RE: Pen-Testing Windows from Solaris

From: Ballowe, Charles (CBallowe_at_usg.com)
Date: 05/12/03

  • Next message: Aleksander P. Czarnowski: "RE: Pen-Testing Windows from Solaris"
    To: "'peter.king'" <peter.king@ziplip.com>, pen-test@securityfocus.com
    Date: Mon, 12 May 2003 13:08:32 -0500
    
    

    Interesting challenge - hope the customer doesn't claim security of
    their MS network based on the success or failure to compromise it
    from a Solaris box.

    Will you have root on the Sun? I suggest getting samba installed,
    mostly for the ability to browse shares etc. if you manage to find
    an unsecured share or a weak password. You may also want to search
    for tools to do NULL session enumeration against various boxen on
    the windows network. Of course, you'll want old favorites line nmap
    and a sniffer handy.

    Are you allowed to social engineer (via e-mail or otherwise) a set
    of tools onto their systems? There are keygrabbers or even BO that
    can be fairly easy to install if you can convince a user to double
    click a trojaned binary.

    What is the goal of the pen test? Every test should have a goal of
    some sort - whether it is take down services or gather sensitive
    information doesn't really matter, but there should be a goal.

    -Charlie

    > -----Original Message-----
    > From: peter.king [mailto:peter.king@ziplip.com]
    > Sent: Monday, May 12, 2003 10:10 AM
    > To: pen-test@securityfocus.com
    > Cc: peter.king@ziplip.com
    > Subject: Pen-Testing Windows from Solaris
    >
    >
    >
    >
    > Hi
    >
    > I have recently been given the task of Pen-Testing several
    > large Windows networks, running a variety of versions of windows.
    >
    > Unfortunatly the only platform I will have to conduct the
    > tests will be a Sparc Solaris 2.6 box. I will have command
    > line access only to this box.
    >
    > I envisage the main problems with the boxes to be poor
    > passwords, open shares, IIS, and MS SQL.
    >
    > Given these limits what command line tools would people
    > suggest as the best ones to use that will run under Solaris
    > 2.6? I have my own ideas for several of them but would
    > appreaciate any extra input.
    >
    > Cheers,
    >
    > Peter
    >
    > --------------------------------------------------------------
    > -------------
    > Did you know that you have VNC running on your network?
    > Your hacker does.
    > Plug your security holes.
    > Download a free 15-day trial of VAM:
    > http://www.securityfocus.com/StillSecure-pen-test
    > --------------------------------------------------------------
    > --------------
    >

    ---------------------------------------------------------------------------
    Did you know that you have VNC running on your network?
    Your hacker does.
    Plug your security holes.
    Download a free 15-day trial of VAM:
    http://www.securityfocus.com/StillSecure-pen-test
    ----------------------------------------------------------------------------


  • Next message: Aleksander P. Czarnowski: "RE: Pen-Testing Windows from Solaris"

    Relevant Pages

    • RE: Pen-Testing Windows from Solaris
      ... it works on Solaris 2.6. ... their MS network based on the success or failure to compromise it ... > Did you know that you have VNC running on your network? ... > Plug your security holes. ...
      (Pen-Test)
    • Re: Solaris 9 & rarp
      ... It was sloppy posting: ... NIC, or Solaris. ... just in the event I dorked up a network setting somewhere. ... Sun storage isn't so hot. ...
      (comp.unix.solaris)
    • Re: Networking With Windows
      ... Windows machines? ... It might be helpful to mention what sort of network you are asking ... Are there symptoms other than dropped database connections? ... You didn't mention what version of Solaris you are asking about! ...
      (comp.unix.solaris)
    • Re: Is lpr outdated, unsupported?, ie. lpr or lp?
      ... an lpr process hangs on our Solaris 8 system. ... not feeding the print jobs to a real print server. ... If the printer's network card decides ... the print job stays in the Solaris holding directory. ...
      (comp.unix.solaris)
    • Re: [very_newbie] internet problem
      ... during instalation i chose 'not networked' option and now i have absolutely no idea how to change it ... If you have an Ethernet port, plug a patch cord into it and connect the other end to your network (switch, hub, or the Ethernet port on your Solaris system. ... "Basic Administration" and "Advanced Administration" are the first two on the list and should be the first two you read. ...
      (comp.unix.solaris)