Non-GUI intrusion

From: KK Mookhey (kkmookhey@yahoo.com)
Date: 09/25/01


Message-ID: <000901c14583$de186ea0$0200a8c0@vsnl.net.in>
From: "KK Mookhey" <kkmookhey@yahoo.com>
To: <pen-test@securityfocus.com>
Subject: Non-GUI intrusion
Date: Tue, 25 Sep 2001 11:05:19 +0530

Hi All,
This is the scenario. We are conducting a pen-test with the capture-flag as the source-code files of the client ( a s/w firm).
We have managed to penetrate most of their servers in the DMZ (all Win NT/2K).
Using pwdump and L0phtcrack, we have the username/password of over 20 users in the admin group (this is a very large company).
These same users have admin rights on the intranet machines too.
We have a GUI remote control over the servers.
We also know that they have a Blue Team (or is it White Team) which is monitoring logs/traffic and our activities, to demonstrate to
their bosses that they could detect an attack like ours.
We need to get to the inside machines, since thats where the source code is. We could do it using the Net Neighb icon on the NT/2k
machines thru the GUI we already have, using the password we have cracked. But that would be like a bull in a china shop.
We already have remote command prompt access on the DMZ machines. We need to be able to query shares (enum?), and get source files
from the inside, without raising any alarms.
So,
What we need is a command line utility, or a GUI utility which does not raise red flags at their ends.
Anyone any ideas?
Sorry for the slightly long mail.
TIA,
KKM


_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • RE: Non-GUI intrusion
    ... nbtdump.exe, winfo.exe, or enum.exe on to one of the machines you ... At that point upload your access tool to the internal machine. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: Modem detection in a LAN
    ... probably be modified to check *nix machines. ... This script checks remote NT machines for the existence of a modem driver. ... This list is provided by the SecurityFocus Security ...
    (Pen-Test)
  • Re: Non-GUI intrusion
    ... This query was on a pen-test we had to conduct where we had access to the DMZ ... but needed to go really under the radar to get to the machines in the intranet. ... our objective of capturing the source code files, ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Non-GUI intrusion
    ... We need to get to the inside machines, since thats where the source code is. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)