Re: W2K Terminal Services pwd cracker

From: Victor A. Rodriguez (Bit-Man) (victor@bit-man.com.ar)
Date: 11/27/01


Message-Id: <200111271903.fARJ3ed01257@macky.cvcti.com.ar>
To: pen-test@securityfocus.org
From: "Victor A. Rodriguez (Bit-Man)" <victor@bit-man.com.ar>
Subject: Re: W2K Terminal Services pwd cracker
Date: Tue, 27 Nov 2001 17:03:43 -0200

Hi david,

The following message was sent by David Smith <dzs999@yahoo.com> on Tue, 27 Nov 2001 04:30:39 -0800 (PST).

> Does anyone know of a password cracker for Win2K
> terminal services? During a pentest I've found port
> 3389/tcp open on the client's web server, and can get
> access to a login prompt.

The login/passwords are the NT ones, that are needed to access it.First you need to obtain the SAM for this machine and try to obtain
the passwords using L0pthCrack.

Cheers

--
Victor A. Rodriguez (http://www.bit-man.com.ar)
El bit Fantasma (Bit-Man)
"aMail: a lot of fun in a bunch of Perl scripts"

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • W2K Terminal Services pwd cracker
    ... W2K Terminal Services pwd cracker ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: MS Terminal Services open to the world
    ... but facts, facts, and more facts would be my choice. ... You may find the terminal services [with version control, ... not to have servers / services / clients exposed ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Secure / Encrypt Terminal Services
    ... There was a pretty decent paper on securityfocus about 2 months ago ... encryption, and I believe zebedee to work fine for terminal services. ... (gotta love security made insecure by politics) ...
    (Focus-Microsoft)
  • Re: Terminal Services Holes
    ... TCP/IP addresses of terminal services connections (even before the ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)