Re: Scanning for blank admin passwords on a windows box

From: Anders Thulin (Anders.Thulin@kiconsulting.se)
Date: 07/15/02


Date: Mon, 15 Jul 2002 11:05:33 +0200
From: Anders Thulin <Anders.Thulin@kiconsulting.se>
To: Jason <cisspstudy@yahoo.com>


Jason wrote:

>
> I am looking for a fast multithreaded tool that can scan a range of IP
> addresses and look for blank administrator (or other user accounts)
> passwords on a windows NT/2000 server.

>
> If it can also try the username as password, server name as password that
> would also be nice.

   Take a look at the multithreaded beta of userinfo 1.9 at
http://www.clicknet.ch/chscene/chscene.php. It's not fully multithreaded,
though -- it only does it over 64-subnets. It's also in the SecurityFocus
tools list, but there is at least one other tool with the same name to
confuse you.

   Main problem is that it reports in web page format...

   There are several non-mt tools that does the same thing.

-- 
Anders Thulin   anders.thulin@kiconsulting.se   040-661 50 63	
Ki Consulting AB, Box 85, SE-201 20 Malmö, Sweden

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • Re: faster scans? (nmap)
    ... one host using nmap for syn scans in burst mode with the ... >>>This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: pen test help please asap
    ... > Machine A on client site makes a configurable encrypted OUTBOUND ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: ettercap help
    ... Anyways have never tried Ettercap for VNC. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: CFM SQL injection
    ... You should better use union or alike get unauthorized data from the ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: ettercap help
    ... > I can get it to sniff telnet, ftp, pop, smb, but no vnc. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)