RE: penetration test in a Windows 2000/NT network

From: Matthew Wagenknecht (Matthew.Wagenknecht_at_quantum.com)
Date: 05/17/03

  • Next message: Michael Tsentsarevsky: "RE: HTTPS Web site testing"
    To: "'heron heron'" <h.heron@firemail.de>, pen-test@securityfocus.com
    Date: Sat, 17 May 2003 07:06:56 -0600
    
    

    LHFTools.com has two tools that may prove useful as well; winlhf and sqllhf.

    Winlhf is a windows account brute force tool. SQLLHF is a SQL account brute
    force tool.. They are rather fast and work well. They can look for the easy
    stuff - the "low hanging fruit" - while you are directing your attacks
    elsewhere..

    ..:: Matt ::..
     
    Bother!, said Pooh as his network froze..
    -----------
    varified gramaticly correckt using EverRight Spellchecher v1.0

    -----Original Message-----
    From: heron heron [mailto:h.heron@firemail.de]
    Sent: Wednesday, May 14, 2003 7:30 AM
    To: pen-test@securityfocus.com
    Subject: penetration test in a Windows 2000/NT network

    Hi,

    I will accomplish a penetration test in a Windows 2000/NT network shortly. A
    goal is to get confidential information (files) and if possible get admin
    rights. I will be with my computers in the LAN. A computer for normal uses
    (thus no Admin access) is likewise put to me at the disposal.

    Is there a possibility on a Windows 2000 computers (physical access is
    possible) to attain admin rights without to overwrite the admin account.
    Background: I would like try to crack the password of the local admin (e.g.
    by means of pwdump and John). There ist the possibility that all admin
    passwords (also for the
    domain) is alike.

    Is there a tool, with which I can crack NTLMv2 hashes. Background: I will
    try to sniff hashes during the registration at the DC (e.g. CAIN, ettercap)
    and to crack them. Unfortunately me is still no tool known in order to crack
    NTLMv2 hashes.

    A further possibility at to come to information, would be the employment of
    a SMB Proxy. By ARP Spoofing it would be nevertheless theoretically possible
    to intercept the LM/NTLM(v1/v2) authentication . Then the attacker could
    itself instead announce at the server. Does it give there already such a
    Tool?

    Who has suggestions? For Tools please give always in the Web URL (if
    possible of the programmer).

    Greeting
    Heron

    __________________________________________________________________
    Arcor-DSL Flatrate - jetzt kostenlos einsteigen und bis zu 76,18 Euro
    sparen! Arcor-DSL gibt es jetzt auch mit bis zu 1500 Mbit/s Downstream!
    http://www.angebot.arcor.net/cgi-bin/angebot.cgi?key=b13e92247022

    ---------------------------------------------------------------------------
    *** Wireless LAN Policies for Security & Management - NEW White Paper ***
    Just like wired networks, wireless LANs require network security policies
    that are enforced to protect WLANs from known vulnerabilities and threats.
    Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.

    To get your FREE white paper visit us at:
    http://www.securityfocus.com/AirDefense-pen-test
    ----------------------------------------------------------------------------


  • Next message: Michael Tsentsarevsky: "RE: HTTPS Web site testing"

    Relevant Pages

    • Windows,Linux, admin accounts, su,runas, and user switching
      ... I just recently started running as a non-admin on my windows 2000 pro ... which i hope is a nice compromise between security and convenience. ... "mini Admin shell". ... Better Management for Network Security ...
      (Security-Basics)
    • Network Path Not Found
      ... I have recently been hired to be the IT admin for a screwed up network ... comprising various Windows 2000 Pro, Windows XP Pro and Home machines. ...
      (microsoft.public.win2000.general)
    • Re: taking our health care back......
      ... cert Unix admin, but they're all over the Windows-based server world. ... that our Windows colleagues have when it comes to security-related ... the "network" no longer exists. ...
      (rec.sport.football.college)
    • Re: Network Path Not Found
      ... > I have recently been hired to be the IT admin for a screwed up network ... > comprising various Windows 2000 Pro, Windows XP Pro and Home machines. ... > network is based on Windows 2003 Standard Server with a domain which had ... > been upgraded from Windows 2000 Advanced Server. ...
      (microsoft.public.win2000.general)
    • Re: PID 1212 slowly maxing out?
      ... Windows 2003 servers, but could it affect Windows XP as well? ... I'm on a home network running on wireless. ... Logical Disk Manager service ...
      (microsoft.public.windowsxp.help_and_support)