joined: 14-October 03

Posted 11 July 2004 - 11:15 PM

that depends on the situation. on some firms, only one pc has full internet access, and the others are tunnelled on port 80. in this situation, to gain access to the rest of the lan, you must work from "remote remote" shells.
If you want to read more about my security research, visit Tibbar.org
0

#8 User is offline   globey 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 189
  • Joined: 25-March 04

Posted 12 July 2004 - 02:06 AM

i sugjust u try this:
install radmin on the pc u got access
then install lanscanner (find @ google) and scan the rang like that:
123.12.1.*
just the last numebrs.
then u see the comuter with the shring on the lan.
0

#9 User is offline   Stephen79 

  • Sergeant First Class
  • Icon
  • Group: Specialist
  • Posts: 349
  • Joined: 05-September 03

Posted 12 July 2004 - 02:51 AM

ipconfig /all :D

see the setup of the sytem and from there, you know the gateway (internet server), the IP Class, if they use a DNS server or static IPs, and as most places use a set IP scheme, you can easily find the rage for the servers, client pc's, printers and routers.

From there, just explore.
0

#10 User is offline   DougieShiney 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 23
  • Joined: 24-January 04

Posted 21 July 2004 - 06:11 PM

psexec.. .. normally good one to use or even netbios or radmin
0

#11 User is offline   crackie 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 103
  • Joined: 19-August 03

Posted 23 July 2004 - 06:13 PM

you can use every inet exploit even via lan . most of the boxes in big lans like edu or inet provider havnt secured lan intern :) they only block the hacking ports from out of lan
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting